Selfie-authentication for large transactions puts users at risk of fraud, experts say

Influencer Taking a Selfie
(Image credit: Mateus Campos Felipe / Unsplash)

The trend of selfie verification has gained serious traction in recent years, however security experts have warned this method can easily be abused and service providers should be extra careful with it.

In the past half a decade, banks, fintech organizations, and similar, have increasingly started verifying people’s identities through selfie images. Customers are asked to take a selfie photo, sometimes holding an identification document in their hands. This method aims to mimic what customers would be asked to do at the counter. 

Although it looks good on the surface, this approach is far from perfect and comes with risks that need to be addressed. Speaking to The Register, multiple security experts, and market analysts, discussed the practice and identified three major pain points - KYC and AML woes, securing and disposing of image data, and potential data breaches.

Liveness check

Oftentimes, different countries and jurisdictions will have different laws and regulations regarding Know Your Customer (KYC) and Anti-Money Laundering (AML) practices. This, together with the fact that such laws are frequently changed and updated, leads to a “gap in arbitrage”.

Furthermore, many organizations requiring their customers to verify their identities outsource the requirements to a third party. These partners sometimes don’t handle the sensitive data properly, and sometimes don’t even discard the images after the verification is complete. That leads to the third problem - data breaches.

Sensitive data, such as people’s selfies, is very attractive for cybercriminals. They can use it in various ways, from selling it on the dark web, to conducting advanced phishing and identity theft attacks themselves. 

To tackle the threat, organizations have started asking customers to take selfies while holding a piece of paper with a unique message on it. While this helps, it is still not perfect, since the message on the paper can be edited. 

An even better solution would be a “liveness check” - where customers are asked to provide a video of their face, with different facial expressions, or a head turn. Some liveness checks even search for signs of blood flow underneath the skin.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Hands typing on a keyboard surrounded by security icons
Outdated ID verification myths put businesses at risk
Dark Web cybercriminals are buying up ID to bypass KYC methods
Biometrics
Like selling your virtual soul: Researchers uncover extraordinary identity farming operation where the culprits are the victims
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
A graphic showing fleet tracking locations over a city.
How can banks truly understand the changing regulatory landscape?
Hands typing on a keyboard surrounded by security icons
The psychology of scams: how cybercriminals are exploiting the human brain
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Latest in News
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI