IDEMIA WebCapture Passed Biometric Security Audit

The software blocked all attempted injection attacks, meeting standardized benchmarks for biometric defense.

Updated on Oct. 5, 2026 in Cybersecurity

Bold flat-color editorial illustration of a silicon wafer on a plinth, representing the precision of biometric security software.
IDEMIA’s WebCapture software passed a biometric security audit by BixeLab, confirming its resilience against 900 simulated digital injection attacks. AI Illustration. Upload story photo >

Live Poll

Do you trust the security of remote biometric verification systems to keep your identity information safe?

BixeLab tested IDEMIA WebCapture version 3.38 for biometric injection defense, finding that the software successfully blocked 900 simulated attacks. This assessment evaluated the system against recognized cybersecurity specifications.

Why it matters

As biometric systems increasingly secure sensitive infrastructure, testing against objective specifications provides evidence of resilience against evolving spoofing techniques. This assessment confirms the software's performance in preventing unauthorized access attempts.

The laboratory evaluated IDEMIA WebCapture version 3.38 against CEN/TS 18099:2024 Level 2 requirements. The assessment covered 10 distinct species of injection attack instruments, including deepfakes and face swaps.

The players

BixeLab

An independent testing laboratory specializing in the verification of biometric security systems and anti-spoofing performance.

IDEMIA Public Security

A provider of identity-related security technologies and biometric capture systems currently deployed across 600 government and commercial agencies.

The details

BixeLab evaluated the software by simulating various methods used to inject unauthorized biometric data into the system, including sophisticated digital manipulations. The assessment utilized 10 different attack instrument species to ensure the system could correctly distinguish between legitimate user data and forged inputs. This process ensures the system meets the rigorous security standards defined by the European Committee for Standardization technical specification for biometric presentation attack detection.

Timeline

  1. October 5, 2026: Official publication of the assessment results.

The Tech Race

The assessment follows the adoption of the CEN/TS 18099:2024 standard, which creates a unified benchmark for testing biometric injection defenses. This validation moves the industry toward objective verification, distinguishing software that meets international performance levels from unverified security claims.

The performance metrics achieved here serve as a technical baseline for agencies utilizing IDEMIA systems for identity verification. Users interacting with these platforms can expect a system that prioritizes lower classification error rates while maintaining high security against sophisticated spoofing.

The takeaway

Reliable biometric defense now hinges on standardized, third-party audits against defined attack species like deepfakes. Professionals should watch for future audit results as biometric vendors continue to update software to address evolving synthetic presentation attacks.

Further reading

For more information on evolving standards in digital identity, visit the Cybersecurity section.

Live Poll

Do you trust the security of remote biometric verification systems to keep your identity information safe?