27.8 Million Records in Plain Text. The Suprema Breach and the Paradox of Unchangeable Data
Whether it's a smartphone, a laptop, or an office door – biometrics promises security with minimal effort. But what happens when the very physical traits that make someone unique become a security risk?
Just how vulnerable this technology can be was proven in 2019 by the South Korean company Suprema. A massive data breach in its web-based platform BioStar 2 suddenly exposed 27.8 million records belonging to more than a million people in a publicly accessible database. This included passwords, usernames, and, for more than a million users, unencrypted fingerprints and facial recognition records. All of it stored in plain text and freely accessible online.
The case exposes the fundamental risk of biometric authorization: a hacked password can be changed in seconds – a compromised fingerprint or face stays compromised for life. This is exactly where the problem begins: how easily biometric access systems can be defeated, and which protective measures actually work.
What biometrics is and what makes it so popular
Biometric information refers to any kind of measurement data about a person's biological or behavioral characteristics. In theory, almost any physical trait can be used for identification – from gait to body temperature to individual handwriting. In practice, a specific set dominates:
| Biometric | Definition |
|---|---|
| Fingerprint | The classic among these methods. A sensor captures the fine ridges and branches of the skin on the fingertip and converts this unique pattern into a digital code. |
| Face | A camera analyzes the characteristic features of the face – such as the distance between the eyes, the nose, or the jawline. Modern systems use 3D scans to make forgery harder. |
| Iris | An infrared camera scans the fine, colored pattern of the iris. This network of lines and points is extremely complex, unique to every person, and barely changes over a lifetime. |
| Veins | A highly precise trait. The structure of the vein network is typically captured using near-infrared light, since blood absorbs this light more strongly than the surrounding tissue. |
| Voice | The system measures the geometry of the vocal cords and vocal tract through acoustic analysis. |
According to the vzbv market overview (as of January 2024), the most commonly used methods are fingerprint and facial recognition.
These systems are used for authentication, meaning identity verification – either as identification (who is this person?) or verification (is this person really Person X?).
Application examples:
- Unlocking a device (e.g. laptop, smartphone, tablet, or individual apps)
- Logging into a user account
- ID checks, e.g. at airports, where the face is compared to the photo on the ID document
- Government recognition systems (e.g. at train stations/airports)
- Access control, i.e. for applications requiring a high level of recognition accuracy
- General examples: computers, hospitals, ATMs
Whether for personal devices, digital services, ID checks, or physical access systems – the range of applications is broad. The reason for the popularity of biometric traits is obvious. Alongside a high level of security, they offer an inherent, permanent link to the user. Unlike passwords or physical keys, they can't be lost or forgotten, since they're always carried by the person themselves. This makes everyday authentication extremely convenient.
The basic principle of matching
For biometric data to be usable at all, it must be measurable, unique, and stable over time. Authentication follows a basic principle:
- Enrollment: During enrollment, the trait is captured for the first time and stored as a reference template.
- Matching: At login, the system compares the newly captured sample against the stored template for sufficient similarity. On a match, the device confirms correct recognition and grants access.
- Threshold decision: A biometric system never delivers a hundred-percent match, only a statistical probability score. The system's decision is based on a threshold value defined by the manufacturer.
The larger the tolerance allowed by the threshold, the lower the False Rejection Rate (FRR), but the higher the security risk from the False Acceptance Rate (FAR) becomes. A threshold that is too lenient also lets similar, unauthorized traits through.
Vulnerability, and how attackers crack biometrics
The core weakness lies in the fact that physical traits are not secret at all. They are left behind everywhere, and unlike passwords, they can't be changed at will. Once a fingerprint is compromised, criminals can use it to unlock devices, compromise linked services and accounts (if the same biometric is reused), bypass multi-factor authentication, commit identity theft, spread disinformation, or carry out fraud such as modern impersonation scams.
The methods used to trick these systems keep getting more sophisticated, but they all ultimately follow the same principle: acquiring material to precisely replicate the biometric trait.
Fingerprint
Fingerprint biometrics is well established, but it can still be tricked using both analog and highly modern digital methods. The following approaches show how attackers proceed, from physical mold-making to acoustic side-channel attacks.
Face & Voice
Thanks to rapid advances in generative AI models, visual and acoustic biometric data can now be forged at high quality. Attackers use these deepfake technologies to bypass real-time identity checks.
Vein recognition
Recognition of hand or finger vein patterns is considered one of the most secure biometric methods, since the traits lie beneath the skin. However, with the right technique, these infrared patterns can also be captured and replicated without the victim noticing.
The vein pattern already forms in the sixth week of pregnancy and is genetically unique due to random developmental processes. Even so, it can be attacked:
Attackers capture the pattern, for example, using a digital single-lens reflex camera (DSLR) fitted with a suitable infrared filter and specific settings (such as wavelength, exposure time, grayscale levels).
This capture can happen very covertly, for instance by hiding the DSLR camera inside an ordinary hand dryer in a public place. When the victim dries their hands, the system silently creates a copy. After digital image processing and contrast enhancement of the blood vessels, a physical replica is produced via laser, 3D printing, or conductive specialty printing, which can then be used to reproduce the vein structure and gain access to certain services or access-controlled areas.
How do you protect something that can't be changed?
Since biometric traits can't be changed like a password, and these traits are permanently carried around in the open, it's worth using them sparingly and following these rules for the best possible protection against attacks:
- Only use biometric traits for trustworthy applications, and don't blindly trust every app or device that captures biometric data.
- Don't use the same biometric trait across all levels – for example, use the thumb to unlock a smartphone, but the index finger for authentication in security apps.
- Use a second factor, so that logging into a user account requires both a password and a fingerprint.
- Keep operating systems and software up to date at all times to shut down newly discovered exploits as much as possible.
Conclusion: Convenience with an expiration date
Biometric authentication undeniably offers total convenience in everyday digital life: a quick glance, a quick touch – and the system opens. The problem is fundamental: physical traits are public and unchangeable. While a hacked password can be changed in a few clicks, a compromised fingerprint, a forged facial recognition template, or a cloned voice is lost for life. Attackers keep escalating – from simple silicone casts to hidden infrared cameras in hand dryers to AI-powered deepfakes and acoustic side-channel attacks.
The key takeaway for practice: biometrics is an excellent booster for convenience, but not an unbeatable cure-all. Real protection only comes from being sparing with data sharing, diversifying which traits are used where, and above all, consistently using two-factor authentication. Because even the most secure biometric only becomes truly effective when combined with a strong password.
How secure are your biometric access systems, really?
We test your fingerprint, facial, or vein recognition systems against real-world attack scenarios – from simple spoofing attempts to complex side-channel attacks. Free initial consultation.
Request a consultation →