News

Synthetic Identity & Injection Attacks: The 2026 Threat Guide

Moca Network
August 4, 2026

TL;DR — Synthetic identity fraud combines real and fake data to create a person who doesn't exist; injection attacks feed AI-generated video directly into a verification system to bypass the camera entirely. Both are now mainstream fraud tools. The defense is not just better fake detection: it is stronger provenance, reusable verification, selective disclosure, and accountable agent identity. AIR's role should be framed as reusable proof and agentic identity, not as a deepfake-detection vendor.

What is synthetic identity fraud?

Synthetic identity fraud is the creation of a fake identity by blending real data (like a stolen or unused ID number) with fabricated details. Because the identity is partly real, it passes many traditional checks and can build credit or open accounts before anyone notices it was never a real person.

In 2026, generative AI has made synthetic identities cheaper and more convincing, including AI-generated identity documents that look genuine to the naked eye. This is why data-only checks are increasingly unreliable on their own.

What is an injection attack?

An injection attack bypasses the camera. Instead of holding a fake up to a device (a "presentation attack"), the fraudster injects a synthetic video feed, often a deepfake, directly into the verification pipeline through a virtual camera or manipulated data stream.

Through 2026, the attacker's center of gravity has shifted from presenting a fake to a camera toward injecting a synthetic feed into the pipeline. That shift matters because many older liveness systems were built to catch presentation attacks and simply don't see injection attacks.

Updated 2026 fraud signals

Entrust's 2026 Identity Fraud Report reports that:

  • deepfakes account for one in five biometric fraud attempts;
  • deepfake selfies increased 58% in 2025;
  • injection attacks surged 40% year over year.

These numbers replace the earlier draft's unsourced market projection about voice-and-face deepfake checks.

The 2026 threat landscape

ThreatHow it worksWhy it beats old defenses
Synthetic identityReal + fake data combinedPartly real, so it passes data checks
Presentation attackPhoto, mask, replay to cameraBasic liveness catches some, not all
Injection attackDeepfake fed into the pipelineBypasses the camera entirely
AI-generated documentsFake IDs made by generative AILook genuine; fool manual review
Agent impersonationBot or agent claims to act for a user without authorityNeeds KYA, delegation, revocation, and audit

How to defend against synthetic identity and injection attacks

  • Use multi-signal, multi-modal liveness — analyze several independent cues so no single spoof defeats the check.
  • Add injection-attack detection — verify the feed comes from a real device camera, not a virtual or manipulated source.
  • Combine biometrics with document and data checks — no single signal should be decisive.
  • Adopt reusable, verified identity — a credential issued after a strong verification and reused via proof is harder to synthesize than a fresh document each time.
  • Bind identity to accountability — for AI agents, tie every agent to an accountable principal through Know Your Agent, delegation, revocation, and audit.
  • Monitor continuously — watch for behavioral anomalies after onboarding, not just at the gate.

Where reusable identity helps

Synthetic identity thrives when every service verifies from scratch and stores its own copy of the data. A reusable, decentralized credential flips that: the user is verified once to a high standard, then presents a cryptographically signed proof, reducing the number of documents in circulation for attackers to fake or steal.

AIR should not be positioned as a biometric liveness or deepfake-detection vendor. The aligned framing is that AIR Identity / AIR Kit provide credentials, verification programs, selective disclosure, and ZK proof primitives; AIR Agentic Identity adapts those proofs for agents so they can know, prove, collect, store, or share under consent; AIR Policy + Audit provides limits, receipts, revocation, and evidence.

Frequently asked questions

What is synthetic identity fraud?

It's fraud that blends real and fabricated data to create an identity for a person who doesn't exist, which then passes many standard checks.

What is an injection attack in identity verification?

An attack that feeds a deepfake or synthetic video directly into the verification pipeline, bypassing the physical camera to defeat liveness checks.

How do you detect deepfakes in 2026?

With multi-modal liveness that analyzes multiple independent signals and with injection-attack detection that confirms the feed originates from a genuine device camera.

Can reusable identity reduce synthetic identity fraud?

Yes. Verifying once to a high standard and reusing a signed, privacy-preserving credential reduces the number of spoofable documents in circulation and raises the cost of faking an identity.

Checked references: Entrust — 2026 Identity Fraud Report; FIDO Alliance; W3C — Verifiable Credentials Data Model; DIF — KYA-OS.

Digital Identity Verification in 2026: The Complete Guide · Know Your Agent (KYA)

Related reading

More from AIR: AIR Identity and verified user acquisition, or browse the full AIR blog.

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding
MASAK, the CMB and the CBRT now anchor remote onboarding in Türkiye to NFC chip reading, and open it to foreign nationals holding ICAO 9303 passports.
News
US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts
FinCEN and four US banking agencies say a government-issued mobile driver's licence can serve as documentary ID under the CIP Rule. What the 2026 FAQs require.
News
The EU KIDS Act Proposes 15 as the Minimum Age for Independent Social Media Accounts
The EU KIDS Act proposal sets 15 as the minimum age for independent social media accounts, adds supervised accounts from 13 and requires certified age checks.