Spanish police say a suspect tried 38 times to impersonate 30 people and obtain digital identity certificates in their names, succeeding multiple times. Investigators say he targeted a certificate issuer’s live video identity checks using forged documents, altered photos, real-time deepfake face swapping, custom lighting to mimic document holograms, VPNs, and more than 320 phone lines allegedly tied to stolen identities. Police arrested him after a brief deepfake failure exposed his real face during verification.
Why it matters: Fraudulently issued digital certificates can let criminals sign documents, authenticate as victims, and carry out follow-on fraud with a high level of trust. Certificate issuers and identity-verification providers should review liveness checks and document-validation controls, while affected users should watch for account or administrative activity in their names.
2026.08.11
100% relevant
This article establishes a distinct law-enforcement case centered on deepfake-enabled digital certificate fraud, not an update to an existing tracked event.
← Back to all stories