News

Deepfake Identity Fraud Projected to Rise Nearly Sixfold in 2026, Industry Report Finds

Moca Network
August 20, 2026

TL;DR — Shufti's Identity Fraud Index Report projects that deepfake-powered identity fraud will rise 495% in 2026 compared with 2025, close to a sixfold increase in a single year. The report, based on more than one million fraud attempts analysed across Shufti's global verification network, splits AI-driven fraud into four types: synthetic identities, live video deepfakes, face swaps and document deepfakes. Document deepfakes are the fastest-growing category at close to +3,900% year on year. The report's conclusion is that manual review can no longer reliably catch high-quality deepfakes and that single selfie checks are no longer sufficient as a control.

Read the full report: Deepfake-Powered Identity Fraud Is Surging in 2026: Shufti's Identity Fraud Index Report, Shufti, 2026.

The headline number

The report's central projection is a 495% increase in deepfake-powered identity fraud in 2026 versus 2025. Shufti describes it as the sharpest year-on-year acceleration in its dataset.

Four attack types

  • Synthetic identity. 42.3% of AI-driven fraud attempts in 2025, with a projected +173% growth in 2026. Real and fabricated data are blended to create a person who does not exist.
  • Live video deepfakes. 28.1% share. An established threat that has grown every year since 2023.
  • Face swaps. 17.6% share, projected to grow +121% in 2026.
  • Document deepfakes. 11.9% share but the fastest-growing type, at nearly +3,900% year on year, as generative AI makes convincing identity documents cheap to produce.

Why it matters

The report argues that the cost and skill required to mount a credible deepfake attack have collapsed, which moves the threat from a niche concern to a baseline assumption for any remote onboarding flow. It cites Deloitte's estimate that generative AI could enable up to US$40 billion in fraud losses in the United States by 2027.

Shufti's recommended response is layered: capture integrity checks, liveness verification and forensic analysis working together, rather than relying on a single selfie or document check. The findings sit alongside similar warnings this year from the World Economic Forum and Sumsub on AI-generated fake IDs and their effect on KYC controls.

Related reading

More from AIR: AIR Identity and verified user acquisition, or browse the full AIR blog.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
CrowdStrike and Rubrik Automate Identity Attack Recovery at Fal.Con 2026
CrowdStrike and Rubrik announced an agentic workflow that detects, investigates and recovers compromised identity environments in hours rather than days.
News
Central KYC Registry vs Reusable Credentials: Two Models
India's central KYC registry lets firms fetch verified customer data with consent, cutting onboarding 50-70%. One of two architectures for reusable KYC.
News
Retroactive Age Verification: The Existing-Account Problem
Brazil bars new under-15 accounts from 1 September and requires existing ones verified or deactivated by January. The second deadline is the hard one.