Submit incident
Documented

In Wenzhou, Paper Faces Beat a Government's AI Attendance Checks

December 10, 2025
Curated by Team Raidu · Reviewed by Shiva Ganesh
oecd:2025-12-10-cb50View source ↗
LinkedInX

What happened

A worker holding up a printed photo of a coworker's face to fool a scanner sounds like the setup for an office prank, not a security failure. But in Wenzhou, China, that is exactly what happened, and it worked well enough to be repeated by multiple staff before anyone noticed.

Local government employees who wanted to skip a shift handed printed images of absent colleagues' faces to whoever was clocking in that day. The building's biometric check-in system accepted the paper stand-ins without hesitation, logging hours for people who were nowhere near the office. Cameras installed to monitor the building generally, not the attendance system specifically, ended up being the only reason anyone found out.

That is the part worth sitting with. The system built to verify who was present had no way to tell a live face from a flat printout. A basic liveness check, the kind that asks for blinking, head movement, or depth data, would have stopped this in seconds. Instead, the setup appears to have relied on a match against a stored image alone, with no test for whether a real person was standing in front of the lens. Once staff figured that out, gaming the system took nothing more than a printer.

The irony is sharp. Facial recognition was brought in to make attendance harder to fake than a paper sign-in sheet anyone could forge with a signature. It ended up beaten by paper anyway, just printed instead of signed. And the fraud wasn't caught by the tool responsible for catching it. It surfaced only because a separate surveillance feed happened to record the handoff.

That gap matters past one office in Wenzhou. Any organization leaning on biometric checks for payroll, building access, or compliance is trusting a system that may never flag its own failure. Nobody appears to have audited why the scanner kept approving mismatched sessions, and there was no log distinguishing a genuine clock-in from a spoofed one until a human happened to review unrelated footage.

That is the piece missing here: a record showing not just what the system approved, but whether anyone verified the approval was genuine, and when. Without that, an AI system can keep failing quietly for as long as nobody happens to be watching a different camera.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

OECD AI Incidents Monitor
Also catalogued in
In Wenzhou, Paper Faces Beat a Government's AI Attendance Checks
2025-12-10