FB pixel

Turing Institute sees surge in biometric spoof attacks on DPI, offers security advice

Quarterly threat report and upcoming workshop introduce ‘Digital ID Safety Pack’
Turing Institute sees surge in biometric spoof attacks on DPI, offers security advice
 

Countries around the world must protect their digital public infrastructure with a “Digital ID Safety Pack” to meet the minimum cybersecurity baseline, according to the latest report from The Alan Turing Institute’s Cyber Threat Observatory for National Identity Systems. The proliferation of AI tools for spoofing or bypassing biometric verification and the threat they pose to DPI have increased dramatically in recent years, according to the report, demanding a cybersecurity response from governments everywhere.

The Turing Institute explores what that response should be and the tools that make up its “Digital ID Safety Pack” in the report, and will present its findings in an online workshop next week.

The quarterly report for November, 2025 focusses largely on the ability of attackers to use generative AI to create synthetic or manipulated biometric content.

The report, part of the Institute’s Trustworthy Digital Infrastructure (TDI) initiative, pulls in data on Common Vulnerability Exposures (CVEs) and Common Weakness Enumeration (CWE) from the National Vulnerability Database (NVD), as well as sectoral reports from TransUnion, LexisNexis and the UK Finance, reports from academia and industry and policy frameworks including NIST SP 800-63.

CVEs associated with identity systems increased by 300 percent between 2020 and 2024, the Turing Institute found. The most common types of vulnerabilities discovered often involved improper or missing authentication, incorrect authorization, information exposure or hardcoded credentials. They were frequently found in federated digital identity systems, single-sign on (SSO) systems and API-based authentication.

The Cyber Threat Observatory analyzed common CVEs targeting national identity systems in a report and workshop in June.

Advanced economies have experienced sudden surges in fraud attacks using synthetic identities, with a 500 percent increase in the UK over three years as one example. With countries across the Global South expanding their DPI, this trend shows the need for protections to be implemented early.

The Observatory examines the threat landscape, and places in the digital identity lifecycle when biometric presentation attacks, injection attacks, synthetic ID documents or document injections and insider threats can be carried out. It considers the challenges of stopping particularly sophisticated spoof attacks, including biometric face morphing and deepfakes.

The “Digital ID Safety Pack” nations need to preserve the integrity of DPI includes zero trust architecture and biometric anti-spoofing (meaning liveness detection). Multi-modal biometric verification, liveness detection and anti-spoofing algorithms, secure API design and rate limiting, encryption for any stored biometric templates and deepfake detection utilizing AI are all recommended. The Safety Pack also includes DPI safeguard principles against harm and exclusion and providing redress, alignment around international standards, Cyber Assessment Framework adoption and the establishment of coordinated threat intelligence sharing platforms, according to the report.

Workshop December 10 to present practical defense measures

The Institute’s Cyber Threat Observatory is holding an online workshop on December 10 to present the research and the insights governments can digital identity practitioners can take from it to harden DPI defenses.

Speakers will include report co-author Professor Carsten Maple and Dr. Salim Awudu, experts from MOSIP and CDPI and representatives from public-sector authorities in Sri Lanka, Uganda and Ethiopia.

Attendance is free with registration.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Biometrics handling new frontiers and changed expectations, from agents to gait

Successes in airport biometrics are driving deployments and expansions all over the world. But the technology cannot perform miracles like…

 

Financial institutions stumbling into phishing-resistant MFA gaps, report warns

Financial institutions seem aware that phishing is worsening, but that awareness has not translated into stronger authentication across the workforce….

 

Proof, Enigma link KYB to authorized people, AI agents with biometrics

Proof and Enigma have launched Business Certificates, a cryptographic credential that connects a verified business identity to the people and…

 

Investors back Lissi, Gataca’s expansions to meet EU Digital Identity Wallet moment

A pair of European digital wallet developers have new resources to pursue market share in the nascent continental ecosystem for…

 

New Incode age estimation tool processes biometrics on-device

Prompted by the introduction of online safety regulations globally, Incode has released an on-device age estimation product. An announcement from…

 

Western Australia privacy commissioner not consulted on police facial recognition trial

The Office of the Information Commissioner of Western Australia (OIC WA) says it was not invited to participate in any…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events