a split-second glitch exposed a real-time deepfake identity fraud operation

For about one second, the mask slipped. A man sat in front of his webcam holding a forged Spanish national ID card up to the camera, while AI software reshaped his face on screen in real time to match the photo on the document. Then the software glitched. For a heartbeat, his real face flashed onto the screen — and that single second is what ended a fraud operation that had already made 38 attempts to steal the digital identities of more than 30 people.
How the scheme worked
According to Help Net Security, Spain's Policía Nacional arrested the man in Murcia after a company that issues electronic signature certificates flagged a string of suspicious video verification requests. The investigation, first detailed in a police statement, described a layered attack built to defeat every part of a standard video identity check at once:
- Real-time face-swap software that altered his face on screen to match the photo on a forged national ID card, live during the verification call
- Household spotlights fitted with colored bulbs, strategically placed to simulate the light flashes and security features a genuine document shows under real light
- Physically tilting the counterfeit ID in front of the webcam to recreate the shimmer of an official hologram
- VPNs to anonymize his network connections throughout the operation
None of these tricks alone is new. What made this case notable is that all of them were combined into a single, repeatable operation — document forgery, real-time video manipulation, and physical props working together to beat a verification process designed to catch exactly this kind of fraud.
The infrastructure behind one fraudster
This wasn't an improvised, one-off attempt. Tracing the suspect's communications and payment trail, investigators identified more than 320 phone lines linked to 24 mobile devices, most registered using stolen identities and purchased at physical points of sale that police were able to geolocate. A search of his home turned up a laptop protected with high-level encryption, along with additional phones, storage devices, and records tied to the case.
The target: certificates, not just a video call
The end goal wasn't simply passing a verification check — it was obtaining legitimate digital signature certificates issued under real people's identities. In Spain, as in much of the EU, a valid electronic certificate can be used to sign contracts, authorize transactions, and act on someone's behalf with legal weight. Once issued, a fraudulently obtained certificate gives an attacker a durable, reusable credential — which is precisely why the suspect ran this scheme 38 times against more than 30 different identities rather than targeting a single victim.
What caught him, and why it almost didn't
The operation wasn't undone by a technical control designed to catch it. It was undone by a processing delay in the deepfake software itself, which briefly dropped the digital mask during a live call and exposed the suspect's real face to the reviewing staff for about a second. That's a fragile way to catch fraud. A better-resourced attacker running more stable software, or a verification process without an attentive human on the other end, could easily have avoided that one-second failure.
The gap remote verification still has to close
Live video identity checks are common now precisely because they're convenient — for certificate issuers, banks, telecoms, and HR platforms alike, they replace a trip to a physical office. But convenience only holds up if the system can tell the difference between a real, unmodified camera feed and an injected or manipulated one. That requires two things most verification stacks still don't have:
- Proof that the person taking part in the verification is physically present, not represented by injected or replayed video
- A trusted video path that confirms the feed genuinely comes from the device's camera and hasn't been altered in transit
Without those controls, a verification process built to prevent impersonation becomes an entry point for it. This case was caught by luck. The next one might not be.
Corsound AI's Deepfake Detect analyzes audio and video continuously throughout a verification call to flag synthetic faces and injected feeds as they happen — not by waiting for the software to glitch. If your organization relies on live video to verify identity, it's worth confirming your detection doesn't depend on the fraudster's bad luck.
See Corsound AI Voice Intelligence In Action

