Generative AI has changed document and identity fraud faster in two years than in the previous decade. Fake certificates, identity documents and financial statements that once needed a skilled forger and specialist equipment can now be produced from a short text prompt. The figures from identity-verification providers, analysts and regulators all point the same way: more attempts, more convincing fakes, and more of them aimed at the automated systems that are supposed to catch them.
This page collects the most reliable statistics on AI-driven document and identity fraud, each attributed to its primary source and dated, so you can quote them with confidence. It is updated every quarter as new reports are published.
For the implications behind these numbers and what organisations can do about them, read the pillar guide.
Document Fraud in the GenAI Era →Key statistics at a glance
The figures most often cited, with their sources. Each is expanded, with context and caveats, in the sections below.
1 in 5
biometric fraud attempts now involve a deepfake; deepfake selfies rose 58% in 2025.
+180%
rise in sophisticated, multi-step fraud year on year, from 10% of identity fraud in 2024 to 28% in 2025.
2%
of fake documents are now AI-assisted forgeries, up from effectively 0% — roughly one in fifty.
+741%
rise in biometric injection attacks year on year; attacks on iOS devices up 1,151% in H2 2025.
21%
of first-party fraud is driven by synthetic identities — the single most common type.
$20bn+
a year: the cost of synthetic identity fraud to US financial institutions.
$40bn
projected US fraud losses by 2027, up from $12.3bn in 2023, driven by generative AI.
~25%
how often people correctly identify high-quality deepfakes; just 0.1% spot every fake.
The scale and growth of AI document fraud
AI has pushed the cost, skill and time needed to forge a document close to zero, and the volume and quality of fakes have risen sharply as a result.
Sumsub’s Identity Fraud Report 2025–2026, published in November 2025 and based on more than four million fraud attempts analysed across 2024 and 2025, describes what it calls a “sophistication shift”: fewer attacks, but far more professionalised. The share of multi-step, AI-driven fraud rose 180% year on year, climbing from 10% of all identity fraud in 2024 to 28% in 2025. The overall identity fraud rate actually eased over the same period, from 2.6% to 2.2%, which is the point worth holding onto: the number of attempts fell while their quality rose.
A new category appeared in the same report. AI-assisted document forgery, fakes generated with tools such as ChatGPT, Grok and Gemini, rose from effectively 0% to 2% of all fake documents during 2025. That is roughly one in fifty forged documents, from a standing start. Sumsub also found that 40% of surveyed companies and 52% of end users reported being victims of fraud in 2025, and 75% of respondents believed fraud is becoming increasingly AI-driven.
The shift from physical to digital forgery is just as clear. In Entrust’s 2026 Identity Fraud Report, drawn from more than a billion identity verifications across 195 countries, digital forgeries made up 35% of document fraud in 2025, up from a 29% average over 2022 to 2024. National identity cards were the most-targeted document, accounting for 46% of fraudulent submissions globally and 60% across APAC. An earlier Entrust report had already recorded a deepfake attempt roughly every five minutes during 2024, alongside a 244% year-on-year jump in digital document forgeries.
The sophistication shift
Multi-step, AI-driven fraud as a share of all identity fraud
Deepfakes in identity verification
Deepfakes have moved from a novelty to a routine attack on the selfie, video and liveness checks used to confirm a real person is present.
The most-cited business figure comes from Gartner. In a survey of 302 cybersecurity leaders conducted between March and May 2025, 62% of organisations said they had experienced a deepfake attack in the previous year, whether through social engineering, such as impersonating an executive on a video call, or by exploiting automated verification. Of those surveyed, 43% reported at least one deepfake audio incident and 37% a deepfake video incident.
Attacks on the verification pipeline itself are rising fastest. iProov’s 2026 Threat Intelligence Report recorded a 741% year-on-year rise in biometric injection attacks, where a synthetic video feed is fed directly into a verification system rather than shown to a camera, with attacks on iOS devices up 1,151% in the second half of 2025. Face swaps, iProov notes, are now the deepfake of choice. Entrust’s 2026 report found deepfakes behind around one in five biometric fraud attempts, with deepfake selfies up 58% in 2025 and injection attacks up 40% year on year.
The consequences are already concrete. In early 2024, a finance employee at the engineering firm Arup joined a video call with what appeared to be the company’s chief financial officer and colleagues. Every other participant was a deepfake, and the employee approved transfers totalling around $25 million before the fraud was discovered.
Synthetic identity fraud
Synthetic identity fraud, where real and fabricated details are combined into a person who does not exist, is now the most common form of first-party fraud and one of the fastest-growing financial crimes.
Sumsub found synthetic identities behind 21% of first-party fraud in 2025, ahead of chargeback abuse (16%), application fraud (14%) and deepfakes (11%). The cost is concentrated in financial services: the Federal Reserve Bank of Boston estimates that synthetic identity fraud costs US financial institutions more than $20 billion a year, the largest category of identity-related loss in the US market, and warns that generative AI is making these identities faster and more convincing to build.
The trend is broad. LexisNexis reported that synthetic identities featured in around one in ten fraud cases globally, an eightfold increase on earlier years, and Juniper Research projects that fraud losses to financial institutions will rise from about $23 billion in 2025 to $58.3 billion by 2030, with synthetic identity fraud a key driver.
The cost and business impact
The projected financial impact of AI-enabled fraud runs into the tens of billions, and the direction of travel is steep.
The most widely cited projection comes from the Deloitte Center for Financial Services, which estimated that generative AI could enable fraud losses in the United States to reach $40 billion by 2027, up from $12.3 billion in 2023, a compound annual growth rate of around 32%. Juniper Research’s wider estimate puts fraud losses to financial institutions globally at $58.3 billion by 2030. These are forecasts rather than recorded losses, and they rest on assumptions about adoption, so treat them as trajectory rather than fact. The direction, across every source, is consistent.
Why detection and inspection now fail
Both defences most organisations rely on — judging whether a document looks right, and detecting fakes after they arrive — are losing ground against generative AI.
Human inspection has effectively stopped working for high-quality fakes. In an iProov study, people correctly identified high-quality deepfakes only about a quarter of the time, and just 0.1% of participants spotted every fake they were shown. A static PDF or scanned document carries even fewer cues to judge than a video does.
Automated detection helps, but it is reactive by design. Every detector is trained on yesterday’s fakes while generative models release new versions constantly. Sumsub notes that as tools such as Google Veo 3.1 and OpenAI’s Sora 2 push the realism of synthetic content, even protective measures like watermarks are increasingly easy for professional fraudsters to strip or avoid. The common weakness is that both approaches ask the same question, does this artefact look genuine, and once anything can be made to look genuine, that question stops telling you anything.
Where exposure concentrates
The organisations most exposed are those that accept high-stakes documents from people they cannot meet in person: financial services, government, education and recruitment.
Sumsub’s 2025 data puts the highest fraud rates in online media and dating (6.3%), financial services (2.7%), crypto (2.2%), professional services such as consulting, legal and accounting (1.6%) and video gaming (1.6%). In financial services and regulated onboarding, forged documents and deepfakes target the Know Your Customer checks that open accounts, which is why national identity cards, at 46% of fraudulent document submissions globally, are the single most-targeted document type.
Government and licensing carry real downstream authority when a permit, business licence or identity document is faked. Education faces degree and certificate fraud that undermines admissions and hiring alike; we cover the scale of that in a separate degree-fraud statistics page. Recruitment and HR sit on top of the same weakness, clearing fabricated qualifications and references with checks that were only ever a visual glance.
The regional picture: Southeast Asia and the Middle East
While fraud rates fell in Europe and North America over 2024 to 2025, they rose across APAC and the Middle East.
Sumsub recorded the identity fraud rate falling 14.6% in Europe and 5.5% in North America, but rising 16.4% across APAC and 19.8% in the Middle East, with Africa up 9.3%. The highest national fraud rates in the dataset were Iraq at 9.7% in the Middle East and Pakistan at 5.9% in APAC. In its APAC breakdown, Sumsub also flagged money-mule recruitment, with one in four respondents targeted.
Deepfake growth specifically has been steepest in this region. Figures from Sumsub reported by Fintech News Singapore recorded the fastest APAC deepfake growth rates in the Maldives (2,100%), followed by Malaysia (408%), Thailand (199%), Singapore (158%) and Hong Kong (147%). Across APAC fintech, fraud cases rose 116% year on year in the first quarter of 2025, and healthtech rose 723%, the steepest of any industry in the region.
Note on regional data: consistent, like-for-like national statistics for Southeast Asia and the Middle East remain thin, and different providers frame deepfake “growth” differently, so these figures are best read as directional. We will add more regional data points as credible primary sources publish them.
The emerging edge: fraud in agentic AI workflows
As AI agents begin to receive and act on documents automatically, an unverified file becomes both a fraud risk and a security risk. Two problems arise, and they compound.
The first is fraud that clears automated checks: a generated fake passes an agent as easily as it passes a person, and far faster. Sumsub warns that agentic AI scams are set to surge in 2026, with a single agent able to orchestrate a whole fraud chain, from generating a fake ID to passing a live selfie check with a deepfake, at machine speed.
The second is subtler: the document itself can be the attack. A file that looks like an ordinary invoice or CV can carry hidden instructions that an agent executes when it reads the file. This is indirect prompt injection, and it sits at number one on the OWASP Top 10 for LLM Applications (2025). OpenAI has said prompt injection is “unlikely to ever be fully ‘solved’”, because it stems from how these models take in text, treating trusted instructions and untrusted data alike.
What the numbers point to: verifying, not inspecting
The durable response to every figure on this page is to verify a document’s origin cryptographically rather than judge its appearance.
A Verifiable Credential is a digital document signed by its issuer with a cryptographic key. Anyone who receives it can confirm in seconds that it came from the claimed issuer and has not been altered, without inspecting how it looks or contacting the issuer. If a single character is changed, the check fails. This moves the question from “does this look genuine?”, which generative AI has made unanswerable, to “was this issued by who it claims, and is it unaltered?”, which cryptography answers definitively. It also addresses the agentic case directly: an agent can require every incoming document to be a Verifiable Credential and refuse to act on anything that does not verify.
Accredify builds on open standards, including W3C Verifiable Credentials and TrustVC. It is the model behind Singapore’s HealthCerts and the verifiable business records issued with government bodies such as ACRA, credentials designed to be checked by anyone, instantly, without contacting the issuer. For the full argument behind these statistics, see the pillar guide, Document Fraud in the GenAI Era.
Two questions
The question generative AI broke, and the one it can’t
Inspecting
“Does it look genuine?”
A judgement about appearance. Once anything can be made to look genuine, the answer stops telling you anything.
Verifying
“Was it issued by who it claims, unaltered?”
A cryptographic check against the issuer’s key. It resolves in seconds and holds even when a forgery is visually perfect.
See how Accredify’s TrustView lets people and systems verify a credential’s authenticity in seconds, cryptographically, without inspecting a single pixel.
Learn more about TrustView →Sources and methodology
Every statistic on this page is drawn from a named primary source, listed below with its publication date. Figures are reviewed and refreshed each quarter; the “last updated” date at the top reflects the most recent review.
- 1 Sumsub, Identity Fraud Report 2025–2026 (November 2025). Read the report →
- 2 Entrust, 2026 Identity Fraud Report (November 2025). Read the report →
- 3 Entrust, 2025 Identity Fraud Report (November 2024). Read the report →
- 4 Gartner, GenAI attacks survey (September 2025). Read the release →
- 5 iProov, Threat Intelligence Report 2026 (April 2026). Read the report →
- 6 iProov, Threat Intelligence Report 2025 (February 2025). Read the report →
- 7 Deloitte Center for Financial Services, generative AI fraud projection (2024). Read the analysis →
- 8 Federal Reserve Bank of Boston, synthetic identity fraud and generative AI (April 2025). Read the article →
- 9 Juniper Research, fraud losses forecast to 2030. Read the release →
- 10 LexisNexis Risk Solutions, Cybercrime Report (2026). Read the report →
- 11 OWASP, Top 10 for LLM Applications (2025). Read the list →
- 12 Fintech News Singapore, APAC deepfake growth (Sumsub data). Read the article →
Frequently asked questions
How common are deepfake attacks on businesses?
Very common. In a Gartner survey of cybersecurity leaders conducted in 2025, 62% of organisations said they had experienced a deepfake attack in the previous year, through social engineering or by exploiting automated verification.
How much does AI-enabled fraud cost?
The Deloitte Center for Financial Services projected that generative AI could enable US fraud losses of $40 billion by 2027, up from $12.3 billion in 2023. Synthetic identity fraud alone costs US financial institutions more than $20 billion a year, according to the Federal Reserve Bank of Boston.
Can people or software detect AI-generated documents?
Not reliably. In an iProov study, people identified high-quality deepfakes only about a quarter of the time. Automated detectors help but are always trained on older fakes while generative models keep improving, so detection cannot be depended on for high-stakes decisions.
What is the fastest-growing type of identity fraud?
Synthetic identity fraud and deepfake-based attacks. Synthetic identities were behind 21% of first-party fraud in 2025 (Sumsub), and biometric injection attacks rose 741% year on year (iProov).
Which regions are seeing the most AI document fraud growth?
Fraud rates rose across APAC (up 16.4%) and the Middle East (up 19.8%) over 2024 to 2025 while falling in Europe and North America (Sumsub). Deepfake growth has been steepest in parts of Southeast Asia.
How do Verifiable Credentials help against AI document fraud?
A Verifiable Credential is cryptographically signed by its issuer. Anyone receiving it can confirm in seconds that it came from the claimed issuer and has not been altered, without inspecting how it looks. Authenticity becomes a check rather than a judgement, which is what makes it hold up when a forgery is visually perfect.
Accredify works with governments, institutions and businesses across Southeast Asia and the Middle East to issue Verifiable Credentials built on open standards. If document fraud is a risk you are trying to manage, talk to our team to explore how VCs can work for your organisation.
Book a demo →