Identity Fraud Report 2026
How organised crime networks are exploiting deepfakes and shared infrastructure to commit identity fraud
Shufti’s Identity Fraud Report 2026, based on data from its verification network, shows that AI powered identity fraud is no longer limited to individual fraudsters. Organised crime rings and coordinated fraud networks are using shared identities, devices, documents and other infrastructure to bypass KYC checks and facilitate financial crime.
Schedule a DemoGenerative AI has reduced the cost of producing a convincing fake identity
A single operator can now recycle one identity, one document, or one device across many verification attempts. Shufti’s production data for the first half of 2026 shows what that reuse looks like at scale across eleven industries.
Deepfakes are not only used by individual fraudsters attempting to bypass a single verification check. Cross border networks are using the same techniques to recycle one forged document across many identities at once, which means the exposure sits in the repetition rather than in any single attempt.
Attack typologies against remote identity verification
Combating identity fraud effectively begins with understanding the methods that are used to bypass remote identity verification in the first place.
Presentation attacks
A presentation attack introduces a manipulated artefact to the biometric capture subsystem in order to interfere with the operation of the biometric system. The artefact can be an AI generated face, an altered document, a replayed screenshot, or a physical mask, and every one of them has to travel through the camera to reach a decision.
Injection attacks
Injection attacks skip the physical presentation stage entirely and insert manipulated images, biometric data, or video streams directly into the verification pipeline using virtual cameras, emulators, camera feed replacement, and frame injection. Injection therefore becomes a software integrity problem as much as a document problem.
Infrastructure based fraud
Infrastructure based identity fraud describes coordinated attacks in which fraudsters repeatedly leverage shared technical infrastructure, including device emulators, spoofed devices, proxy networks, controlled IP addresses, and reused identity assets, in order to run verification attacks at scale.
Fraud trends across identity verification artefacts
Shufti’s Deepfake Identity Fraud Index Report 2026 sizes the AI driven share of this activity and divides it across four artefacts. The shares below describe AI enabled fraud in the first half of 2026.
Deepfake document fraud
A genuine document is altered through photo substitution, changed data fields, or a reprinted template, through to a wholly counterfeit identity page. The same forged document remains reusable across many applications, which is why it is the artefact most likely to reappear inside a coordinated network.
Synthetic identities
Real and fabricated details are combined into a person who does not exist but who looks legitimate on paper. A synthetic identity is assembled rather than stolen, so it clears checks that only test whether individual data points are internally consistent.
Injected videos
A pre recorded or generated stream is fed straight into the verification pipeline through a virtual camera or a manipulated feed. Nothing is presented to a real sensor, so the question shifts from what the image looks like to whether the capture channel itself can be trusted.
Face swaps
The applicant’s face is replaced with someone else’s face or with a synthetic composite at the biometric and liveness stage. The evidence sits in the mismatch between the presented face, the document portrait, and the way a real face behaves under liveness prompts.
Identity fraud across industries
Identity fraud exposure ranges from 22.49 percent of all verification requests in the crypto sector down to 4.24 percent in banking, and the pattern tracks the industries whose remote onboarding volume is highest.
The rise of coordinated fraud networks exploiting remote onboarding
Shufti’s 2026 Identity Verification Report confirms that organised fraud is increasingly enabled by interconnected criminal ecosystems where technology, specialised services, and supporting infrastructure allow illicit activities to operate at greater scale. Shufti’s verification data reflects that trend at the identity layer, where fraudulent verification attempts share identity artefacts, devices, and infrastructure signals.
One connected identity cluster
The largest connected network observed in the first half of 2026 originated from Nigeria and linked 70 identities through shared fraudulent documents, devices, and IP addresses. Thirteen devices carried those identities and a single device was linked to 16 verification events, which shows how one piece of hardware can anchor a large share of the activity. A single IP address connected five verification events and a reused forged document connected four more.
- Device
- Verification event
- Shared IP address
- Reused document image
- Connection
Cross border activity is the clearest signature of coordination
Data from the first half of 2026 in Shufti’s verification network shows cross border organised crime rings exploiting shared infrastructure. The typical interval between activity in one country and activity in the next is 9 minutes and 33 seconds, and the shortest groups run their full course in well under a minute, which is far too fast for the same person to have travelled between those jurisdictions.
A Multi-Layered Approach to Identity Verification to Prevent Fraud in Remote Onboarding
Detecting the presented artefact is necessary but it is not sufficient on its own. Device fingerprinting and behavioural biometrics are what expose the network behind that artefact, because catching the forgery without catching the infrastructure only removes one disposable identity from a cheap supply.
Document authentication, biometric matching, liveness, and deepfake detection are read together at onboarding so that no single presented artefact is trusted on its own.
Device fingerprinting, network analysis, and shared attribute analysis across documents and devices expose the network behind an attempt rather than the attempt alone.
Behavioural biometrics and re checks at login, recovery, and high value events prevent a network from exploiting an account quietly once it has cleared onboarding.
The available evidence is weighted so that clean attempts clear automatically and edge cases route for review, which allows controls to scale without adding friction for genuine users.
Identity assurance should continue past onboarding as an ongoing capability, because a coordinated network is defined by behaviour across time and across accounts. Trust should therefore be reassessed at login, at account recovery, at high value transactions, at beneficiary changes, and at periodic reviews, using the same network intelligence signals that expose coordinated fraud at onboarding.
Frequently asked questions about identity fraud in 2026
The latest identity fraud statistics in this report cover the first half of 2026 and are drawn from Shufti’s production verification traffic across eleven industries. Identity fraud reached 22.49 percent of all verification requests in the crypto sector, which is the highest exposure measured, and 4.24 percent in banking, which is the lowest. AI powered document fraud accounts for 80.10 percent of AI enabled fraud, synthetic identities account for 12.31 percent, injected video accounts for 4.01 percent, and face swaps account for 3.58 percent.
The Shufti Identity Fraud Report 2026 sets out identity fraud rates for eleven industries, the attack typologies observed against remote identity verification, the identity verification artefacts used in those attacks, and the shared attributes that connect apparently separate verification attempts into coordinated networks. The report also includes cross border coordination timings, cluster size distribution, and an evaluation checklist that compliance and product teams can apply to an identity verification provider.
Fraud ring detection works by linking separate verification attempts through the signals they share rather than by assessing each attempt on its own. Reuse of the same fraudulent identity document accounts for 65.68 percent of matches between separate fraudulent attempts, which makes the reused document the strongest single matching signal, while shared devices and controlled IP addresses corroborate it. Effective fraud ring detection therefore combines document originality checks with device fingerprinting, network analysis, and behavioural signals inside one risk based decision.
Identity fraud reaches 22.49 percent of all verification requests in the crypto sector because the industry combines fully remote onboarding, rapid account creation, and the ability to move value quickly once an account is open. Altered documents reach 10.10 percent in crypto, which is the highest single reading anywhere in this report, and the crypto sector is also one of only two industries where liveness failures outrank replay attempts. That pattern suggests attackers are working the biometric step as hard as the document step, and the Financial Action Task Force identifies virtual asset service providers as exposed to identity fraud at onboarding for the same reasons.
Neither is inferable from the rate alone. A detection rate reflects attempted attacks, the controls applied, and the sensitivity of those controls together. Sectors with high remote onboarding volume attract more attempts. Sectors with more thorough checks confirm more of what they receive. The rates describe exposure, not relative security posture.
Crypto faces the highest identity fraud risk at 22.49 percent of all verification requests, followed by fintech at 18.36 percent, forex at 17.18 percent, and lending and investment at 17.08 percent. Banking records the lowest rate at 4.24 percent, which is consistent with more mature onboarding controls. Altered documents lead nine of the eleven industries measured in this report.
Synthetic identity fraud detection works by testing whether an identity holds together as a person rather than only checking whether its individual data points are internally consistent. A synthetic identity combines real and fabricated details into someone who does not exist but who looks legitimate on paper, and it accounts for 12.31 percent of AI enabled fraud in the first half of 2026. Effective synthetic identity fraud detection therefore pairs document and biometric verification with network intelligence, because a fabricated identity that clears onboarding on its own is often exposed by the device, address, or document it shares with other attempts.
A deepfake identity fraud attempt uses an AI generated or AI manipulated document, face, or video stream in order to pass a remote identity verification check. Deepfake document fraud is the most common form and accounts for 80.10 percent of AI enabled fraud in the first half of 2026, because the same forged document remains reusable across many applications and therefore reappears inside coordinated networks.
Businesses can detect coordinated identity fraud networks by correlating independent layers of evidence rather than trusting any single signal. Document authentication, biometric matching, liveness, and deepfake detection establish whether the presented artefact is genuine, while device fingerprinting, network analysis, and shared attribute analysis establish whether the same operator sits behind several attempts. Trust should then be reassessed after onboarding at login, at account recovery, and at high value events.
Form submitted successfully!
Thank you for your interest — your report is loading now.
Identity fraud prevention built to protect genuine users
Identity verification, KYC and AML screening now have to account for organised fraud rings, synthetic identity fraud and deepfake documents rather than isolated attempts. Shufti delivers identity fraud prevention that combines document verification, biometric authentication, liveness and deepfake detection with fraud ring detection and identity network intelligence inside one risk based decision, so that regulated businesses can meet KYC and AML compliance obligations, onboard genuine customers quickly and identify the coordinated fraud networks operating behind remote onboarding.























