Shoppers entering grocery stores may unknowingly have their faces scanned by security cameras, creating a digital template that remains vulnerable to theft and misuse. Unlike passwords or credit card numbers, a face cannot be changed or revoked if compromised, posing a lifelong cybersecurity risk.
Facial recognition systems convert facial images into mathematical templates, storing the proportions and positions of features. While more secure than raw photos, these templates can still be stolen in data breaches. Once stolen, they enable unauthorised access to systems like bank apps, airport security, or office buildings, as the 'lock' cannot be reset.
Biometric data breaches have already occurred. In 2024, a facial recognition system used at Australian bars and clubs suffered a hack, and in 2019, a U.S. Customs and Border Protection pilot system was breached via a subcontractor. Although no known exploitation of stolen facial data has been documented, the risk remains.
Facial recognition differs from fingerprints or iris scans because cameras can capture faces covertly and from a distance, creating permanent records without consent. Stolen templates can be matched against surveillance images or online photos, enabling tracking or identification.
Device-level biometrics, such as those used to unlock phones, are stored locally and are not shared with cloud services. However, company databases from retailers like Wegmans and Target, which use facial recognition for theft prevention, are centralised and vulnerable. If linked across platforms, these templates become persistent identifiers that can expose individuals to impersonation and tracking.



