Deepfakes in iGaming: are platforms ready?
For iGaming operators, remote identity verification is not just a KYC box to tick anymore. With real-time deepfakes, selfie-based checks can be bypassed at exactly the point where age, jurisdiction, self-exclusion, and bonus abuse controls are supposed to hold.
- In iGaming, the fraud pattern is specific. Players may try to bypass self-exclusion blocks, open multiple accounts to abuse welcome bonuses, or use someone else’s identity to get around age or jurisdiction restrictions. A convincing deepfake, or even a fabricated image injected directly into the app without using the camera, can serve all of those goals at once.
- Brazil has made that more than a fraud problem. Law 14.790/2023 and SPA/MF Ordinance No. 1.231 require betting operators to prove user identity and legal age before allowing registration and financial movement. In that setup, weak facial verification is also a compliance risk.
- The common failure mode is simple: many betting platforms still compare a selfie to an ID photo without checking whether a real person is actually present in front of the camera. That approach can handle bad onboarding data, but it does not hold up against deepfakes, printed photos shown on another screen, or images injected into the app via emulators and virtual cameras.
- The key distinction is between PAD (presentation attack detection) and IAD (injection attack detection). PAD asks whether a real person is in front of the camera. IAD asks whether the image really came from the device camera. A platform that handles deepfakes but ignores injection still leaves the door open.
- The minimum mature setup for iGaming, according to industry specialists, includes three layers: biometric liveness detection that can catch deepfakes and masks, dedicated protection against image injection attacks, and device intelligence to identify emulators, root, and jailbreak before the camera capture even starts. The trick is to raise the bar for new sign-ups without turning routine reauthentication into abandonment at onboarding.
International references are starting to act as the market shorthand for what “good enough” means here: ISO/IEC 30107-3, iBeta PAD, BixeLab PAD and IAD, and the technical standard CEN/TS 18099 for injection attack detection. For PSPs and operators, that is useful not because certification solves fraud, but because it helps separate vendors that can actually survive a deepfake test from those that only look fine in a demo.
Weekly high-risk digest
Regulation, sanctions and payment news across your verticals — once a week, free.
Please check your inbox and click the link to confirm your subscription.
Please enter a valid email address!