Smart Engines Patents AI Method to Detect Holographic Security Features in Documents Using Visible Light Only
Smart Engines has developed and patented a method that allows scanners to detect optically variable devices (OVD) such as holograms on identity documents using only visible light and a series of images taken under changing illumination angles.
One of the most common presentation attacks involves printing a high-quality color copy of a genuine document. While such replicas can accurately reproduce colors, text, and photographs, they cannot replicate the angle-dependent appearance of genuine OVD elements. Traditional verification relies on tilting the document by hand, but this is impossible inside a fixed scanner.
The company’s solution keeps both the document and the camera stationary. Instead, six LEDs positioned around the scanning area are switched on sequentially, producing six perfectly aligned images that differ only in lighting direction. The scanner used in experiments is the PS4-02 model manufactured by Intek Group.
Raw images first undergo dark-current subtraction. A calibration set captured from laminated white paper under the same lighting sequence is then used to normalize brightness variations caused by the illumination system itself. After normalization, pixel color vectors are projected onto a plane of average brightness, and the standard deviation across the six lighting conditions is calculated for every pixel.
Areas containing genuine holograms exhibit high standard deviation because their color changes noticeably with illumination angle. Areas without OVD remain relatively stable. The resulting deviation map is thresholded inside a predefined region of interest; if the relative area of high-deviation pixels exceeds a set limit, the document is classified as genuine.
The entire pipeline requires no new hardware or ultraviolet illumination. It demonstrates that a carefully designed algorithm can extract an additional authenticity signal from existing controlled-lighting scanners, turning six ordinary RGB frames into a reliable OVD presence detector.
Related articles
YooMoney's YuScan Automates E-commerce Risk Assessment Scanning Up to 1,000 Sites Per Hour
YooMoney has detailed the inner workings of its YuScan service, an automated auditing tool designed to help banks and payment providers identify websites that conceal prohibited or high-risk activities. Since 2020 the system has processed more than 550,000 merchant applications without resulting in any fines for servicing illegal operations. YuScan builds comprehensive site maps, executes JavaScript, and handles dynamic content using Playwright combined with Camoufox to evade modern anti-bot protections such as Cloudflare. The crawler is built on Scrapy with FastAPI and PostgreSQL, then applies ML models, embeddings, and LLMs to analyze text, images, reviews, and external signals including Roskomnadzor registries and WHOIS data. The automation has reduced manual review time dramatically, allowing half of compliant merchants to begin accepting payments within 24 hours. YooKassa now offers the service to other banks through NSPK, the operator of the Mir payment system.
Scammers Pose as Employers to Remotely Lock iPhones and Demand Ransom
Russian police have warned of a new social engineering scheme in which fraudsters impersonate potential employers to gain control of victims' Apple devices. The attackers instruct targets to sign out of their personal Apple accounts and authenticate using credentials supplied by the supposed employer. Once the device links to the fraudster's account, the scammers can remotely lock the iPhone or iPad and demand payment for unlocking it. Authorities emphasize that paying the ransom does not guarantee recovery of the device and may lead to further extortion demands. Victims are advised never to enter third-party Apple credentials on personal hardware and to contact Apple Support with proof of purchase if a device is already locked. The scheme exploits the Find My and Activation Lock features built into iOS devices.
Scammers Target Remote Workers with Fake Compensation for Home Internet and Devices
Russian remote employees are being targeted by fraudsters impersonating employers, government agencies, and corporate IT departments. Attackers lure victims with promises of compensation for home internet costs and personal computers, directing them to fake sites for identity verification or SMS code submission. Instead of receiving payments, victims risk handing over account credentials or banking details to criminals. Another tactic involves urgent messages from supposed IT services demanding immediate access renewal or software updates via malicious links. The pressure of urgency aims to bypass caution, leading users to click links, enter passwords, or execute files before verifying the sender. Home networks present additional risks because users manage their own routers and connected devices, unlike secured office environments. Experts from Yandex recommend changing default router passwords, updating firmware, disabling quick device pairing, and isolating smart devices on a separate guest network.
Phishing Reports Fall 42.6% in June While Abused URLs Rise 3.2%
The Phishing Countermeasures Council recorded 72,370 phishing reports in June 2026, a 42.6% drop from 126,061 reports the previous month. Despite the decline in reports, the number of malicious URLs increased to 42,241, up 3.2% from the prior month. More than 90% of the phishing emails received by the council's monitoring addresses used unique domains. The largest share of attacks targeted the EC sector at 42.7%, followed by credit and finance services at 27.4%. The council noted that this marks the second consecutive month of declining reports after a peak in April.