朋友们,今天的槽点是真的能让你后背发凉的那种。
8月16日央视报道了一起案子:长沙一名大学生吴某,临近毕业不好好找工作,跑去黑产群里买了一套"AI人脸伪造视频"技术,把静态的人脸照片做成动态视频,居然能绕过支付平台的人脸识别验证。
四个月,盗刷三个人的银行卡,共计5万多块钱。最终获刑一年十个月,罚金3000。
你可能觉得:这不就是普通的诈骗嘛,有什么好槽的?
兄弟,你细想一下这个技术门槛和成本:一个大学生,从非法网站买套技术,几百块钱成本,几分钟时间,一张你的自拍照,就能生成一段能通过银行支付平台人脸识别的动态视频——眨眼、张嘴、转头,系统要什么动作就有什么动作。
你手机里有多少张自拍?你朋友圈发过多少张正脸照?这些照片,现在在黑产市场上都是明码标价的原材料。
它是怎么骗过人脸识别的?
原理说穿了其实不复杂,但防不胜防。
第一步,拿到你的人脸照片。怎么拿?太容易了——朋友圈、社交平台头像、公司官网团队介绍、甚至你简历上的照片,都能扒下来。不法分子还能通过给你发钓鱼链接,远程控制你手机偷你相册里的生活照。
第二步,用AI把静态照片做成动态视频。什么眨眼、点头、转头、张嘴,你能想到的人脸识别验证动作,AI全能生成。而且不是预先录好的——有一个叫"虚拟相机"的软件,可以实时操控画面,系统提示什么动作,它就输出什么动作的视频。你以为对面是一个真人在做动作,其实是AI在播放提前生成好的动作片段。
第三步,用验证码+人脸视频重置你的支付密码,然后把你的钱转走。整个流程不需要你本人出现,只要你的个人信息泄露了,你的脸和你的钱,都不再是你能控制的。
你看,技术的门槛已经低到这个程度了:不需要什么技术背景,不需要什么昂贵设备,一个大学生花几百块钱就能搞定。而黑产产业链已经分工到了什么程度?上游卖技术、中游接单做视频、下游洗钱车队负责转钱——一条龙服务,各司其职,进去接单还要先交虚拟货币当押金,生怕你私吞。
这产业链的成熟度,比很多正规公司还完善。
给大家提三个醒
槽归槽,安全提醒还是要给的,都是实打实的:
第一,人脸识别不是万能的,重要账户一定要开双重验证。别觉得刷脸比密码安全——密码丢了能改,脸丢了你改不了。支付、银行、政务这些关键账号,除了人脸,一定要再开一层验证——短信验证码、U盾、硬件密钥,多一层就多一道保险。
第二,别什么平台都上传你的人脸信息。很多APP为了所谓的"实名认证"就让你做人脸识别,其实很多根本没有必要。不是信不信任平台的问题,是你上传的人脸数据越多,泄露的风险就越大——平台本身可能不滥用,但万一被拖库了呢?
第三,社交平台发自拍注意点。不是说不能发自拍,是说尽量别发高清正脸大特写,别发太多同角度的照片。你朋友圈一张随手拍的自拍照,可能就是黑产的原材料。实在想发,加点滤镜、加点贴纸、稍微糊一点——好看是其次,安全才是第一位的。
AI技术本身是中性的,但总有人拿着好技术去干坏事。我们能做的,就是多留个心眼。
今天就槽到这里,明天继续。
Friends, today's cao is the kind that sends a chill down your spine.
On August 16, Chinese state media reported a case: a college student in Changsha named Wu, approaching graduation and skipping the normal job hunt, bought an "AI face forgery video" toolkit from a black market group. He turned static face photos into dynamic videos that could actually bypass payment platform face verification.
In four months, he stole from three victims' bank accounts, totaling over 50,000 yuan. Final sentence: one year and ten months in prison, plus a 3,000 yuan fine.
You might be thinking: isn't this just regular fraud? What's so cao about it?
Bro, think about the barrier to entry and the cost: a college student, buying a toolkit from an illegal website for a few hundred bucks, a few minutes of time, and one selfie of you—and he can generate a dynamic video that passes bank payment face verification. Blinking, mouth-opening, head-turning—whatever action the system asks for, the AI provides it.
How many selfies are on your phone? How many front-facing photos have you posted to Moments? These photos are now raw materials with price tags on the black market.
How Does It Fool Face Recognition?
The原理 is straightforward when you break it down—but hard to defend against.
Step one: get your face photo. Too easy—Moments, social media profile pictures, company website team pages, even the photo on your resume can all be scraped. Scammers can also send phishing links to remotely control your phone and steal lifestyle photos from your album.
Step two: use AI to turn static photos into dynamic videos. Blinking, nodding, head-turning, mouth-opening—every face verification action you can think of, AI can generate. And it's not pre-recorded—there's software called "virtual camera" that can manipulate the feed in real time. Whatever action the system prompts, it outputs a video of that action. You think there's a real person performing the动作 on the other end—actually, it's AI playing back pre-generated action clips.
Step three: use the verification code + face video to reset your payment password, then transfer your money out. The entire process doesn't require you to be present at all. Once your personal information leaks, neither your face nor your money is under your control anymore.
You see—the technical barrier has dropped this low: no technical background required, no expensive equipment needed, a college student can pull it off for a few hundred bucks. And how sophisticated is the black industry chain? Upstream sells the technology, middlemen take orders to make videos, downstream money-laundering crews handle the transfers—a full一条龙 service with specialized roles. You even have to deposit virtual currency as collateral before joining, to prevent people from running off with the money.
The maturity of this industry chain is more polished than many legitimate companies.
Three Real Reminders for Everyone
Cao aside, here are genuine safety reminders—all practical:
First: face recognition isn't foolproof. Enable 2FA on important accounts. Don't assume face payment is safer than passwords—if your password gets stolen you can change it; if your face gets stolen, you can't. For payment, banking, government, and other critical accounts, always add a second layer beyond face—SMS verification, U-dongles, hardware security keys. One more layer is one more safeguard.
Second: don't upload your face data to every platform. Many apps make you do face verification for so-called "real-name authentication" when many don't actually need it. This isn't about trusting the platform or not—it's about risk: the more places your face data lives, the higher the leak risk. The platform itself might not misuse it, but what if they get breached?
Third: be mindful of selfies on social platforms. Not saying you can't post selfies—just try to avoid high-resolution close-ups of your full face, and don't post too many from the same angle. That casual selfie on your Moments might be raw material for black markets. If you really want to post, add some filters, stickers, a little blur—aesthetics are secondary; safety comes first.
AI technology itself is neutral. But there are always people who take good technology and use it for bad things. All we can do is stay alert.
That's it for today's cao. See you tomorrow.
Face recognition isn't foolproof—enable 2FA on important accounts, don't upload face scans to every platform, and consider blurring faces in public social media selfies.