Deepfakes Turn Identity Fraud Into Organised Crime Threat As Fraud Rings Recycle Identities Across Borders
Organised fraud networks are increasingly using deepfakes, forged documents, synthetic identities and shared digital infrastructure to bypass remote KYC checks, exposing digital businesses to a...
Organised fraud networks are increasingly using deepfakes, forged documents, synthetic identities and shared digital infrastructure to bypass remote KYC checks, exposing digital businesses to a growing financial crime threat, according to Shufti’s 2026 Identity Fraud Report.
The report, based on identity verification data processed between January and June 2026 across 11 industries, found that fraudsters are no longer relying on isolated identity scams. Instead, coordinated networks are recycling the same fraudulent identities, documents, devices and IP addresses across multiple institutions and jurisdictions.
Forged identity documents accounted for 65.68 per cent of the matching signals connecting separate fraudulent verification attempts. Shared controlled IP addresses accounted for 17.67 per cent, while shared devices represented 16.64 per cent.
The largest connected fraud cluster identified by the report involved 70 identities operating across 13 devices, with one device linked to 16 separate verification events. The findings suggest that criminals can repeatedly submit altered identities after an earlier attempt has been rejected elsewhere.
Cross-border activity adds another layer of risk. Shufti found that 2.01 per cent of network fraud cases crossed national borders. In one striking finding, the typical gap between activity in different countries was just nine minutes and 33 seconds, while the fastest observed transition occurred within 38 seconds.
Digital asset businesses recorded the highest share of remote onboarding fraud at 22.49 per cent, followed by fintech at 18.36 per cent and forex at 17.18 per cent.
Deepfake document fraud accounted for 80.10 per cent of AI-enabled fraud identified in the study, significantly ahead of synthetic identities, injected videos and face swaps.
For compliance teams, the findings reinforce the limits of one-off document verification. Effective KYC increasingly requires continuous monitoring, device and network intelligence, behavioural analysis and the ability to connect apparently separate onboarding attempts.
The report warns that once fraud networks operate across borders, individual institutions may see only fragments of the same criminal operation, creating downstream AML exposure.


No Comment! Be the first one.