January 7, 2025
Deepfakes and injection attacks are no longer a future problem for identity verification and cybersecurity teams to plan around. They are the primary attack vector against face biometrics today, and the leading independent research houses covering this space have converged on a similar set of conclusions about how organizations need to respond.
We pulled together analyst reports that, considered in sequence, tell a complete story: what the threat actually looks like, how fast it is growing, where it is now hitting organizations hardest, and who the market considers to be ahead of the curve.
Gartner: Deepfake Identity Threats – Mitigate Risk in Identity Verification and Face Biometrics
The start; the framework. Gartner analysts Akif Khan, Nayara Sangiorgio, and James Hoover make a case that reframes how buyers should evaluate vendors entirely: stop comparing solutions on the basis of “deepfake detection” claims. The research argues this is a probabilistic, unstandardized approach with no reliable way to verify vendor claims or compare providers against each other.
Instead, the report argues the real defense has two required layers:
- Presentation attack detection, tested against the established ISO/IEC 30107-3 standard, for artifacts physically shown to a camera such as masks, printed photos, or a screen replay.
- Injection attack detection, tested against the newer CEN/TS 18099 standard, for attacks that bypass the camera entirely and feed fabricated media directly into the data stream.
The report also draws a distinction that’s easy to miss in vendor marketing: liveness detection isn’t a separate category from presentation attack detection, it’s one of the techniques PAD testing covers. See how liveness detection fits into a broader defense stack or test your current liveness detection here.
Contextual signals such as device and location intelligence are also highlighted, since no single defense catches every attack. Learn more about multi-layered defense and contextual signals here.
The burden shifts to independently tested presentation and injection attack detection to close the gap. Our next report puts a hard number on exactly how fast that gap is widening.
Read the Gartner report abstract.
Goode Intelligence and Biometric Update: 2026 Injection Attack Detection Market Report and Buyer’s Guide
This report puts numbers behind the framework above. Goode Intelligence forecasts injection attack attempts growing from 122 million in 2026 to more than 301 million by 2028, driving upward of 4 billion injection attack detection checks annually by the end of that window.
It also draws a distinction worth internalizing: injection attack detection, presentation attack detection, and deepfake detection are related but not interchangeable. Presentation attack detection looks at what is shown to the sensor. Deepfake detection analyzes the media itself for signs of manipulation. Injection attack detection protects the integrity of the pipeline between the camera and the processing system, which is where an attacker using a virtual camera or emulator actually operates.
The report credits iProov as an early mover on this specific threat, noting warnings about injection attacks dating back to 2020, well before the wider industry treated it as a distinct category. It also cites iProov’s May 2024 FIDO Face Verification certification and a CEN/TS 18099 Level 4 (High) evaluation completed by Ingenium in November 2025, which aligns with the surge this report forecasts. For more on what that standard actually tests for, see our breakdown of CEN/TS 18099.
Read the full Good Intelligence report (PDF).
Gartner: Workforce Identity Verification Requires Unique Capabilities
Identity verification has historically been a customer-facing, KYC-driven tool. This report, also from Khan, Sangiorgio, and Hoover, documents why that is changing fast: attacks on IT service desks by groups like Scattered Spider, tied to breaches at organizations including MGM and Marks & Spencer, and the well-documented pattern of organizations unknowingly hiring IT workers from sanctioned states using deepfakes during remote interviews.
The report’s central argument for buyers is that workforce identity verification is not the same procurement as customer identity verification. The core defenses (presentation and injection attack detection) still apply, but workforce use cases add requirements most customer-focused vendors are not built for: integration with HR systems, IT service desk platforms, and access management tools, plus automated matching against employee records rather than manual lookups. We wrote about the KnowBe4 case specifically in our breakdown, and it is the exact scenario this report is built around. See our Workforce Solution Suite for how this maps to a real deployment.
Download the full Gartner report.
Acuity Market Intelligence: Biometric Digital Identity Deepfake and Synthetic Identity Prism Report
This is the independent validation that ties the other three together. Acuity’s Prism Project evaluates the biometric digital identity market across nine categories using six weighted criteria, and this report, its sixth, is the first to focus specifically on the deepfake and synthetic identity threat rather than a single industry vertical.
It introduces a useful taxonomy for anyone trying to make sense of synthetic identity fraud: full synthetic identities built entirely from counterfeit elements, partial synthetic identities that combine one authentic element with a counterfeit one, and hybrid synthetic identities that blend both in varying combinations. Acuity names iProov as one of only two organizations across the entire report to earn “Trailblazer” status, citing its early and sustained focus on the deepfake threat, and scores it a full 6 out of 6 on deepfake and synthetic identity leadership specifically.
Read more about what that Trailblazer designation means and see the report’s own summary of the findings.
Why These Analyst Reports, Together?
Individually, each report answers a different question: how do you defend face biometrics, how fast is the threat growing, why does workforce identity verification need different tooling, and who does the market consider ahead of the curve. Read together, they make the case that this is not a niche technical concern. It is a threat that spans customer onboarding, employee hiring, and account recovery, and the organizations that treat presentation attack detection and injection attack detection as two distinct, non-negotiable requirements are the ones best positioned for what is coming.
None of these four treat the threats as solved. They keeps moving, and we will keep updating this page as the standards, forecasts, and attack types worth watching keep shifting.
For a closer look at how these attacks are playing out right now, see iProov’s Threat Intelligence Report 2026.


