Verdict: True

Quick Answer: On many phones, yes — a printed photo can unlock cheap 2D face systems in seconds. So can facial recognition be fooled by a photo? It depends on your handset. Basic 2D cameras get tricked too easily. Proper 3D systems, like Apple Face ID, use depth sensors and liveness checks a flat picture can’t beat.

KEY POINTS
  • Which? tested 208 phones since October 2022, and 133 (64%) unlocked with a 2D-printed photo.
  • Failures hit 53% in 2023, peaked at 72% in 2024, then settled near 63% in 2025.
  • Apple Face ID, the newest Google Pixels and the Galaxy S26 passed the test.
  • Face unlock is for convenience. Use a fingerprint or PIN for anything serious.

How Facial Recognition Actually Works

Your phone never keeps a photo of your face. A camera grabs your image, and the software finds landmarks like your eyes, nose and mouth, turning them into a string of numbers called a template, a maths fingerprint. To let you in, it compares your live face with the saved one.

McAfee states that top-brand phones keep this template in secure hardware, not the cloud, so there are very few chances to steal it in a breach. Digital Sense explains that your face is converted into a list of numbers. If two lists are identical, often around 0.5, it’s a match.

Also Read: Does Incognito Mode Really Hide Your Browsing History?

Can Facial Recognition Be Fooled by a Photo?

For millions of handsets, yes. Which? has tested phones for years, and the numbers aren’t pretty.

Year Phones fooled by a photo
2023 53%
2024 72% (the peak)
2025 About 63%
Overall since Oct 2022 64% — 133 of 208

And it’s not just cheap phones. As ITVX News reported, the £1,000-plus Oppo Find X9 Pro got fooled, along with Samsung’s old Galaxy S25 range, the Honor 70, various Motorola, Nokia and Xiaomi models, and even the £949.99 Motorola Razr 2022.

A voluntary rule from the European Telecommunications Standards Institute says a 2D system shouldn’t be duplicated more than 1 in 50,000 times. The brands do warn you: Samsung says its fingerprint reader is top-tier and face unlock can’t open Samsung Wallet, while Motorola, OnePlus and Honor flag it as less secure and push a PIN or a 3D pro model.

Why Cheap 2D Systems Fail

A basic system takes one flat snap from the front camera — no depth, no clue whether it’s a real person or a printout. So the photo waltzes through.

3D systems differ. They fire thousands of invisible infrared dots to map the real shape of your face, so a flat photo flops instantly.

Google backs this up. Android grades biometrics into classes: Class 3 (the strong stuff) can be fooled 7% of the time or less, while Class 1 (the weakest) fails 20% or more. Most photo-beaten phones sit in Class 1, so apps and banks won’t trust them.

Also Read: Is 5G Actually Harmful to Health? What the Science Says

How Liveness Detection Fights Back

The defence is liveness detection: it checks that you’re a real, breathing human. The passive kind studies skin texture, reflections and micro-movements a screen can’t fake; the active kind asks you to blink, smile or turn your head.

But attackers adapt. The researchers at Securing bypassed the bank check with a printed paper mask. For complicated cases, they used the open-source faceswap tool to drop a deepfake face into the video. Their blunt advice: run every check on the server; never trust the phone alone.

The Banking and Fraud Risk

Unlock someone’s phone with a photo and they’d never know — most apps stay logged in, so a thief strolls into your emails, wallet and saved cards. That’s why UK banks rarely rely on face unlock alone — many only allow it on iPhones, then add liveness tests or extra passwords for risky moves like new payments.

Wallet apps need care too — Google Wallet lets you tap-and-pay up to £45 without unlocking and may still reveal who you bank with. Bias is a worry too: the National Institute of Standards and Technology (NIST) found accuracy varies across systems and groups, leaving some people wrongly flagged.

Where Else Facial Recognition Shows Up

It’s spreading fast. It is being used at airport passport gates, police investigations, office door access and shop loss prevention. That last one can backfire: in 2024 the FTC banned Rite Aid from AI surveillance for five years after wrongly branding shoppers as shoplifters.

And beware “surveillance creep” — billions of images scraped from social media. Unlike a password, you can’t change your face.

How to Protect Yourself

Switch off face unlock on any affected phone and use a fingerprint or a long PIN — six digits beat four. Lock sensitive apps separately, keep your face data on the device, and add a second lock to Google Wallet. On an iPhone, wipe your data via Settings, Face ID & Passcode, and then Reset Face ID.

For your online photos, the SAND Lab at the University of Chicago built a free tool called Fawkes. It “cloaks” pictures with tiny pixel tweaks to confuse recognition models. It’s not flawless – tests found that cloaked and normal photos still matched closely – but it’s a start.

Also Read: 8 Mixed Reality Experiences You Need to Try in the UK Right Now

Final Verdict

So, can facial recognition be fooled by a photo? On most budget and mid-range Android phones, yes, a simple printout does the trick. On 3D systems like Apple Face ID, the latest Pixels and the Galaxy S26, no chance. If your phone uses basic 2D face unlock, turn it off — a fingerprint or solid PIN keeps your stuff far safer.

Frequently Asked Questions

Can facial recognition be fooled by a photo on an iPhone?

Ans: No. Apple Face ID uses 3D depth mapping and liveness checks. In Which? testing, a printed photo couldn’t unlock it.

Which phones can be unlocked with a printed photo?

Ans: Mostly budget and mid-range Androids with 2D face unlock – some Samsung, Motorola and Nokia models and the pricey Oppo Find X9 Pro.

Is face unlock safe for banking apps?

Ans: Not on its own. UK banks add liveness checks, stronger biometric classes or extra passwords, and most block weak 2D face unlocks.

What is liveness detection?

Ans: A check that you’re a real, present person — it looks for blinking, skin texture and movement, so a flat photo can’t sneak through.

Is fingerprint or face unlock more secure?

Ans: A fingerprint is more secure. It’s often Class 3 and much harder to trick. A 2D face unlock is often the weakest lock on the phone.

How do I turn off face unlock?

Ans: Go to your phone’s settings, find Face Unlock or Face ID, and switch it off. Then set a PIN, pattern or fingerprint instead.

Sources & References:

Alfie Turner

Alfie Turner is a writer at Facts Check, where he specializes in verifying viral tech claims, emerging digital trends, online misinformation, and Science & Nature stories. His work focuses on separating fact from fiction by analyzing trending topics, evaluating reliable sources, and presenting clear, evidence-based explanations that readers can trust.

Alongside his interest in technology and science, Alfie is also passionate about Travel. He covers destinations, travel trends, tourism developments, travel innovations, and unique experiences, offering practical and well-researched insights for readers planning their next journey. His travel writing combines factual research with an interest in discovering new places, cultures, wildlife, and experiences.

Alfie regularly covers Science & Nature, explaining scientific discoveries, wildlife, environmental topics, and viral nature-related claims in an accurate and easy-to-understand way. Whether investigating a trending technology story, fact-checking a viral nature claim, or exploring a travel destination, he is committed to accuracy, transparency, and thorough research. His work delivers clear, fact-based information that helps readers stay informed and make well-informed decisions.

Read more

Leave a Reply

Your email address will not be published. Required fields are marked *