BSI Explores Increased Biometric Risks Linked to AI, High-Resolution Photography, and 3D Printing

In a recently issued alert, Germany’s Federal Office for Information Security, commonly known as BSI, has underscored the escalating risks associated with the reliance on fingerprint biometrics for unlocking smartphones and accessing sensitive applications. This warning comes in light of advancements in high-resolution photography, artificial intelligence (AI), and 3D printing technologies, which together present a formidable threat to biometric security.
BSI’s cautionary statement, made via a social media post, highlighted a troubling reality: “Your fingerprint is online, without you knowing.” The agency elaborated that even seemingly harmless images, such as one depicting an individual making a “peace” gesture, could provide sufficient visual cues for cybercriminals. These malicious actors could deploy AI tools to extract the fingerprint from such images, subsequently utilizing 3D printers to create a counterfeit fingerprint capable of bypassing biometric authentication systems.
BSI officials expressed concerns over the increasing quality of photographs found online, which makes it easier for attackers to orchestrate such impersonation efforts. Consequently, victims are advised to think twice before posting images that reveal details about their fingertips. Additionally, limiting the resolution of photos and videos can further reduce the chances of fingerprint extraction.
The agency strongly recommended that individuals relying solely on fingerprint biometrics for accessing banking applications or password management tools reconsider their security strategies. Unlike passwords, which can be changed when compromised, fingerprints are irreplaceable. Hence, BSI advocates transitioning to a multifactor authentication model that incorporates passwords or personal identification numbers (PINs) alongside biometric verification.
A spokesperson from BSI clarified to ISMG that the post served as an educational initiative aimed at raising awareness regarding the inherent vulnerabilities associated with biometric authentication. The spokesperson elaborated that “criminals can utilize a representation of a fingerprint to fabricate a synthetic version that closely resembles the actual fingerprint, enabling potential access to smartphones lacking advanced security features designed to detect such counterfeit prints.”
While Apple has phased out fingerprint readers in favor of its Face ID technology, many manufacturers continue to include fingerprint scanners in their devices. Security researchers have begun demonstrating the feasibility of bypassing these systems. For instance, in 2020, Cisco Talos research teams conducted a study that revealed they could use 3D-printed fingerprints to overcome biometric security measures across various devices, achieving an 80% success rate at least once with certain models. Notably, they found particular vulnerabilities with ultrasonic sensors, which utilize sound waves to create 3D images of fingerprints and are currently popular among manufacturers.
This research particularly targeted the first generation of Qualcomm’s 3D Sonic Sensor, which the company claimed could counteract spoofing by identifying blood flow in the user’s fingertip. Following this, Qualcomm released a second generation of the sensor, although there is little evidence regarding its vulnerability status compared to its predecessor, especially in high-end smartphones.
Moreover, BSI is not operating in isolation on this front; it plays an active role in the ongoing research surrounding biometrics, jointly operating Germany’s Biometrics Evaluation Center (BEZ) and collaborating with the Institute for Security Research at Bonn-Rhein-Sieg University of Applied Sciences. The BEZ focuses significantly on identifying techniques to detect spoofing attempts, employing groundbreaking methods for testing biometric authentication systems used in smartphones.
Recent explorations at the center include the application of optical coherence tomography (OCT), a light-based technique typically utilized in medical imaging, which has shown potential for creating highly detailed fingerprints and could render traditional spoofing methods less effective.
Fingerprint biometrics have been fraught with political sensitivity in Germany, shaped largely by historical experiences with invasive surveillance. Notably, the hacking collective Chaos Computer Club famously demonstrated biometric vulnerabilities nearly two decades ago when they lifted the fingerprint of then-Interior Minister Wolfgang Schäuble from a glass and made it public. This act sparked widespread debate regarding the implications of biometric data collection.
In subsequent years, hacker Jan “Starbug” Krissler successfully reproduced the fingerprint of former Defense Minister Ursula von der Leyen using high-definition photographs, showcasing significant risks associated with publicly available images. Such incidences underscore ongoing vulnerabilities as technological sophistication increases, prompting critical discourse about privacy and security.
While Germany’s biometric databases have seemingly remained unbreached, numerous incidents worldwide have exposed sensitive biometric data. Earlier this year, the U.S.-based NYC Health reported a breach affecting nearly two million patients, potentially compromising their fingerprints and palm prints, sparking alerts within the community regarding the safety of biometric information.
Additional high-profile breaches, including those affecting the U.S. Office of Personnel Management and South Korean biometric vendor Suprema, have highlighted vulnerabilities in the handling of irreplaceable biometric data, raising questions about security practices and data management in the face of evolving technological threats.

