Forex Fraud Intelligence Report
Shufti’s Forex Fraud Intelligence Report shows that Forex sector reported 19.07% fraud in first half of 2026. Of those fraudulent cases, 37.55% were connected to identities previously associated with fraud, while 3.68% involved VPNs, proxies or anonymised networks.
Schedule a DemoThe hidden patterns behind identity fraud in Forex
According to Shufti’s Identity Verification Network data, fraud in the Forex sector during the first half of 2026 stood at 19.07%, highlighting the scale of fraudulent activity at the account creation stage.
The data indicates that fraudulent activity extends across several connected patterns, including duplicate identities, multiple account creation, coordinated fraud rings and geographic evasion. These patterns can create financial exposure for Forex firms when apparently separate accounts are connected through common identities, devices, registration behaviour or locations.
Historical fraud intelligence provides an additional indicator of repeat activity. 37.55% of Forex fraud was associated with identities with a previous history of fraud, showing how the sector is vulnerable to repeat offenders. This also demonstrates the importance of connecting new registrations with established fraud intelligence.
The analysis therefore focuses on how identity, device, velocity, IP and historical fraud signals can be assessed together to identify connected fraudulent activity while reducing the risk of legitimate customers being incorrectly rejected.
Three areas stand out in this Forex industry report
Multi trader accounts
One individual can establish multiple accounts using the same identity. This creates opportunities for bonus abuse and for circumvention of the restrictions placed on a single account.
Fraud rings
Multiple traders can operate through shared infrastructure and closely timed registrations. Coordinated activity of this kind is difficult to identify when each account is assessed individually.
Geographic evasion
Location masking can obscure the origin of account activity. 3.68% of Forex fraud was associated with VPNs, proxies or anonymized networks, which makes connections between fraudulent registrations harder to establish.
Methodology: how this Forex fraud report counts fraud
The analysis examines Forex onboarding activity during H1 2026, focusing on the signals that can reveal duplicate account creation, connected fraud activity and geographic evasion.
Figure 1. The six signals assessedReuse of the same identity document across registrations
Correlation between device fingerprints
The timing between connected registrations
IP intelligence covering VPN, proxy and anonymized network use
Historical fraud associated with the identity
Resemblance to identity verification patterns already associated with fraud
Six signals are assessed together rather than in isolation.
How Shufti detects the Forex fraud while making sure that legitimate customers are not rejected
Several of these signals also appear in entirely legitimate use, which is what makes the assessment difficult. Customers may maintain multiple trading accounts in order to separate strategies, manage different portfolios or operate under different account structures, and a single device or network can be shared by household members, by colleagues, or by customers who were verified in the same location or through the same assisted onboarding process. A shared device count on its own therefore says nothing about whether the accounts behind it are fraudulent.
For that reason no single signal decides the outcome. A connection is only treated as evidence of fraud once two or more of these signals corroborate one another, or where the identity carries an established history of fraudulent activity. Where one signal appears and nothing further supports it, the registration proceeds; where several reinforce each other, the case is escalated. That requirement for corroboration is what allows a fraud decision to be strengthened without rejecting legitimate customers whose activity happens to resemble a fraud pattern.
of Forex fraud was associated with identities that had a previous history of fraud.
Historical fraud sits alongside the other signals rather than above them, and where an identity has been associated with fraud before, that record gives the assessment a reference point which a new registration on its own cannot provide.
Forex identity fraud through multi trader accounts
Multi trader account activity creates exposure when the same underlying individual establishes multiple trading accounts while appearing to the Forex firm as separate customers.
Duplicate identities can be used to circumvent account restrictions, repeatedly access promotional incentives and fragment an individual’s activity across multiple customer records. This makes it difficult to establish whether a new registration represents a genuinely new customer or an existing trader returning through another account.
of Forex fraud involved Shared identity documents.
Loss to Forex exchanges through multi trader accounts
Where several accounts trace back to one trader, the firm applies limits, prices risk and pays acquisition costs against records that do not describe separate people. Promotional value is claimed repeatedly, and restrictions placed on one account are circumvented through another.
Customer histories fragment across those records, which weakens the view a firm holds of any individual trader. Previously fraudulent traders can also return through new registrations without that history following them.
Where the exposure shows up
Bonus abuse across connected accounts
Promotional incentives can be accessed repeatedly through several accounts used together. Detection of bonus abuse across connected Forex accounts requires connecting account, identity, device and trading relationships before promotional value is released, rather than investigating each account after the event.
Coordinated hedging across multiple accounts
Multiple accounts can take opposing or coordinated positions to reduce trading risk while exploiting bonuses or account structures. Detection of coordinated hedging in Forex requires connecting trading patterns, account relationships and promotional activity across accounts rather than assessing each one independently.
Hidden connections between apparently separate accounts
Two accounts may appear legitimate in isolation while sharing devices, IP addresses, identity details, payment information or trading patterns. Confirmation that those similarities reflect legitimate shared access rather than coordinated activity requires corroborating signals across the wider customer network.
Ring fraud in Forex
Fraudulent activity in the Forex sector is not limited to one individual opening several accounts. Groups of traders can register through common infrastructure and within narrow time windows, producing a set of accounts that appears independent when each registration is reviewed on its own.
The registrations described here were not classified as fraudulent because of a single fraud signal such as shared device. A shared device is treated as a starting point and nothing more. Every registration in this set was confirmed through corroboration, where the device link was accompanied by further evidence such as reuse of the fake identity document, resemblance to identity verification patterns already associated with fraud, or an identity carrying an established history of fraudulent activity.
Figure 2. Registration velocity within confirmed fraudWithin that confirmed set, registration velocity is tightly compressed. Accounts sharing a device were typically opened inside a 13 hour period, and a quarter of them inside a single 1.2 hour window. Additional signals were applied so that clusters arising from a shared corporate setting, where several employees are verified from the same office network and the same equipment, were not quantified as ring fraud.
Loss to Forex exchanges through ring fraud
Coordinated account creation scales fraudulent activity across multiple identities, and promotional or bonus value can be distributed across several accounts rather than concentrated in one. The exposure therefore grows with the size of the network rather than with the individual account.
Where each account is assessed independently, the relationships between traders remain concealed. Action taken against a single registration can leave the connected accounts active and trading, so the loss continues after the case appears closed.
Geographic evasion and Forex compliance exposure
of Forex fraud identified during the first half of 2026 was associated with geographic evasion.
These cases were detected through IP intelligence, which identifies registrations arriving through VPNs, proxy servers and other anonymized networks that conceal the address an account is operating from.
Location masking places distance between an account and its actual operating environment. Where the origin of a registration cannot be established, the firm loses a signal it relies on both for applying market access rules and for connecting one fraudulent registration to another.
Figure 3. How location masking breaks the origin signalThe address the firm observes belongs to the anonymizing service, not to the customer behind the registration. Actual location, not observed.
Loss to Forex exchanges through geographic evasion
Geographic restrictions can be circumvented where the true origin of an account is concealed. This exposes a firm to customers in markets it does not serve, and to the regulatory consequences that follow from onboarding them.
Location signals that conflict with identity and account information also reduce the value of the wider case file. Fraud investigations lose contextual information, and geographically distributed networks become considerably harder to connect.
How the signals behind Forex fraud connect
The findings show that fraudulent activity can manifest through multiple connected account behaviours. Duplicate identities can reveal repeat account creation, shared devices and registration velocity can expose relationships between traders, while anonymized networks can obscure the geographic origin of account activity.
Historical intelligence adds another layer of context, with 37.55% of Forex fraud associated with identities that had a previous history of fraud.
For Forex firms, combining these signals provides a broader view of the relationships behind account creation. Identity, device, IP and behavioural signals can be assessed together to establish stronger evidence of fraudulent activity while allowing legitimate customers to proceed when individual signals do not provide sufficient grounds for rejection.
How to assess a Forex fraud detection and identity verification solution
In the Forex sector, identity verification is not simply a part of customer due diligence carried out to satisfy KYC and AML obligations. It is a safeguard against the financial loss caused by identity fraud, whether that fraud is committed by one individual operating several accounts or by a network operating together. It has to perform that role without penalising legitimate customers whose activity happens to resemble a fraud signal.
The right solution must therefore hold the following attributes.
Identity document coverage
Passports, national identity cards and residence permits verified across every market you onboard from.
Device fingerprinting
Devices fingerprinted so that separate registrations sharing the same hardware can be connected.
Synthetic identity detection
Identities assembled from a mix of real and fabricated attributes identified before an account is opened.
Deepfake detection
Synthetic video, face swaps and camera injection attacks detected, not only printed photographs and screen replays.
eIDV and digital wallets
Identities confirmed against authoritative electronic data sources, with digital identity wallet credentials accepted.
IP intelligence and spoofing checks
VPN, proxy and anonymized network use identified, along with attempts to spoof the address the firm observes.
Liveness and anti-spoofing
Presentation attack detection independently tested to iBeta Level 3 conformance rather than assessed in house.
Behavioural biometrics
Typing, navigation and interaction patterns assessed during onboarding alongside the document check.
1:N verification for deduplication
Each new face checked against every previously enrolled identity, not only the document presented with it.
Frequently asked questions (FAQs)
Forex fraud covers deception carried out against a broker, a trading platform or its customers. At the account creation stage it usually takes the form of identity fraud: stolen, synthetic or manipulated identities used to open accounts, one individual operating several accounts, or groups registering together to exploit promotions, limits and account structures.
Multi-accounting is the practice of one individual holding several trading accounts that appear to the broker as separate customers. It is used to claim promotional incentives more than once, to work around limits or restrictions applied to a single account, and to split activity across records so that no single account shows the full picture.
No. Customers may hold multiple accounts to separate strategies, manage different portfolios or trade under different account structures, and brokers often permit this. The question is whether the accounts were opened to conceal a connection, and that is established from corroborating signals rather than from account count alone.
A fraud ring is a group of accounts opened by connected people or by one operator using several identities, typically registering through shared devices, shared networks or reused documents and within narrow time windows. Each registration can look independent when reviewed on its own, which is why rings are identified through relationships between accounts rather than through individual reviews.
The common methods are identity deduplication against the existing customer population, 1:N biometric matching that compares each new face against every enrolled identity, checks for reuse of the same identity document, and device fingerprinting that links registrations made from the same hardware. Together, these signals show whether a new registration belongs to an existing customer.
Device fingerprinting builds an identifier from the characteristics of the hardware, browser and configuration used during a session, so separate registrations made from the same device can be connected. It is a starting point rather than a verdict: households, offices and assisted onboarding all produce legitimate shared-device activity.
Some use them for ordinary privacy reasons. Others use them to conceal the country an account is operating from, which can place a broker in a market it is not licensed to serve, and to break the link between one registration and another. IP intelligence identifies VPN, proxy and anonymized network use so the origin of a registration can be assessed alongside identity and document evidence.
A synthetic identity is assembled from a mixture of genuine and fabricated attributes, for example a real national identity number combined with an invented name, date of birth or address. Because parts of it are real, it can pass checks that verify individual data points in isolation, so detection depends on assessing the identity as a whole and against previously seen fraud patterns.
Bonus abuse is the repeated or coordinated claiming of deposit bonuses, rebates or other promotional value through multiple accounts that trace back to one person or one connected group. To prevent it, brokers run duplicate-identity and shared-device checks before promotional value is released, not only at registration.
Brokers are generally required to identify and verify each customer, screen against sanctions and politically exposed person lists, assess risk, understand source of funds where relevant, and monitor activity on an ongoing basis. Requirements vary by jurisdiction and licence, so the applicable regime should be confirmed with the relevant regulator.
Corroboration is required before a broker acts. One anomaly, a shared device, a VPN origin, a foreign-issued document, is treated as a reason to look further rather than a reason to decline. Where further evidence supports the customer, the registration proceeds; where several signals reinforce one another, the case is escalated, restricted or declined.
1:N matching compares a new customer’s face against all previously enrolled identities, rather than only against the document presented in the same session. It answers whether this person has already been onboarded under another name or another account.
A document check establishes whether the document is genuine and belongs to the person presenting it. It does not show whether the same identity has already been used to open other accounts, whether several registrations share a device or network, or whether the identity has been associated with fraud before. Those answers come from connecting identity, device, IP and behavioural signals.
Signals are read against one another rather than one at a time. A shared device, a VPN origin, a reused identity document, a burst of registrations within a short window and an identity with a previous fraud record each carry limited weight alone. A broker sets a threshold at which two or more of those signals corroborate one another, treats that combination as evidence, and escalates or declines on it. Where only one signal appears and nothing supports it, the registration proceeds.
Form submitted successfully!
Thank you for your interest — your report is loading now.
See What Identity Fraud Looks Like Across Forex Onboarding
Fraud detection is only part of the challenge. Forex firms also need enough evidence to act without wrongly rejecting legitimate traders. The report covers multi trader accounts, ring fraud and geographic evasion, along with the signals that separate coordinated activity from ordinary customer behaviour.
Learn how Forex fraud detection connects multi account and fraud ring activity
























