In the last month, we've heard from three separate clients or contacts who fell victim to Identity verification (IDV) fraud. Some cases were highly sophisticated: real-time "injection attacks" that fed synthetic video straight into a live verification flow. Others were far simpler: forged documents, some of them likely AI-generated, that walked straight through document checks. The common factor across all three wasn't the sophistication of the attack. It was a heavy reliance on Identity verification as the primary, and in some cases only, control.
This isn't three isolated bad-luck stories. It's a pattern that shows up in the data too.
The trend is real
Over the past 10 years, specialist providers such as Onfido and Veriff have made IDV simple for firms to integrate; and quick and (relatively) painless for customers to complete. As a result it has rapidly become the “go to” solution for anyone needing to verify a customer’s identity for credit or regulatory purposes.
But that’s also made IDV a target for fraudsters. A March 2026 survey of 713 anti-fraud professionals by the Association of Certified Fraud Examiners found that 75% had seen a sharp rise in AI-generated document forgery over the past 2 years. 77% reported the same for deepfake social engineering. Only 7% said their organisation was more than moderately prepared to deal with it.
The January 2026 World Economic Forum Cybercrime Atlas, produced with Banco Santander and Group-IB tested 17 face-swapping tools and 8 camera injection tools against live KYC flows. The good news was that live IDV checks were still hard to bypass: most of the tools tested were detectable if the IDV was configured well.
The bad news was that a subset of tools already deliver real-time, high-fidelity impersonation capable of undermining digital IDV. And the trend line is moving fast. Injection attacks specifically rose 783% in 2024 according to iProov, and 88% year-on-year in 2025 according to Jumio (source: WEF report).
The anatomy of IDV injection
Here's how a typical injection attack actually works. Someone gets hold of a fake or stolen ID document. They use an AI tool to generate a face that matches it. Then, instead of presenting their own face to the webcam during the IDV, they use software that tricks the system into thinking the fake video is coming from their webcam in real time. Finally, they take steps to disguise their device and IP address, so they don’t get recognised as the same individual when they come back again under a new fake identity.
A single check is a single point of failure
“This has changed everything, and we thus drift towards unparalleled catastrophe” - Albert Einstein, not talking about ID spoofing
In our view the answer is not to look for a better IDV provider. It is to diversify by using a much broader range of signals to detect fraud.
At Liquidity Lab, we’ve historically focused on detecting fraud (in particular ID theft) at B2B checkouts. That meant we could never rely too heavily on IDV because of the friction it creates. Instead we always had to draw on a range of data signals to evaluate the probability that a customer is who they say they are. These include technical factors (e.g. device fingerprint or IP address), behavioural factors (e.g. how the customer navigates the page), and various coherency checks (e.g. would we expect a customer with this profile to be taking this product?).
This “multi-strand” approach becomes even more important in a world where no method is 100% foolproof. The more factors firms take into account in their fraud screening the harder it becomes for a fraudster to bypass all of them. And this applies to bank account or loan applications just as much as it applies to B2B checkouts.
Doesn’t this also introduce complexity?
Yes, this is undeniable. Many of the factors we need to use aren’t black and white: fraudsters frequently use a VPN to disguise their IP address, but so do many genuine customers; a delivery address far from the company’s registered address raises some questions, but it’s not hard to think of reasons why that would genuinely happen.
Broadening the set of factors which are considered in a fraud decision inevitably means implementing a more complex rules engine which can weigh up factors in combination, striking the right balance between false positives and false negatives.
It also means moving to a more dynamic approach to fraud management. Being able to associate cases with each other and to monitor velocity metrics is a critical tool to limit the size of losses once a vulnerability has been found. And of course, firms also need the ability to implement rule changes quickly to close an identified vulnerability.
So what?
None of this is really a story about identity verification. It's a story about what happens when any single defence becomes common knowledge among fraudsters, whether that's a document check, a credit score, or a delivery address rule. The response isn't to patch that one defence and wait for the next workaround. It's to build a fraud function that treats detection as an ongoing contest rather than a one-off setup job: enough signals that no single blind spot sinks you, enough speed to close a gap once it's found, and enough of a trail to know which cases are connected before they turn into a pattern. The firms that get hurt worst by this shift won't be the ones with the weakest IDV. They'll be the ones who never built anything else to fall back on.
Reviewing your fraud processes, or wondering if you should be? We help B2B platforms move from single-point checks to layered fraud detection that actually holds up. Get in touch.