\
Insight
\
New Gartner® report — Reality Defender is named a Market Shaper in deepfake detection, as of June 2026.
Get the report\
Insight
\
Dharva Khambholia
QA Engineer
A live person completed Google’s liveness test using a deepfake. Under the conditions we tested, the deepfake enrollment succeeded.
On July 23, 2026, Google introduced selfie video as an account-access and recovery option for eligible personal Google Accounts. During setup, a user records a short video while following guided head-movement prompts. Google stores that video as a reference and may compare it with a new recording if the user later needs help signing in.
Google says the feature uses multiple layers of security to help prevent impersonation with fake photos, videos, and deepfakes. For Reality Defender’s red team, that raised a straightforward question:
Can a system confirm that an interaction is live without confirming that the face it sees is authentic?
We conducted a controlled assessment to find out.
Our red team used an eligible personal Google Account owned and controlled by Reality Defender. No third-party accounts were involved.
A team member entered the selfie-video enrollment flow and responded to Google’s instructions in real time. When prompted to center or move their head, the operator performed the requested movement.
At the same time, commercially available real-time face-swap software transformed the operator’s appearance into that of another person. The manipulated stream was then presented to the enrollment flow as camera input.
The distinction is important: the operator was real, the interaction and movements were live, but the visible identity was synthetic.
We did not develop a custom deepfake model, exploit Google infrastructure, or build purpose-made attack software. Because this research may expose a security weakness, we are not publishing the names of the tools, their configuration, or the precise method used to deliver the transformed stream.
The real-time transformation followed the operator’s movements as they completed the on-screen challenge. Google’s enrollment flow accepted the presentation and registered the synthetic face as the selfie-video reference associated with the company-controlled test account.
We conducted two complete enrollment attempts, and both succeeded. The tests were performed in Microsoft Edge on a Windows 11 laptop equipped with an NVIDIA GPU, using commercially available real-time face-swap software and camera-input manipulation techniques.
Under the conditions tested, a live operator was able to enroll a face that was not their physical face in two out of two attempts.
This demonstrates repeatability in that environment, but it does not establish a universal success rate across other accounts, devices, browsers, regions, or account-risk conditions.
Liveness checks are designed to establish that an interaction is happening in real time. Guided movements can help reject basic attacks such as a static photograph or simple replay.
Real-time face transformation changes that threat model. A live operator can respond to unpredictable instructions while software changes the identity presented to the system. The resulting video can contain genuine, prompt-responsive movement without being an authentic representation of the person performing it.
That leaves identity systems with two separate questions:
In our test, the answer to the first question was yes. The answer to the second was no.
The finding also highlights the importance of capture provenance: understanding where media originated and what happened to it before reaching the verification service.
The security boundary does not end at the face. It includes the camera, operating system, media-processing layer, browser or application, and the path used to deliver the video. Manipulation introduced anywhere along that path can change what the system ultimately receives.
Our finding is specific:
Under the tested conditions, Google’s selfie-video enrollment flow accepted a real-time synthetic facial presentation while a live operator completed the required movement challenge.
It does not demonstrate arbitrary takeover of Google Accounts, recovery of an account belonging to another person, or defeat of every security and risk signal Google may apply.
We did not access another person’s account, steal credentials, obtain private user information, or interfere with Google services. This is also an account-access and recovery feature, not a KYC process that verifies a government identity.
Enrollment integrity still matters because the saved video becomes a reference the system may rely on later. If manipulated media can be registered at that stage, the system may anchor future comparisons to a synthetic representation rather than an authentic physical capture.
We have not established that a different operator could later use that representation to recover the account. That would require separate controlled testing.
No single control is likely to stop every real-time synthetic-media attack. More resilient systems combine independent signals, including:
Reality Defender develops deepfake-detection technology that identity-verification and fraud-prevention providers can use as an additional signal in this broader decision stack.
We do not believe any single detector—or any single security control—should be treated as a complete solution.
The wider lesson is not that selfie-based recovery is unworkable. It is that the threat model has changed. A person can be present, attentive, and moving correctly while the identity visible to the system is transformed in real time.
Liveness remains valuable. But liveness alone is no longer enough.
This assessment was conducted on a company-controlled account. No third-party accounts or user data were accessed.
We are withholding operational details that would materially simplify reproduction.
\
Insights