Measured consumer harm, AI-enabled identity attacks, South African context and layered defence.
Sixteen core sections with a September official-source update for South Africa.
Losses levelled off, but victim exposure and attack quality increased
Traditional identity fraud cost US consumers $27.3 billion, equal to about R441.10 billion at the report's exchange rate, in 2025. Javelin estimates 18 million victims. New-account fraud victims rose 31%, from 4.2 million to 5.4 million, while account-takeover victims rose 18%, from 5.1 million to 6 million. (Javelin 2026 Identity Fraud Study)
AI-enabled methods are present, but there is no defensible global incident total. Deepfakes accounted for roughly one in five biometric fraud attempts in Entrust's network. iProov observed a 741% annual rise in iOS-targeted injection attacks. These measures use different populations and must not be added together. (Entrust 2026 Identity Fraud Report) (iProov 2026 Threat Intelligence Report)
Identity proofing must treat the capture channel as part of the evidence. NIST requires genuine-sensor confidence, forged-media analysis, protected channels, documented testing and manual review where needed. It says biometric comparison and presentation-attack detection do not cover every injection or forged-media case. (NIST SP 800-63A-4, July 2025)
About R441.10bn · traditional identity fraud · 2025
Representative consumer survey
4.2m to 5.4m
5.1m to 6.0m
Loss, victims and reports answer different questions
Javelin's survey measures US adult experiences and estimates population totals. FTC Consumer Sentinel records reports submitted to the agency and its contributors; those reports are not verified cases and are not a population survey. In 2024, Sentinel received 6.5 million consumer reports across fraud, identity theft and other consumer-protection categories, including more than 1.1 million identity-theft reports. (FTC Consumer Sentinel Data Book 2024)
Millions of United States adults · 2024 versus 2025 · Javelin consumer survey
| Fraud type | 2024 victims | 2025 victims | Change |
|---|---|---|---|
| New-account fraud | 4.2m | 5.4m | +31% |
| Account takeover | 5.1m | 6.0m | +18% |
The useful distinction is how the identity is obtained and used
A stolen, fabricated or synthetic identity is used to open a new financial, telecoms, retail, betting or other account.
An attacker gains control of an existing account through stolen credentials, social engineering, SIM compromise or recovery-process abuse.
Documents or biometric media are forged, altered, replayed, deepfaked or injected into a remote identity-proofing process.
Real and fabricated attributes are combined into an identity that may be cultivated over time before higher-value abuse.
A stolen identity or payment credential is used for account opening, card-not-present payments, refunds or withdrawals.
A criminal convinces a person, employee or support agent to disclose credentials, change an account or approve a transaction.
Consumer reports · United States · 2024 · categories may overlap
Attack realism improved; the measurement remains fragmented
Entrust's 2026 report draws on more than one billion verifications from September 2024 to September 2025. It reports that physical counterfeit documents represented 47% of document fraud in its network, digital forgeries 35%, physical forgeries 10% and digital counterfeits 9%. The total is 101% because the published values are rounded. (Entrust 2026 Identity Fraud Report)
Share of document fraud · Entrust verification network · 2025 · rounded values
Entrust linked roughly one in five biometric fraud attempts in its network to deepfakes.
Entrust reported an approximately 40% annual increase in injection-attack cadence.
iProov reported annual growth in iOS-targeted injection attacks in its monitored environment.
Sumsub network · 2023 to 2025 · not a global population rate
The identity decision must survive login, recovery and payout
New-account fraud and account takeover now affect more US adults than they did a year earlier. The two risks require different controls. New-account fraud tests whether the person and evidence are genuine; account takeover tests whether the current actor is still the legitimate customer. (Javelin 2026 Identity Fraud Study)
Document validation, genuine-sensor checks, biometric comparison where lawful, device integrity, identity-attribute consistency, sanctions and risk screening.
Phishing-resistant or risk-based authentication, device change detection, credential-stuffing controls and session-risk analysis.
Treat phone, email and password changes as high-risk identity events. Prevent a support interaction from bypassing stronger login controls.
Check payer or beneficiary ownership, transaction velocity, profile consistency and recent account changes before releasing value.
The same identity can be abused differently by sector
New accounts, credit applications, payment fraud, account takeover and mule activity connect identity risk directly to financial loss and AML obligations.
Stolen or repeated identity, underage access, bonus abuse, third-party payments, account takeover and laundering risks appear at different lifecycle stages.
SIM compromise and account recovery can redirect authentication and weaken controls used by other sectors.
Stolen accounts, new-account promotion abuse, card-not-present fraud and refund diversion link identity to payment risk.
Fabricated credentials, impersonation and synthetic profiles affect onboarding, access to systems and payout accounts.
Identity misuse can redirect benefits, create fraudulent records or exploit high-volume remote-service channels.
Grey-list exit does not end the control work
FATF removed South Africa from increased monitoring on 24 October 2025 after the country addressed the strategic deficiencies in its action plan. FATF's statement points to improvements in beneficial-ownership access, risk-based supervision, use of financial intelligence, money-laundering investigations, confiscation and targeted financial sanctions. (FATF, 24 October 2025)
The removal is not evidence that identity fraud or money-laundering risk disappeared. For businesses, the practical question remains whether customer due diligence, beneficial-ownership work, transaction monitoring, sanctions controls and reporting operate effectively in the current channel.
Risk models must support the identity documents and populations the service actually accepts without treating document format alone as proof of fraud.
Device, SIM, application, network and account-recovery signals matter where onboarding and authentication happen primarily on a phone.
An external verification result should retain source, time, input, decision, confidence and fallback information for later review.
Latest public figures available on 1 September 2026
Stats SA's 2025/26 survey estimates that about 325,000 South Africans aged 16 and older experienced consumer fraud across roughly 560,000 incidents. Around 39% reported some or all of the incidents to the police. The survey category covers consumer deception involving goods or services, including advance-fee, 419 and online-shopping fraud. (Stats SA GPSJS 2025/26, 1 September 2026)
Police records, banking data, regulator notifications and survey estimates describe separate parts of the fraud picture. Their original units stay visible throughout this update so each figure keeps its reporting period and population.
Estimated incidents · Stats SA 2025/26
Police-recorded cases · Jan to Mar 2026
POPIA notifications · 2025/26
SABRIC member incidents · 2025
| Official measure | Latest figure | Scope |
|---|---|---|
| Consumer fraud survey | 560,000 incidents affecting about 325,000 people | Stats SA estimate for 2025/26. About 39% reported some or all incidents to police. The 2024/25 survey estimated 811,000 incidents affecting 566,000 people. (Stats SA GPSJS 2025/26, 1 September 2026) |
| Police-recorded commercial crime | 36,797 cases, up 4.0% | SAPS national count for January through March 2026, compared with 35,374 in the same quarter of 2025. The category includes fraud, attempted fraud, forgery and uttering. (SAPS fourth-quarter crime statistics 2025/26) |
| POPIA security-compromise notifications | 2,693 in 2025/26; 800 more from April to July 2026 | Notifications submitted to the Information Regulator by responsible parties. The audited prior-year figure was 2,374, up 37% from 1,727. One filing can concern many people or records. (Department of Justice, Information Regulator update, 30 July 2026) (Information Regulator Annual Report 2024/25) |
| Digital-banking fraud | 110,074 incidents; R2.4067bn in gross client claims (US$148.95m) | SABRIC member data for 2025. Gross claims rose 29.2% from 2024. SABRIC is the banking industry's risk-information not-for-profit. (SABRIC Annual Crime Statistics Report 2025) |
| Card false-application fraud | R23.9m (US$1.48m) | SABRIC's combined 2025 value for applications using stolen, fabricated or synthetic identity information. (SABRIC Annual Crime Statistics Report 2025) |
| Smart ID delivery | 4,002,964 cards, up 17% | Home Affairs administrative output for calendar 2025. The department describes the green ID book as fraud-prone and estimates it is 500% more vulnerable to fraud than a Smart ID. (Department of Home Affairs Smart ID update, 28 January 2026) |
| National Population Register verification | Failure rate reduced from above 50% to below 1% | Home Affairs' reported service performance after the July 2025 verification-system upgrade. This is a control and availability measure. (Department of Home Affairs verification-service update, 23 June 2025) |
| Financial-sector impersonation warnings | 140 public warnings; about 20% involved impersonation | FSCA activity during 2025/26. The regulator also opened 29 regulatory-exam identity-fraud investigations, finalised 58, issued 19 debarments and referred eight matters to police. (FSCA Regulatory Actions Report 2025/26) |
| Financial-intelligence reports | 4,196 reports; 474 tagged as fraud | FIC output for 2024/25. The Centre also issued 164 section 34 directives involving R157.5m in suspected criminal proceeds, equal to about US$9.75m. (Financial Intelligence Centre Annual Report 2024/25) |
INTERPOL received survey responses from 36 of Africa's 49 member countries for its 2026 assessment. Online scams made up 17% of reported cybercrime cases, while identity theft and financial fraud supplied 14%. AI was involved in 55% of reported cases in some capacity. Scam centres were present in 72% of responding countries. (INTERPOL African Cyberthreat Assessment Report 2026)
The assessment placed Africa's cybercrime-related losses at US$484 million, or about R7.82 billion, after a US$192 million estimate for 2024, equal to about R3.10 billion. INTERPOL's member-country and partner inputs cover cybercrime across the continent. The figures describe reported or detected activity within those sources.
Reported African cybercrime cases · INTERPOL survey
Reported cybercrime cases · responding countries
Share of responding African countries
About R7.82bn · INTERPOL 2026 assessment
| Source | Latest figure | Measurement |
|---|---|---|
| INTERPOL Global Financial Fraud Assessment | +54% in fraud-related Notices and Diffusions | Change from 2024 to 2025. INTERPOL supported more than 1,500 cases involving US$1.1bn in reported lost assets, about R17.77bn. (INTERPOL Global Financial Fraud Threat Assessment 2026) |
| INTERPOL Operation First Light | 142,000 victims; US$293m intercepted (R4.73bn) | Results from a 2026 operation involving 97 countries and territories, with 5,811 arrests. (INTERPOL Operation First Light 2026) |
| INTERPOL Operation Serengeti 2.0 | 1,209 arrests; 88,000 victims; US$97.4m recovered (R1.57bn) | Results from 18 African countries and the United Kingdom between June and August 2025. (INTERPOL Operation Serengeti 2.0) |
| FATF | 156 jurisdictions, or 90% | Share of assessed jurisdictions that identified fraud as a major money-laundering risk. (FATF Cyber-Enabled Fraud paper, 24 February 2026) |
| FBI IC3 | 31,675 identity-theft complaints; US$185.8m lost (R3.00bn) | United States reports submitted during 2025. (FBI IC3 Annual Report 2025) |
| UK Office for National Statistics | 4.5m fraud incidents; 3.8m victims | Accredited survey estimates for England and Wales in the year ending March 2026. Victim count rose 10%. (UK ONS Crime in England and Wales, year ending March 2026) |
| Canadian Anti-Fraud Centre | 8,403 identity-fraud reports | Reports received during 2025. Identity fraud was the most frequently reported category. (Canadian Anti-Fraud Centre 2025 statistics) |
| Australian National Anti-Scam Centre | Identity-theft reports up 13.1% | Change in Scamwatch reports during 2025. The combined report recorded 481,523 scam reports across five sources. (Australian National Anti-Scam Centre 2025 report) |
Coverage and assurance are different questions
Cross-border identity proofing introduces different documents, scripts, registries, privacy rules, sanctions exposure and fraud patterns. A provider's country list proves availability, not equal assurance. Organisations should define what evidence is accepted, which checks are authoritative, how transliteration is handled and when manual review is required.
| Risk | Control question | Evidence |
|---|---|---|
| Document coverage | Does the check validate this exact document version and issuing country? | Document type, version, issuer, capture quality and validation result. |
| Name and script | Can the workflow preserve the original script and explain transliteration? | Original value, transliterated value, match logic and reviewer decision. |
| Data source | Is the result based on document analysis, a database, user assertion or a combination? | Provider, source class, response time and returned attributes. |
| Privacy and transfer | Where is personal or biometric data processed and retained? | Lawful basis, notices, processor terms, transfer controls and deletion record. |
| Fallback | What happens when the strongest source is unavailable? | Fallback reason, reduced-assurance label and any additional manual evidence. |
A breach supplies attributes; later systems decide whether they are enough
Stolen identity attributes can support phishing, credential stuffing, synthetic profiles, help-desk impersonation and knowledge-based verification. Breach volume is therefore not the same as identity-fraud loss, but it changes the value of static questions and reused personal information as evidence.
POPIA section 19 requires a responsible party to identify foreseeable internal and external risks, establish appropriate safeguards, verify that safeguards are implemented and update them. Section 22 addresses notification when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. (Information Regulator, POPIA guidance)
Resolution time is part of the harm
Time spent resolving identity-fraud issues in 2025, up from 9.5 hours in 2023.
Average resolution time reported by account-takeover victims.
Average resolution time reported by new-account fraud victims.
These Javelin measures are United States survey estimates. They show why customer-impact monitoring should include time to restore access, repeated evidence requests, complaint volume and the quality of communication, not only reimbursed loss. (Javelin 2026 Identity Fraud Study)
Privacy, financial crime and identity assurance have different scopes
Applies to the lawful and secure processing of personal information. Identity and biometric workflows need purpose, proportionality, safeguards, processor controls, retention decisions and incident handling. (Information Regulator, POPIA guidance)
Applies where the business is an accountable institution. Duties include registration, an RMCP, customer due diligence, ongoing monitoring, records, reporting, governance and training. (Financial Intelligence Centre compliance guidance)
Financial services, telecoms, gambling, credit, employment and other sectors add their own licensing, conduct, customer-protection and reporting requirements.
A technical standard rather than South African law. It is useful for designing and testing remote identity proofing, especially injection and forged-media controls. (NIST SP 800-63A-4, July 2025)
No single biometric, database or score closes the problem
Collect the minimum necessary attributes, validate authoritative evidence where available and record the source and time of each result.
Test document integrity, media manipulation, device integrity, virtual cameras, emulators and genuine-sensor confidence.
Combine biometric comparison with presentation-attack and injection controls. Define accessibility and manual-review paths.
Detect repeated identity elements, shared infrastructure, payment-owner mismatch and new beneficiaries.
Reassess risk at login, recovery, profile change, transaction and payout. Do not treat onboarding as permanent proof.
Give reviewers the complete event sequence, preserve evidence, measure confirmed outcomes and test controls against current attack artefacts.
Evidence that can survive a later investigation
Watch attack paths, not unsupported loss forecasts
Bots and automated agents can imitate normal interaction, test defences and operate accounts at a scale that manual rules miss.
Live face swaps, generated documents and injected video reduce the value of unauthenticated camera capture.
Stolen documents, credentials, devices and biometric media can be sold together as a reusable onboarding or takeover kit.
An identity that fails in one provider or sector may be retried through a different channel with altered evidence.
Support agents, SIM changes and credential recovery remain attractive because they can bypass controls at normal login.
Synthetic documents and profiles can enter internal and third-party data sources, making later corroboration less independent.
Start with the decision and evidence, not a product label
An identity control should state what it decides, which evidence it uses, the population it covers, its failure and fallback conditions, and the record retained. That makes provider changes, audits and investigations possible without confusing a vendor response with the final business decision.
What action is being permitted, restricted or referred, and what assurance is required?
Which document, registry, biometric, device, account and transaction signals support the decision?
Can a reviewer reconstruct the source, time, rule, exception and human judgement later?
VerifyNow can help scope the evidence and controls around account opening, recovery, high-risk transactions or cross-border verification.
Request an enterprise assessmentMeasured results are separated from reports, network data and standards
The July 2026 revision removed unsupported projections, interpolated deepfake counts, synthetic AI-share estimates, unconfirmed breach figures and legal claims that could not be matched to a current official source.
Consumer survey estimates, consumer reports and vendor-network detection rates answer different questions. The report keeps those evidence types separate. Competitor research is named where it supplies a necessary statistic but competitor websites are not linked.
The 1 September 2026 update adds the latest available South African figures from official public bodies, INTERPOL and SABRIC. Currency translations use the SARB rate of R16.1574 per US dollar dated 31 August 2026.
Published 12 February 2026. Fact-checked 26 July 2026. Official-source update added 1 September 2026. This report is general research, not legal or regulatory advice.