Jake Moore, Global Cybersecurity Advisor at ESET, conducted a series of experiments in April 2026 that shook the digital security industry. Using only off-the-shelf equipment and free software, he hacked three facial recognition systems – in a public place, a bank, and a railway station.
The study's findings, quickly picked up by The Guardian, BBC and Forbes, call into question the fundamental assumptions about the security of biometric data.
When a face is no longer proof of identity
Facial recognition is considered today one of the most reliable methods of identity verification.
Banks use it when opening accounts online, airports during passenger check-in, and city surveillance systems – to identify wanted individuals. Moore decided to check how justified this trust is. His conclusion after three experiments proved devastating: biometric systems are fragile in a way that has real consequences when someone decides to break them.
The study's findings were published by ESET on the WeLiveSecurity blog in March 2026 and presented as a live demo during the RSAC 2026 conference in San Francisco. The session bore the telling title: "Facing Reality: Hacking Facial Recognition". After this presentation, industry media almost unanimously recognized Moore's demonstration as one of the most important events of the conference.
Three experiments, three broken security measures
Each of the three tests concerned a different use case for facial recognition technology. Together they paint a picture of a security ecosystem with fundamental gaps – and, importantly, gaps accessible to anyone with a laptop and patience.
The first experiment concerned smart glasses. Moore bought a pair of Meta Ray-Ban glasses with a built-in camera, which he then paired with the commercial facial recognition system Corsight. Walking through a public space, he captured in real time the faces of people passing by and compared them with publicly available databases.
Within seconds, the system returned first names, surnames and social media profiles. Within 30 minutes, he managed to identify more than 10 people. Earlier, he had also conducted a simpler test – he uploaded a photo of the face of his acquaintance, lawyer Amy, to PimEyes, a publicly available face search engine, and within a dozen or so seconds obtained a list of places on the web where her image appears.
"Seeing is no longer believing. Identity verification systems must evolve quickly – and this is not a matter of the distant future." – Jake Moore, Global Cybersecurity Advisor, ESET.
The second scenario was aimed at the financial sector.
Moore created a fictitious identity: he forged an identity document using widely available graphic software, and then generated a synthetic face using an AI tool. The set prepared in this way was submitted to the eKYC system (electronic customer identity verification) of a certain bank – a system similar to those used by institutions such as HSBC or Revolut.
The biometric platform accepted the fictitious person as a real customer. The account was opened in less than 5 minutes. Moore immediately closed it and disclosed the gap to the institution, which has since blocked that particular attack path.
The third experiment took place at London's Waterloo railway station. In cooperation with the facility's security services, Moore added himself to the list of people monitored by a surveillance system based on Corsight – the same software used by British police.
He then walked through the monitored zone, running real-time face-swapping software that, in the camera's view, replaced his face with the image of Tom Cruise. To human operators, the CCTV footage looked completely normal. To the algorithm – Moore was not Moore. The system did not detect him. The alarm did not go off.
The cheapest tools, the greatest threats
What makes the experiment's results particularly alarming is the simplicity of the means used. Moore did not use advanced laboratories or costly military equipment. Smart glasses cost a few hundred dollars and are available in retail sales. Face-swapping software such as DeepFaceLive or Faceswap is free.
Synthetic face generators – such as the website ThisPersonDoesNotExist – are available to anyone in a web browser. The virtual camera OBS Studio with the Roop module allows real-time video signal manipulation using a single photo.
"The market adopted facial recognition technology too quickly.The attacks I carried out do not require expensive equipment or specialized knowledge – a laptop and widely available software are enough."
– Jake Moore, Global Cybersecurity Advisor, ESET.
The expert pointed out that the current architecture of identity verification is structurally broken.
Faces and voices are easy to fake because most systems rely on weak liveness detection mechanisms – verification of whether a living person is standing in front of the camera, rather than a digital copy of them. Meanwhile, behavioral and cryptographic signals are almost entirely omitted.
How facial recognition was hacked in practice
Global context: a multi-billion-dollar market, vulnerability measured in percentages
Moore's experiment fits into the broader picture of a crisis of trust in biometric technologies.
According to NIST (National Institute of Standards and Technology) data from the FRVT 2025 report, the accuracy of the best facial recognition algorithms exceeds 99% for clean test data – but drops to 80-90% under deepfake attacks or in low light. In other words: the technology is nearly flawless in laboratory conditions and unreliable precisely when someone is actively trying to break it.
The global facial recognition market is valued at $7 billion in 2026 (Statista data) and covers more than 50 countries. However, according to the Deepfake Detection Challenge 2025 report, face-swapping software bypasses biometric systems with effectiveness at the level of 70-95%. In turn, iProov – a company specializing in detecting synthetic identities – indicates in a 2026 report that AI models generate faces indistinguishable from real ones in more than 90% of test cases.
The scale of abuse is already visible in regulators' data. The FCA (Financial Conduct Authority) in the United Kingdom recorded an increase in bank fraud using deepfakes of more than 300% compared with 2024. In Poland, the situation is regulated by a combination of GDPR and the incoming AI Act, which from 2026 requires the implementation of liveness detection mechanisms in biometric verification systems.
Nevertheless, according to UOKiK data, as many as 40% of banking systems used in Poland have not implemented this protection.
Experts: This is not a problem of technology, but of trust
The revelations from Moore's experiment confronted the industry with a question that – as the discussions after RSAC 2026 showed – had been asked for a long time, but too rarely out loud: do we implicitly assume that facial recognition technology is secure because its manufacturer says so? The answer is: yes, and that is the fundamental mistake.
"Facial recognition systems are deployed with a default trust that does not match their actual resistance to intrusion attempts – even using store-bought equipment and freeware software." – Tomáš Foltýn, editor of WeLiveSecurity, ESET.
Similar observations are made by the biometrics research community.
Standards such as ISO 30107, concerning presentation attack detection (photos, video replay), assume effectiveness at the level of 20-40% – which means that even with full compliance with the norm, one in three attack attempts may succeed. When deepfakes come into play, the numbers become even more alarming.
Security experts consistently point out that the key solution is the zero-trust biometrics approach – a strategy promoted by, among others, ESET. It means abandoning the treatment of the face as the sole and sufficient identity signal in favor of multi-layered verification. Multi-factor authentication (MFA) should be the standard, not an option.
Polish financial institutions, such as mBank or PKO BP, are already testing hybrid solutions combining facial recognition with behavioral biometrics – analysis of behavioral patterns such as mouse movements or the way a mobile device is held.
Consequences for companies and marketers: risk and opportunity at the same time
Moore's experiment has significant implications not only for IT and compliance departments, but also for marketers and communication strategists. Growing awareness of gaps in biometrics translates into concrete consumer trends: trust in digital identity verification services is falling, and demand for transparent communication about security methods is rising.
Cybersecurity education campaigns are seeing increased engagement – the hashtag #FaceTheft on platforms such as TikTok or Instagram Reels generated in the weeks after RSAC 2026 25% higher engagement than typical tech-category content. At the same time, social media platform algorithms are fighting deepfakes more aggressively: Meta blocks an estimated 80% of such materials, while TikTok – about 60%.
For companies offering security solutions or handling customer data in digital channels, the experiment is both a warning and a starting point for building a communication advantage. Transparency regarding the identity protection methods used and proactively informing customers about risks and safeguards are becoming part of reputation management – not just a regulatory obligation.
- Use multi-factor authentication (MFA) as a standard, not an optional supplement – especially in loyalty and e-commerce apps
- Verify biometric system vendors for liveness detection implementation compliant with AI Act requirements
- Regularly test identity verification systems under simulated attack conditions – so-called red teaming
- Build educational campaigns informing customers about deepfake threats and ways to protect their biometric data
- Monitor indicators: the percentage of fraud attempts using synthetic identities, the effectiveness of liveness check, the system's response time to anomalies
ESET
ESET is a European cybersecurity leader headquartered in Bratislava, founded in 1992. The company employs more than 2,000 specialists and protects more than 110 million users in 200 countries. It is the creator of the popular antivirus ESET NOD32 and an extensive ecosystem of security solutions for businesses and consumers.
ESET is known for aggressive research into digital threats – including, among others, the discovery of the Industroyer malware that attacked Ukrainian energy infrastructure. The WeLiveSecurity platform is one of the most respected cybersecurity blogs in the world, awarded by industry organizations from the USA, Europe and Asia.
Read also:
- mBank – Cyber fraudsters don't take holidays. A summer thriller enters the "Self-Defense Online" campaign
- Empik denies information about a customer data leak
- ARKEUS – Raises €15.5 million for a revolution in AI perception. "Machines still operate by trial and error. This is exactly the problem we decided to solve"