No Code SaaS Mobile App Security.  

Start Free Trial

“All I Did Was Take a Selfie…”

How Facial Images and Personal Information Were Stolen Through a Fake Beauty App

“All I Did Was Take a Selfie…”

How Facial Images and Personal Information Were Stolen Through a Fake Beauty App

“I only took a photo to analyze my skin. After that, I started receiving strange messages.”

This story began with a user of a beauty application.

Today, features such as skin tone analysis, pore diagnostics, and makeup recommendations powered by smartphone cameras have become a natural part of many beauty apps.

Without any suspicion, the user installed the application and took a selfie.

The interface looked familiar.

The features appeared to work perfectly.

There was only one problem.

The application was not genuine.

“It Looked Like a Legitimate App—So What Was Wrong?”

An investigation later revealed that the application had not been distributed through the official app store.

Instead, it was a fake application created by repackaging a legitimate beauty app.

The icon was identical.

The user interface was identical.

Even the skin analysis workflow appeared exactly the same.

However, behind the scenes, something entirely different was happening.

What Actually Happened?

The fake beauty app operated in the following way:

• ✔ A legitimate beauty application was repackaged and redistributed

• ✔ The facial capture screen and profile input pages were duplicated

• ✔ Facial images and personal information collected from users were transmitted to an external server while the normal analysis process appeared to run successfully

From the user's perspective, they had simply granted camera permission.

In reality, their facial images and personal information were being stolen simultaneously.

This was especially concerning because facial data is:

• ✔ More than just a photograph

• ✔ Biometric information that can be used for identity-related purposes

As a result, the privacy risks were significantly higher than ordinary data leakage incidents.

Where Did Security Fail?

The core issue was clear.

• ✔ There was no reliable way to verify whether the application was an officially distributed version

• ✔ There was no mechanism to confirm that the facial capture screen was genuine

In other words, the moment users trusted the application, they effectively handed over all permissions.

Users were cautious, but they lacked the technical means to distinguish a legitimate application from a malicious one.

How Was the Threat Prevented?

LIAPP – Detecting Fake and Repackaged Applications

The first security measure implemented was LIAPP.

When an application launches, LIAPP verifies:

• ✔ Application signatures

• ✔ Code structure

• ✔ Resource integrity

This allows it to distinguish officially distributed applications from modified or repackaged versions.

As a result:

• ✔ Repackaged fake applications can be blocked from running

• ✔ Fake facial capture interfaces can be neutralized

• ✔ Access from counterfeit application environments can be denied

Users could no longer take selfies through malicious applications masquerading as legitimate services.

LIKEY – Protecting Personal Information Input

Facial images were not the only assets at risk.

Names, phone numbers, and profile information also required protection.

LIKEY addressed this issue by:

• ✔ Providing a secure keypad for profile information input

• ✔ Preventing credential and data theft through keylogger-based attacks

Even within a legitimate application environment, sensitive user information remained protected from unauthorized collection.

What Changed After Implementation?

The impact of these security measures was immediate and measurable.

• ✔ Access attempts through fake beauty applications were blocked

• ✔ Leakage of facial images and personal information was prevented

• ✔ User concerns and anxiety decreased

• ✔ Brand trust was restored

However, the most important change was not technical.

It was a change in mindset.

The focus shifted from:

“Users must protect themselves”

to

“Applications must protect their users.”

The Key Lesson from This Case

In beauty applications, facial data is not merely a feature.

Facial data is not simply a photograph—it is personal information.

That is why the following principles are essential:

• ✔ Verify that the application is genuine

• ✔ Confirm that facial capture screens have not been tampered with

• ✔ Protect personal information throughout the entire user journey

No matter how innovative an application's features may be, users will not trust them without security.

For beauty applications, security begins not with functionality, but with authenticity verification.

#BeautyAppSecurity #FakeApps #CounterfeitApps #PersonalDataLeakage #FacialDataProtection #PrivacySecurity #MobileSecurity #AppTampering #RepackagedApps #SelfieSecurity #CameraPermissions #MobileAppSecurity #SecurityCaseStudy #CybersecurityStories #SecurityTrends #LIAPP #LISS #LIKEY

Contact Us