A Deepfake Blinked for Barely a Second. That Was Enough | AI-Proof

Опубликовано: 22 Сентябрь 2026
на канале: InfallibleSecurity
158
1

The machines are learning. So should you.

Every time you open a bank account online, you run the same gauntlet: photograph your ID, take a selfie, turn your head for the camera. That process is called KYC, short for Know Your Customer, the legally required check that you are who you say you are. This episode is about the people beating it. A suspect in Spain who faked ID holograms with household spotlights and a real-time face swap, and was only exposed when the deepfake glitched. A tool called ProKYC, sold to criminals specifically to bypass these checks. And a red-team demo where the phone's camera was never used at all: a synthetic video stream went straight into the app, and the liveness check passed it.

Voice stopped being proof in #004. Faces fell in #005. This is the batch closer: the verification systems themselves, why a live selfie is now one weak signal instead of strong proof, and the boring, layered moves that still hold.

No jargon left undecoded. No fear, just preparation.

In this episode
KYC in plain language: the four-step check standing between a stranger and an account in your name
The Spain case: 38 attempts to impersonate 30 people, a lighting rig for the holograms, and the split-second blink that broke it
ProKYC, the deepfake tool sold as a KYC-bypass product (per MITRE ATLAS)
The virtual-camera trick: passing a "live selfie" check with no camera at all
Why the piles of ID photos and selfies these systems collect are themselves the risk (including one reported leak the company disputes)
The three moves that protect you, and the layered-signals rule for anyone building these systems

Chapters
00:00 The Face That Was Never There
01:33 What KYC Actually Checks
02:30 The Arrests in Spain
03:21 The Injection Path
03:56 The Rig: Lights, Camera, No Person
04:31 The Frame That Glitched
05:39 Sold as a Product
06:26 The Red Team That Walked Through
06:42 The Virtual Camera
07:40 When the Document Is Generated Too
08:22 The Data That Was Already Out
09:22 Your Selfie Is Not a Password
09:56 The Checklist
11:00 Layers, Not One Wall
12:15 Three Proofs, All Expired

Reference Desk (every claim traces to a source)
The Register, "Deepfake hiccup unmasks suspected digital certificate fraudster" (Connor Jones, Aug 11 2026), incl. the Spanish National Police statement (machine translated)
Help Net Security on the same case and how the investigation opened (Aug 12 2026)
MITRE ATLAS case study AML.CS0034: ProKYC (research by Cato CTRL, reported late 2024)
MITRE ATLAS / iProov Red Team liveness-injection case study (published Dec 2025)
Biometric Update (Apr 17 2026), reporting on MIT Technology Review's investigation (Apr 15 2026) of 22 public Telegram channels selling KYC-bypass tools
zyphe.com (Mar 1 2026) on the reported IDMerit exposure; Biometric Update (Feb 20 2026) on IDMerit's dispute of that report

New here? AI-Proof breaks down one AI security threat per episode, in plain language, so you can prepare for it. This one closes a three-part arc: start at #004 (voice cloning) and #005 (deepfake video calls), or jump in cold, it stands alone.

Stay human. Stay ready.

#Deepfake #KYC #IdentityVerification #AISecurity #CyberSecurity #Biometrics