Skip to main content
WebID
WebID
All contributions
Use Cases

Pen tests with GenAI contribute to security and trust in an online real estate marketplace for short- and long-term homestays

Marketplace security: WebID & Firstsource rely on AI

Author
Authored byChristiane Hattemer
Published on05/28/2025

Introduction

The operator of a global online marketplace for short- and long-term stays in a wide range of private and commercial properties wanted to strengthen the security of the platform and thus increase user confidence. With the help of GenAI-supported penetration tests (pen tests), the team, consisting of IT consultants from WebID and the Firstsource domain experts first analyzed evolving threats. Based on this analysis, the team implemented a scalable methodology to manage future risks related to identity and offer fraud. To do this, over ten thousand high-quality video and image materials were created using GenAI and non-GenAI methods to simulate fraudulent behavior while penetration tests were conducted.

The challenges

The platform operators wanted to proactively uncover potential vulnerabilities and develop solution strategies to improve user trust and security. In this context, the team faced multifaceted challenges:

  • Increasing sophistication of AI-generated fraud attempts
  • Need for scalable, proactive security testing
  • Complex identity verification requirements
  • Risk of fraudulent entries affecting trust in the platform
  • Evolving threat landscape that requires adaptable and scalable solutions.

The solution

The implementation of a scalable playbook for GenAI-based pen testing, equipped with the essential resources, created the basis for testing the platform’s defenses and strengthening its defenses against identity and listing fraud. The key factors for the success of our approach were:

High-quality assets covering GenAI-based and non-GenAI-based fraud techniques

Creating an extensive library of image and video assets for pen testing scenarios involving identity and real estate fraud, including government IDs, photos and videos for identity verification, business documents, interior and exterior views, and videos of real estate listings.

Holistic taxonomy of potential threats and verification landscape

With WebID’s expertise in digital identification, a detailed taxonomy of potential threats and the latest fraud techniques were developed and provided.

Simulation of threats with realistic test cases

By using GenAI and non-GenAI-based resources, robust test cases could be provided to simulate potential security breaches. This is the basis for evaluating the platform’s ability to deal with sophisticated fraud tactics.

Penetration testing for platform security

Conducting thorough penetration tests provided crucial insights into how to improve the platform’s defenses by identifying vulnerabilities and providing the client with important recommendations for enhanced protection.

Building a scalable test framework

The guide provided includes recommendations for future scaling penetration tests. The results and outlined preventive measures help ensure long-term platform security against new threats.

About WebID

Since its foundation in 2012, WebID has been setting global standards for innovative digital identification methods with the quality feature ‘Made in Germany’. WebID is one of the largest providers of identification services in Europe and offers international solutions and a wide range of products for digital know your customer processes (KYC): from fully automated processes with artificial intelligence to video identification. Furthermore, with TrueID WebID has the explicit consent of more than 19 million individuals to reuse the data from previously completed and verified identification stored on our high-security servers.

About Firstsource

Firstsource is a leading global provider of Business Process Management (BPM) services and an RP-Sanjiv Goenka Group company, providing transformational solutions and services spanning the customer lifecycle across Healthcare, Banking and Financial Services, Communications, Media and Technology, Retail, and other diverse industries.

Leveraging UnBPOᵀᴹ, its differentiated approach to reimagining traditional outsource, Firstsource delivers real-world, future-focused solutions that drive speed, scale, and smarter decision, turning transformation into tangible results for its clients.

In collaboration with WebID group, Firstsource strengthens platform security and digital identity verification for clients to enhance trust and safety and prevent fraud.

The complete use case for download

Download the complete WebID & Firstsource use case here as a PDF to save and refer to anytime.

Download now

Verification knowledge: No matter when and where

Subscribe to our newsletter to regularly receive exclusive insights, updates and offers about WebID.