Legitimuz gets BixeLab IAD certification for facial verification image injection attacks
Brazil’s Legitimuz has added BixeLab IAD (Injection Attack Detection) certification for its LegitFace liveness product, giving it another checkmark against a fraud vector that matters to banks, fintechs, and betting platforms: image injection, where the biometric signal never comes through the device’s physical camera.
- The certification is aligned with CEN/TS 18099, a technical standard focused on detecting when an image has been inserted by software instead of being captured by the device camera. In other words: not whether there is a face on screen, but whether the system is being fed a face from the wrong place.
- Legitimuz says the attack differs from the usual deepfake-on-camera scenario. Here, the image is injected directly into the app through frameworks, emulators, or virtual cameras. For iGaming operators, that maps to multi-accounting, bonus abuse, and synthetic identities used to get around operator blocks.
- The company says LegitFace already had iBeta PAD Levels 1 and 2 and BixeLab PAD Levels 1, 2 and 3 certifications for presentation attack detection (PAD), which covers photos, videos, and masks. The new BixeLab IAD layer addresses a different question: whether the image really came from the device camera or was fabricated before it reached the verification system.
- Legitimuz says the two layers together cover both sides of the problem: falsifying the person and falsifying the image source. The company also says LegitFace is operating with 0% fraud approved in production and less than 5% rejection of legitimate users, which it uses as its balance point between security and onboarding friction.
- Kayky, CEO of Legitimuz, said the company has built “the only 100% Brazilian and 100% passive liveness” in the market, with technology developed entirely by its engineering team. Legitimuz says it serves iGaming, fintechs, and other regulated industries, and also holds ISO/IEC 27001, ISO/IEC 30107-3, iBeta PAD, and BixeLab certifications.
For PSPs and risk teams, the useful bit is the split between PAD and IAD. PAD asks whether there is a real person in front of the camera; IAD asks whether the app is even seeing a camera feed at all. If your onboarding stack only tests one of those, you are not testing the whole fraud path.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!