Skip to content
The Cyber Security Place

Threats

Identity fraud in 2026: the applicant who never existed

The crime used to require a victim. The most expensive version of it no longer does — and the layer that decides whether somebody is who they claim to be has become the cheapest thing in the whole system to defeat.

Last reviewed August 25, 2026

Consumer identity fraud in the United States ran near $27.3bn in 2025 across about 18 million people, roughly flat for two years. Account takeover carries most of it — some $16bn, close to 59% of losses, about 6 million victims and up 18% — costing around $2,500 per victim against $1,296 for new-account fraud. Synthetic identity fraud is estimated separately at $30–35bn a year and reached 20% of fraud losses in one half-year. Identities are advertised from about $15 and toolkits that defeat document, selfie and liveness checks from roughly $20. Injection attacks against verification rose several hundred per cent in a year. The measures that work are a credit freeze, a carrier lock and phishing-resistant sign-in.

What does tightening the check actually cost?

Every proposal to fix this ends with somebody saying the checks should be stricter. Move the control and watch both columns, because they never move the same way.

Worked exampleTen thousand applications, one setting

37fraudulent applications approvedof 300 attempts
74genuine customers turned awayof 9,700 real people

Both columns are non-zero at every setting on the scale, which is the point of the exercise.

The same trade at seven settings
StrictnessFraud approvedCustomers turned awayTurned away per fraud stopped
02858—
15144160.1
3073350.3
4537741.1
60191564.6
80842424.4
10031,152145.6

Illustrative curves, not a vendor's measurements: a three per cent fraud rate and two exponentials that reproduce the shape the problem has. What is real is the shape. The last column is the one that decides where the setting ends up, because it is the number the growth side of the business reads, and it climbs steeply long before the first column reaches zero.

The first column is what a security team is measured on. The second is what the growth side of the business is measured on, and it is the one that wins arguments, because a rejected customer complains immediately while an approved fraud is discovered months later by somebody else.

That asymmetry explains a great deal of behaviour that looks negligent from outside. An institution sitting at the middle of that scale is not ignorant of fraud; it has priced the trade and concluded that the marginal customer is worth more than the marginal fraud prevented. Whether that calculation is correct depends entirely on who ends up carrying the loss, which is the subject of a later section and is not always the party doing the arithmetic.

The way out is not a better setting on the same dial. It is a check that is expensive to defeat and cheap to pass — binding a session to a device rather than judging a photograph, or accepting a credential a bank has already verified rather than re-verifying from a document. Those move both columns at once, which is the only thing that ever helps.

The bigger number nobody reports

Two annual figures, drawn to the same scale. One is counted from complaints. The other is estimated, because there is nobody to complain.

Account takeover — $16bnNew-account and existing-account fraud — $11.3bnMeasured: $27.3bnconsumer identity fraud, from complaintsSynthetic identity$30–35bn, estimatedno complainant to count

The band on the right starts above the top of the column on the left. Synthetic identity fraud — where the applicant is assembled rather than impersonated — is estimated to cost more each year than every measured category of consumer identity fraud put together, and it is the one most people have never heard of.

The reason for that obscurity is structural. Fraud statistics are built from complaints, and a complaint requires somebody who noticed. When an identity is constructed from a real but unused identification number, a fabricated name and a date of birth that belongs to nobody, there is no person whose credit file is damaged and no one to file a report. The loss is discovered by a lender, written off as a default, and frequently recorded as ordinary credit loss rather than as fraud at all.

Which means the two numbers are not measuring the same kind of thing, and the more familiar one is smaller partly because it is the one that can be counted. That is worth holding onto whenever a figure in this field is quoted as though it were the whole picture.

How a person who does not exist is built

The construction is patient, and the patience is what makes it hard to catch.

It starts with a real identification number that nobody is using. Numbers issued to children, to people who have died, or to anyone who has never borrowed sit unused in the registries for decades, and a number with no history attached is not suspicious — it is simply new. Around it goes a fabricated name, a date of birth belonging to nobody, and an address that may be entirely real.

Then the file is cultivated. The first application is expected to fail; what matters is that it creates an enquiry, and enquiries create a record. A secured card follows, then a small limit somewhere lenient, then payments made faithfully for a year or two. Every one of those behaviours is exactly what a good customer does, and the scoring systems reward it, because they were built to identify people who repay and this file repays.

The end is abrupt and has a name in the trade: every available line is drawn at once and nothing is ever repaid. By that point the file has a credit history longer than many genuine applicants, and the loss is recorded against a person who cannot be found because they were never anywhere.

Two consequences follow from that shape. The first is that the fraud is invisible while it is happening — the cultivation phase is indistinguishable from ordinary custom, and any control tuned to catch it will reject real people establishing credit for the first time. The second is that when it completes, most institutions do not classify it as fraud at all. It looks like a default, it is written off against credit loss, and it never reaches the statistics that fund fraud prevention, which is a large part of why the estimate on the chart above is so much less certain than the measurement beside it.

Why is account takeover the biggest category?

Because it is the cheapest route to money that the system will not question.

Consider what an existing account provides that a new one cannot. A transaction history that fraud models read as normal. A device and location the institution has seen before. A relationship old enough that the alerting is calibrated to expect activity. Every signal that makes a new application suspicious makes an established account trustworthy, and taking one over inherits all of it.

The inputs are also, at this point, essentially free. Credentials from a decade of breaches are collated and searchable. The personal details that recovery questions ask about — an address history, a mother's maiden name, a first car — sit in the same collections. And the recovery channel most institutions still trust, a phone number, can be moved to a different device by persuading a shop assistant.

The result is a category worth roughly sixteen billion dollars a year, with about six million victims and a growth rate near eighteen per cent, where the average loss is close to double that of new-account fraud. It is also the category least affected by everything consumers are advised to do: a credit freeze is excellent and does nothing here, because no new account is being opened.

The raw material was being catalogued long before the fraud economics caught up: Russian Gang Steals 1.2 Billion User Credentials in Biggest Ever Hack ran in August 7, 2014, when the story was still the size of the collection rather than what it would eventually be worth.

The verification layer became the cheapest thing to defeat

For a decade the answer to identity fraud was to check harder: a photograph of a document, then a selfie, then a selfie that moves. Each step raised the cost of an attempt, and each has now been undercut by tooling that costs less than lunch.

The technique that matters is injection. Rather than holding a screen in front of a camera — which the checks were designed to catch — the attacker feeds a synthetic video stream directly to the application through a virtual camera, so the pixels arriving at the check are perfect because they never passed through a lens. Reported volumes rose by several hundred per cent year on year, with one financial institution recording over eight thousand biometric injection attempts against a single onboarding flow in eight months.

Published red-team work has evaded both passive liveness, which judges the image, and active liveness, which asks the applicant to turn their head or blink. Neither distinguishes a real face from a rendered one when the renderer controls the video pipeline, because both are examining content rather than provenance.

The economics are what make this different from previous escalations. Synthetic identities have been advertised from around fifteen dollars and complete toolkits from roughly twenty, against verification systems that cost dollars per check and took years to build. When the attack is three orders of magnitude cheaper than the defence, the defence cannot win by being better at the same task.

Does liveness detection still work?

Against the threat it was designed for, yes. Against the one that now dominates, much less than its deployment implies.

The distinction worth drawing is between checking content and checking provenance. Content checks ask whether this image looks like a living person, and they are in a contest with generation quality that they lose a little more of every year. Provenance checks ask whether this video came from a real camera on a real device in a real session, which is a question about the pipeline rather than the pixels and does not degrade as models improve.

Provenance is where the durable answers are. Attestation that the frames came from a physical sensor rather than a virtual one. Binding the session to hardware the applicant possesses. Reading the cryptographically signed chip in a passport instead of photographing its printed page — the chip cannot be rendered, which is the entire advantage.

The strategic shift beyond that is to stop performing the verification at all. Digital credential frameworks let an institution that has already verified somebody issue a reusable attestation, so the next organisation checks a signature rather than a face. That moves the problem to whoever is best placed to solve it once, and it is the only approach on this page that gets cheaper as it scales rather than more expensive.

A decade in which the vocabulary changed

This section carried 571 reports across seven years, and reading them in order shows a subject whose terms were replaced faster than its mechanics.

Reports in this section, by year
2015201620172018201920202021
7967126121834130

The reporting through that period is overwhelmingly about stolen credentials, breached databases and what appears for sale afterwards. The words that dominate the subject in 2026 — synthetic identity, injection attack, account takeover as a named category — are almost entirely absent, and their absence is informative rather than embarrassing. They describe an economy that had not yet organised itself.

What the archive does capture, in quantity, is the supply side being assembled. The breaches happened first and the market for what they produced came later, which is why the coverage reads as a decade of raw material accumulating in front of an industry that had not yet worked out what it would be used for.

655K Healthcare Records Go Up for Dark Web Sale, for Millions - Infosecurity Magazine ran in June 28, 2016, when the marketplace framing was still novel enough to need explaining. The prices quoted in stories like that one were the first sign that this had stopped being opportunistic theft and become a supply chain with wholesale rates.

And the advice of the period, visible in pieces such as Five million identities found on seized servers from April 20, 2015, was aimed almost entirely at the individual: choose better, reuse less, watch your statements. Reasonable, and aimed at the one participant with the least leverage over the outcome.

Who carries the loss?

Two different things are lost and they land on two different parties, which is the source of most of the misaligned incentives in this field.

The money largely lands on institutions. Card and payment rules in most developed markets reimburse the individual for unauthorised transactions, and lenders write off the accounts that synthetic identities default on. Those losses are real, insured, priced into products, and treated as a cost of doing business — which is exactly the treatment that produces a tolerance threshold rather than an elimination programme.

The time lands on the individual, and it is not reimbursed by anybody. Restoring a damaged credit file, disputing accounts opened in your name, re-establishing identity with agencies that will not talk to each other: this is months of correspondence conducted during working hours by somebody with no leverage, no expertise and no compensation. There is no line item for it anywhere in the statistics quoted at the top of this page.

That split is why the trade in the interactive above resolves the way it does. The party choosing the setting is optimising against the loss it carries, and it does not carry the other one. Any serious proposal to change outcomes has to change which costs land where, because the arithmetic will otherwise keep giving the same answer.

There is one group for whom the split is worse still, and it rarely appears in the numbers. Somebody whose identification number was used to build a synthetic file as a child discovers it when they apply for their first loan, at eighteen, against a credit history they have never seen and cannot explain. No institution lost money it is aware of, no complaint was ever filed, and the burden of proving a negative falls entirely on the person least equipped to carry it.

The slow arrival of a credential worth trusting

Every organisation currently verifies every person from scratch, using documents designed to be read by humans across a counter. That arrangement is the root cause of most of what is described above, and it is finally being replaced.

The European framework for digital identity wallets is the furthest along: a credential issued once by a party in a position to check properly, then presented cryptographically to anybody who needs it, with member states obliged to make one available to citizens and large platforms obliged to accept it. Mobile driving licences in the United States are travelling the same road from a different starting point, and the banking sector has its own reusable-verification schemes in several markets.

What matters technically is that presenting such a credential is a signature check rather than a perception task. There is no photograph to render, no liveness to simulate, no document to forge — the verifier confirms a signature chains to an issuer it trusts, and a synthetic identity has no issuer willing to sign for it. That is the first control in this field whose cost to defeat rises rather than falls as generation quality improves.

The honest caveats are worth stating. Adoption is slow and uneven, the fallback path for people without a wallet will remain document-and-selfie for years, and a fallback is exactly where fraud concentrates. Concentrating identity in one credential also concentrates the consequences of losing it, which makes recovery design the hard part again. And a credential proves who somebody is without proving that they are acting freely, which leaves coerced and consented fraud entirely untouched.

None of that changes the direction. The organisations that will handle the next decade well are the ones treating their current verification stack as an interim arrangement rather than an investment to defend, because the alternative is to keep buying better answers to a question that is becoming the wrong one.

Is identity theft protection worth buying?

It depends entirely on distinguishing what these services do from what their marketing implies, and the distinction is sharp.

Monitoring tells you that something has already happened. That has genuine value — the discovery gap between an account being opened and its owner finding out is frequently months, and shortening it materially reduces the eventual cleanup — but it is detection, not prevention, and it is sold with the vocabulary of prevention.

The measures that actually prevent are free. A credit freeze stops a lender pulling the file that a new application depends on, which closes new-account fraud almost entirely. A carrier lock on the phone number protects the recovery channel that takeover depends on. Phishing-resistant sign-in removes the credential as something that can be stolen and replayed at all.

The restoration assistance some policies include is the part worth paying for, if anything is, because it addresses the cost that falls on the individual — the months of correspondence rather than the money. Read what is actually promised there: the difference between a caseworker who makes the calls and a document explaining how to make them yourself is the difference between the product being worth its price and not.

Where to start on a Monday

Three for an organisation that onboards people, and three for a person. Neither set requires a purchase.

Measure your own trade, then publish it. Take last quarter's approvals and rejections and produce the two columns from the exercise above with your real numbers. Most institutions have never seen their fraud rate and their rejection rate on the same page, which is why the setting gets argued about rather than chosen.

Check whether your verification looks at provenance or only at content. Ask the supplier directly whether a virtual camera is detected. The answer is frequently no, and it is frequently not in the documentation.

Find out what your recovery flow trusts. If a phone number and a date of birth can restore access to an account, then that is your authentication, whatever the sign-in page does.

For an individual the list is shorter and the return is higher: freeze the credit file at each bureau, add a carrier lock or port-out PIN to the mobile number, and move the accounts that matter to a hardware-backed sign-in. Those three take an afternoon and close most of what is described above. Nothing else on any consumer checklist comes close.

One caveat on the freeze, because it is the measure people abandon. It has to be placed at every bureau rather than the one whose name is familiar, and it has to be lifted temporarily whenever you genuinely apply for something. That second step is where most people give up and leave it off permanently, so decide in advance how you will lift it and write the details down somewhere you will find them a year from now.

Common questions

How large are identity fraud losses?

Traditional identity fraud against consumers ran at about $27.3 billion in the United States in 2025, affecting roughly 18 million people, and has been broadly flat for two years. Synthetic identity fraud is estimated separately at $30–35 billion a year, and that figure lands on lenders rather than on individuals.

Which category costs the most?

Account takeover, by a wide margin: around $16 billion, close to 59% of consumer identity fraud losses, with about 6 million victims and an increase of roughly 18% in a year. The average takeover victim loses about $2,500 against roughly $1,296 for new-account fraud.

Why is account takeover growing fastest?

Because it needs no new identity. Everything required is already published: credentials from breaches, personal details for the recovery questions, and a phone number that can be redirected. The account has an established history, which is exactly what the fraud checks are looking for.

What is synthetic identity fraud?

An identity assembled from parts rather than stolen whole — often a real, unused national identification number combined with a fabricated name and date of birth. Nobody reports it because nobody is impersonated, so it is discovered by the lender rather than by a victim.

How much does a synthetic identity cost?

Research into criminal marketplaces has found synthetic identities advertised from around $15, with toolkits capable of defeating document checks, selfies and liveness detection available for roughly $20. The economics of the defence and the attack are not comparable.

Can deepfakes get through identity verification?

Repeatedly, and the trend is steep. Injection attacks — feeding synthetic video directly into the application rather than holding a screen up to a camera — rose several hundred per cent year on year, with one institution recording over eight thousand biometric injection attempts in eight months. Published red-team work has evaded both passive and active liveness.

Does liveness detection still work?

Against somebody holding a photograph, yes. Against an injected video stream from a virtual camera, frequently not, because the check is validating pixels rather than a device. The durable defences bind the session to hardware instead of judging the image.

Why not simply make verification stricter?

Because the same control that rejects fraud rejects customers, and the second effect grows faster than the first. Past a certain point each additional fraud prevented costs several genuine applicants, which is why settings end up where they do.

Does a credit freeze help?

For new-account fraud it is the single most effective consumer measure, because it stops a lender pulling the file that an application depends on. It does nothing against takeover of an account you already have, which is the larger category.

Is identity theft protection worth paying for?

Monitoring tells you afterwards, which has some value in shortening the discovery gap. It does not prevent anything, and the preventive measures — a freeze, phishing-resistant sign-in, a carrier lock on the phone number — are free.

Who carries the loss?

The institution usually carries the money, and the individual carries the time. Regulated card and payment losses are largely reimbursed; the months of correspondence to restore a credit file and reverse fraudulent accounts are not compensated at all.

What actually reduces the risk?

Phishing-resistant sign-in removes the credential as a stealable object, a carrier lock protects the recovery channel, and a credit freeze closes new-account fraud. Those three cost nothing and address the categories that carry the losses.

Fraud and identity theft coverage

571 reports, newest first. Most cited sources: helpnetsecurity.com (72), infosecurity-magazine.com (45), itproportal.com (41), itsecurityguru.org (21), informationsecuritybuzz.com (18), csoonline.com (15).