Designing for injection: What fraud systems must do now

Injection attacks now represent one of the most dangerous threats to financial institutions, but many organizations continue to operate their fraud defenses as if injection isn’t a critical vulnerability. By the end of 2025, injection attacks increased 200% relative to deepfakes – and they’re three times more likely to require specialized detection tools to catch.

Organizations evaluating how to prevent injection attacks should note that in a recent study, 70% of advanced fraud cases, like injection attacks, required an additional screening layer that goes beyond traditional protections for biometric capture. Injection attacks will, inevitably, target your organization. Your fraud defense architecture must be specifically equipped to stop them.

The injection problem: Why traditional defenses fail

Most fraud systems were built on the simple premise that a person must be verified to be real and present at the point of capture. They use liveness detection and facial recognition plus document analysis to confirm what’s happening in front of the camera.

That’s excellent for stopping presentation attacks. But as an injection attack defense strategy, this approach is incomplete.  Injection attacks don’t occur at capture, and instead, attack the pathway used by the data to travel to your system. This attack might happen anywhere in the process: the camera or hardware device drivers, application code, browser environment, or during network transmission. And the injected content might be a single static photo replayed as video frames, a previously recorded video of a real person, or an AI-generated, realistically-moving deepfake. If injection is successful, the system will accept the falsified data as a match, because all of the checks at the camera layer were bypassed. Thus, point solutions focused only on capture-level defenses will miss these types of attacks entirely, versus a layered injection attack defense strategy.

Why layered defense architecture matters

To mount an effective defense against fraud, an architectural approach to defense is required. This defense should focus on three critical zones of layered fraud detection architecture:

Capture-level defense

Many organizations have focused heavily on and invested significantly in capture-level defense. Passive liveness checks, AI-powered document verification, and facial recognition are essential for stopping presentation attacks. Alone, though, they leave systems open to other types of attacks. Capture-level defenses can confirm “is the person or document in front of the camera real and present right now?” They cannot confirm if the data the system is receiving is truly what was captured.

Transit-level defense

This is where injection attacks happen, and where many organizations need additional reinforcement in securing biometric onboarding workflows. As biometric data moves through your infrastructure, from the user’s device to your system and comparison engines, attackers have multiple opportunities attempt to intercept and manipulate it. Transit-level controls are used to verify data integrity, detect channel manipulation, monitor for any anomalies on how data is flowing through your system, and identify if authentication streams were interfered with by an outside party. Without transit-level monitoring, your system can’t tell if the enrollment data submitted is actually the enrollment data it received.

Comparison-level defense

Even when the capture level and transit level are secured, the comparison engine can provide an additional layer of protection against injection attacks – like detection of known fraud profiles and behavioral anomalies that are specific to injection campaigns. The comparison layer asks “Does this biometric data match the authorized user’s existing data, and seem consistent with legitimate use?”

Real-world impact: The wave-based campaign

In a recent, coordinated injection attack, more than 3,000 injection attempts were made in waves as part of a targeted phishing campaign. The attack was identified through multi-layered fraud detection architecture.

Attackers organized bursts of over 600 injection attempts in each wave, timing them strategically and attacking different parts of the pipeline. Some targeted capture verification, and others targeted pipeline manipulation. The level of sophistication of the campaign made it clear that the attackers had an idea of where institutions’ defenses are typically the weakest.

A system that relied solely on liveness detection and document verification may have flagged the attempts that targeted the capture layer. But detecting the campaign pattern and coordinated waves of attacks on the pipeline required comparison-layer profiling and transit-level monitoring. 

Fortunately, this institution had planned ahead to protect every layer of its system with architectural decisions made at the time of design.

The point solution problem: Creating blind spots

To reinforce the importance of strategically architecting your defenses to protect every layer and create an effective injection attack defense strategy, consider the limitations of a system that was assembled by cobbling together pieces of fraud defenses from multiple vendors. Perhaps the system had protections for liveness, document verification, biometric matching, and behavioral analytics all added on at different times from different vendors and little integration. This approach creates blind spots.

When vendors don’t share info about anomalies detected at capture, transit detection can’t correlate that info with channel manipulation. When comparison engines are operating independently, they can’t leverage any patterns detected during authentication. And when liveness checks don’t communicate with transit monitoring, injected data appears legit.

The figure we cited earlier, where 70% of advanced fraud cases required an additional screening layer to detect, reflects exactly what we’re discussing here. Organizations might add security layers one at a time only to discover after a breach that the layers weren’t talking to each other. A layered defense architecture requires not just protection at each layer, but the ability for each layer to communicate the information needed to support integrated analysis across all three zones.

What to ask vendors: The decision framework

As part of the evaluation process for fraud detection systems capable of injection attack prevention in banking and for other types of institutions, demand clarity on these three specific questions that assess the capabilities necessary for injection attack prevention and securing biometric onboarding workflows.

Do you detect capture integrity anomalies?

Ensure that the solution can specifically identify virtual cameras and emulators that attempt to spoof liveness. Passive liveness implementations should correlate multiple signals, not rely on single-point checks. Content analysis should flag document template anomalies as well as injection-specific document fraud. Often, injection attacks will succeed because they appeared to pass capture checks. Your system needs visibility into why a capture passed, not just confirmation that it did.

Can you detect transit manipulation?

This is the zone where many organizations are the weakest today. Detecting transit manipulation requires monitoring the integrity of your data stream, and the ability to identify interruptions, replayed data, or modified authentication flows, as well as channel integrity verification that can detect third-party plugins, proxy interference, or emulator environments. Look for the ability to detect data state changes between capture and comparison and conduct behavioral analysis of the submission itself in real-time.

Are injection-specific controls independent of liveness?

Attackers know that once they’re past liveness detection, many systems drop their guard. Look for a system that still applies injection-specific controls to the comparison layer. You need known fraud profile matching that can operate independent of liveness results, template attack detection that checks for fraudulent documents even if they passed document verification, and behavioral anomaly detection that looks for replay attacks and account takeover patterns. The use of multiple, AI-powered checks purpose-built for identity verification ensures no single bypass suffices.

The injection reality for fraud leaders

Fraud defense architecture must defend at all levels rather than relying on point solutions. Multi-layered detection systems have demonstrated 99.9% injection detection accuracy, while maintaining a 99% pass rate during biometric verification for legitimate users.

Systems must integrate signals across all layers, so anomalies detected in one later can inform analysis in the others. And adversarial testing that uses a Purple Team approach – collaborative, cross-functional approaches that combine offensive Red Team tactics with defensive Blue Team strategies – should be used to validate your defenses.

The approach must be comprehensive and requires a vendor that demonstrates architectural commitment to layered defense. Point solutions result in blind spots and high latency, and are weaker than a unified defense.

Are you ready to evaluate how your current architecture stacks up against injection attack vectors

Download the Layered Defense Report for a comprehensive analysis of the ways injection attacks are impacting identity verification or request a fraud strategy discussion to map your current defenses against real-world injection threats.

Get the report