Deepfakes and liveness spoofing are now the primary way fraudsters defeat facial verification systems used by African banks, fintechs, and government platforms. As biometric onboarding becomes standard across Nigeria and the wider continent, criminals have matched that shift with synthetic faces, cloned voices, and manipulated videos convincing enough to pass automated checks.
This is no longer an edge case confined to advanced fraud rings. It is a structural risk embedded inside cyberthreats in digital identity ecosystems, and it demands sustained attention from security and compliance leaders, not just technical teams working in isolation.
Southern African deepfake verification attempts climbed from under 200 a month in 2024 to more than 3,000 by the end of 2025. In South Africa, 22% of fraud cases now involve AI-generated impersonation, and nearly nine in ten rejected verification attempts trace back to spoofing or face-match failures.
Zambia recorded a 967% surge in deepfake attempts, while the Democratic Republic of Congo saw a 367% rise. Verification providers are responding with sharper investment in AI cybersecurity across Africa, aimed at catching AI-generated impersonation before it reaches account approval, particularly in high-volume onboarding channels.
Nigeria carries similar exposure. The country processes more than 10 billion real-time financial transactions annually, yet ranks 110th out of 112 countries for fraud protection, with a cybersecurity workforce gap of roughly 90%. That gap sits at the centre of ongoing cybersecurity threats in Africa, where fraud tactics are advancing faster than institutional defences and skilled staffing has struggled to keep pace with demand.
Liveness spoofing tricks a biometric system into wrongly accepting a fake image, video, or mask as a genuine, live person.
A presentation attack involves holding a physical or digital artefact, such as a printed photo, a mask, or a replayed video, in front of a camera. It exploits systems that rely on a single still image or short clip captured once at onboarding, with no ongoing checks afterwards.
An injection attack skips the camera entirely. Fraudsters intercept the data feed and insert synthetic or pre-recorded footage directly into the verification pipeline. iProov recorded a 1,151% rise in iOS-targeted injection attacks in the second half of 2025 alone, with 741% growth across the full year, and injection attacks are now treated as a central threat category because they bypass the camera altogether.
Human reviewers cannot reliably catch synthetic media. Veriff and Kantar, in a study, found human visual detection scores of 0.07 to 0.08, on a scale where zero represents chance. Separate research found that only 0.1% of participants could consistently identify a deepfake. Manual review alone is therefore not a reliable safeguard, and treating it as such creates a false sense of security.
Traditional identity checks verify a person once, at onboarding, then assume the risk is closed. That assumption no longer holds. Cyberthreats in digital identity ecosystems can re-emerge at login, during transaction approval, and during account recovery – stages that a one-time identity check was not designed to continuously protect, leaving periods in which identity-related risk may go unmonitored.
Independently certified presentation attack detection gives organisations a verifiable benchmark instead of relying solely on a vendor’s claim. Certification exposes a system to real spoofing methods, including masks, deepfake video, and screen replays, before it is trusted in production, reducing the chance of untested gaps reaching customers.
Effective defence does not stop at onboarding. Behavioural signals, device fingerprinting, and transaction context should combine with biometric checks to flag anomalies as they happen. This continuous model is where serious investment in AI-driven cybersecurity is now concentrated, treating detection as ongoing rather than a single gate at the start of a customer relationship.
Regulatory pressure is rising fast. The Central Bank of Nigeria issued 17 regulatory actions within 14 months covering cybersecurity, anti-money laundering, and data protection, with six compliance deadlines running from March 2026 to March 2028. Leaders overseeing cybersecurity in the banking sector in Nigeria should treat these deadlines as the most basic standard, not a ceiling to work towards gradually.
Procurement decisions carry equal weight. Security teams should require proof of certified spoof detection, injection attack monitoring, and independent audit results before signing any verification vendor. Given how fast cybersecurity threats in Africa shift, contracts should allow annual reassessment rather than locking in multi-year, unreviewed technology that ages quickly against new attack methods.
CyFrica 2026 brings together regulators, bank security leaders, and identity verification specialists dealing with deepfake fraud and other forms of digital identity abuse. Sessions will look at how cybersecurity in Nigeria’s banking sector is changing, what certified liveness detection involves in practice, and how financial institutions are responding to new regulatory requirements without adding unnecessary friction to customer onboarding.
For security, fraud and compliance leaders, hearing how those decisions are being made by the people responsible for security, identity and risk inside Nigerian institutions holds real practical value. Understanding what gets deployed, what gets rejected, where the difficult cases sit, and what happens when stronger controls collide with the realities of Nigerian digital banking is crucial now more than ever. CyFrica therefore offers the timely opportunity to examine those decisions directly, while the rules, technologies and threat landscape are still changing.
Register today!
What is liveness spoofing?
Liveness spoofing tricks a biometric system into falsely accepting a fake image, video, or mask as a genuine, live person.
How common are deepfake attacks in Nigeria’s financial sector?
Deepfake and injection attempts are rising sharply across African banking, mirroring regional surges recorded in Zambia, DRC, and South Africa.
Can people reliably detect deepfakes without technology?
No. Research shows unaided human detection performs close to random chance, making manual review an unreliable safeguard against modern fraud.
What makes injection attacks different from presentation attacks?
Injection attacks bypass the camera entirely, feeding fabricated data straight into verification software rather than displaying it to a lens.
How should banks respond to rising deepfake risk?
Banks should adopt certified liveness detection, monitor identity continuously beyond onboarding, and require proof of vendor performance against real attacks.