"The alleged perpetrator used household spotlights with strategically placed colored bulbs to simulate the flashes and security features found on physical identity documents under real light," Spain's national police said (machine translated).
What investigators say happened
Spain's national police say they arrested an unnamed man after a momentary technical glitch exposed his real face to a video identity-verification platform. Authorities allege the suspect made 38 attempts to impersonate 30 different people in order to obtain digital certificates in their names, and that those attempts succeeded on "multiple" occasions. Police say the man planned to use fraudulently obtained credentials in further cybercrimes.
Tools and techniques allegedly used: deepfakes, forged documents, and a lighting rig
Police describe a multi‑layered effort to defeat the certificate issuer's identity checks. The suspect allegedly used forged documents and altered photographs together with deepfake tools to alter his face in real time during live video verification. He is also accused of staging a custom lighting setup: household spotlights fitted with colored bulbs to imitate document flashes and holographic security features. "He then balanced the counterfeit documents in front of the webcam, perfectly recreating the official holograms," police said.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildTarget: a security company authorized to issue digital certificates
The man is accused of targeting a security company that is authorized to issue digital certificates. The verification process used by that issuer required a live video check comparing the applicant's face with the photograph on the identity document. According to the police account, the suspect anonymized connections with VPNs and submitted manipulated documents showing apparent security features in order to pass those checks.
Why digital certificates matter in Spain and the EU
A digital certificate “uses public key infrastructure to bind a cryptographic key to a verified identity,” the police account noted, allowing its holder to authenticate and create legally recognized electronic signatures. In Spain and other EU countries, certificates can be used to sign contracts, authorize transactions and deal with public bodies online—functions that historically required in‑person appointments for administrative procedures. A certificate issued in someone else's name would therefore give a scammer a powerful tool for impersonation, police said.
Breakdown of the investigation and evidence seized
Investigators allege the suspect's operational setup included more than 320 phone lines across 24 devices, most of them registered under stolen identities; police traced the sale of those SIMs to outlets in the Murcia region. The suspect's "luck" changed when the face‑changing software suffered a momentary processing delay and the disguise dropped for "barely a second," exposing his real face to the verification camera. After identifying and locating the suspect, police arrested him on suspicion of repeatedly forging official documents. A search of his home yielded a laptop protected by high‑grade encryption, several mobile phones, storage devices and documents, according to the police statement.
What this means for technologists, certificate issuers, and public bodies
- Technologists and security teams: the incident highlights how real‑time face alteration and manipulated lighting can be combined to defeat live‑video identity checks and how temporary processing failures can reveal otherwise well‑disguised deception.
- Certificate issuers and affected security companies: the account raises questions about the robustness of remote verification workflows where hologram simulation, deepfakes and forged documents are used to mimic official IDs.
- Public bodies and citizens who rely on electronic signatures: because certificates enable legally recognized signatures and online dealings with government, successful fraud could allow impersonation in contract signings and administrative transactions.
Police reports provide a detailed chain of alleged methods and a clear arrest narrative, but they also leave a central fact stated plainly: authorities did not disclose exactly how many of the 38 attempts succeeded, only that certificates were issued on "multiple" occasions. The case’s immediate outcome is an arrest and a cache of devices and documents; the broader question remains concrete and narrow—how many certificates were issued and where were they used?




