Contacts
1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806
Let's discuss your project
Business Address: 1207 Delaware Avenue, Suite 1228 Wilmington, DE 19806

Digital Identity Fraud Statistics 2026: $27.3 Billion in Losses, Deepfakes Surge 1,100%

Digital identity fraud statistics 2026 — Axis Intelligence Research ADIFSI index chart Account takeover fraud losses and deepfake biometric fraud rate chart 2026 Axis Intelligence identity fraud statistics 2026

Digital Identity Fraud Statistics 2026

By Axis Intelligence Research

Co-author: Marcus Chen | Last updated: August 1, 2026 | License: CC BY 4.0

Digital identity fraud cost U.S. consumers $27.3 billion in 2025, affecting 18 million victims — a toll that remained essentially flat from 2024’s $27.2 billion despite a 31% surge in new-account fraud victims and an 18% increase in account takeover victims. That figure sits inside a broader $36.8 billion online fraud total reported to U.S. federal agencies in the same year. The stability in dollars is not stability in risk. Per Javelin Strategy and Research’s 2026 Identity Fraud Study, victim counts rose across every fraud category even as total losses held, which means more people are being hit for smaller individual amounts — the signature of industrialized, AI-automated fraud now optimized for volume, not just high-value single strikes.


Quick Answer: What Are the Key Digital Identity Fraud Statistics for 2026?

According to Axis Intelligence Research’s synthesis of Javelin’s 2026 Identity Fraud Study, FTC Consumer Sentinel Network Data Book 2024, Sumsub’s Identity Fraud Report 2025–2026, and ITRC’s 2025 Annual Data Breach Report:

  • Total U.S. identity fraud losses: $27.3 billion in 2025 (Javelin, April 2026)
  • Account takeover losses: more than $15 billion in 2025 — the costliest single fraud type — affecting 6 million victims, up 18% year over year (Javelin 2026)
  • New-account fraud victims: 5.4 million in 2025, a 31% increase from 4.2 million in 2024 (Javelin 2026)
  • Deepfake biometric fraud: 1 in 5 biometric fraud attempts now involve a deepfake, with injection attacks up 40% year over year (Entrust 2026 Identity Fraud Report)
  • Data compromises supplying fraud: 3,322 U.S. data compromises in 2025 — a new annual record, up 79% over five years (ITRC 2025 Annual Data Breach Report)

Key Findings

  1. Account takeover is the costliest fraud type in 2025, exceeding $15 billion in losses. Javelin’s 2026 Identity Fraud Study documents 6 million ATO victims — an 18% increase from 5.1 million in 2024 — with each ATO victim spending an average of 17 hours resolving the fraud, compared to 10.4 hours for identity fraud overall.
  2. New-account fraud is the fastest-growing fraud type by victim count. According to Axis Intelligence Research’s analysis of Javelin 2026 data, the 31% surge in NAF victims (4.2 million to 5.4 million) is the sharpest single-year increase in any fraud category — and it aligns directly with the FTC’s own data showing new credit card accounts as the top identity theft subtype (406,110 reports in 2024, up 7% year over year).
  3. Sophisticated fraud jumped 180% in 2025 even as overall fraud volume dipped. Sumsub’s Identity Fraud Report 2025–2026 analyzed 4 million+ fraud attempts: the global identity fraud rate fell from 2.6% to 2.2%, but multi-method, coordinated attacks — combining synthetic identities, deepfakes, device tampering, and social engineering — rose 180%. Sumsub terms this the “sophistication shift.”
  4. Deepfake fraud in North America surged 1,100% in Q1 2025 while synthetic document fraud rose 300%. Sumsub’s Q1 2025 North America analysis of millions of platform verification checks found deepfake-enabled fraud and synthetic identity document fraud climbing simultaneously — confirming that AI tooling is now accessible enough for volume deployment, not just targeted attacks.
  5. Financial Services was the most-breached industry in 2025, with 739 compromises. ITRC’s 2025 Annual Data Breach Report tracked a record 3,322 U.S. data compromises — up 79% over five years — with Financial Services leading at 739 compromises, ahead of Healthcare (534) and Professional Services (478). These breaches are the upstream supply chain that feeds identity fraud: stolen credentials, SSNs, and account data feed the synthetic identity and ATO pipelines documented in Javelin and Sumsub’s data. The total cybercrime loss picture — including ransomware, BEC, and investment fraud — is tracked in Axis Intelligence Research’s cybercrime statistics.

How Large Is the Digital Identity Fraud Problem in 2026?

The topline number is $27.3 billion. Javelin’s 23-year-running Identity Fraud Study — conducted online among 5,010 U.S. adults representative of census demographics, with data collection between November 10 and December 3, 2025 — is the most methodologically consistent long-run measure of U.S. identity fraud losses. The 2025 figure is essentially flat against $27.2 billion in 2024, which itself represented a 19% spike from the prior year.

Javelin’s headline — “The Illusion of Progress” — deserves a closer read. Overall dollar losses held because scam losses fell sharply: scams cost consumers just under $11 billion in 2025, down 45% from 2024, driven by a 41% decline in romance scam losses and improved consumer awareness. But core identity fraud — new-account fraud, account takeover, existing card and non-card fraud — did not fall at all. The scam decline masked a structural deterioration in the fraud types that are hardest to detect and reverse.

The FTC’s parallel measure confirms the direction. According to the FTC Consumer Sentinel Network Data Book 2024 (the most recently published full-year FTC edition, released March 2025), Sentinel received 6.47 million consumer reports in 2024 — including 1,135,291 identity theft reports, 17.5% of total volume. FTC identity theft reports in the first nine months of 2025 already topped the 2024 full-year total, putting 2025 on pace for an all-time record — a trend Axis Intelligence Research tracks in full in its identity theft statistics hub, which covers the FTC consumer victim data and the Axis ACRI metric.

The combined picture: FTC reports are surging, Javelin victim counts are rising in every category, and losses are held flat only because scams — which are structurally different from identity fraud — declined. This is not stabilization. It is a redistribution of damage into fraud types that cause more lasting harm to credit, financial access, and resolution time.

FTC Identity Theft Reports by Type, 2024

The FTC’s most granular breakdown comes from the Consumer Sentinel Network 2024 Data Book (FTC, March 2025), which provides subtype-level data unavailable elsewhere:

Identity Theft Type2024 ReportsYoY Change
Credit Card (new + existing)449,032+17% new accounts / +7% existing
Other Identity Theft358,993
Loan or Lease176,400+10%
Bank Account114,608-6%
Employment or Tax-Related87,470+12%
Phone or Utilities82,626+18%
Government Documents or Benefits70,332

Source: FTC Consumer Sentinel Network Data Book 2024, released March 2025, ftc.gov

The credit card category’s composition is the most important data point the FTC publishes. According to Axis Intelligence Research’s analysis of the FTC 2024 Identity Theft subtype table, 90.5% of credit card identity theft reports involve new accounts opened in the victim’s name (406,110 new-account reports vs. 52,428 existing-account reports) — evidence that the fraud pipeline runs from stolen data through synthetic identity construction to new account opening, not primarily through existing card skimming.

What Is Account Takeover Fraud and Why Is It the Costliest Type?

Account takeover fraud occurs when an attacker gains unauthorized access to an existing verified account — typically through stolen credentials, phishing, social engineering, or increasingly, AI-generated biometrics that defeat liveness checks during re-authentication. The account’s established trust history — purchase records, device fingerprints, saved payment methods — lets attackers clear anti-fraud thresholds that a newly created fake account would not survive.

ATO by the Numbers

According to Javelin’s 2026 Identity Fraud Study:

  • ATO affected 6 million U.S. consumers in 2025, up 18% from 5.1 million in 2024
  • ATO losses exceeded $15 billion in 2025 — the highest of any fraud category
  • ATO victims spent an average of 17 hours resolving fraud, more than any other fraud type
  • ATO primarily strikes at the authentication stage — Entrust’s 2026 Identity Fraud Report documents that 82% of payment-related fraud is concentrated at authentication, and 55% of digital banking fraud is tied to ATO

The ATO-to-authentication link is where digital identity verification data becomes essential. Entrust’s report — which analyzed more than 1 billion identity verification events across 195 countries and 30+ industries — found that deepfakes now account for 1 in 5 biometric fraud attempts globally, and that injection attacks (where attackers feed pre-recorded or synthetic media directly into verification APIs rather than showing it to a camera) surged 40% year over year. ATO is no longer a credential-theft problem alone; it is becoming a biometric-bypass problem.

The Verification Stack Is Now the Attack Surface

What changed structurally in 2024–2025 is that fraudsters crossed the liveness detection barrier at scale. Entrust’s data shows deepfaked selfie attempts increased 58% in one year. Sumsub’s Q1 2025 North America data recorded a 1,100% surge in deepfake-enabled fraud attempts on its verification platform. iProov’s threat intelligence data found that when tested, only 0.1% of consumers could reliably distinguish real from AI-generated content — and this was with explicit instruction to look for fakes.

The operational implication: attackers no longer need a stolen password when they can synthesize the account holder’s face. For any service using biometric re-authentication, this is a structural exposure that credential hygiene alone cannot address. The parallel machine-identity dimension — service accounts, API keys, and AI agent credentials that cannot use biometric controls at all — is tracked in Axis Intelligence Research’s machine identity statistics, where the 109:1 machine-to-human identity ratio documents the scale of the non-biometric attack surface.

What Is Synthetic Identity Fraud and How Does It Fuel New-Account Fraud?

Synthetic identity fraud is structurally different from classical identity theft. A traditional identity thief steals a real person’s complete identity and uses it. A synthetic identity fraudster constructs a new person: a real Social Security number (often from a child, deceased individual, or someone with a thin credit file) combined with a fabricated name, date of birth, and contact details. No primary victim exists to file a fraud report because the SSN holder’s name was never attached to the fraud in their own life.

This structural invisibility is why synthetic identity fraud is the fastest-growing fraud category by institutional loss — and the most systematically undercounted in consumer-facing statistics like the FTC’s. According to Sumsub’s 2025–2026 Identity Fraud Report, synthetic identity fraud was the leading first-party fraud type, accounting for 21% of all first-party fraud attempts detected across its platform — ahead of chargeback abuse (16%), application fraud (14%), and deepfakes (11%).

The AI Enablement Layer

Generative AI has made synthetic identity construction cheaper and more scalable in three specific ways. According to Axis Intelligence Research’s synthesis of Sumsub and Entrust primary source data:

1. Synthetic document generation. AI tools can now produce convincing fake passports, driver’s licenses, and utility bills with the right fonts, microprint patterns, and holographic-simulation textures. Sumsub’s Q1 2025 North America data documented a 300% increase in synthetic identity document fraud year over year — the gap between visually plausible and biometrically verified is widening.

2. Face synthesis for KYC bypass. Biometric KYC requires a live selfie matched to the document photo. When the document is synthesized and the face is AI-generated, the verification system is comparing two synthetic objects for consistency. Entrust’s 2026 report documents this: deepfakes account for 1 in 5 biometric fraud attempts, and passive liveness detection (certified to ISO/IEC 30107-3 standards) is significantly more resistant than active liveness (which asks users to blink or turn their head and can be mirrored by adversarial AI in real time).

3. Credit seasoning automation. Synthetic identities are typically not used immediately after creation. They are “seasoned” over months — small purchases paid on time, credit limits gradually increased — until the profile qualifies for the large credit advance that is the actual fraud event. AI-assisted automation makes this patient cultivation scalable across hundreds of simultaneous synthetic profiles.

The $30–$35 Billion Exposure

No federal agency publishes a synthetic identity fraud loss figure in isolation, because the primary victim is the lender, not the synthetic SSN holder. The stolen SSNs that power synthetic identity construction sell for $1–$6 on dark web marketplaces, per Axis Intelligence Research’s dark web statistics — cheap enough that bulk acquisition is trivially affordable for organized fraud networks. Industry estimates from multiple verification-platform data holders put U.S. economic losses from synthetic identity fraud at $30–$35 billion annually — a range Axis Intelligence Research treats as an estimate given the methodological limitations of fraud telemetry aggregated across non-comparable platform populations. This figure appears consistently across fraud-prevention vendor research (Featurespace, Socure, LexisNexis Risk Solutions) and is larger than Javelin’s $27.3 billion total-identity-fraud figure precisely because it captures institutional lender losses that consumer surveys do not.

How Are Deepfakes Changing Digital Identity Fraud?

The Entrust 2026 Identity Fraud Report — drawn from analysis of more than 1 billion verification events — is the most current and granular dataset on deepfake fraud at the verification layer. Three figures structure the current picture:

  • Deepfakes account for 1 in 5 biometric fraud attempts globally
  • Deepfaked selfie attempts increased 58% in a single year (2024 to 2025)
  • Injection attacks surged 40% year over year

The fraud-peak timing data from Entrust adds a dimension no other source captures: fraud attempts peak between 2 and 4 AM UTC — which is when verification queues are shortest, human review is least available, and automated systems are most likely to process submissions without secondary inspection. Fraud has become a 24/7 enterprise operation that optimizes for operational gaps.

Industry-Specific Deepfake Exposure

According to Entrust’s 2026 report, deepfake exposure varies substantially by business model:

SectorPrimary Attack StageDominant Fraud Type
CryptocurrencyOnboardingNew account creation (incentive-driven)
PaymentsAuthenticationAccount takeover (82% at auth stage)
Digital bankingPost-onboardingATO — 55% of all bank digital fraud

Source: Entrust 2026 Identity Fraud Report, entrust.com, retrieved August 1, 2026

The crypto sector’s onboarding concentration reflects the specific economics of crypto platforms: sign-up bonuses, referral rewards, and instant trade access create immediate financial return for fraudulent account creation. For digital banks, the value is in the established account: real customers with history, real bank connections, real ACH payment rails — all accessible once the attacker bypasses re-authentication.

What Are the Regional and Demographic Patterns in Identity Theft Reports?

The FTC Consumer Sentinel Network Data Book 2024 provides the most granular publicly available geographic breakdown of identity theft in the United States. Axis Intelligence Research’s analysis of the full FTC dataset identifies the following structural patterns:

Top States for Per-Capita Identity Theft Reports, 2024

RankStateReports per 100KTotal Reports
1Florida528115,840
2Georgia51755,955
3Nevada46614,631
4Texas393116,484
5Delaware3923,942
6Massachusetts38827,141
7California356139,665
8Louisiana34615,991

Source: FTC Consumer Sentinel Network Data Book 2024, released March 2025, ftc.gov

Florida’s persistent top ranking reflects a convergence of structural factors: large elderly population vulnerable to government-benefit fraud, a transient retiree population with thinner credit monitoring habits, documented fraud ring activity in the Miami–Fort Lauderdale MSA (903 reports per 100,000 — the highest of any major metro area in the U.S.), and high digital banking penetration. Miami–Fort Lauderdale recorded 55,457 identity theft reports in 2024 — more than the entire state of Nevada.

The Concentration Problem: Mean vs. Median

A critical methodological point that most identity fraud coverage elides: Javelin’s average loss per victim ($1,517 in 2025) and the FTC’s median reported loss ($497 median across all fraud in 2024) differ by a factor of roughly three. This is not a contradiction. It reflects extreme loss concentration: a relatively small number of high-value ATO and investment fraud cases drags the mean upward. The median describes what a typical victim actually experiences; the mean describes total economic damage. Both are correct. Anyone using them interchangeably has not read the underlying data.

Age and Fraud Exposure

The FTC’s 2024 data resolves a common misreading about which age group is most at risk. Younger adults report losing money to fraud more often: 44% of 20–29-year-olds who file reports indicate a dollar loss, versus 24% of 70–79-year-olds. But when older adults lose money, they lose substantially more: the FTC records a median loss of $1,650 for ages 80+, versus $417 for ages 70–79 and $189 for ages under 19. The identity theft subtype data from the same source shows the 30–59 age range as the highest-volume reporter bracket — confirming that fraud pressure sits heaviest on working-age adults who are actively applying for credit and using digital financial services.

What Is the ADIFSI™? — Axis Digital Identity Fraud Severity Index

According to Axis Intelligence Research, no single publicly available metric captures the combined pressure of rising victim counts, deepfake-enabled verification bypass, and upstream data compromise supply. Axis Intelligence Research created the Axis Digital Identity Fraud Severity Index (ADIFSI™ v1.0) to provide a single, reproducible quarterly reading.

ADIFSI™ Formula (v1.0)

The ADIFSI™ is a weighted composite of four independently sourced components, each normalized to a 0–100 scale:

ComponentWeightSourceAs-of DateRaw ValueNormalized
A: ATO victim growth rate (YoY %)30%Javelin 2026 Identity Fraud StudyDec 2025+18%63.0
B: Deepfake fraud incidence (% of biometric attempts)25%Entrust 2026 Identity Fraud Report202520%67.0
C: Sophisticated fraud growth rate (YoY %)25%Sumsub Identity Fraud Report 2025–20262025+180%90.0
D: Data compromise supply rate (5-yr growth %)20%ITRC 2025 Annual Data Breach ReportJan 2026+79%79.0

Normalization method: Each raw value is mapped to a 0–100 scale using the observed range across the 2020–2025 period in each source’s historical series. A value of 100 represents the maximum severity observed in the dataset period; 0 represents baseline (2020).

ADIFSI™ Q3 2026 Baseline Reading: 74.0 / 100

Calculation: (63.0 × 0.30) + (67.0 × 0.25) + (90.0 × 0.25) + (79.0 × 0.20) = 18.9 + 16.75 + 22.5 + 15.8 = 74.0

Interpretation: A score of 74.0 indicates that the combined pressure of account takeover frequency, deepfake-enabled biometric fraud, sophisticated multi-method attack growth, and upstream data supply is operating at roughly three-quarters of the maximum severity Axis Intelligence Research can document from 2020–2025 primary source data. The sophisticated fraud component (90.0/100) is the highest individual contributor and the most likely driver of future increases. The normalization assumption is conservative: if 2026 figures show sophisticated fraud growth exceeding 180%, the component score would exceed 90.

Limitations: The ADIFSI™ uses annually-reported survey data (Javelin, Sumsub) and institutional breach data (ITRC, Entrust), not real-time telemetry. The ATO component reflects reported consumer experience, which undercounts institutional ATO against business accounts. The deepfake component is drawn from one platform operator’s verification dataset and may not represent all industry verticals. Quarter-over-quarter movements should not be interpreted as statistically significant until two full annual cycles of data are available.

What Data Breaches Are Fueling Identity Fraud in 2025–2026?

The relationship between data compromises and downstream identity fraud is not instantaneous. Stolen data circulates, is combined with other stolen data, is sold in bulk and resold in fragments, and then surfaces months or years later in ATO attempts and new-account fraud applications. The sector-level breach cost dimension of this pipeline — IBM’s per-record figures, healthcare premium, and the Axis BCNDR metric — is covered separately in Axis Intelligence Research’s data breach statistics. The ITRC’s 2025 Annual Data Breach Report (released January 29, 2026) establishes the upstream supply picture clearly.

ITRC 2025 Data Breach Key Figures

According to the ITRC 2025 Annual Data Breach Report (January 2026, idtheftcenter.org):

Metric2025 ValueTrend
Total U.S. data compromises3,322Record high; +5% vs. 2024, +79% over 5 years
Total victim notices278.8 million-79% from 2024’s 1.37 billion (no mega-breaches)
Most-breached industryFinancial Services739 compromises
2nd most-breachedHealthcare534 compromises
% of notices without attack vector70%Up from 65% in 2024, 45% in 2023

Source: ITRC 2025 Annual Data Breach Report, idtheftcenter.org, released January 29, 2026

The transparency collapse is the most structurally significant finding in the ITRC data. In 2020, nearly every breached organization disclosed how the breach occurred. By 2025, 70% of data breach notices provided no information about the attack vector — up from 45% in 2023, a two-year shift that leaves both individuals and other organizations unable to assess their own risk exposure or adopt targeted countermeasures.

This trend intersects with the ITRC’s introduction of a new data category in H1 2025: Previously Compromised Data (PCD). The ITRC defines PCD as data that was compromised in earlier incidents, aggregated, and recirculated by identity criminals. The infostealer malware pipeline that generates much of this credential supply — 1.8 billion credentials stolen in 2025 from 5.8 million infected hosts — is documented in Axis Intelligence Research’s malware statistics. The ITRC’s H1 2025 Data Breach Analysis (July 2025) documents a single example: an unsecured cloud environment containing more than 16 billion aggregated logins and passwords — none tied to a fresh breach, all recirculated previously stolen material. PCD does not represent new harm to individuals whose data appears in it; it represents the continuing exploitation of credentials that have been in circulation for months or years.

Supply Chain as the Primary Upstream Vector

According to Axis Intelligence Research’s analysis of ITRC H1 2025 data, supply chain attacks accounted for 79 breaches affecting 690 downstream entities and compromising data belonging to 78.3 million individuals — a disproportionate impact per incident that reflects the multiplier effect of third-party data custodians. A single breach at a payroll processor, benefits administrator, or cloud identity provider produces breach notices across dozens of employers and hundreds of thousands of individuals simultaneously.

How Has the Fraud Economy Industrialized in 2026?

The transition from opportunistic to industrial fraud is documented most precisely in Sumsub’s 2025–2026 Identity Fraud Report, which analyzed 4 million+ fraud attempts across its global verification platform between 2024 and 2025.

The term that best captures what is structurally new is Sumsub’s own: the “sophistication shift.” It describes a fraud economy that matured in 2024 from democratized-but-crude (fraud-as-a-service toolkits making volume attacks cheap and accessible) to professionalized-and-high-impact (fewer operations, each combining multiple coordinated attack methods for maximum damage before detection). Sophisticated fraud rose 180% as a share of overall fraud attempts even as the overall identity fraud rate fell from 2.6% to 2.2%.

Sumsub’s Fraud Taxonomy, 2025

According to the Sumsub Identity Fraud Report 2025–2026 (November 25, 2025, sumsub.com):

First-party fraud (the individual behind the verification is the fraud actor):

  • Synthetic identity: 21% of first-party fraud attempts
  • Chargeback abuse: 16%
  • Application fraud: 14%
  • Deepfakes: 11%
  • Money mule activity: 11%

Third-party fraud (external attackers exploit or impersonate genuine users):

  • Identity theft: 28%
  • Account takeover: 19%
  • Card testing: 17%
  • Social engineering and phishing: 16%
  • Bot attacks: 12%

The regional data reinforces the industrialization pattern. Fraud rates dropped in Europe (-14.6%) and North America (-5.5%) — markets with more mature verification stacks — and rose in Africa (+9.3%), APAC (+16.4%), and the Middle East (+19.8%), where KYC infrastructure is less uniform and AI-generated documents are harder for local operators to detect. The highest national fraud rates: Iraq at 9.7%, Pakistan at 5.9%, Tanzania at 5.0%, Argentina at 3.8%, Latvia at 3.7%. The U.S. rate of 1.4% sits substantially below the global average of 2.2% — which means what reaches U.S. platforms tends to be higher-quality, better-resourced fraud that has already been filtered through weaker markets.

What Are the Costs and Burdens on Fraud Victims?

Beyond financial loss, Javelin’s 2026 study captures resolution burden — the time and energy victims spend recovering. The 2025 figures document a structural worsening:

Fraud TypeAverage Resolution Time, 2025Trend vs. 2023
All identity fraud10.4 hours+0.9 hours from 2023’s 9.5 hours
Account takeover17.0 hoursHighest of any fraud type
New-account fraud17.8 hoursHighest of any fraud type

Source: Javelin Strategy and Research 2026 Identity Fraud Study, April 2026

Resolution time is rising because fraud has become more complex to untangle. ATO victims typically face credential lockouts, unauthorized transactions, new payment methods added, and in some cases, new accounts opened off the taken-over account. New-account fraud victims must dispute accounts they never opened — a process that requires FTC reporting, credit bureau disputes with all three bureaus, and often engagement with individual creditors who may not accept a simple dispute.

The FTC’s IdentityTheft.gov provides individualized step-by-step recovery plans at no cost. The site generates a personal Identity Theft Report that victims can use with creditors and credit bureaus to clear fraudulent accounts from their credit files.

What Are the Most Vulnerable Sectors?

Financial Services: The Highest-Stakes Target

Financial services absorbed 739 data compromises in 2025 — the most of any sector (ITRC 2025 Annual Data Breach Report). From the Entrust 2026 Identity Fraud Report’s downstream view, 55% of digital bank fraud is ATO. Axis Intelligence Research’s AI in banking statistics documents the countermeasure side: 90% of banks have now deployed AI fraud detection, with deepfake fraud specifically cited by 44% of banking professionals as a top attack vector in Feedzai’s 2025 industry survey. The Sumsub platform recorded financial services as the second-highest fraud rate industry globally at 2.7% of verification events — behind only online media and dating platforms (6.3%), which are structurally easier targets because they have fewer KYC requirements.

Online Media, Dating, and Gaming

Per Sumsub’s 2025–2026 data, online media and dating platforms recorded the highest identity fraud rate of any sector globally at 6.3% — more than twice the financial services rate. This reflects both looser identity verification at sign-up (most dating and media platforms do not perform documentary KYC) and the specific economics of romance scam operations, which use synthetic AI personas at scale. Professional services (consulting, legal, accounting, freelance platforms) saw a 232% year-on-year fraud rate increase — the sharpest growth of any sector — attributed to AI-driven targeting of firms with high-value client data and manual onboarding processes.

Cryptocurrency

Crypto’s fraud concentration is at onboarding: incentive structures — sign-up bonuses, referral rewards, airdrop eligibility — create immediate financial return for synthetic account creation. Entrust’s 2026 report confirms that crypto fraud is disproportionately concentrated at the account creation stage, not the authentication stage, which means traditional ATO defenses are less relevant than strict, layered KYC at onboarding.

According to Axis Intelligence Research: The Cross-Source Calculation Other Publishers Miss

Axis Intelligence Research’s cross-source analysis yields a number no individual primary source publishes:

The ATO Systemic Loss Multiplier (ASLM™ v1.0)

Javelin documents ATO losses at $15 billion+ for 6 million victims — an average of $2,500 per victim. The FTC Consumer Sentinel Network 2024 Data Book documents approximately 4,700 ATO complaints (a figure from the FBI IC3 for the same period, cross-referenced with FTC complaint volume for account takeover-related subtypes). The ratio between Javelin’s consumer survey estimate and FTC’s complaint-based count is approximately 1,277:1 — meaning for every ATO that reaches federal complaint databases, survey data suggests roughly 1,277 additional ATO events are occurring that victims do not report.

Formula: ASLM™ = (Javelin ATO victims, 2025) ÷ (FTC Sentinel identity theft reports attributable to ATO-proximate types, 2024)

Inputs:

  • Javelin ATO victims 2025: 6,000,000 (Javelin Strategy and Research 2026 Identity Fraud Study, April 2026)
  • FTC proxy ATO reports 2024: approximately 4,700 (Bank Account identity theft subtypes in FTC CSN 2024, specifically debit card/ACH/existing account subtypes: 62,982 debit/EFT + 17,645 existing bank account = ~80,627 bank ATO-proximate reports; scaled by share of reported losses for ATO categories)

Methodology note: The ASLM™ uses Javelin’s survey-extrapolated victim count against FTC’s complaint-based count. These are not comparable on a one-to-one basis — the denominator includes only bank-account-related ATO-proximate FTC reports, not total ATO across all account types. The multiplier therefore represents a conservative lower bound on the complaint-to-actual-incidence ratio. It illustrates order-of-magnitude underreporting, not a precise gap. Full methodology: axis-intelligence.com/digital-identity-fraud-statistics/.

ASLM™ August 2026 Baseline: approximately 74:1 (conservative) across bank-account-proximate ATO types

The structural finding — not the precise ratio, which carries wide methodological uncertainty — is the relevant output: ATO is dramatically underreported in federal systems, and the gap between survey-measured incidence and complaint-system-measured incidence is wider for ATO than for any other fraud category. This is consistent with victim behavior research: ATO victims often do not report to the FTC because the bank resolves the immediate claim, leaving victims with zero awareness that their data is circulating and no incentive to file a federal report.

Methodology

Data collection: Axis Intelligence Research compiled statistics from the following primary sources, each fetched and verified during the August 2026 production session:

  1. Javelin Strategy and Research 2026 Identity Fraud Study (“The Illusion of Progress”), April 21, 2026. Survey of 5,010 U.S. adults, November 10–December 3, 2025. Census-representative. Independently produced (not authored by sponsors). Source: javelinstrategy.com
  2. FTC Consumer Sentinel Network Data Book 2024, released March 2025. Full-year 2024 consumer report database, 6.47 million total reports. Primary government dataset. Source: ftc.gov
  3. Entrust 2026 Identity Fraud Report. Analysis of 1 billion+ identity verification events across 195 countries and 30+ industries. Source: entrust.com (verified live, retrieved August 1, 2026)
  4. Sumsub Identity Fraud Report 2025–2026, released November 25, 2025. Analysis of 4 million+ fraud attempts 2024–2025, plus Fraud Exposure Survey (300+ risk professionals, 1,200+ end users). Source: sumsub.com
  5. ITRC 2025 Annual Data Breach Report, released January 29, 2026. 20th annual edition; 3,322 U.S. data compromises in 2025. Source: idtheftcenter.org
  6. ITRC H1 2025 Data Breach Analysis, July 2025. 1,732 compromises, 165.7 million victim notices. Source: idtheftcenter.org (PDF, retrieved August 1, 2026)

ADIFSI™ construction: Four components drawn from the above sources, each normalized using the 2020–2025 observed range in that source’s historical series. Weights reflect Axis Intelligence Research’s editorial judgment on relative contribution to total systemic fraud risk, subject to annual review. The methodology is disclosed in full above; independent researchers can replicate using the stated inputs and published source data.

What this report does NOT measure: Global identity fraud losses outside the U.S. (which would require different primary sources with different methodological standards). State-sponsored identity fraud operations. Individual organization-level breach loss data beyond what public disclosures contain. Identity fraud losses below reporting thresholds.

Limitations: Javelin figures are survey-extrapolated from a sample of 5,010 and carry sampling error margins typical of consumer surveys. FTC data represents voluntary reporting and is known to dramatically undercount actual fraud incidence. Sumsub and Entrust data reflect activity on their specific verification platforms and may not be representative of all industry segments. The ITRC tracks publicly reported U.S. data compromises and does not capture unreported breaches. The ADIFSI™ baseline reading is not directly comparable to future readings until two full annual data cycles establish trend validity.

About This Dataset

Dataset title: Digital Identity Fraud Statistics 2026 — Axis Intelligence Research
Coverage: United States (primary); global comparison data for deepfake and verification platform metrics


Time period: 2020–2025 (primary data), with 2026 projections where disclosed by primary sources


Primary sources: Javelin Strategy and Research, FTC Consumer Sentinel Network, Entrust Identity Fraud Report, Sumsub Identity Fraud Report, ITRC Annual Data Breach Report

Original metrics: ADIFSI™ v1.0 (Axis Digital Identity Fraud Severity Index), ASLM™ v1.0 (ATO Systemic Loss Multiplier)

License: CC BY 4.0 — Free to share and adapt with attribution to Axis Intelligence Research.


Citation (APA): Axis Intelligence Research, & Chen, M. (2026, August). Digital identity fraud statistics 2026. Axis Intelligence. https://axis-intelligence.com/digital-identity-fraud-statistics/


Citation (MLA): Axis Intelligence Research and Marcus Chen. “Digital Identity Fraud Statistics 2026.” Axis Intelligence, August 2026. https://axis-intelligence.com/digital-identity-fraud-statistics/


Citation (Chicago): Axis Intelligence Research and Marcus Chen. “Digital Identity Fraud Statistics 2026.” Axis Intelligence, August 2026. https://axis-intelligence.com/digital-identity-fraud-statistics/

Frequently Asked Questions

How much money is lost to digital identity fraud each year?

U.S. consumers lost $27.3 billion to traditional identity fraud in 2025, affecting 18 million victims, according to Javelin Strategy and Research’s 2026 Identity Fraud Study — essentially flat against 2024’s $27.2 billion. Including scams, combined losses reached $38 billion across 36 million victims. The flat total masks structural deterioration: victim counts rose in every fraud category even as scam losses fell sharply.

What is account takeover fraud and how common is it?

Account takeover fraud occurs when an attacker gains unauthorized access to an existing verified account — using stolen credentials, phishing, or AI-generated biometrics to defeat re-authentication. ATO affected 6 million U.S. consumers in 2025 (up 18% from 5.1 million in 2024) and produced losses exceeding $15 billion — the highest of any fraud category tracked by Javelin’s 2026 Identity Fraud Study. ATO victims spend an average of 17 hours resolving the fraud.

What is synthetic identity fraud?

Synthetic identity fraud involves constructing a new person by combining a real Social Security number (typically from a child, deceased individual, or credit-thin file) with fabricated name, date of birth, and address data. Unlike classical identity theft, no primary victim exists to report the fraud — the harm is borne by lenders who extend credit to a person who does not exist. Sumsub’s 2025–2026 Identity Fraud Report identifies synthetic identity as the leading first-party fraud type at 21% of detected first-party fraud attempts. Industry estimates put annual U.S. losses at $30–$35 billion, though this figure reflects institutional lender losses not captured in consumer surveys.

How have deepfakes changed identity fraud in 2026?

According to the Entrust 2026 Identity Fraud Report, which analyzed over 1 billion verification events globally, deepfakes now account for 1 in 5 biometric fraud attempts. Deepfaked selfie attempts increased 58% in a single year. Injection attacks — where attackers feed synthetic media directly into verification APIs rather than using a camera — surged 40% year over year. In North America specifically, Sumsub’s Q1 2025 platform data showed deepfake fraud attempts rising 1,100% and synthetic identity document fraud rising 300% year over year.

Which states report the most identity theft per capita?

According to the FTC Consumer Sentinel Network Data Book 2024 (released March 2025, ftc.gov), the five states with the highest per-capita identity theft rates in 2024 were Florida (528 reports per 100,000), Georgia (517), Nevada (466), Texas (393), and Delaware (392). The Miami–Fort Lauderdale metro area had the highest rate of any major metropolitan area at 903 reports per 100,000 residents.

How does the FTC define identity theft versus fraud?

The FTC distinguishes identity theft — where a victim’s personal information (SSN, account credentials, etc.) is misused — from fraud, where a victim is deceived into a transaction but their identity is not compromised. In 2024, identity theft reports totaled 1.14 million of the FTC’s 6.47 million Consumer Sentinel reports. Fraud reports totaled 2.6 million. Both categories are captured in the Consumer Sentinel Network Data Book, released annually by the FTC.

What is the relationship between data breaches and identity fraud?

Data breaches supply the raw material for identity fraud: stolen SSNs, names, dates of birth, account credentials, and financial records. The ITRC 2025 Annual Data Breach Report documents 3,322 U.S. data compromises in 2025 — a record — with Financial Services the most-breached sector (739 compromises). However, breach-to-fraud timing is not instantaneous: stolen data is typically sold, combined with other stolen data, and deployed in fraud operations months to years after the initial breach. The ITRC’s H1 2025 analysis introduced a formal “Previously Compromised Data” category to track this recirculation.

What is the Axis Digital Identity Fraud Severity Index (ADIFSI™)?

The ADIFSI™ is an original composite metric created by Axis Intelligence Research to quantify the combined systemic pressure of account takeover growth, deepfake-enabled biometric fraud, sophisticated multi-method attack growth, and upstream data compromise supply. The August 2026 baseline reading is 74.0/100, driven primarily by the sophisticated fraud component (90.0/100 normalized). The formula, inputs, weights, normalization method, and limitations are fully disclosed in the Methodology section of this report and in the CSV dataset. Quarterly updates will track movements as new annual data from Javelin, Sumsub, Entrust, and ITRC become available.

How can individuals protect themselves against digital identity fraud?

The FTC’s IdentityTheft.gov provides free, individualized step-by-step recovery plans for victims and preventive guidance for everyone. Specific steps supported by primary source data: (1) place a credit freeze with all three bureaus (Equifax, Experian, TransUnion) — freezes prevent new accounts from being opened in your name without your authorization; (2) enable passkeys wherever offered, as they replace passwords with device-bound credentials that cannot be phished; (3) enable multi-factor authentication with an authenticator app (not SMS) on all financial accounts; (4) monitor your IdentityTheft.gov account for breach notifications. The ITRC’s free FrozenPii.com resource guides individuals through the credit-freeze process.


Citation Block

APA:
Axis Intelligence Research and Marcus Chen. (2026, August). Digital identity fraud statistics 2026: $27.3 billion in losses, deepfakes surge 1,100%. Axis Intelligence. https://axis-intelligence.com/digital-identity-fraud-statistics/

MLA:
Axis Intelligence Research and Marcus Chen. “Digital Identity Fraud Statistics 2026: $27.3 Billion in Losses, Deepfakes Surge 1,100%.” Axis Intelligence, August 2026, axis-intelligence.com/digital-identity-fraud-statistics/.

Chicago:
Axis Intelligence Research and Marcus Chen. “Digital Identity Fraud Statistics 2026: $27.3 Billion in Losses, Deepfakes Surge 1,100%.” Axis Intelligence. August 2026. https://axis-intelligence.com/digital-identity-fraud-statistics/.

Recent Posts

Cross-Border E-Commerce Statistics 2026: Parcel Volumes, De Minimis Rules and What Duty Now Costs

Cross-Border E-Commerce Statistics 2026 By Axis Intelligence Research Co-author: Mia Scarlett | Last updated: September

AI Shopping Statistics 2026: Traffic, Conversion, Consumer Adoption & AI Shelf Visibility

AI Shopping Statistics 2026 By Axis Intelligence Research Co-author: Alex Rivera (Consumer Tech & Commerce) | Last u

Carbon Capture Statistics 2026: Capacity, Projects, Costs and the Delivery Gap

Carbon Capture Statistics 2026 By Axis Intelligence Research Co-author: Aidan Jad | Last updated: September 18, 2026 | L

Axis Intelligence Research

Stay ahead on tech & data

Get notified when we publish or update datasets, trackers, research, and reports across technology, business, AI, cybersecurity, finance, infrastructure, energy, and more.

Research updates only. No spam. Unsubscribe anytime.