APromptRiskDBThreat intelligence atlas
AI Case Study

Camera Hijack Attack on Facial Recognition System - AI Case Study

This type of camera hijack attack can evade the traditional live facial recognition authentication model and enable access to privileged systems and victim impersonation. Two individuals in China used this attack to gain access to the local government's tax system. They created a fake shell company and sent invoices via tax system to supposed clients. The individuals started this scheme in 2018 and were able to fr...

IncidentShanghai government tax office's facial recognition serviceTwo individualsResource DevelopmentReconnaissanceAI Model Access

Overview

Case steps8Steps described in the case record.
Techniques8Attack methods mentioned in the case steps.
Linked CVEs0Known vulnerabilities mentioned in the record.

Risk patterns

Patterns found in the case record and its linked vulnerabilities.

  • 1Dominant ATLAS tactic. Resource Development appears in 4 case steps.
  • 2Multiple attack methods. The case connects to 8 unique AI attack methods.

Procedure timeline

Search the case steps or filter them by attacker goal.

Resource Development4Reconnaissance1AI Model Access1Initial Access1Impact1
  1. Initial Access

    The attackers successfully evaded the face recognition system. This allowed the attackers to impersonate the victim and verify their identity in the tax system.

  2. Impact

    The attackers used their privileged access to the tax system to send invoices to supposed clients and further their fraud scheme.

Mitigations

Defenses connected to the attack methods in this case.

Sources

Original public records and references for this case.