
AI-driven fraud networks are scaling through reused identities, devices, and documents, exposing platforms to coordinated attacks.
According to Shufti’s Identity Fraud Report 2026, 22.49% of verification requests in the crypto sector were identified as identity fraud during the first half of 2026, giving the industry the highest exposure among all sectors measured.
The figure comes as fraud operations increasingly move beyond individual attempts, with organised networks reusing identities, documents, devices and other infrastructure to bypass remote verification checks.
The scale of the exposure varies significantly across industries. Fintech recorded the second-highest rate at 18.36%, followed by forex at 17.18% and lending and investment at 17.08%. Banking had the lowest exposure among the sectors measured, at 4.24%.
AI is adding another layer to the threat. Generative tools have reduced the cost of producing convincing fraudulent identities, allowing the same identity artefacts to be reused across multiple verification attempts.
Deepfake document fraud accounted for 80.10% of AI-enabled identity fraud identified in the first half of 2026, making it the dominant attack type. Synthetic identities accounted for 12.31%, followed by injected videos at 4.01% and face swaps at 3.58%.
The issue extends beyond individual fraudulent applications. Shufti’s verification data shows that 65.68% of matches between separate fraudulent attempts were linked to the reuse of the same fraudulent identity document. Nearly all linked clusters, at 98.78%, contained between two and 10 identities, indicating that coordination often occurs through relatively small networks rather than large, centralised operations.
Cross-border activity provides an indication of coordination. The typical interval between the same operation appearing in one country and another was nine minutes and 33 seconds, while the fastest observed interval was just 38 seconds. Such short intervals point towards shared infrastructure being used across jurisdictions rather than genuine movement between countries. The US accounted for 25.2% of identified cross-border activity, followed by the UK at 11.3%.
These patterns are changing how identity verification needs to be approached. Detecting a forged document or deepfake at the point of onboarding may remove one fraudulent attempt, but it does not necessarily identify the wider network behind it.
Read more about the report here.
Stay updated on crypto and AI by following our socials


