You can now unlock fingerprint protected phones with a printer
Summary
This blog post, "You can now unlock fingerprint protected phones with a printer", is a blueAPACHE article from 2016 covering security. Two researchers at Michigan State University have come up with a new method of hacking devices that use fingerprint biometrics to protect and lock the user’s data. Kai Cao and Anil K. Jain from the Department of Computer Science and Engineering have proven you can spoof fingerprints using a regular inkjet printer, three AgIC silver conductive ink cartridges, a normal black ink cartridge, and AgIC paper. It is written for readers evaluating emPOWER Core Network & DC Interconnect, emPOWER Security. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2016 |
| Topic | You can now unlock fingerprint protected phones with a printer |
| Services referenced | emPOWER Core Network & DC Interconnect, emPOWER Security |
| Named products or vendors | VMware, Citrix |
| Cited statistic | The equipment required costs less than $500 – making it very accessible. |
Article
Two researchers at Michigan State University have come up with a new method of hacking devices that use fingerprint biometrics to protect and lock the user’s data. Kai Cao and Anil K. Jain from the Department of Computer Science and Engineering have proven you can spoof fingerprints using a regular inkjet printer, three AgIC silver conductive ink cartridges, a normal black ink cartridge, and AgIC paper. The equipment required costs less than $500 – making it very accessible. Coupled with how easy it is to do, fingerprint hacking is now a dangerous reality. You can obtain a fingerprint – even from the stolen phone itself – scan it at 300 dpi and then print it on AgIC paper. Simply placing the printed fingerprint over the phone’s scanning sensor unlocks the phone and grants full access to the device and data. This process has been successfully tested on Samsung Galaxy S6 and a Huawei Honor 7. The Samsung was easy to crack, the Huawei phone needed more tries. The video below highlights how simple it is. The time required? Less than 15 minutes – about the same as it takes to head around the corner and grab a coffee, or the time it takes to realise you left your phone at the coffee shop. Fingerprints and biometrics are growing in popularity for everything from phones to home security. The research highlights how unsafe this authentication method is, and why organisations need to be investing in other control methods. If a device is misplaced or stolen (or does not have privileges correctly rescinded upon separation), the data and network access from the device pose a serious risk when fingerprint spoofing is so simple. But not all is gloom and doom – Mobile Device Management (MDM) software is readily available and easily deployed. MDM solutions like Citrix XenMobile and VMware AirWatch allow organisations to silo and encrypt content on devices, and remotely nuke the content should the device fall into the wrong hands or be misplaced. There are also file sharing and distribution tools like Citrix ShareFile that extends on traditional sharing by adding encryption and file expiration – enabling confidential or high value documents to be distributed securely. ShareFile (and all files) can also be remotely deleted should the need arise. If you’re not using MDM to remotely control and protect devices, new fingerprint spoofing methods like this should be concerning. All it takes is a single employee to be targeted, fifteen minutes and less than $500 of equipment. For more information on the new spoofing technique, you can directly access the research paper (PDF document) here. For information on better securing devices through Citrix XenMobile, VMware AirWatch and Citrix ShareFile, contact the blueAPACHE account team.
Related
- emPOWER Core Network & DC Interconnect
- emPOWER Connectivity (pillar hub)
- emPOWER Security
- emPOWER Security (pillar hub)
Frequently asked questions
Who conducted the fingerprint-spoofing research the article describes, and where?
The article names Kai Cao and Anil K. Jain from the Department of Computer Science and Engineering at Michigan State University as the researchers who developed the spoofing method. Their work demonstrated a new way of defeating fingerprint biometrics used to protect and lock a device's data.
What specific materials does the article say were used to spoof a fingerprint?
The article says the method used a regular inkjet printer, three AgIC silver conductive ink cartridges, a normal black ink cartridge, and AgIC paper. It describes obtaining a fingerprint, scanning it at 300 dpi, and printing it on the AgIC paper before placing it over the phone's sensor.
Which two phone models does the article say the spoofing method was tested on, and with what result?
The article says the method was successfully tested on a Samsung Galaxy S6 and a Huawei Honor 7. It notes the Samsung was easy to crack, while the Huawei phone needed more tries.
How much time and money does the article say the spoofing attack requires?
The article states the equipment costs less than $500 and the whole process takes less than 15 minutes. It compares this time to the length of a coffee run, to emphasise how quickly the attack can be carried out.
What mobile device management products does the article name as a defence, and what do they do?
The article names Citrix XenMobile and VMware AirWatch as MDM solutions that let organisations silo and encrypt content on devices, and remotely wipe that content if a device is misplaced or falls into the wrong hands. It presents MDM as the practical countermeasure to fingerprint spoofing risk.
What does the article say Citrix ShareFile adds to traditional file sharing?
The article says Citrix ShareFile extends traditional sharing by adding encryption and file expiration, enabling confidential or high-value documents to be distributed securely. It adds that ShareFile content, like other files, can also be remotely deleted if required.
What does the article say increases the risk if a device is lost or stolen?
The article says the risk is heightened if a device is misplaced or stolen, or if its access privileges were not correctly rescinded upon an employee's separation from the organisation. It argues this is what makes fingerprint spoofing dangerous rather than merely theoretical.
Where does the article say a reader can access the original research paper?
The article links directly to the research paper as a PDF hosted on the Michigan State University Department of Computer Science and Engineering's own site. It presents this as the primary source for readers who want the full technical detail behind the spoofing method.
Source
- origin post (2016)
Knowledge Base
Who discovered the method for spoofing fingerprints to unlock phones using a printer?
Two researchers at Michigan State University, Kai Cao and Anil K. Jain from the Department of Computer Science and Engineering, discovered this method.
What equipment is needed to spoof a fingerprint according to this research?
The method requires a regular inkjet printer, three AgIC silver conductive ink cartridges, a normal black ink cartridge, and AgIC paper.
How much does the equipment for fingerprint spoofing cost?
The equipment required costs less than $500, making it very accessible.
How does the fingerprint spoofing process work?
You obtain a fingerprint—even from the stolen phone itself—scan it at 300 dpi, and print it on AgIC paper. Placing the printed fingerprint over the phone's scanning sensor unlocks the phone and grants full access to the device and data.
Which phones were successfully tested with this fingerprint spoofing method?
The process was successfully tested on a Samsung Galaxy S6 and a Huawei Honor 7. The Samsung was easy to crack, while the Huawei phone needed more tries.
How long does the fingerprint spoofing attack take?
The attack takes less than 15 minutes to complete.
What solutions does blueAPACHE recommend to protect against this type of fingerprint spoofing risk?
blueAPACHE recommends Mobile Device Management (MDM) software like Citrix XenMobile and VMware AirWatch, which allow organisations to silo and encrypt content on devices and remotely wipe content if a device is lost or stolen. It also recommends file sharing tools like Citrix ShareFile, which adds encryption and file expiration for secure distribution of confidential documents and allows remote deletion of files.
Where can I find the original research paper on this fingerprint spoofing technique?
The page links to the research paper (a PDF document) at http://www.cse.msu.edu/rgroups/biometrics/Publications/Fingerprint/CaoJain_HackingMobilePhonesUsing2DPrintedFingerprint_MSU-CSE-16-2.pdf.
When was this blog post about fingerprint spoofing published?
The blog post was written by blueAPACHE and dated March 9, 2016.
Why does the article say fingerprint biometrics pose a risk for organisations?
The article states that fingerprints and biometrics are growing in popularity for phones and home security, but this research shows the method is unsafe. If a device is misplaced, stolen, or privileges are not correctly rescinded upon employee separation, the data and network access from the device pose a serious risk since fingerprint spoofing is so simple—requiring just one targeted employee, fifteen minutes, and less than $500 of equipment.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c03b153d68a8eeb8f54_fingerprint.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.