Your biometrics may not be as safe as you think

creative illustration
Image credit: Shutterstock (Image credit: Shutterstock)

Using your biometric data, such as your fingerprint, to login and authenticate your identity may not be as secure as you think.

This is according to NordVPN, whose researchers claim to have found 81,000 stolen fingerprints across dark web forums. The VPN provider also added that since users can't change their fingerprints - as they can a compromised password - they are at risk of being permanently compromised.

While acknowledging that biometrics are generally a very safe method of authentication, Adrianus Warmenhoven, a cybersecurity expert at NordVPN, said that, "all recorded data is hackable... biometric information a valuable target for cybercriminals, and hacking of this type of data becomes a popular way of identity theft."

Up for grabs

NordVPN identified 20 different types of biometric data that can be used, with the most popular being fingerprints, face, and voice. It further claims that all are vulnerable to compromise in different ways. 

With regards to fingerprints, one common method of theft is to place something called a skimmer on ATMs or other fingerprint scanning machines. This collects fingerprints and duplicates them for cybercriminals to use to breach victims' accounts. 

NordVPN notes that using skimmers are an old-fashioned way to steal fingerprints, and that now deepfake technology is making the theft of biometric data even easier for threat actors to pull off. 

It says that by taking a target's photos and videos from their social media profiles, the technology can create fake versions of their face, voice and even their fingerprints to fool authentication processes. 

Warmenhoven explains that, "while we are the owners of our own faces and voices, we are not the only ones with access to them. Over the years of being active social media users, people left so much biometric data that with the current capabilities of artificial intelligence to create deepfakes, it becomes a weapon against our privacy."

Biometric data stored on a smart device is usually quite secure as it is encrypted. However, if malicious apps are granted access to this data, then unscrupulous developers can steal it. 

Even in the case of safe and reliable apps, if a user's biometric data ends up being stored in the app vendor's cloud or servers, then this is again vulnerable to breach from threat actors. During the transmission of the biometric data between the device and servers, a threat actor could intercept the data.  

Therefore, Warmenhoven recommends that users think carefully before opting in to a new app's request to access their biometric data. He also advises to use Two-factor authentication (2FA) or multi-factor authentication (MFA) where possible, along with strong passwords, and to use a VPN to prevent criminals from intercepting data in transmission.

TOPICS
Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
Dark Web cybercriminals are buying up ID to bypass KYC methods
Hand holding smartphone and scan fingerprint biometric identity for unlock her mobile phone
Passwordless authentication continues to grow, with biometrics helping push adoption
Cartoon illustration of multiple smartphones
Are you oversharing? These are the 10 pieces of information you don't want to give away – ranked
Biometrics
Like selling your virtual soul: Researchers uncover extraordinary identity farming operation where the culprits are the victims
Hands typing on a keyboard surrounded by security icons
Outdated ID verification myths put businesses at risk
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
Monster Hunter Wilds
Monster Hunter Wilds Title Update 1 launches in early April, adding new monsters and some of the best-looking armor sets I need to add to my collection
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'