Thank you for subscribing!
They could trick banks, landlords, government agencies, and more
The strict identity checks used to open bank accounts, pass age verification filters, and authenticate digital IDs might not be as secure as everyone thought. Researchers from Cybernews have uncovered a new toolkit — a utility used to build, design, and manage apps on Android devices — designed specifically to cheat identity verification.
With this toolkit, anybody could bypass these identity checks — hijacking both the front and rear cameras on your device, feeding fake images or videos that appear as if they're being captured in real time.
Instead of the short video or multiple selfies required to prove your identity, banks and age verification checks can be fooled with pre-prepared fakes. Using the toolkit, fraudsters could take over genuine accounts or create fake ones to steal identities. The discovery raises serious questions about how bulletproof these verification systems truly are.
With widespread adoption of these authentication methods, this type of scam may only grow.
For instance, Downing Street has been mulling over a nationwide rollout of digital IDs to make verification checks quicker, easier and potentially more private, allowing you to prove things such as your age or identity without repeatedly handing over sensitive documents.
This national scheme was sold as a way to make it faster and easier to access government services, apply for benefits, rent a home and prove your right to work. However, that wider plan is now on hold.
Prime Minister Andy Burnham has scrapped the proposed national digital ID scheme, redirecting resources towards cost-of-living measures. But these systems are already used for bank account opening procedures, right-to-work checks, right-to-rent checks, and DBS criminal record checks, while GOV.UK One Login lets you prove your identity digitally when accessing certain government services.
And if your identity is falsified for any of these reasons by a fraudster, it could be very dangerous.
If someone combined the toolkit with stolen ID documents and convincing facial imagery, they could potentially create fake accounts, take over existing ones, or steal someone's identity entirely.
For businesses, the fallout could mean costly manual investigations, fraudulent transactions, customer refunds, and awkward disputes about whether their security measures were up to scratch.
There's also a nasty wrinkle for biometric systems — someone's face could be misused without the attacker ever needing to hack into a company's database.
The toolkit can take a saved photo, a pre-recorded video, or even a live video stream controlled remotely, and pipe it straight into an app as though it's coming directly from the phone's camera.
The tool can even mimic the natural movements and timing you'd expect from someone holding a phone, making the fake feed look convincingly real. On top of that, it can fiddle with the phone's details too, spoofing things like the device model, location, browser fingerprint, and security status.
This matters because most verification systems use both cameras. The rear camera grabs a high-resolution shot of your passport or driving licence, then the front camera kicks in for a live selfie and face-matching check. The toolkit lets an operator feed different fake content into each camera independently.
However, this isn't something your average fraudster can just download and start using on any old phone.
The Cybernews team found that setting this up requires a heavily modified Android device — a phone that's been unlocked and given what's known as root access, which means stripping away the normal security barriers built into the operating system.
Extra software needs to be installed to change how the phone and its apps behave at a deep level.
That's not something a casual user could normally pull off, and it comes with its own downsides — a phone set up this way has much weaker security, potentially exposing the hacker's own data. So it would likely only be used on a device dedicated purely to fraud.
The good news is that there's no evidence any identity verification provider has been tricked by this toolkit. Developers, banks, and governments can add other steps — like document authenticity checks, unpredictable liveness challenges, device analysis, fraud scoring, and manual reviews — to add extra safeguards on top of the video and selfie checks.
The launch of this toolkit shows that fraudsters are just as innovative as those trying to keep your digital life safe and secure. As cybercriminals continue to launch more advanced digital schemes, the threat to digital IDs may only grow.






