Nevada, 47284 Queenie Drive, Suite 865

Fraud Just Got Smarter Than Most Security Teams: What the 2026 Data Actually Shows

Fraud Just Got Smarter Than Most Security Teams: What the Data Actually Shows

A finance employee in Hong Kong joins a routine video call with his CFO and several colleagues. They discuss an urgent wire transfer. He authorizes $25 million. Every person on that call was a deepfake. The employee was the only real human in the meeting.

That happened to engineering firm Arup in 2024. Two years later, this type of attack has become so common it barely makes headlines anymore.

Sumsub’s Identity Fraud Report 2025-2026, based on over 4 million fraud cases across 230 countries, paints a picture that should concern anyone who uses the internet — which is everyone. Sophisticated fraud surged 180% globally. Deepfake-specific incidents jumped tenfold since 2022. And a new breed of AI-powered scams is emerging that makes everything we’ve seen so far look primitive.

Here’s what the numbers actually say, what they mean for you, and — most importantly — what to do about it.

The Sumsub Report by the Numbers: A Fraud Explosion

Sumsub processes identity verification for companies like Revolut, Binance, and dozens of other fintech and crypto platforms. Their annual report isn’t based on surveys or projections — it’s built from real fraud attempts they intercepted across their platform.

The headline numbers from the 2025-2026 report are staggering. Sophisticated fraud rose 180% year-over-year globally. This isn’t just more fraud — it’s smarter fraud. Multi-step schemes that combine identity document forgery, deepfake biometrics, and social engineering have replaced the crude Photoshop edits of a few years ago.

Synthetic identity document fraud surged 300% in the United States alone, according to a separate Sumsub analysis published in June 2026. Fraudsters no longer just steal identities — they create entirely fictional people by mixing real and fabricated data. These synthetic identities pass automated checks, open bank accounts, and rack up credit before disappearing.

In the APAC region, synthetic personal data fraud soared 142% year-over-year. And 84% of attacks in APAC targeted social media platforms and government portals rather than financial services — a shift that caught many security teams off guard.

The fintech sector saw identity fraud increase 73%. But the hardest-hit industries might surprise you: e-commerce, healthtech, and professional services are now firmly in the crosshairs.

Deepfakes: From Curiosity to $25 Million Weapon

The deepfake fraud explosion deserves its own section because the scale is hard to overstate.

Sumsub’s data shows deepfake-specific fraud cases increasing tenfold between 2022 and 2025. Other tracking firms report even more alarming figures. Memeburn compiled data showing a 3,892% surge in deepfake-related fraud incidents. ASIS International projects deepfake identity fraud will increase nearly 500% through 2026.

In the UK specifically, deepfake attacks doubled in 2025 compared to the previous year, according to Financial IT’s analysis of the Sumsub data.

These aren’t hypothetical threats. The Arup case — $25 million stolen via a deepfake video call — was just the most publicized example. Brightside AI documented CEO fraud cases where voice cloning technology created convincing enough audio to authorize wire transfers exceeding $50 million. Adaptive Security catalogued 11 major deepfake attack cases in their 2026 analysis, spanning corporate fraud, political manipulation, and financial scams.

The technology has become disturbingly accessible. A three-second voice sample is enough to clone someone’s voice convincingly. Video deepfakes that once required expensive hardware now run on consumer laptops. Sumsub’s own research on the “creator economy” found that influencers and public figures — people with hours of video and audio available online — are the easiest targets.

The Deepfake Video Call Playbook

Here’s how a typical corporate deepfake attack works in 2026, based on real cases documented by cybersecurity firms.

The attacker identifies a target company and its key executives through LinkedIn and public filings. They scrape video and audio of those executives from earnings calls, conference presentations, and YouTube videos. Using commercially available AI tools, they generate real-time deepfake video and cloned audio. They schedule a video call — often timed during travel periods or across time zones when informal verification is harder. On the call, the deepfake executive instructs a finance employee to process an “urgent” transfer.

AI Agents in 2026: What They Are, How They Work, and 10 You Can Use Today

The whole operation from research to execution takes days, not months. And it costs the attacker under $100 in AI tool subscriptions.

The FBI’s $20.9 Billion Wake-Up Call

The Sumsub data doesn’t exist in isolation. The FBI’s Internet Crime Complaint Center (IC3) report for 2025 shows U.S. cybercrime losses hit $20.9 billion — a 26% increase over the previous year. The FBI explicitly called out AI scams and cryptocurrency theft as primary drivers.

Internet scam losses globally reached an estimated $16.6 billion in 2025, with AI-powered attacks accounting for a growing share that’s impossible to quantify precisely because many victims don’t realize AI was involved.

Cryptocurrency-related fraud remains the largest loss category. “Pig butchering” scams — long-con investment frauds that blend romance scams with fake crypto platforms — continue to evolve. AI has supercharged these operations by allowing a single scammer to maintain dozens of convincing fake personas simultaneously, each with unique voice, video, and messaging patterns.

CryptoTimes reported that 2026 saw the biggest crackdowns on pig butchering networks, but also the biggest losses. The operations have industrialized: networks run from compounds in Southeast Asia now use AI-generated faces, voices, and even real-time video to build trust with victims over weeks or months before the extraction phase.

What’s New in 2026: Agentic AI Scams and Fraud-as-a-Service

Sumsub’s report identified a threat that barely existed a year ago: agentic AI scams. These aren’t deepfakes or chatbot-assisted phishing. They’re autonomous AI agents that can independently execute multi-step fraud operations.

Think about what AI agents can already do legitimately: browse the web, fill out forms, send emails, make phone calls, process payments. Now imagine those same capabilities deployed for fraud. An agentic AI scam could scrape a target’s social media to build a psychological profile, generate a convincing phishing email personalized to their interests, create a fake website mimicking their bank, and process the stolen credentials — all without human intervention between steps.

Experian’s 2026 Fraud Forecast identified three specific agentic AI threats. First, deepfake job candidates — AI-generated personas that pass video interviews, get hired, and gain access to company systems. Second, automated “cyber break-ins” where AI agents probe for vulnerabilities and exploit them at machine speed. Third, fully automated social engineering campaigns that adapt in real-time based on the victim’s responses.

Sumsub’s blog on fraud trends warns that “fraud-as-a-service” platforms — essentially subscription services that provide fraud tools to anyone willing to pay — are making sophisticated attacks available to low-skilled criminals. What once required a team of skilled hackers now requires a credit card and a Telegram username.

Context Engineering Is the Only AI Skill That Matters in 2026

The Regional Breakdown: Where Fraud Hits Hardest

Fraud doesn’t hit every region equally, and the Sumsub data reveals patterns that matter for both businesses and consumers.

APAC leads in synthetic data fraud, with the 142% year-over-year increase driven largely by rapidly growing digital economies in Southeast Asia, India, and the Pacific Islands. Social media platforms bear the brunt — a shift from the financial services focus seen in Western markets.

Europe faces a “new phase” of fraud, according to FinTech Weekly’s analysis. Sophisticated attacks are surging as the EU’s regulatory framework creates a patchwork of compliance requirements that fraudsters exploit by operating across borders.

Latin America and Africa are seeing dramatic increases in identity document fraud as digital financial inclusion expands. More people coming online means more targets, and verification infrastructure hasn’t kept pace.

The United States remains the epicenter of synthetic identity fraud (up 300%), driven by the combination of a credit-heavy financial system and the availability of personal data from decades of breaches.

Industries Under Fire

The fraud landscape has shifted away from its traditional concentration in banking and financial services.

E-commerce platforms are now heavily targeted because they combine payment processing with weaker identity verification than banks. Healthtech is the rising concern — medical identity theft enables insurance fraud, prescription fraud, and access to controlled substances. Professional services and consulting firms face deepfake-powered impersonation attacks. And the creator economy — influencers, streamers, content creators — faces both impersonation fraud and account takeover attacks.

The common thread: any sector that onboards users digitally and processes payments is a target. The sectors with the weakest verification suffer the most.

How to Protect Yourself: The No-Nonsense Guide

The data is alarming, but the good news is that most fraud — even AI-powered fraud — exploits predictable weaknesses. Here’s what works.

For Individuals

Treat every unexpected call as suspicious. If someone calls claiming to be from your bank, your boss, or a family member in trouble — hang up and call them back at a number you look up yourself. This single habit defeats most voice cloning attacks because scammers can’t intercept callbacks to legitimate numbers.

Set up a family code word. Choose a word or phrase that only your family knows. Any urgent call asking for money gets verified with the code word. It sounds old-fashioned. It works against the most advanced AI.

Freeze your credit. In the U.S., freezing your credit at all three bureaus (Equifax, Experian, TransUnion) costs nothing and prevents synthetic identity fraud from destroying your credit history. Unfreeze temporarily when you need new credit. This is the single most effective defense against identity theft.

Question video calls from unknown contacts. Ask the person to perform an action that real-time deepfakes struggle with: turn their head sharply, hold up a specific number of fingers on request, or move to a different light source. Current deepfake technology often glitches during sudden, unpredictable movements.

Use hardware security keys for important accounts. Phishing can steal passwords and even two-factor codes sent by SMS. A hardware security key (YubiKey, Google Titan) cannot be phished — it physically verifies you’re on the legitimate website.

For Businesses

Implement multi-person authorization for wire transfers. The Arup attack succeeded because one person could authorize $25 million. Requiring two separate individuals to confirm transfers above a threshold — using out-of-band verification (phone call, in-person, separate secure channel) — defeats most deepfake video call attacks.

Deploy liveness detection in identity verification. Sumsub and competitors like Shufti and Veriff offer liveness detection that can spot deepfakes during onboarding. This technology analyzes micro-movements, skin texture, and light reflection patterns that current deepfakes can’t replicate perfectly.

Train employees specifically on AI-powered threats. General “don’t click suspicious links” training isn’t enough. Staff need to see examples of voice clones, understand how deepfake video calls work, and know the specific verification procedures for high-risk requests.

Monitor for synthetic identities. Cross-reference new account applications against known data breach databases, check for impossible combinations (Social Security numbers paired with inconsistent age or address history), and flag accounts that show unusual early behavior patterns.

What Sumsub Gets Right — and What’s Missing

Sumsub’s report is the most comprehensive data-driven look at identity fraud available today. Their dataset of 4 million fraud cases across 230 countries gives them a view that no academic study or government report can match. The 180% increase in sophisticated fraud isn’t an estimate — it’s what they measured.

But the report has blind spots worth acknowledging. Sumsub sees fraud at the identity verification stage — the point where someone tries to onboard onto a platform. They don’t capture fraud that happens after successful onboarding (account takeover, authorized push payment fraud, social engineering within legitimate sessions). They also primarily serve fintech and crypto companies, which skews the industry data.

The deepfake numbers are particularly tricky to interpret. Different sources report wildly different figures: Sumsub says tenfold since 2022, Memeburn cites 3,892%, ASIS International says nearly 500%. These aren’t contradictions — they’re measuring different things (fraud attempts vs. successful fraud vs. deepfake incidents broadly). But it means anyone citing a single number is oversimplifying.

What every source agrees on: the direction is sharply upward, the tools are more accessible than ever, and traditional defense is insufficient.

The $300 Billion Question: What Happens Next

Every forecast points the same direction. Sumsub predicts agentic AI scams will be the dominant new threat in 2026-2027. Experian warns about deepfake job candidates infiltrating companies. The FBI’s data shows losses accelerating, not stabilizing.

Three developments will shape the next 18 months.

AI vs. AI becomes the real battlefield. Detection tools are improving rapidly — companies like Sumsub, Resemble AI, and TruthScan are deploying models specifically trained to catch deepfakes. But generators improve at the same pace. The analogy to antivirus vs. malware is apt: it’s an arms race with no finish line.

Regulation is catching up — slowly. The EU AI Act (effective August 2, 2026) requires labeling of AI-generated content and imposes obligations on deepfake creators. But enforcement across jurisdictions remains the weak link. Fraud operations based in countries with minimal enforcement face no meaningful deterrent.

The cost of trust is rising. As AI makes deception cheaper, verification gets more expensive and more intrusive. Every video call may require liveness verification. Every wire transfer may need multi-party confirmation. Every new account may need enhanced due diligence. The friction that fraud creates is itself a cost — one that rarely appears in the loss statistics.

The Sumsub report’s most striking finding isn’t any single number. It’s the pattern: fraud isn’t just growing, it’s evolving faster than defenses. The 180% increase in sophisticated attacks signals that we’ve entered a phase where the old approach — react after the fact — is guaranteed to fail.

The winners in this environment won’t be the companies with the biggest security budgets. They’ll be the ones that build verification into every interaction by default, train their people to question everything, and accept that the cost of trust is now a permanent line item.

Start with the basics: freeze your credit, use a code word with family, question unexpected calls. Then build from there. Because the fraud landscape of 2026 has one clear message: if it seems too good to be true, too urgent to verify, or too familiar to question — that’s exactly when you should stop and check.

Leave a Reply

Your email address will not be published. Required fields are marked *

Expert Reviews

In-depth, unbiased analysis

Free Resources

Guides, tools and templates

Trusted by Thousands

Readers across 50+ countries

100% Independent

No sponsored rankings