Connect with us

NEWS

Google Adds Selfie Video Sign-In as Deepfake Fraud Surges

Google’s selfie video sign-in fights AI impersonation, even as deepfake rings already beat identical liveness checks at banks in Vietnam and Indonesia.

Published

on

Google will now let people unlock a locked account with a video of their own face. The company said this week that eligible users can record a short reference clip of guided head turns, then use a live version of that same clip later to sign in or recover an account when passwords, phones and two-factor codes are not an option.

Fraud researchers have spent the past year documenting deepfake rings that already beat this exact style of face-and-movement check at real banks, from Hanoi to Jakarta. Google’s own consent language, meanwhile, leaves the door open to reusing that same recording to train its future facial recognition and age-estimation tools.

How the Selfie Video Sign-In Works

The feature is called selfie for sign-in. Setup happens once, inside a user’s account settings, where guided prompts ask someone to turn their head in different directions while the camera records.

Google’s own announcement frames it as an extension of work the company has already done on passkeys and recovery contacts. When someone gets locked out later, they record a fresh clip, and Google compares it against the saved reference video before granting access back into the account.

Liveness detection sits at the center of the design. Users have to perform specific, unpredictable movements on request, a defense meant to rule out a static photo or a looping video someone holds up to a camera. Google has said its systems also look for signs of impersonation, including AI-generated or manipulated video, before trusting a match.

The company is rolling the option out gradually to eligible personal accounts worldwide, and a computer without a built-in camera can still be used by scanning a QR code that hands the recording step off to a phone.

Selfie video joins a recovery toolkit that already includes passwords, recovery phone numbers, trusted contacts and passkeys, each with its own weak spot.

Recovery Method How It Confirms You Known Weak Point
Password Matches a memorized string Phished, reused or guessed
Recovery phone number Sends a one-time code by text message SIM-swap takeover
Trusted contact A person you named approves the request Slow, depends on a cooperative contact
Passkey Cryptographic key stored on a trusted device Useless once that device is lost
Selfie video Matches live head movement to a saved reference clip Targeted by deepfake and camera-injection attacks, fraud researchers say

Each method covers a gap the others leave open. Selfie video is pitched as the layer for the worst-case scenario: no phone, no trusted device, no memory of a password.

The Fine Print on Reusing Your Face

Storage is where the feature gets more complicated. Google stores the reference recording only after a user consents, and it can be deleted at any time through account settings, according to the company.

Multiple layers of security help prevent impersonation attempts like fake photos and videos.

Google said in the blog post announcing the feature. The company has also said the recording will not be used beyond authentication unless a user separately agrees to other uses. That separate consent screen is doing a lot of work. As reported by The Hacker News, Google’s own language tells users the data can go toward efforts to

develop and improve facial recognition, age estimation, and other verification methods

if they opt in, a use case entirely distinct from simply signing back into a locked account. In other words, the same clip a user records to get back into Gmail can, with one extra toggle, become training material for Google’s next identity-verification model, or for building a personal AI avatar in that user’s likeness. Nothing about that reuse is forced. But it sits right next to the sign-up flow for a feature most people will click through in under a minute.

India Is Ground Zero for Deepfake Fraud

The launch lands in a country, and a region, already living through a deepfake fraud surge. Indians lost roughly 22,495 crore rupees, about $2.7 billion, to cyber fraud in 2025, with reported cases jumping 24% to about 2.8 million, according to Ministry of Home Affairs and Indian Cyber Crime Coordination Centre data.

Deepfakes are a growing slice of that picture. Research from the Observer Research Foundation found that 47% of Indian adults have either been victimized by, or personally know a victim of, an AI voice-cloning or deepfake scam, nearly double the 25% global average. Among Indian victims of AI voice scams specifically, 83% lost money, and almost half lost more than fifty thousand rupees.

The raw volume of fake material is climbing fast too. India’s Cyber Crime Coordination Centre and industry estimates put the country on track for roughly 8 million deepfake files in 2025, up from about 500,000 in 2023, a jump of nearly 900% in two years.

The Same Trick Is Already Beating Banks

This is not theoretical for the banking sector. Liveness checks built on head turns and blinking, the same basic idea behind Google’s new feature, have already been beaten in production fraud, not lab demonstrations.

  • $38.4 million laundered by a 14-person ring Vietnamese authorities dismantled in May 2025, after it used AI-generated face biometrics to slip past bank facial recognition checks.
  • 8,065 attempts to defeat one financial institution’s liveness checks using AI-driven biometric injection between January and August 2025, tracked by threat-intelligence firm Group-IB.
  • $138.5 million in potential losses tied to more than 1,100 deepfake attempts that bypassed digital KYC checks at a single Indonesian financial institution over three months, per Group-IB’s research.
  • 1,100% jump in deepfake fraud attempts industrywide during the first quarter of 2025 alone.

Identity verification firm Sumsub reported that synthetic identity document fraud in North America also rose 311% year over year in the same period. The World Economic Forum’s Cybercrime Atlas, published in January 2026, tested seventeen face-swapping tools and eight camera-injection tools and concluded that even moderate-quality fakes, combined with software that injects a fabricated video feed in place of a real camera, can already deceive certain biometric systems. The Financial Action Task Force said plainly in a December 2025 report that fraud detection has not kept pace with generative AI, warning that deepfakes can pass through liveness and biometric checks and only trigger alarms once money has already moved.

Google Has Paid for Faces Before

Google is not new to the legal risk that comes with storing biometric data at scale. In 2022, it agreed to pay $100 million to settle an Illinois class action over Google Photos, which had quietly built facial geometry templates, sometimes called faceprints, from users’ uploaded pictures without the consent Illinois law requires.

Ahdoot Wolfson, the law firm that led that case, secured the payout along with limits on how long Google could keep collecting and storing facial biometrics. Google was far from alone.

Company Settlement What Was Collected
Google (Google Photos) $100 million, finalized 2022 Facial geometry templates built from users’ uploaded photos
Meta (Facebook) $650 million Facial-recognition tag suggestions across users’ photos
Instagram $68.5 million Facial-recognition tagging active through November 2021
Snap $35 million Biometric privacy claims under Illinois’ BIPA law
Google (Workspace for Education) $8.75 million, 2025 Voice Match and Face Match models built from students’ accounts

Illinois remains one of only two states, alongside Texas, with a law strict enough to force payouts like these. Selfie video sign-in is opt-in and consent-gated by design, which is very likely a direct response to that legal history. It still means Google is once again asking users worldwide to hand over exactly the kind of data that has cost it, Meta, Snap and Instagram a combined total well north of $850 million in Illinois alone.

The Accounts This Feature Skips

Selfie video sign-in is not available everywhere yet. Google Workspace accounts, child accounts and any account enrolled in the Advanced Protection Program, Google’s own toughest security tier for people it considers likely targets, cannot use it at launch.

That leaves the feature rolling out first to the broadest, least specialized slice of Google’s user base, ordinary personal accounts, rather than the enterprise and high-risk accounts Google itself treats as needing the most protection. Google continues to recommend layering multiple recovery methods, including backup codes and recovery contacts, rather than relying on any single option alone.

Frequently Asked Questions

How do I set up Google’s selfie video verification?

Go to Security and sign-in in a Google Account, choose Selfie video, and follow the guided head-turn prompts. If a computer has no built-in camera, the setup can be finished by scanning a QR code that shifts the recording step to a phone instead.

Can a deepfake actually fool Google’s selfie video check?

Google has not disclosed any confirmed bypass of its own system. Fraud researchers have already documented deepfake rings defeating comparable liveness checks at banks in Vietnam and Indonesia, so the underlying technique has proven effective elsewhere, even without a documented case against Google specifically.

Is the saved selfie video encrypted?

Yes. Google stores the reference recording in encrypted format at rest and says it is used only to help with sign-in and recovery unless a user separately opts in to other uses.

Can my selfie video be used for anything besides signing in?

Only with a separate opt-in. Google’s consent settings note the recording can otherwise support efforts to improve facial recognition and age-estimation tools, or even help build a personal AI avatar based on a user’s face, but only when a user actively agrees to that additional use.

What is Google Cloud’s new hand gesture reCAPTCHA?

It is a related but separate tool from Google Cloud Fraud Defense that asks users to perform simple hand gestures on camera to pass a reCAPTCHA check, replacing the traditional image-selection puzzles most people are used to.

Does selfie video sign-in replace two-factor authentication?

No. Google positions it as an additional recovery path for situations where standard two-factor authentication, a trusted device or a recovery phone are unavailable, not a replacement for those layers.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending