Fraud statistics age fast, and 2026 has aged them faster than most. Halfway through the year, the picture that's emerging isn't a gradual climb - it's a step change, driven almost entirely by generative AI reaching fraudsters' hands.
This is a source-linked roundup of the numbers worth knowing if you onboard customers, underwrite loans, or pay claims. Each figure links to its source so you can cite it directly.
A note on the big percentages below: several are projections that annualise fraud rates from early 2026. They signal direction and velocity, not settled year-end fact. We've flagged which is which.
The headline: document deepfakes are the fastest-growing fraud type
The single most striking number this year concerns document deepfakes - AI-produced documents (IDs, statements, certificates) submitted as genuine.
That ~3,892% figure - about a 40-fold increase - comes from Shufti's Identity Fraud Index, annualising the document-deepfake rate observed from January to May 2026. It's the fastest-growing category they track, outpacing face swaps and live video manipulation. (Biometric Update, Shufti report)
The reason is simple economics: generating a convincing synthetic ID or statement used to take skill and time. Deepfake-as-a-service dropped both to near zero.
What it's costing
Notably, the FBI's Internet Crime Complaint Center tracked "AI-related" fraud as its own category for the first time in its 2025 report - a quiet but telling signal that the threat crossed from novelty to line-item. (reported losses overview)
Reported losses are the floor, not the ceiling. Document fraud is chronically under-reported: much of it surfaces months later as a bad loan, an inflated claim paid, or a synthetic account written off - by which point it's rarely traced back to the forged document that started it.
The detection reality: eyes don't work anymore
The most operationally important finding of 2026 isn't a fraud volume - it's a detection failure.
- 1 in every 100 identity-check failures now involves a deepfake document, image, or liveness video, per LexisNexis. (LexisNexis Risk Solutions)
- In controlled tests, most people can't reliably tell a real document or face from a deepfake - and, worse, they overestimate their own ability to do so.
- Manual review, the traditional backstop, is no longer dependable against AI-generated documents.
Put together, these say something uncomfortable: the human review step many compliance workflows still lean on has quietly stopped being a control.
The other AI-driven surfaces
Deepfakes get the headlines, but 2026's AI fraud wave is broader. Three adjacent surfaces worth watching:
- AI-generated receipts now make up roughly 71% of flagged expense fraud, up from near zero a year earlier - see how to spot an AI-generated fake receipt.
- Synthetic identities - part-real, part-fabricated personas - remain one of the hardest fraud types to catch at onboarding. (why synthetic identity fraud is so hard)
- AI-assisted invoice and payment fraud is rising across B2B accounts-payable workflows, where a single altered PDF can reroute a real payment.
The market's response
The spend follows the threat. Combined voice and facial deepfake detection checks are projected to more than double, from 6 billion in 2026 to 12.2 billion by 2028, with market revenue growing from ~$3 billion to ~$6.1 billion over the same window. And 82% of financial institutions now report using advanced AI in KYC/AML operations, up from 42% a year earlier. (market projections, KYC AI adoption)
What the numbers mean for your workflow
Strip away the individual figures and three implications remain:
- The attack got cheap and automated. A 40x jump in document deepfakes isn't a smarter fraudster - it's the same fraud at machine scale. Defenses priced and paced for occasional fakes won't hold.
- Visual review is no longer a control. If a step in your process depends on a human spotting a fake by eye, treat it as decorative until proven otherwise. The data says people can't, and they don't know they can't.
- Detection has to move to forensics. The reliable signals aren't "does this look right" but "was this document authentically produced" - provenance, generation signatures, structural and arithmetic consistency. That's the question document tampering detection is built to answer, across deepfake IDs, statements, and certificates alike.
Put a document to the test
Upload a real document - or a deepfake - and get a forensic verdict in about a minute. See where automated detection lands on your own files. $5 in free credits.
Test a document →FAQ
- How much is document and deepfake fraud growing in 2026?
Document deepfakes are projected to grow roughly 3,892% in 2026 - about 40x over 2025 - making them the fastest-growing fraud category tracked, while overall deepfake identity fraud is projected to rise around 495%. These are projections annualised from early-2026 data, so they indicate velocity rather than a settled year-end total, but the direction is unambiguous.
- What is a document deepfake?
A document deepfake is an AI-produced document - an ID card, passport, bank statement, payslip, or certificate - generated or manipulated to look genuine and submitted as real. Unlike a document edited in a PDF tool, a full deepfake may never have existed as a real document at all, which is why detection focuses on generation signatures and provenance rather than tampering traces.
- Can people detect deepfake documents by eye?
Generally no. Controlled tests in 2026 found most people can't reliably distinguish real documents and faces from deepfakes, and that they tend to overestimate their own accuracy. This is why manual review is no longer considered a dependable control against AI-generated documents, and why detection is shifting to automated forensic analysis.
- How much is deepfake fraud costing businesses?
Reported global losses to deepfake fraud have surpassed $1.5 billion, and the FBI's IC3 logged $893 million across 22,364 AI-related fraud complaints in its 2025 report - the first year it tracked AI fraud as its own category. Because document fraud is heavily under-reported and often surfaces months later, these figures are widely regarded as a floor rather than the true total.
- What's the most effective defense against AI-generated document fraud?
Automated forensic verification at the point of submission. Rather than asking whether a document looks right, forensic detection asks whether it was authentically produced - checking for AI-generation signatures, capture provenance, structural and arithmetic consistency, and reuse across submissions. This catches the AI-generated and deepfake documents that visual review and OCR-based tools miss.