When the camera never sees it: The rise of injection-based fraud

For banks and other institutions, identity verification systems are the first line of defense against fraud. Troublingly, there’s a new and sophisticated threat that is able to circumvent them entirely. With injection attack fraud, a fraudster doesn’t try to trick your cameras or AI. Instead, they are bypassing biometric systems altogether and injecting forged biometric data directly into your verification pipeline – while your system remains confident it’s processing legitimate footage.

This is an architectural vulnerability that requires anyone managing fraud risk to consider a new defensive strategy, one that extends past camera-level defenses and even beyond advanced liveness detection tactics.

What is an injection attack?

In identity verification, an injection attack is the direct insertion of fraudulent biometric content into the verification pipeline – bypassing the use of the camera or sensor. The attacker doesn’t present a photo, video, or prosthetic to the camera like they might do in a presentation attack. Instead, they manipulate the data stream itself.

For example, this could happen when virtual camera drivers that are installed on a jailbroken or compromised device intercept video streams before they reach your verification layer. Your application will receive what appears to be live camera data that was captured, but instead, it’s actually a pre-recorded video. The video might be synthetic, AI generated content, or it could even be real video or photos of the target, acquired from social media or via a data breach. In another method, a USB hardware device might emulate a camera, but actually contain video it can inject directly. With these approaches, your system’s camera detection can pass and your liveness checks can trigger, but the underlying data is forged. These types of API and middleware manipulation target the transmission layer, rather than capture or analysis. They intercept the request for biometric data and deliver their synthetic payload to your comparison engine.

With injection attacks in identity verification, your verification system never interacts with a genuine physical camera. The data it receives from the biometric injection attack will appear to be from a legitimate capture device, but the entire interaction is dictated by compromised software or hardware.

Injection attacks vs presentation attacks vs deepfakes

To appropriately defend against injection attacks, they must be separate from other attack vectors like presentation attacks and deepfakes.

Presentation attacks

A presentation attack occurs at the point of capture. In a presentation attack, a fraudster might use a variety of physical materials, like a printed photo, a replayed video, a mask, or prosthetics. These are presented in front of a camera. They can be stopped by modern liveness detection tools, which analyze micro-expressions, eye-tracking, or other passive movement to detect the physical spoof. As liveness technology continues to mature, these attacks are declining in their effectiveness.

Deepfake attacks

In a deepfake attack, fraudsters use synthetic media they’ve created with generative AI. Where presentation attacks replay old but real footage, deepfakes use face-swap techniques or fully generative models to create content that depicts the target individual. At the capture stage, this deepfake content is presented to the camera. Passive liveness detection uses digital artifacts and anomalies to identify that the content is not genuine but is AI generated. For known deepfake generation engines, detection accuracy has reached 99.9%.

Injection attacks

An injection attack instead bypasses the capture stage and thus also bypasses its checks for signs of physical spoofing and generative artifacts. Unlike manipulation at capture, instead, the fraudster manipulates the data pipeline, and inserts their pre-recorded content directly into the input stream. This allows the attack to bypass a system that may be well-optimized for defense at one point, taking advantage of how it is totally blind at the other.

How do injection attacks bypass biometric systems?

Injection attacks exploit an assumption built into most biometric systems – the assumption that the data that comes from the camera layer is trustworthy.

The injection attack, however, never interacts with the actual capture device or the camera layer. The compromise that allows it to happen has occurred at the operating system level through virtual cameras, the hardware interface level through USB camera emulators, or the application middleware level through interception of API calls. Through this, the biometric system receives data that can pass all standard validation checks, via spoofed camera device identifiers and video metadata and the use of appropriate frame rates and compression.

It’s a significant issue on devices that have been jailbroken or have enterprise management, as these are mechanisms that allow attackers to obtain elevated access. But, it’s also enabled by compromised APIs, man-in-the-middle (MITM) attacks and corrupted mobile SDKs.

Why are injection attacks increasing?

By the end of 2025, injection attacks were at nearly 200% of the volume of deepfake attack attempts. This method of bypassing biometric systems, which requires purpose-built detection capabilities, has become the fastest-growing type of fraud.

Fraud tools and techniques have also been, in many ways, democratized by AI and the wide reach of social media networks. Generative AI has made it faster and easier than ever before to create convincing deepfakes without specialized expertise, and fraud-as-a-service operators make virtual camera drivers and USB hardware devices easy to obtain using social apps. This has made it easy for bad actors to experiment with multiple fraud vectors at once, by reducing the level of effort needed to make attempts of any type.

The age of most identity verification systems also makes injection attacks a known blind spot that attackers can exploit. Systems that were architected before injection attacks became a recognized threat are structurally blind to this type of pipeline manipulation, even if they’re optimized to protect against presentation attacks and have been subsequently equipped to detect deepfakes at the camera layer.

Deloitte predicts that the losses to generative AI fraud could surge from $12.3 billion in 2023 to $40 billion by 2027. The attack surface continues to expand as synthetic media and pipeline manipulation techniques proliferate.

Why existing tools don’t catch injection attacks

While most organizations don’t lack fraud defenses, they do lack the ability to address this specific problem. Most widely deployed tools were designed to address the problem at a different layer. Injection attacks slip through a category gap.

Device intelligence and fingerprinting tools are designed to detect device-level anomalies. These might catch a suspicious IP, an emulator signature, or a device tied to previous fraud attempts. While these tools are valuable, they only address the device and session, not the media stream traveling through it. An injection attack can originate from a device that looks entirely clean while the video itself is forged.

Identity verification and identity-graph platforms, meanwhile, rely on document analysis and biometric matching for confirming that a face matches a document and that an identity is real. But their logic makes an assumption that the media input is authentic. When the input stream itself has been replaced with injected content, the match can still succeed against fraudulent data.

The common thread is that these tools operate at or above the identity layer, while injection attacks operate below it, at the media capture layer, where live footage is assumed rather than verified. Closing the gap created by this assumption requires controls that are purpose-built to confirm that the media itself was genuinely captured, rather than inserted.

Why this demands a new defensive approach

When an attack can bypass the camera entirely, it renders camera-level defenses, no matter how advanced and otherwise necessary, insufficient for protecting your institution on their own against injection attack fraud. Injection attacks are three times more likely to be flagged by injection-specific defenses than systems that don’t have specific, layered protection.

To be effective, biometric injection attack defenses must operate at three levels simultaneously. At the capture level, it must analyze presented content itself for any signs of synthetic generation or pre-recording, including the use of passive liveness detection to examine videos for AI artifacts or other anomalies that indicate synthetic origins. At the transit level, it must monitor the transmission channel for data integrity, using encrypted end-to-end verification, secure enclaves, and cryptographic verification of data sources. This allows it to detect if content has been modified or intercepted in transit. And at the comparison level, behavioral and biometric pipeline anomaly detection is needed to cross-reference identity verification attempts against everything from known fraud patterns to device and network properties to a user’s historical baseline, if available.

If an organization is reliant on only one or two layers, that organization will miss some injection attacks, even if they perform very well against the ones that target those specific layers. The future of identity verification defense is layered, architectural, and multi-vector.

How Mitek’s Digital Fraud Defender detects injection attacks

Mitek’s Digital Fraud Defender (DFD) was built specifically to close the media-layer gap left open by other fraud detection tools. Instead of assuming the camera feed is trustworthy, DFD treats the media stream as something that also must be verified, using several complementary signals that work together in real time.

Virtual camera detection

Most injection attacks rely on a virtual camera. This is a software driver that poses as a physical camera, but feeds pre-recorded or synthetic video instead. DFD identifies the fingerprints of these synthetic video sources to distinguish whether the device detected is a genuine hardware capture device or an emulated one before the forged stream is ever trusted.

Duplicated frame analysis

Injected media often betrays itself by duplicating frames. The fraudster may have limited original video or stills of their target to work with, or may have only been able to generate a short clip of a synthetic person. When a looped clip or a single still is replayed as “live” video, this produces detectable repetition and timing patterns that would not be seen in a genuine capture. By analyzing video frames for duplication and replay signatures, DFD spots these looped and recycled injection streams that pass a surface-level liveness check.

Injection stream identification

DFD additionally looks for the type of real-time signals that make it possible to separate live capture from injected media. These include inconsistencies in how the stream is delivered, metadata that doesn’t match a genuine capture device, and integrity anomalies that are introduced when content is inserted into the pipeline. Together, these signals enable the system to flag an injection attempt, even when the underlying footage is otherwise a convincing image of the real person.

These controls are purpose-built to operate independent of liveness results. Because attackers are keenly aware that many systems relax their controls once a liveness check has been passed, DFD continues applying injection-specific scrutiny through to the comparison stage so scrutiny is maintained at every layer. This means a single bypass isn’t able to defeat the entire system.

What this looks like in practice: Benchmark results

Digital Fraud Defender has demonstrated 99.9% detection accuracy in testing against known injection vectors while still maintaining a high pass rate for legitimate users, effectively stopping fraud without adding friction for your real customers.

For a fraud team, that accuracy translates directly into avoided losses. Injection attacks now outpace deepfake attempts, and generative-AI fraud losses are projected to reach $40 billion by 2027. The difference between detecting and missing this attack class shows clear value when measured in prevented account takeovers and protected high-value transactions. By catching the vectors that other layers allow to pass through, injection-specific detection quickly demonstrates its return.

Close the injection attack gap

The gap injection attacks exploit is the moment a forged media stream is trusted as a live capture. When this gap exists, every downstream identity check can effectively be defeated. Mitek’s Digital Fraud Defender closes that gap at the media layer, detecting virtual cameras, replayed frames, and injected streams, stopping fraudsters in their tracks. See how it works on the Digital Fraud Defender product page. (or other CTA)

How well does your identity architecture stand up to today’s injection attack methods?

Download the Layered Defense Report to explore how injection attacks are reshaping identity verification and learn how a layered approach can help expose vulnerabilities and strengthen your fraud defenses.

Download the report

Frequently asked questions

What is an injection attack in identity verification?

An injection attack directly inserts fraudulent biometric data into a verification pipeline, bypassing the camera layer entirely. Biometric injection attacks can use virtual camera drivers, USB hardware devices that emulate cameras, API manipulation and other means to insert pre-recorded or synthetic video. This video is then processed as legitimate camera input.

How does injection attack detection work?

Injection attack detection verifies that the media reaching a system was genuinely captured by a real device, not inserted into the pipeline. Injection attack detection is designed to identify virtual cameras as well as emulated video sources. It analyzes frames for duplication and replay patterns, and inspects stream integrity and metadata in real time. These checks target the media layer rather than the identity match, making them capable of detecting forged input that otherwise passes document and biometric verification.

How is injection attack detection different from liveness detection?

Liveness detection confirms that a real person is present in front of the camera at the moment of capture. Injection attack detection layers additional protection onto liveness detection to confirm that the media stream itself is authentic, and was not replaced or manipulated on its way to the system. An injection attack never interacts with the camera, so it can defeat liveness detection entirely, which is why injection-specific controls must operate independently of liveness results.

How do injection attacks bypass liveness detection?

Because they never actually interact with the camera, they completely bypass liveness detection. The system assumes the content came from the live camera. But since it’s been injected, it won’t have some of the physical imperfections like a moire pattern from a screen or a low-res texture that liveness detection looks for. It could be injected content of the real person, or synthetic content designed to move in the way that a liveness check inspects for.

Are injection attacks more dangerous than deepfakes?

Both are dangerous threats, and complement one another, requiring a layered defense to protect against each. Deepfakes involve manipulated content created with generative AI and presented at the capture stage, while injection attacks manipulate the data pipeline itself. A system that’s optimized for one might miss the other, so an effective defense must use detection strategies that address both simultaneously.

Which vendors protect against injection attacks?

Because most device-intelligence and identity-verification tools were designed to only inspect the device or the identity, rather than providing additional scrutiny for the media stream itself, they don’t address injection attacks directly. This is a category gap rather than a single vendor’s flaw. Mitek’s Digital Fraud Defender is purpose-built for this layer, designed to be capable of detecting virtual cameras as well as replayed still or video frames and injected streams that other tools will assume to be genuine once the user has passed the checks required to reach that layer.

What industries are most targeted by injection attacks?

Financial institutions and cryptocurrency trading platforms see the highest rates of injection attacks because of the high value of account takeovers on these platforms. Similarly, fintechs, as well as online gaming platforms are also popular targets that must perform high-volume identity verification and have high-value fraud incentives.