Skip to content

What is an injection attack?

The threat your sensors were never designed to see

Injection attacks represent one of the most significant and fastest-growing threats to biometric and identity systems.
Unlike traditional attacks, they don’t target what your system can see. They target what it can’t.

Not a hack. An impersonation.

Most people imagine a cyberattack as someone trying to force their way in: testing passwords, probing defences, triggering alerts. An injection attack uses a completely differently method. exactly what it expects to see.

An injection attack occurs when a threat actor bypasses a device sensor (camera or fingerprint scanner) entirely, inserting an instrument from which an injection attack can be launched. Once inserted, fabricated data such as a deepfake face, a synthetic fingerprint or a replayed video stream, can be injected directly into the system’s data pipeline. The sensor never sees it. The system processes it as if it were genuine. And if the system isn’t specifically designed to detect this class of attack, it has no reason to deny access.

The result is a successful fraudulent authentication that leaves no trace of anything unusual.

How injection attacks work

Two components. One attack.

Understanding how injection attacks are constructed is essential to understanding how to defend against them. 
Every injection attack has two distinct parts, and effective detection must account for both.

The Injection Attack Method (IAM)

The IAM is the delivery mechanism: the technical means by which an attacker gains access to the data stream and positions their payload inside the system. Common methods include:

  • Software and hardware virtual cameras
  • Mobile device emulators
  • External video capture cards
  • Driver injection and API or OS-level function hooking
  • Network payload interception and manipulation

A successful attack always begins with a successful IAM. Without it, the payload never reaches its target.

The Injection Attack Instrument (IAI)

The IAI is the payload itself,  the fraudulent data injected once access has been established. This includes:

  • Deepfake video sequences
  • Replays of previous genuine biometric captures
  • Face-swapped or animated imagery
  • Synthetic biometric data and identities

The sophistication of IAIs is increasing rapidly. What once required significant expertise and resources is now accessible, automated, and available as a service across online communities that number in the tens of thousands of participants.

Why the distinction matters

Most detection mechanisms target either the method or the instrument, not both. A system that blocks virtual cameras may still be vulnerable to a novel IAM. A system that detects deepfakes may be bypassed by a replay or a splice. Robust injection attack detection requires coverage across the full attack surface: IAM and IAI, in combination.

This is the framework that underpins Ingenium’s testing methodology, and why the scope and depth of testing directly determines the security gaps that remain.

Understanding the terminology: IAD, IAM, IAI – what the standards say

As the field has matured, so has the vocabulary used to describe it. Under emerging standards, specifically CEN/TS 18099, injection attack threats are classified across two distinct dimensions. Understanding the distinction matters, because a test that addresses only one dimension leaves material gaps.

Injection Attack Instruments (IAIs) refer to the payload, the fraudulent data being introduced into the system. This includes deepfake imagery, replayed video streams, AI-generated documents, and synthetic biometric samples of any modality.

Injection Attack Methods (IAMs) refer to the delivery mechanism, meaning how that payload is introduced into the system’s data pipeline. This includes virtual cameras, function hooks, network manipulation, and malicious execution environments.

Effective injection attack detection (IAD) must account for both. A system tested only against known instruments, without testing the range of methods through which they might be delivered, provides assurance that a sophisticated attacker will simply route around.

For a detailed breakdown of standards and compliance requirements, see biometric compliance standards & IAD testing

Scalable. Automated. Getting easier to execute.

Injection attacks are not new. What has changed is the accessibility of the tools required to execute them, and the sophistication of the data that can be injected. Three forces are accelerating the threat:

Generative AI

Large-scale models now produce biometric and document data of sufficient quality to defeat systems not specifically hardened against synthetic inputs. The cost and technical barrier to producing convincing fraudulent payloads has dropped significantly.

Automation and scale

Injection attack toolkits are increasingly available as commoditised services. A threat actor does not need to develop bespoke capabilities, they can purchase access to automated attack infrastructure and execute attacks at volume, across multiple systems simultaneously.

Continuous innovation

When an attack method fails, threat actors adapt. New delivery mechanisms, new payload types, and new techniques for evading detection are continuously developed and shared across criminal networks. The threat does not stand still.

The consequence is an attack surface that expands faster than most organisations, and many standards, are equipped to track.

What a compromised system actually costs

The downstream consequences of a successful injection attack extend well beyond the moment of breach.
Fraudulent identity creation.

Injected synthetic identities can be used to open accounts, access services, or establish a foothold for subsequent fraud at scale.

Account takeover.

Attackers who can bypass biometric authentication can access any system or service that depends on it,  impersonating legitimate users without triggering standard security alerts.

Compromised onboarding and recovery.

Identity verification at onboarding or during account recovery is a critical trust checkpoint. A system vulnerable to injection attacks cannot provide that assurance.

Compounding exposure.

A successfully compromised system doesn’t just enable a single fraudulent transaction. It creates a persistent attack surface that can be exploited repeatedly and shared.

Beyond direct financial and operational impact, the reputational consequences of a disclosed breach, particularly in regulated sectors, carry long-term costs that are substantially harder to quantify and recover from.

Detection isn't a feature. It's a tested outcome.

Injection attack detection is not a single technology or a checkbox on a compliance form. It is a measurable property of a system that can only be established through rigorous, adversarial testing.

A system without verified IAD capability may still pass a standard audit. It may carry compliance certification. It may have been signed off by the vendor. None of those assurances tell you whether it would hold against the methods currently being deployed by organised threat actors.

That gap between formal assurance and actual resilience is precisely what injection attack detection testing is designed to close.

The threat is real. The assurance should be too.

Ingenium is an independent biometric and identity testing laboratory with specialist expertise in injection attack detection. We test across the full range of current attack instruments and methods, not just those mandated by minimum standards, to give organisations and technology vendors a clear and defensible picture of where they stand.