SardineCon SF/2026

Learn More

What is Morphing attack?

SUBSCRIBE

A morphing attack blends two or more faces into one document photo so the ID matches multiple people. A single genuine-looking document can then serve several accomplices and quietly defeat face match, usually by slipping the morphed image in at enrollment before any downstream check can catch it.

What is a morphing attack, in plain English?

A morphing attack takes two or more real faces and blends them into a single photo that looks like a plausible person while sharing enough features with each contributor to match all of them. That morphed image is then used as the photo on a document. The result is one genuine-looking ID that a face match will accept for multiple different people.

The clever part is where it strikes. A morph usually enters at the enrollment or document-issuance stage, when a photo is submitted to obtain a real, officially issued document. If the morph passes there, the fraud is baked into a legitimate credential before any downstream verification runs, so later face-match checks compare a live person against an image built to match them.

In fraud and AML, morphing is dangerous precisely because an ordinary face match can pass it. Catching it needs morph-specific analysis of the image, and, where possible, comparing the signed chip photo against the printed one, since a morph submitted at issuance can sit inside an otherwise valid document.

How a morph gets in and pays off

  1. Blend — Create the morph. Two or more faces are merged into one image that resembles each contributor.
  2. Enroll — Submit at issuance. The morph is used as the photo when applying for a real, officially issued document.
  3. Share — One document, several people. Because the photo matches multiple faces, accomplices reuse the same genuine document.
  4. Pass — Defeat face match. Each accomplice clears an ordinary face-match check against the morphed photo.
    • Caught — Morph analysis or chip check. Morph-specific detection or comparing the chip photo to the print exposes the blend.
    • Missed — Plain face match only. A standard match accepts the morph, so several people pass on one document.

Who is involved?

Who

Their role

The accomplices

Two or more people who contribute faces and share the resulting document.

The issuer

The agency that accepts the morphed photo and issues a genuine document around it.

The verifier

Your onboarding flow, where each accomplice tries to pass a face match against the morph.

The fraud team

Adds morph detection and chip-to-print comparison to catch what face match cannot.

What it looks like in practice

In practice

Two people who look somewhat alike blend their faces into one photo and use it to obtain a genuine passport at issuance. The document is real, officially printed, with a valid strip and chip. Nothing about the paper is fake; only the photo is a composite.

Both accomplices later open accounts at your service, each submitting a selfie against that same passport. The face match clears both, because the morphed photo was built to resemble each of them. The pattern only surfaces when an analyst notices two different live faces passing against one document image, and a chip-to-print comparison reveals the blend.

Why it matters to operators

Morphing quietly breaks the assumption that one document equals one person. Because the fraud is embedded in a genuinely issued credential, every standard check downstream can pass it, and each accomplice looks like a clean, verified customer. That makes it a favorite for building multiple trusted identities off a single real document.

Standard face match will not save you here, since the morph is engineered to match each contributor. The defenses that work are morph-specific image analysis and, where the document supports it, comparing the signed chip photo against the printed one. Watching for one document image passing more than one live face is a practical detection signal too.

What to watch in the data

  • One document, many faces. The same document image passing face match for more than one live person is the core morphing signal.
  • Blend artifacts. Subtle ghosting, doubled edges, or unnatural symmetry around the eyes and hairline can betray a morphed photo.
  • Chip versus print gap. A signed chip photo that differs from the printed image points to a morph introduced at issuance.
  • Borderline matches from lookalikes. Accounts with similar-looking applicants clearing against one document warrant a closer look.
  • Genuine document, odd photo. A real, valid document whose photo fails morph analysis is a strong case to hold.

Quick questions

Why can a normal face match not catch a morph?

Because the morph is deliberately built to share features with each contributor, so it genuinely matches all of them. A standard match sees a legitimate similarity and passes, which is exactly what the attack exploits.

Where does a morphing attack usually happen?

At the enrollment or document-issuance stage, when a photo is submitted to obtain a real document. If the morph passes there, it becomes embedded in an officially issued credential before any downstream check runs.

How do you detect a morph?

With morph-specific image analysis that looks for blend artifacts, and, where the document supports it, comparing the cryptographically signed chip photo against the printed one. Watching for one document matching multiple live faces also helps.

Is the document itself fake?

Often not. In the strongest version, the document is genuinely issued and only the photo is a composite. That is what makes morphing so effective, since the paper, strip, and chip can all be authentic.

How does a morph differ from a deepfake?

A morph blends real faces into a static photo used on a document. A deepfake generates or manipulates video or images of a face, often in real time. Morphing targets the enrollment photo; deepfakes usually target the live capture.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

What to know alongside Morphing attack