Learn more about the latest security and privacy threats
Editorial illustration for the article "Identity fraud drives 59% of UK fraud risk cases in Cifas H1 2026 data".

Cifas members filed over 220,000 UK fraud risk cases in the first half of 2026. Identity fraud hit 59% of them, SIM swap filings rose 402% and muling rose 69%.

Table of contents

Identity fraud accounted for 59% of the fraud risk cases filed to the UK National Fraud Database in the first half of 2026, the highest January to June total recorded by Cifas. Cifas is the UK not for profit fraud prevention service. Cases rose 9% to nearly 130,000. Unauthorised SIM swap filings climbed 402%, and muling cases rose 69%.

  • Cifas members filed more than 220,000 fraud risk cases to the National Fraud Database between January and June 2026, the highest January to June total recorded. Cifas is the UK not for profit fraud prevention service, with nearly 800 members.
  • Nearly 130,000 of those were identity fraud, up 9% year on year, with bank accounts and plastic cards making up 68% of the total.
  • Unauthorised SIM swap cases rose 402% against the same six months of 2025, which puts pressure on any control that leans on an SMS one time code.
  • Money muling cases rose 69% to more than 13,000 and now make up 30% of misuse of facility filings, with 57% of mule cases involving people under 30.
  • Cifas flags synthetic identities, AI enabled impersonation and digitally manipulated documents as the growing intelligence concerns behind the numbers.

What did the Cifas half year data find?

Cifas released the Fraudscape 2026 six month update on 5 August 2026. It covers cases filed by members to the UK National Fraud Database, the shared fraud database Cifas operates for its members, between January and June. More than 220,000 fraud risk cases were recorded, and identity fraud was the largest single category at 59%.

The detail matters more than the headline. Identity fraud cases rose 9% to nearly 130,000, and bank accounts and plastic cards accounted for 68% of them. Most victims were aged 61 and over, but the sharpest rise fell on people aged 21 to 30, where cases increased by almost a third. Mike Haley, chief executive of Cifas, said that "stolen personal data often provides the entry point".

Metric, January to June 2026FigureChange on H1 2025
Fraud risk cases filed to the National Fraud DatabaseMore than 220,000Roughly flat, highest January to June total
Identity fraud casesNearly 130,000, or 59% of all filingsUp 9%
Facility (account) takeover casesNearly 40,000Up 5%
Money muling casesMore than 13,000Up 69%
Unauthorised SIM swap casesNot disclosedUp 402%

Two sub trends sit underneath. Online retail account takeovers rose 84% and plastic card takeovers rose 59%, which underlines the value of compromised accounts and payment facilities. And Cifas records criminal use of synthetic identities, AI enabled impersonation and digitally manipulated documentation as a growing intelligence concern, not a fringe technique.

Why does a 402% rise in SIM swap matter?

A SIM swap moves a victim's mobile number onto a device the attacker controls. Every code, reset link and push prompt sent to that number then lands with the attacker. A 402% rise in unauthorised SIM swap filings in six months is therefore not a telecoms problem. It is an authentication problem.

The attacker collects enough personal data to pass a mobile operator's account checks, ports the number, then uses it to intercept security codes and defeat account protections. Cifas describes exactly this chain: the swap is the means, and further fraud is the objective. This is why account takeover and identity fraud numbers move together rather than independently.

For anyone relying on SMS codes as the possession factor in strong customer authentication, that chain breaks the assumption. The factor is supposed to prove the customer holds a specific device. After a swap it proves only that someone holds the number. Device bound credentials, app based authenticators and chip verified identity remove the SIM swap exposure, because the secret never travels over a mobile network. They do not remove real time phishing, which needs separate handling.

What does this change for your compliance obligations?

The Cifas data does not create new law, but it changes what a supervisor will treat as reasonable under existing UK duties. Four areas move first: customer due diligence, suspicious activity reporting, authentication design, and the corporate failure to prevent fraud offence. Each has a specific statutory hook rather than a general instruction to be careful.

DutySourceWhat the H1 2026 data changes
Customer due diligence and ongoing monitoringMoney Laundering Regulations 2017, regulation 28(18)Weaker basis under the reliable, independent source test in regulation 28(18)
Suspicious activity reportingProceeds of Crime Act 2002, section 330More mule accounts meeting the suspicion or reasonable grounds test, skewed young
Authentication and step upPayment Services Regulations 2017, regulation 100, and the SCA technical standardsSMS possession factors degraded by a 402% rise in number porting attacks
Failure to prevent fraudEconomic Crime and Corporate Transparency Act 2023, sections 199 and 201Insider and staff facilitated fraud is the exposure, not being defrauded

Customer due diligence and ongoing monitoring

Under regulation 28(18) of the Money Laundering Regulations 2017, customer due diligence has to verify identity from a reliable source that is independent of the person being verified. Where nearly 130,000 filings a half year involve stolen or fabricated identities, and manipulated documents are a named concern, an uploaded image of a document is a weaker evidence base than a chip read.

The chip is signed by the issuing authority and the signature can be checked, which an edited image cannot match. Monitoring also has to account for a genuine record being taken over after onboarding.

Suspicious activity reporting

Money muling is where fraud data becomes an anti money laundering duty. A 69% rise in mule filings means more accounts meeting the test in section 330 of the Proceeds of Crime Act 2002, which catches reasonable grounds for suspicion as well as actual suspicion, and triggers a suspicious activity report to the UK Financial Intelligence Unit, part of the National Crime Agency.

With 57% of mule cases involving people under 30 and 17% under 21, expect a higher share of reports on young, thin file customers whose accounts look ordinary until the flow starts.

Authentication and step up

Regulation 100 of the Payment Services Regulations 2017 requires strong customer authentication where a user accesses a payment account online or initiates an electronic payment transaction, subject to the exemptions in the technical standards. Online account access is exactly the takeover surface in this data. The SIM swap trend argues for treating a recent number port as a risk signal in its own right, and for demoting SMS in high value or high risk journeys. Multi factor authentication that leans on one intercepted channel is a single factor with extra steps.

Failure to prevent fraud

This one is often misread, so be precise about direction. The offence in the Economic Crime and Corporate Transparency Act 2023 came into effect on 1 September 2025. It bites where an employee, agent or other associated person commits fraud intending to benefit the organisation or, in some circumstances, its clients.

A fraud committed against the organisation does not trigger it, because the offence turns on intent to benefit. Section 199(3) is narrower than it is often described. It removes liability only where the organisation is the victim or intended victim of a fraud intended to benefit its clients, and the guidance confirms that indirect harm such as reputational damage does not make an organisation a victim.

Section 201 defines a large organisation as meeting, in the guidance wording, "two or three out of the following criteria", that is two or more: more than 250 employees, more than £36 million turnover, and more than £18 million in total assets. The Cifas relevance runs through the insider side of the dataset, since Fraudscape combines the National Fraud Database with the Insider Threat Database. The scenario most likely to be in scope is staff bypassing customer due diligence to hit onboarding targets, where the benefit runs to the firm and the conduct amounts to a base fraud offence listed in Schedule 13. An insider paid by criminals to open mule accounts generally falls outside this offence, because the benefit runs the wrong way, though it remains a money laundering and insider threat matter.

What is still uncertain in the identity fraud figures?

The main limit is that the National Fraud Database is a filing dataset, not a census. It measures what nearly 800 Cifas members recorded, so a rise can reflect better detection, wider membership or changed filing behaviour as well as more crime. Cifas itself credits greater reporting and stronger detection for part of the clearer picture.

That cuts both ways. If part of the increase is detection, the volume in earlier years was higher than recorded, and any internal baseline built on prior filings understates the threat. If part of it is real growth, controls tuned two years ago are calibrated to the wrong volume. Neither reading supports leaving thresholds alone.

The headline percentage needs the same care. Cifas published the SIM swap change as a percentage only. Without a base count the 402% cannot be sized against the 220,000 total, and a low starting volume would produce a large percentage from a modest absolute rise.

Three further questions are open. The report does not resolve how much of the identity fraud growth is fully synthetic versus stolen real identities, and the two need different countermeasures. Liability for a SIM swap chain is unsettled, sitting between the mobile operator that approved the port and the firm that accepted the code. And there is a cost question: chip based verification and device bound credentials reduce the attack surface, but they exclude customers without a compatible document or handset, which is a real inclusion risk.

How does this compare with the first half of 2025?

Year on year, the totals moved modestly while the composition shifted sharply. Overall filings rose from more than 217,000 to more than 220,000, a plateau at a high level. Identity fraud, however, went from a little over half of all filings to nearly three in five, which is the change worth acting on.

MeasureH1 2025H1 2026
Total fraud risk cases filedMore than 217,000More than 220,000
Identity fraud casesMore than 118,000Nearly 130,000
Identity fraud share of all filingsAround 54% (Zyphe calculation)59% (Cifas)
Facility (account) takeover casesMore than 38,000Nearly 40,000
Headline intelligence themeAI generated documents and identity sellingSynthetic identities, AI impersonation, muling

Two notes on the arithmetic. Cifas states the identity fraud rise as 9%, while the rounded values above imply closer to 10%, which points to the percentage being calculated on unrounded figures. And Cifas billed H1 2025 as a record six month total too, so two consecutive record halves reinforce the risks section: records track filing behaviour as much as offending.

The 2025 update described criminals using AI to forge documents and bypass verification. The 2026 update adds distribution: muling to move the proceeds and SIM swap to defeat the checks. The threat has completed its supply chain.

How should compliance teams respond?

UK firms should act on three controls after this data. Re-run the onboarding risk assessment against document manipulation and synthetic identity specifically, not fraud in general. Remove SMS one time codes from the highest risk journeys, and treat a recent SIM change as a step up trigger. Review mule typologies for young account holders.

Then check the reporting path. A 69% rise in mule filings across the sector means your route to the UK Financial Intelligence Unit has to absorb more volume. One design point we plan for at Zyphe: any chip verification rollout still needs a path for documents without a readable chip. That image based fallback is the route an attacker will choose, so it needs its own controls. Our earlier coverage of deepfake identity fraud in verification data goes further on that point.

Then look at the data you hold. Every copy of a passport image, address and date of birth in your systems is raw material for the fraud recorded in this report. Zyphe reads the document chip over NFC to the ICAO Doc 9303 standard, with two step liveness and no image upload. The personal data is then sharded across a decentralised network so no single node holds a complete record, and the customer holds a reusable credential. If that is the direction you are moving, see KYC software, decentralised PII storage, or book a demo.

The bottom line

The signal in this release is not the record total, it is the mix. Identity is now the entry point for the majority of fraud risk cases recorded in the UK, and the techniques around it have industrialised: manipulated documents to get in, SIM swaps to defeat the check, mule accounts to move the money.

Controls designed when identity fraud was one category among several now face the dominant one. The practical response is to verify identity against something an attacker cannot fabricate or intercept, and to hold less of the personal data that fuels the next round of attacks.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

It is the half year edition of Cifas' annual fraud report, released on 5 August 2026 and covering January to June. Fraudscape combines data from the National Fraud Database and the Insider Threat Database, alongside intelligence from members, partners and law enforcement. Cifas is a not for profit fraud prevention service with nearly 800 member organisations.

Nearly 130,000 cases, a rise of 9% on the same period in 2025, out of more than 220,000 total fraud risk cases filed by Cifas members. That makes identity fraud 59% of all filings. Bank accounts and plastic cards were the products targeted in 68% of those cases.

Cifas links the increase to criminals using SIM swaps to intercept security codes, bypass account protections and commit further fraud. Once the number moves to an attacker controlled device, any one time code sent by SMS goes with it, which makes the technique valuable wherever text messages are used as an authentication factor.

No new obligations, but it raises the evidential bar under existing ones. The duties in play are customer due diligence under the Money Laundering Regulations 2017 and suspicious activity reporting on suspected mule accounts under section 330 of the Proceeds of Crime Act 2002. Fraud risk assessment is judged against known threats, and this is published evidence of what is known.

Most recorded victims are aged 61 and over, but the largest increase was among people aged 21 to 30, where cases rose by almost a third. On the offending side, people under 30 accounted for 57% of money muling cases and 17% were under 21, which is why Cifas emphasises early intervention and education.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo