As deepfakes, digital injection, and synthetic identities raise fraud risk in remote onboarding, regulated organizations face growing pressure to prevent financial losses, compliance exposure, and loss of customer trust
Innovatrics commissioned Citadelo, an ethical hacking firm, to test whether its Identity Verification could resist attempts to bypass facial liveness detection. After 16 days of independent black box testing, including an evaluation of digital injection scenarios, the attacks were unsuccessful.
The assessment was designed to reflect how a determined attacker would approach a real identity verification system. Citadelo worked without access to source code, internal architecture, or proprietary instructions.
“During a major customer engagement, we were required to provide independent proof that our identity verification solution is resilient against injection attacks. We selected Citadelo for their expertise, reputation, and ability to meet the customer’s demanding timeline. Their assessment provided valuable independent validation and reinforced confidence in the robustness of our technology,” said Viktor Bielko, Product Manager for Identity Verification Toolkit.
This matters because remote onboarding is now a core part of financial services, telecom, insurance, and digital platforms. As fraud tools become easier to access, companies need proof that their identity verification systems can resist more than simple photo or video attacks.
The goal of the assessment in a controlled lab setting was to test how it behaved under pressure from an external security team.
Citadelo reviewed Innovatrics Identity Verification with a focus on video injection and resistance to tampering. The team attempted to interfere with the capture process, replace biometric inputs, and challenge the connection between the user’s device and the verification system.
“The combination of strict native-layer code isolation, hardware-anchored data correlation, and server-side validation models ensures the solution provides elite protection for enterprise digital ecosystems. After days of intensive reverse engineering and injection attempts, we could not bypass the IDV solution within the timeframe. This just confirms the robustness and overall security of the technology,” explained Oliver, Ethical Hacker at Citadelo.
For organizations that rely on remote onboarding, the ability to combat video injection attacks is a key part of fraud prevention. It helps confirm that the person completing a verification process is present and not represented by a manipulated image, video, or synthetic input.
Independent testing adds another layer of confidence. It gives security, fraud, and compliance teams a clearer view of how identity verification performs when exposed to actual attack methods.
It also reflects a practical reality. A secure onboarding flow cannot depend only on the end user’s device. Modern identity verification needs layered protection, server-side validation, and checks that make it harder to manipulate the process from software alone.
Innovatrics continues to invest in biometric security built on independent validation and continuous testing that helps organizations protect digital onboarding while keeping the user experience simple.
Talk to our identity verification experts.