Measured consumer harm, AI-enabled identity attacks, South African context and layered defence.
Sixteen sections with measured figures separated from network and survey evidence.
Losses levelled off, but victim exposure and attack quality increased
Traditional identity fraud cost US consumers $27.3 billion in 2025. Javelin estimates 18 million victims. New-account fraud victims rose 31%, from 4.2 million to 5.4 million, while account-takeover victims rose 18%, from 5.1 million to 6 million. (Javelin 2026 Identity Fraud Study)
AI-enabled methods are present, but there is no defensible global incident total. Deepfakes accounted for roughly one in five biometric fraud attempts in Entrust's network. iProov observed a 741% annual rise in iOS-targeted injection attacks. These measures use different populations and must not be added together. (Entrust 2026 Identity Fraud Report) (iProov 2026 Threat Intelligence Report)
Identity proofing must treat the capture channel as part of the evidence. NIST requires genuine-sensor confidence, forged-media analysis, protected channels, documented testing and manual review where needed. It says biometric comparison and presentation-attack detection do not cover every injection or forged-media case. (NIST SP 800-63A-4, July 2025)
Traditional identity fraud · 2025
Representative consumer survey
4.2m to 5.4m
5.1m to 6.0m
Loss, victims and reports answer different questions
Javelin's survey measures US adult experiences and estimates population totals. FTC Consumer Sentinel records reports submitted to the agency and its contributors; those reports are not verified cases and are not a population survey. In 2024, Sentinel received 6.5 million consumer reports across fraud, identity theft and other consumer-protection categories, including more than 1.1 million identity-theft reports. (FTC Consumer Sentinel Data Book 2024)
Millions of United States adults · 2024 versus 2025 · Javelin consumer survey
| Fraud type | 2024 victims | 2025 victims | Change |
|---|---|---|---|
| New-account fraud | 4.2m | 5.4m | +31% |
| Account takeover | 5.1m | 6.0m | +18% |
The useful distinction is how the identity is obtained and used
A stolen, fabricated or synthetic identity is used to open a new financial, telecoms, retail, betting or other account.
An attacker gains control of an existing account through stolen credentials, social engineering, SIM compromise or recovery-process abuse.
Documents or biometric media are forged, altered, replayed, deepfaked or injected into a remote identity-proofing process.
Real and fabricated attributes are combined into an identity that may be cultivated over time before higher-value abuse.
A stolen identity or payment credential is used for account opening, card-not-present payments, refunds or withdrawals.
A criminal convinces a person, employee or support agent to disclose credentials, change an account or approve a transaction.
Consumer reports · United States · 2024 · categories may overlap
Attack realism improved; the measurement remains fragmented
Entrust's 2026 report draws on more than one billion verifications from September 2024 to September 2025. It reports that physical counterfeit documents represented 47% of document fraud in its network, digital forgeries 35%, physical forgeries 10% and digital counterfeits 9%. The total is 101% because the published values are rounded. (Entrust 2026 Identity Fraud Report)
Share of document fraud · Entrust verification network · 2025 · rounded values
Entrust linked roughly one in five biometric fraud attempts in its network to deepfakes.
Entrust reported an approximately 40% annual increase in injection-attack cadence.
iProov reported annual growth in iOS-targeted injection attacks in its monitored environment.
Sumsub network · 2023 to 2025 · not a global population rate
The identity decision must survive login, recovery and payout
New-account fraud and account takeover now affect more US adults than they did a year earlier. The two risks require different controls. New-account fraud tests whether the person and evidence are genuine; account takeover tests whether the current actor is still the legitimate customer. (Javelin 2026 Identity Fraud Study)
Document validation, genuine-sensor checks, biometric comparison where lawful, device integrity, identity-attribute consistency, sanctions and risk screening.
Phishing-resistant or risk-based authentication, device change detection, credential-stuffing controls and session-risk analysis.
Treat phone, email and password changes as high-risk identity events. Prevent a support interaction from bypassing stronger login controls.
Check payer or beneficiary ownership, transaction velocity, profile consistency and recent account changes before releasing value.
The same identity can be abused differently by sector
New accounts, credit applications, payment fraud, account takeover and mule activity connect identity risk directly to financial loss and AML obligations.
Stolen or repeated identity, underage access, bonus abuse, third-party payments, account takeover and laundering risks appear at different lifecycle stages.
SIM compromise and account recovery can redirect authentication and weaken controls used by other sectors.
Stolen accounts, new-account promotion abuse, card-not-present fraud and refund diversion link identity to payment risk.
Fabricated credentials, impersonation and synthetic profiles affect onboarding, access to systems and payout accounts.
Identity misuse can redirect benefits, create fraudulent records or exploit high-volume remote-service channels.
Grey-list exit does not end the control work
FATF removed South Africa from increased monitoring on 24 October 2025 after the country addressed the strategic deficiencies in its action plan. FATF's statement points to improvements in beneficial-ownership access, risk-based supervision, use of financial intelligence, money-laundering investigations, confiscation and targeted financial sanctions. (FATF, 24 October 2025)
The removal is not evidence that identity fraud or money-laundering risk disappeared. For businesses, the practical question remains whether customer due diligence, beneficial-ownership work, transaction monitoring, sanctions controls and reporting operate effectively in the current channel.
Risk models must support the identity documents and populations the service actually accepts without treating document format alone as proof of fraud.
Device, SIM, application, network and account-recovery signals matter where onboarding and authentication happen primarily on a phone.
An external verification result should retain source, time, input, decision, confidence and fallback information for later review.
Coverage and assurance are different questions
Cross-border identity proofing introduces different documents, scripts, registries, privacy rules, sanctions exposure and fraud patterns. A provider's country list proves availability, not equal assurance. Organisations should define what evidence is accepted, which checks are authoritative, how transliteration is handled and when manual review is required.
| Risk | Control question | Evidence |
|---|---|---|
| Document coverage | Does the check validate this exact document version and issuing country? | Document type, version, issuer, capture quality and validation result. |
| Name and script | Can the workflow preserve the original script and explain transliteration? | Original value, transliterated value, match logic and reviewer decision. |
| Data source | Is the result based on document analysis, a database, user assertion or a combination? | Provider, source class, response time and returned attributes. |
| Privacy and transfer | Where is personal or biometric data processed and retained? | Lawful basis, notices, processor terms, transfer controls and deletion record. |
| Fallback | What happens when the strongest source is unavailable? | Fallback reason, reduced-assurance label and any additional manual evidence. |
A breach supplies attributes; later systems decide whether they are enough
Stolen identity attributes can support phishing, credential stuffing, synthetic profiles, help-desk impersonation and knowledge-based verification. Breach volume is therefore not the same as identity-fraud loss, but it changes the value of static questions and reused personal information as evidence.
POPIA section 19 requires a responsible party to identify foreseeable internal and external risks, establish appropriate safeguards, verify that safeguards are implemented and update them. Section 22 addresses notification when there are reasonable grounds to believe personal information has been accessed or acquired by an unauthorised person. (Information Regulator, POPIA guidance)
Resolution time is part of the harm
Time spent resolving identity-fraud issues in 2025, up from 9.5 hours in 2023.
Average resolution time reported by account-takeover victims.
Average resolution time reported by new-account fraud victims.
These Javelin measures are United States survey estimates. They show why customer-impact monitoring should include time to restore access, repeated evidence requests, complaint volume and the quality of communication, not only reimbursed loss. (Javelin 2026 Identity Fraud Study)
Privacy, financial crime and identity assurance have different scopes
Applies to the lawful and secure processing of personal information. Identity and biometric workflows need purpose, proportionality, safeguards, processor controls, retention decisions and incident handling. (Information Regulator, POPIA guidance)
Applies where the business is an accountable institution. Duties include registration, an RMCP, customer due diligence, ongoing monitoring, records, reporting, governance and training. (Financial Intelligence Centre compliance guidance)
Financial services, telecoms, gambling, credit, employment and other sectors add their own licensing, conduct, customer-protection and reporting requirements.
A technical standard rather than South African law. It is useful for designing and testing remote identity proofing, especially injection and forged-media controls. (NIST SP 800-63A-4, July 2025)
No single biometric, database or score closes the problem
Collect the minimum necessary attributes, validate authoritative evidence where available and record the source and time of each result.
Test document integrity, media manipulation, device integrity, virtual cameras, emulators and genuine-sensor confidence.
Combine biometric comparison with presentation-attack and injection controls. Define accessibility and manual-review paths.
Detect repeated identity elements, shared infrastructure, payment-owner mismatch and new beneficiaries.
Reassess risk at login, recovery, profile change, transaction and payout. Do not treat onboarding as permanent proof.
Give reviewers the complete event sequence, preserve evidence, measure confirmed outcomes and test controls against current attack artefacts.
Evidence that can survive a later investigation
Watch attack paths, not unsupported loss forecasts
Bots and automated agents can imitate normal interaction, test defences and operate accounts at a scale that manual rules miss.
Live face swaps, generated documents and injected video reduce the value of unauthenticated camera capture.
Stolen documents, credentials, devices and biometric media can be sold together as a reusable onboarding or takeover kit.
An identity that fails in one provider or sector may be retried through a different channel with altered evidence.
Support agents, SIM changes and credential recovery remain attractive because they can bypass controls at normal login.
Synthetic documents and profiles can enter internal and third-party data sources, making later corroboration less independent.
Start with the decision and evidence, not a product label
An identity control should state what it decides, which evidence it uses, the population it covers, its failure and fallback conditions, and the record retained. That makes provider changes, audits and investigations possible without confusing a vendor response with the final business decision.
What action is being permitted, restricted or referred, and what assurance is required?
Which document, registry, biometric, device, account and transaction signals support the decision?
Can a reviewer reconstruct the source, time, rule, exception and human judgement later?
VerifyNow can help scope the evidence and controls around account opening, recovery, high-risk transactions or cross-border verification.
Request an enterprise assessmentMeasured results are separated from reports, network data and standards
The July 2026 revision removed unsupported projections, interpolated deepfake counts, synthetic AI-share estimates, unconfirmed breach figures and legal claims that could not be matched to a current official source.
Consumer survey estimates, consumer reports and vendor-network detection rates answer different questions. The report keeps those evidence types separate. Competitor research is named where it supplies a necessary statistic but competitor websites are not linked.
Published 12 February 2026. Fact-checked and updated 26 July 2026. This report is general research, not legal or regulatory advice.