By NHI Mgmt Group Editorial TeamBased on SumSub: “Inside Sumsub's 2025 Identity Fraud Report” (June 8, 2026)

TL;DR: Overall fraud volume fell 50% while sophisticated attacks nearly tripled and now combine synthetic identities, deepfakes, and telemetry tampering to defeat verification systems, according to SumSub’s annual Identity Fraud Report based on over 4 million fraud attempts globally. Fraud controls built for static checks are losing ground to coordinated operations that adapt in real time.


At a glance

What this is: This is a SumSub discussion of how AI-powered fraud is becoming more coordinated and harder to detect, with sophisticated attacks nearly tripling while overall attempts fell.

Why it matters: Identity teams need to treat fraud as an adaptive control problem, not a static verification problem, because AI-generated media and telemetry tampering can invalidate assumptions built into current onboarding and liveness checks.


Context

AI-powered fraud now looks less like isolated impersonation and more like coordinated operations that combine synthetic identities, deepfakes, and telemetry manipulation. In identity verification programmes, that matters because the control stack is still often designed for one signal at a time, while attackers are composing several weak points into one workflow.

SumSub’s discussion frames this as a shift in attacker quality rather than just attacker volume. Overall attempts are down, but the attempts that remain are more capable, more organised, and more willing to invest in bypassing verification controls. That is a different governance problem for fraud, KYC, and identity assurance teams.


Key questions

Q: How should compliance and fraud teams respond when AI-assisted identity fraud increases?

A: They should update risk appetite, escalation paths, and review thresholds together rather than treating fraud as a back-office exception. When AI-enabled deception becomes common, faster approvals must be balanced against loss limits, stronger monitoring, and clearer ownership for suspected synthetic identities.

Q: Why do deepfakes create more risk than ordinary identity fraud?

A: Deepfakes compress the time needed to impersonate a real person and make the attack look legitimate at the exact moment trust is granted. That means controls built for post-event review or manual judgment often react too late, especially in onboarding, recovery, and high-risk approvals.

Q: What signs show that identity verification controls are being adapted to by fraudsters?

A: Look for sudden success after repeated failures, inconsistent device or telemetry patterns, clusters of similar-looking submissions, and attacks that switch tactics across attempts. Those are signs the fraud actor is learning the control boundaries. If the same workflow is being probed repeatedly, static thresholds are usually not enough.

Q: How should fraud teams decide whether to hold transactions for manual review?

A: Fraud teams should hold transactions when the business can absorb delay, the order is risky enough to justify more scrutiny, and review can improve decision quality. Holding makes less sense when fulfillment must be instant or when a bad order can be reversed with little cost. The key is balancing fraud loss, customer friction, and operational response time.


Technical breakdown

How AI-generated identities defeat verification workflows

Synthetic identities are constructed to survive automated checks by blending real and fabricated attributes, then iterating against whatever the verification stack reveals. The real problem is not the image itself but the feedback loop: every failed attempt teaches the attacker which signals the system relies on. Liveness checks, document analysis, and risk scoring can each be individually sound yet still fail when the fraudster treats them as separate hurdles rather than a single control boundary. When fraud becomes adaptive, assurance has to account for how one signal can be tuned to bypass the next.

Practical implication: review identity assurance as a chained workflow, not a set of isolated checks.

Deepfakes and liveness checks: where human verification breaks down

Deepfakes undermine liveness because they attack the assumption that the camera feed reflects a real person acting in the moment. Once that assumption fails, even strong biometric or document review controls can be forced into deciding between two convincing false signals. The article’s mention of deepfakes in fraud attempts shows that identity teams are no longer dealing only with stolen documents or poor photos. They are dealing with convincing media that can be generated, modified, and replayed fast enough to exploit operational review windows.

Practical implication: harden liveness review against replayed or generated media, not just low-quality capture.

Telemetry tampering and the verification stack as a target

Telemetry tampering changes the threat model because it targets the verification environment itself, not just the applicant. If fraudsters can alter device signals, browser traces, or behavioural indicators, then the system may classify a risky session as trusted before the user is even accepted. That shifts fraud from content abuse to control-plane abuse. In practice, this means teams must treat verification telemetry as security-relevant evidence, with integrity and anomaly monitoring, rather than assuming it is merely supporting context for a decision engine.

Practical implication: protect verification telemetry with the same discipline used for other high-trust decision inputs.


NHI Mgmt Group analysis

Identity verification is no longer a point-in-time decision problem: AI-powered fraud turns onboarding into an adversarial feedback loop. The control no longer fails only when a document is fake; it fails when every signal in the workflow can be tuned in sequence. For IAM and fraud teams, the practical conclusion is that assurance must be designed as a system boundary, not a single check.

Sophistication is now a more useful risk signal than raw volume: A 50% drop in total attempts does not mean the fraud problem is shrinking. It means the average attacker is spending more effort to defeat controls that were built for lower-quality abuse. That shifts programme prioritisation toward resistance, not just detection.

Deepfakes expose a trust boundary problem in human identity programmes: Liveness checks assume the video stream is a live representation of the applicant. Once synthetic media becomes reliable enough to pass that test, the control is no longer validating presence, only plausibility. Identity teams should treat media authenticity as a core governance issue, not an edge-case fraud tactic.

Telemetry tampering shows that verification evidence itself has become an attack surface: If device and behavioural signals can be altered, then the decision engine is consuming potentially compromised inputs. That creates an integrity problem across KYC, onboarding, and fraud prevention workflows. The conclusion is straightforward: evidentiary trust in identity systems now needs explicit governance, not implicit confidence.

AI fraud is pushing identity assurance toward adaptive control design: The article points to coordinated operations that combine synthetic identities, deepfakes, and system manipulation. That combination means the next control weakness will usually not be a single missing safeguard, but a gap between safeguards. Practitioners need to think in terms of fraud orchestration, not isolated defects.

From our research library:

  • Sophisticated multi-step fraud rose 180%, according to Sumsub's Identity Fraud Report 2025-2026.

What this signals

Adaptive fraud breaks the logic of static verification: Once attackers can combine synthetic identities, deepfakes, and telemetry tampering, the decision point is no longer whether a check exists but whether the whole workflow can be gamed in sequence. Identity teams should assume the adversary is learning from every failure.

Fraud prevention now needs evidence integrity as much as evidence quality: If the signals feeding a decision engine can be manipulated, the control is already compromised even when each signal looks normal on its own. Programme owners should treat verification telemetry as part of the protected trust boundary, not just as supporting context.


For practitioners

  • Tighten control chaining across verification steps Map the full onboarding and verification path to identify where one successful signal can be reused to satisfy later checks without fresh evidence.
  • Harden liveness against replay and generation Review how liveness decisions handle synthetic video, replay attacks, and manipulated capture conditions, then raise scrutiny where passive checks are easy to fool.
  • Treat telemetry integrity as a control requirement Validate the integrity of device, browser, and behavioural signals before they are used in automated decisioning, especially where fraudsters can influence the client environment.
  • Separate high-risk review queues from standard verification Route suspicious document patterns, deepfake indicators, and anomalous telemetry into manual or enhanced review so adaptive attacks do not pass through the default flow.

Key takeaways

  • AI-powered fraud is shifting identity verification from a single-screen check into a multi-stage adversarial process.
  • The article describes a market-wide pattern where overall fraud attempts fell but sophisticated attacks increased sharply, which is a warning sign for control design.
  • Identity teams need to govern signal integrity, liveness resilience, and review escalation together or coordinated fraud will keep finding the gaps between them.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP API Security Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP API Security Top 10API8 — Security MisconfigurationVerification stacks fail when client telemetry and decision inputs are too easy to manipulate.
Recommendation — Harden verification pipelines so tampered telemetry cannot steer identity decisions.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsIdentity assurance governs who gets trusted access after verification.
Recommendation — Align verification decisions with documented authorization thresholds and review exceptions.
NIST SP 800-63SP 800-63A — Enrollment and Identity ProofingThe article centres on identity proofing failures and fraudulent enrolment patterns.
Recommendation — Apply stronger identity proofing controls where synthetic identities and deepfakes are likely.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Fraudulent applicants are external identities attempting to authenticate into trust.
Recommendation — Use external-user identity controls to raise the bar for fraudulent enrolment and access.
OWASP ASVSV8 — AuthorizationThe article shows how assurance gaps can lead to inappropriate trust decisions.
Recommendation — Review authorization decisions so weak identity evidence cannot satisfy high-trust flows.

Key terms

  • Synthetic Identity: A synthetic identity is a software-based actor that can authenticate, request access, and execute actions without being a human user. In practice, this includes AI agents, bots, service accounts, tokens, and other machine identities that need clear ownership, scope, and revocation.
  • Active Liveness Check: An active liveness check requires the user to complete a prompt during verification, such as blinking, smiling, or turning the head. The system uses the response to confirm presence and detect replay or spoofing attempts. It is stronger against fraud, but it adds friction and depends on user participation.
  • Telemetry Tampering: Telemetry tampering is the manipulation of the signals a system uses to judge risk, such as device, session, or behavioural data. The attack matters because decision engines often assume those inputs are trustworthy, which allows fraudsters to shape the score instead of merely avoiding it.
  • Verification workflow: A verification workflow is the sequence of checks, decision branches, and escalation rules used to approve or reject an onboarding attempt. Strong workflows are configurable by risk and geography, and they preserve an audit trail showing why each identity decision was made.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org