TrueID

Why Biometric Liveness Detection Is the Missing Layer in Your MFA and Onboarding Stack? 

Get An Enquiry

Get an Enquiry

Summary: Organizations often assume that passwords, OTPs, and document verification provide complete protection, but these methods do not confirm that a real, present person is interacting with the system at that moment. This gap is increasingly exploited through deepfakes, synthetic identities, and session hijacking. Biometric liveness detection—whether passive or active depending on the use case—helps close this vulnerability, making it a critical part of modern identity verification. The strongest security strategy is a multi-layered, multi-channel defense that combines complementary verification methods rather than relying on fixed authentication factors alone.



Most organizations believe their MFA and onboarding stack is complete even without biometric liveness checks. It usually is not. 

Passwords, OTPs, and document-and-selfie matching all verify something. None of them verify that a real, present human being is on the other end of the request right now, which is exactly the gap attackers are learning to exploit with session hijacking, synthetic identities, and deepfake video. Biometric liveness detection closes that gap, and the right type, passive or active, depends on where in the stack it sits.  

The most appropriate security shield for an organization is employing a multi-channel defence mechanism rather than relying on fixed factors for all situations. 

The stack most companies already have, and where it breaks 

A typical identity stack combines a first factor, a second factor, session management, and document-based onboarding. A password or passkey covers the first factor, an OTP or push notification covers the second, a provider like Okta or Azure AD manages the session, and onboarding adds a document upload with a selfie match. 

This combination stops most low-effort attacks. Phishing-resistant MFA blocks more than 99% of identity-based attacks even when a password is already compromised, according to Microsoft’s Digital Defense Report 2025

The real gap sits between the factors, not inside them. Various adversary-in-the-middle (AiTM) kits relay a real login page, capture the session cookie the moment it is issued, and walk into the account without triggering another prompt. 

Microsoft attributes 80% of MFA-bypass breaches to exactly this kind of session-token theft. Reports suggest that an AiTM platform alone reached more than 500,000 targeted organizations a month before a coordinated takedown in March 2026  

Onboarding carries the same weakness. A stolen or synthetic ID paired with a selfie can pass a basic match check without confirming a real person is on camera. 

Entrust’s 2026 Identity Fraud Report, drawn from more than a billion verifications across 195 countries, found that deepfakes now account for one in five biometric fraud attempts. Deepfake selfie attempts alone rose 58% year over year. 

The financial sector shows the cost of this gap. CrowdStrike’s 2026 Financial Services Threat Landscape Report found that the most active threat group targeting banks skipped phishing altogether, instead calling IT support to reset MFA and register a new device, a technique that didn’t involve a biometric check and left standard logs looking normal. 

What liveness detection actually checks 

Liveness detection answers a question neither password-based MFA nor a static selfie match can answer: is a real, present human being making this request right now? 

Passive liveness analyzes texture, depth, and micro-movement in a single frame to flag a screen replay, a printed photo, or a mask. Active liveness prompts a blink, a head turn, or a spoken phrase to confirm the response is happening live rather than being replayed. Both are tested against a formal benchmark, ISO/IEC 30107-3, the international standard for presentation attack detection, which defines how systems are measured for their ability to reject spoofed biometric samples across three escalating levels of attack sophistication, from printed photos to lab-grade 3D masks. 

This is a different layer of defense than either half of the usual stack provides. Most MFA systems verify possession of a device or a code. Document-and-selfie matching verifies that a photo resembles an ID. Liveness detection verifies that the thing being photographed, or the thing approving the push notification, is a living person and not a replayed session, a synthetic face, or a voice clone. 

Why passive checks alone are no longer enough 

Passive liveness was long considered sufficient on its own. It reads texture, depth, and micro-movement without asking the user to do anything, which kept onboarding friction low. 

However, high-quality 3D masks can now bypass texture-only analysis, and advanced deepfakes can clear passive checks when the detection model has not seen a similar attack pattern before. 

Injection attacks compound the problem. Global injection attempts are projected to rise steeply as attackers increasingly bypass the camera rather than presenting something to it. 

This is why active liveness now matters for higher-risk moments, even though passive liveness remains the right default for high-volume onboarding. Passive checks keep friction low for routine signups, while active checks suit account recovery, MFA resets, and high-value transactions where stronger assurance is worth the extra step. 

Independent testing backs this distinction. In the U.S. Department of Homeland Security’s Remote Identity Validation Rally, Aware’s active liveness system blocked all Class A and B spoof attacks, while its passive system blocked all Class C attacks, showing the two modes catch different attack classes rather than one simply outperforming the other. 

The table below summarizes how each check contributes to a layered defense. 

Check type How it works Defends against Best suited for Limitation 
Selfie-to-document match, no liveness Compares a live photo to an ID image Basic identity mismatch Low-risk, low-value signups Passes a printed photo, screen replay, or static image 
Passive liveness Reads texture, depth, and micro-movement from a single capture, no user action required Printed photos, screen replays, basic masks High-volume onboarding where friction must stay low Advanced 3D masks and untrained deepfake patterns can still pass 
Active liveness Prompts a blink, head turn, or spoken phrase and confirms the response happens live The above, plus deepfake video that cannot yet mimic a prompted action in real time Account recovery, MFA resets, high-value transaction approval Adds friction, and real-time deepfakes are starting to mimic prompted motion 
Injection attack detection Detects virtual cameras and manipulated data streams entering below the camera layer Deepfake video or audio fed directly into the app, bypassing the physical camera Any remote verification step, paired with passive or active liveness Not a full liveness check on its own; works alongside PAD, not instead of it 

No single check in this table is sufficient by itself. The strongest stacks pair passive liveness for routine onboarding with active liveness and injection attack detection at the moments that carry the most risk. 

Why this layer closes the specific gap attackers are exploiting 

Deepfake and synthetic-identity attacks are growing precisely where liveness detection is absent. Several organizations recorded an unprecedented surge in deepfake fraud attempts in the previous year, and many have also documented a steep spike in virtual-camera injection attacks against identity verification systems. Gartner projects that by 2026, 30% of enterprises will no longer treat identity verification as reliable on its own because of AI-generated deepfakes. 

Liveness detection is what turns identity verification back into a reliable control. It does not replace MFA or document checks. It closes the specific hole both leave open: the moment where a fraudster substitutes a synthetic presentation for a live one, whether that is a face-swapped video during onboarding or a cloned voice authorizing a high-value transfer. 

Building liveness into the stack, not bolting it on 

The strongest identity stacks now treat liveness as a control at every stage where a human is supposed to be present, not just at account creation. That means liveness checks at onboarding, at password or MFA resets, and at high-value transaction approval, since each of these is a point where an attacker can substitute a synthetic presentation for a real one. 

Latest reports suggest that solutions that only verify identity at onboarding leave the authentication and ongoing-usage stages exposed. A complete and reliable stack secures all three. 

For organizations still relying on document-and-selfie matching alone, the fix is not a rebuild. It is one additional, ISO-tested layer that answers the question every other control in the stack assumes but never actually checks: is this a real person, right now? 

Recent Blog

Why Biometric Liveness Detection Is the Missing Layer in Your MFA and Onboarding Stack? 

Why Biometric Liveness Detection Is the Missing Layer in Your MFA and Onboarding Stack? 

Summary: Organizations often assume that passwords, OTPs, and document verification provide complete protection, but these methods do not confirm…

Can You Really Trust Digital Interactions? And Can You Afford to Avoid Them? 

Can You Really Trust Digital Interactions? And Can You Afford to Avoid Them? 

Summary: Digital interactions have become essential for services like banking, healthcare, hiring, and government, but growing AI-powered fraud is…

How to Balance Privacy and Security When Using Facial Recognition in Video Surveillance 

How to Balance Privacy and Security When Using Facial Recognition in Video Surveillance 

Summary: Facial recognition technology (FRT) has become an increasingly valuable tool in modern video surveillance because it helps identify…