Learn more about the latest security and privacy threats
Editorial illustration for the article "Deepfake identity fraud now taints one in every 100 failed checks".

LexisNexis says deepfake identity fraud now taints 1 in 100 failed identity checks, up 180% in a year. What it means for your KYC and liveness controls.

Table of contents

Deepfake identity fraud now appears in one of every 100 failed identity checks, according to a LexisNexis Risk Solutions report published on 14 July 2026. Attacks rose 180% year on year and hit the document, image and liveness stages alike. For KYC teams, selfie and photo based proofing can no longer stand on its own.

  • One in every 100 failed identity checks now contains a deepfake document, image or liveness video, LexisNexis reported on 14 July 2026.
  • Deepfake attacks climbed 180% year on year, with passports and national ID cards from the US, UK, Germany and France the most forged.
  • Juniper Research projects 100.4 billion digital identity checks in 2026, a base large enough that even a 1 in 100 failure rate implies a very large absolute volume of forged attempts.
  • Synthetic identities featured in 11% of frauds in 2025, an eightfold rise over 2024.
  • Reading a signed passport chip, rather than a photo, removes the surface most deepfakes attack.

What did the LexisNexis deepfake identity fraud report find?

LexisNexis Risk Solutions reported on 14 July 2026 that deepfake identity fraud now taints one in every 100 failed identity checks. The finding draws on its Digital Identity Network, which analysed more than 116 billion transactions in 2025. Attack volume rose 180% year on year, and forged documents keep improving.

Kimberly Sutherland, the firm's Global Head of Fraud and Identity, said deepfakes "vastly complicate digital identity verification." The report frames the problem as structural rather than seasonal: as generative models get cheaper, the marginal cost of a convincing forgery falls, while the payoff from a single reusable credential stays high. That asymmetry is what pushes the deepfake identity fraud rate up.

MetricFigureSource
Failed checks containing a deepfake1 in 100LexisNexis, 14 Jul 2026
Year on year rise in deepfake attacks180%LexisNexis, 14 Jul 2026
Projected digital identity checks in 2026100.4 billionJuniper Research, 2026
Transactions analysed in 2025116 billionLexisNexis CCR, Mar 2026
New account creations that were fraud (2025)1 in 11LexisNexis CCR, Mar 2026
Frauds involving a synthetic identity (2025)11%LexisNexis CCR, Mar 2026

How do deepfakes defeat document and liveness checks?

Most remote onboarding runs three checks: a document image, a selfie matched to that document, and a liveness video proving a real person is present. A generative model can now forge all three: it can render a passport image, produce a matching face, and inject a synthetic liveness clip through a virtual camera.

The weak assumption is that a captured image reflects a genuine person in front of the device. Presentation attacks, where a fraudster holds up a screen or mask, were the old threat. Injection attacks bypass the camera entirely and are far harder to spot, because there is no physical artefact to detect. This is why deepfake KYC fraud clusters at remote onboarding rather than in-branch checks. Chip based proofing breaks the chain differently: it reads data signed by the issuing state, so there is no photo to fake.

Verification stageHow the attack worksWhat resists it
Document uploadAI forged passport or ID imageCryptographic read of the passport NFC chip
Selfie or face matchAI face swap matched to the documentChip portrait signed by the issuing authority
Liveness videoInjected deepfake via a virtual cameraTwo step liveness bound to the chip read

What does deepfake identity fraud change for your KYC obligations?

Deepfake identity fraud does not create new duties; it raises the evidentiary bar for the ones you already carry. Customer due diligence requires you to verify identity against evidence you did not generate. A forged image fails that test, so photo only proofing quietly weakens the CDD file you must defend in an examination.

Under FATF Recommendation 10, identification must rest on reliable, independent source documents, data or information. A passport chip read to ICAO 9303 carries a signature from the issuing state, which is independent and tamper evident; an uploaded selfie is neither. For enhanced due diligence and ongoing monitoring, a reusable KYC credential that was proofed against the chip gives you a stronger anchor to re-present than a stored photo.

Detection also feeds your reporting duties. A deepfake caught at onboarding can itself be grounds for a Suspicious Activity Report or Suspicious Transaction Report, because a forged submission is evidence of attempted fraud, not a failed capture. From 2 August 2026, the EU AI Act adds a transparency layer: providers and deployers of systems that generate synthetic media face disclosure duties, a change we covered in our AI Act deepfake obligations briefing. Your record keeping must now evidence how a check defeated a deepfake, not merely that a check ran.

What is still uncertain about the deepfake fraud figures?

The headline rate measures detected deepfakes against failed checks, not against all checks. Where detection is weak, the figure understates the real volume; where detection is strong, it can overstate it. The true undetected rate is unknowable: the attacks that matter most are the ones no vendor counts.

Incentives deserve a plain naming. The firms publishing deepfake identity fraud numbers also sell detection, so the data and the remedy come from the same source. That does not make the trend false, but it argues for triangulating across providers before you rewrite a risk assessment. Liability is the second open question. When a deepfake passes, who absorbs the loss: the verification vendor, the onboarding institution, or the customer whose identity was cloned? Most contracts are silent, and no regulator has drawn a bright line.

Cost is the third. Chip based document authentication needs a phone with a working NFC reader and a document with a readable chip, and not every customer or older passport has both. Falling back to photo capture in those cases reopens the surface you closed. Deadline pressure from the EUDI Wallet rollout may also push some teams to ship image based flows now and harden them later, which is precisely the sequence attackers exploit.

Which documents and sectors are most targeted?

Fraudsters favour high value, reusable documents: passports, driver's licenses and national ID cards issued by the US, UK, Germany and France are the most sought after. A single forged passport can seed accounts across many services, so the return on one good forgery is high.

That reuse logic is why document-grade forgery grows faster than one off image edits. By sector, the broader LexisNexis cybercrime data attributes an 8% global rise in fraud to attacks concentrated in gaming, gambling and ecommerce, where fast onboarding and thin friction are competitive features. Regulated finance is not spared: one in every 11 new account creations in 2025 was a fraud attempt, and 11% of frauds involved a synthetic identity. The pattern that recurs after each large identity data breach is the same: stolen personal data feeds the synthetic identities that deepfakes then dress up.

How should compliance teams respond to deepfake identity fraud?

Start with controls, not vendors. Add chip based document authentication, an NFC read to ICAO 9303, wherever the document supports it, and bind liveness to that read rather than treating the two as separate steps. Test your stack against injection attacks through a virtual camera, not only presentation attacks, because injection is the vector the report flags as rising.

Then align policy. Reassess any reliance on selfie only proofing in your enterprise risk assessment, log the deepfake signal when a check fails, and file a SAR or STR where a forged submission indicates suspicion rather than a benign capture error. Review your KYC verification flow end to end and confirm your record keeping can evidence how each deepfake was defeated.

Zyphe was built for this failure mode. It reads the passport NFC chip to ICAO 9303 and eIDAS standards with two step liveness and no image upload, so there is no uploaded photo for a generative model to forge, and it splits personal data into shards held across separate nodes, so there is no single database for the next breach to drain. If deepfakes are reshaping your onboarding risk, book a demo to see chip first verification in practice.

The bottom line

The LexisNexis figures put a number on what onboarding teams already sensed: the image is no longer proof. When one in every 100 failed checks carries a deepfake and attacks are up 180% in a year, any control that trusts an uploaded photo or an unbound selfie is running on borrowed time. The durable answer to deepfake identity fraud is to verify against data the issuing state signed and to hold less of it afterwards, so a passed forgery is harder and a future breach is smaller. Deepfakes made the picture unreliable; cryptography and data minimisation are how you stop relying on it.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

Deepfake identity fraud is the use of AI generated documents, faces or liveness videos to pass an identity check as someone else, or as a person who does not exist. It targets remote onboarding, where a fraudster never has to present a physical document and can inject a synthetic image straight into the verification feed.

LexisNexis Risk Solutions reported on 14 July 2026 that one in every 100 failed identity checks now contains a deepfake document, image or liveness video, an increase of 180% year on year. Against a projected 100.4 billion digital identity checks in 2026, that rate implies a very large absolute volume of forged attempts.

Liveness detection helps against presentation attacks, where someone holds up a photo or mask, but it is weaker against injection attacks that feed a synthetic video through a virtual camera. Liveness is strongest when it is bound to a cryptographic read of the document chip rather than treated as a standalone selfie step.

Reading the passport NFC chip to the ICAO 9303 standard checks data signed by the issuing state, so a rendered or edited document image does not pass. It removes the uploaded photo that generative models attack. It does not help where a passport has no readable chip or the device lacks NFC, so a fallback policy still matters.

A deepfake caught at onboarding can support a Suspicious Activity Report or Suspicious Transaction Report, because a forged submission is evidence of attempted fraud rather than a technical failure. Your policy should tell staff when a detected forgery crosses from a declined check into a reportable suspicion, and your records should capture the signal.

See privacy-first KYC in action

Verify identity without storing a single document. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo