Geography of Identity Fraud: What the Latest Data Shows

Find out which fraud types are most common across different industries based on KYC bypass attempts, and explore iDenfy’s recent in-house research on real ID verifications, based on the geography of identity fraud and other risk signals.

Reviewed by

Compliance Team Lead

12 min read
Add iDenfy as a Preferred Source
Identity fraud and its statistics based on different regions and the geography risk factor

Identity fraud isn’t a new concept. From stealing physical wallets and IDs or printed credit card statements from the mail, bad actors have moved to synthetic identities and impersonation for greater gain. At a later stage, more platforms and services moved online, allowing criminals to use phishing or data breaches, including stolen personal information bought off the dark web, to bypass Know Your Customer (KYC) systems or successfully take over existing accounts and then conduct unauthorized charges. 

Now, with generative AI fraud and deepfakes, realistically looking videos have left the need for physical masks behind, and stricter KYC checks, like proper liveness technology and multi-step ID verification workflows (both using doc-based checks and selfie verification), are mandatory, especially in high-risk industries, where identity fraud numbers are universally considered to be higher. That’s why there are industry-specific fraud signals and geography-specific signals that make the chances of fraud higher. 

Key takeaways:

  • Identity fraud patterns differ based on the region and geography. 
  • Duplicate faces and personal detail elements are a common tactic both for fraud and attempts to bypass KYC verification multiple times.
  • Deepfakes and serious injection attacks are a real threat, but they remain less common globally. 
  • Not every KYC session flag and risk identification can be automatically labeled as fraud. 
  • You should have multiple user onboarding workflows to effectively detect fraud and still have a high KYC conversion rate. 

Recently, our team at iDenfy collected data from iDenfy’s KYC software using 130K+ flagged cases in various regions to analyze whether the geography aspect makes a significant difference in the rate/type of identity fraud. Based on these new in-house expert insights, I explain the tactics behind the geography of identity fraud and look into this topic in a more detailed manner. 

What Counts as Identity Fraud?

Identity fraud is anything that’s related to the theft of personal data with the goal of benefiting from someone else’s identity, for example, to bypass an identity verification check and create a new account to stay hidden. This type of fraud is also commonly used to access financial benefits or gain access to KYC-restricted services, just to later commit further crimes. 

For example, a Social Security number (SSN) is often stolen to create a new, merged/synthetic ID to then access medical or financial benefits. That’s why it’s best to use a multi-layer security check and KYC flow. If one fails, the other one catches the identity fraud. 

For that, multiple KYC methods are useful, such as:

  • An ID document check + a liveness check with selfie verification
  • SSN cross-matching via a government pre-recorded database

Different forms of identity fraud can be used at the initial customer onboarding stage and later on, for example, when the user is monitored and identified as high-risk, and then the platform requires them to reverify and resubmit certain data. It can also be a simple face authentication check, which is a non-document KYC flow designed to improve conversions. 

Related: Choosing a Good Identity Verification Solution [Buyer’s Guide]
Fraud Prevention

Stop fraud before it starts

From deepfakes to document forgery — iDenfy catches fraud attempts with AI-powered liveness detection and document checks.

Explore Fraud Prevention

Common Types of Identity Fraud

There are different forms of ID fraud. For example:

  • Document forgery. Criminals use fake, altered, or expired ID documents on purpose to make a new or an existing identity appear legitimate. 
  • Biometric-related fraud. A form of identity fraud where criminals attempt to pass the selfie identity verification step during KYC and use fake videos, such as AI-generated deepfakes. 
  • Stolen identities. A classic form of ID fraud, where the bad actor steals or buys already stolen personal information to create a new identity for impersonation. 
  • Synthetic identities. Bad actors combine legitimate personal details with fake and manufactured elements to create a new, possibly more convincing identity, which might have KYC elements that match (for example, if a legitimate address and a utility bill are used during address verification that cross-checks the user’s entered data (not a government-issued ID, which is considered to be a more secure method)). 

Some users aren’t automatically fraudulent, but they are still rejected by identity verification software due to errors on their part, such as a blurry attempt to capture an ID document or a straight-up abandonment of the KYC process. That’s why you can’t have a too much of a strict identity verification process that would put off genuine users trying to access your services. The balance is needed, and it can be found when you customize the KYC flows, creating multiple versions depending on the risk. 

Popular types of identity fraud and bypass measures that KYC software is designed to spot automatically.

For example, if you’re a monetized e-commerce platform owner, a possible challenge could be account takeover (ATO) fraud, which is also a form of identity fraud that occurs later in the user’s lifecycle. That means you’ll need stricter re-checks and reverification triggered by atypical changes to the user’s profile, for example, an address change (significant when used for shipping) or a new IBAN (to make an unauthorized payout). 

Why is Identity Fraud a Threat to KYC Systems?

Identity fraud is designed to help criminals fake their way into accessing important financial information and is a threat to various industries, not just banking or fintech, as KYC checks are widely used in various online platforms. Fake applicants can appear as legitimate users, which is not appropriate in any way, especially if your identity verification system is poor and can determine fake users with forged IDs as genuine applicants. 

“You’ve got to have it all nowadays, and I’m talking about important fraud prevention elements like automated ID document authenticity checks, virtual camera detection, or duplicate face detection,” explained Domantas, our CEO, adding:

“At iDenfy, we allow you to customize your blocklist and add custom rules based on risk, such as the geography risk factor, rejecting users from certain countries, such as sanctioned jurisdictions.”

Domantas Ciulde, the CEO of iDenfy

To achieve this in practice, automated add-on solutions, like a KYC risk assessment tool, can be helpful. Of course, you can use a manual approach and adopt a KYC review team that’s able to review each KYC session, but this isn’t a sustainable approach for some firms, especially smaller startups that are just starting out their operations and don’t have the budget to hire a whole analyst team. 

Our internal data regarding the geography of identity fraud and collected numbers on the attempts to deceive iDenfy’s KYC software show the scale of this issue. Out of 1,813,146 identity verifications from various jurisdictions, 131,762 (7%) had at least one flag (meaning the system flagged the user’s ID verification as “suspected” of fraud based on different risk signals and KYC failure reasons). 

Threat to KYC Signal detected Verifications flagged Share of suspected verifications
Multi-accounting Duplicate document face 22,887 17.4%
Duplicate selfie face 18,697 14.2%
Duplicate personal data 3,943 3.0%
Document fraud Photo of document from a screen 6,198 4.7%
Printed (spoofed) document 2,516 1.9%
Liveness bypass Virtual camera (injection attack) 1,630 1.2%
Repeat offenders Blocklist matches (face, document, data) ~3,940 ~3.0%
AML risk AML suspicion 3,542 2.7%
Data manipulation Name mismatch 27,834 21.1%
Surname mismatch 23,253 17.6%
Document information mismatch 12,511 9.5%
Age assurance Underage user 4,801 3.6%

iDenfy’s in-house research using 1.8 million+ verification sessions, of which 7% were flagged

For example, out of 750,000+ verifications in the EU alone, 60,000+ were flagged by the system as “suspected” or potentially fraudulent, resulting in an 8% suspicion rate, close to the global average. In Bulgaria in particular, 53% of all suspected verifications belonged to this country, with most fraud signals consisting of the “duplicate face” error or “duplicate document”. 

This comes as no surprise, as the country is widely known for its iGaming and gambling sector, which is known to be prone to multi-accounting and linked issues like bonus abuse. 

Other KYC bypass methods flagged by iDenfy’s KYC system in our research include:

Reusing the Same Face for Multiple Accounts

Users attempting to bypass KYC systems and commit identity fraud often use the same face during the biometric verification stage, even though the policy requires one account per user, banning multiple account use for security reasons. 

iDenfy’s statistics show that:

  • 22,887 verifications were flagged for a duplicate document face (17% of all flagged KYC sessions)
  • 18,697 were flagged for a duplicate selfie face (14%)
  • 3,943 reused the same personal data piece across different verifications (3%)

Using Spoofing or Presentation Attacks

This includes malicious practices that aim to successfully carry out an identity fraud-related KYC bypass, such as printouts, screen photos, or videos. 

iDenfy’s statistics show that:

  • 6,198 verifications used a photo of a document taken from a screen instead of a real physical ID (5%)
  • 2,516 used a printed (spoofed) document (2%)

Poor KYC systems can read fabricated security elements and pass them as the real deal, not a fake document. That’s why it’s important to use software that’s able to assess texture, microprint and holograms, not just the MRZ zone or the personal information written on the ID document. 

Related: How to Spot a Fake ID in Different States? [With Examples]

Employing a Virtual Camera or Deepfake Technology

These methods are used in attempts to bypass liveness checks during the biometric verification stage. This is considered to be the highest-risk threat and a real possibility of identity fraud during KYC. 

Common KYC software flags that get detected during KYC submissions, showing the severe issue that identity fraud brings if bad actors get onboarded to a sensitive, monetized platform.

That’s because injection attacks and well-made gen-AI deepfakes look very real, especially to the untrained naked eye and even some basic IDV software solutions. 

iDenfy’s statistics show that:

  • 1,630 verifications were flagged for a virtual camera, a common method for injecting pre-recorded or deepfake video into the selfie step in the KYC flow (1%) 
  • 23 involved portrait substitution, where the face on the document was swapped (less than 1%)

However, these fraudulent KYC sessions were the least common type in our research.

Blocked Users Still Attempting to Pass KYC Multiple Times

Known fraudsters are also a group that shouldn’t be overlooked, as they keep coming back with new methods of identity fraud, still attempting to bypass security systems over and over again. Often, they use different IPs, new devices, synthetic identities, and similar tactics. 

iDenfy’s statistics show that:

  • The blocklist alert generated almost 4,000 findings on user faces, faces on IDs and personal data (3%)
  • 3,542 verifications were flagged for AML suspicion (3%)
  • 396 for suspected criminal background records (less than 1%)

Submitting Incorrect Personal Details

This includes standard data mismatches that the system flags. Even though not all of them are automatically treated as identity fraud, it can be a signal to trigger a different KYC flow or add such measures, like allowing the user to try to complete their verification up to five times max. 

iDenfy’s statistics show that there were:

  • 27,834 first name mismatches 
  • 23,253 surname mismatches
  • 12,511 document information mismatches
  • 6,804 date of birth mismatches
  • 5,356 personal code mismatches

This helps avoid onboarding repeated offenders or those who deliberately try to combine a new identity and get away with it. 

Minors Attempting to Access Age-Restricted Products

Age verification and, in some cases, age estimation methods are required in the adult industry. Age-restricted platforms that display adult-only content or e-commerce platforms that sell items like tobacco or alcohol online should always check the user’s age before checkout or before they create an account on the platform. 

iDenfy’s statistics show that:

  • 4,801 verifications were flagged as underage (4%)
  • In Algeria, underage attempts account for 48% of all suspected verifications

Without properly verifying age, attempts to use someone else’s document (for example, taken from an older family member) or even stolen details, which are considered a type of identity fraud, are a risk that can lead to non-compliance. 

Related: Weak Age Assurance: How It Costs Businesses Millions

Geography-Specific Identity Fraud Statistics

Some countries have specific identity fraud trends, showing the differences between each region and the most common issues in that area.

Signal EU UK USA Asia Africa
Verifications 756,471 35,038 179,994 102,009 58,746
Flagged sessions 60,938 3,684 15,551 ~13,300 ~11,360
Suspicion rate 8.1% 10.5% 8.6% 13.0% 19.3%
Duplicate document face 21.0% 8.9% 12.0% 17.1% 24.1%
Duplicate selfie face 16.6% 7.7% 6.9% 15.7% 21.2%
Screen photo of document 4.0% 3.8% 4.3% 12.9% 2.7%
Virtual camera 0.8% 1.6% 2.0% 1.6% 0.6%
AML suspicion 2.1% 14.3% 7.2% 1.8% 0.9%
Underage 2.3% 6.1% 2.1% 6.8% 8.9%
iDenfy’s collected data on identity fraud signals and flagged KYC sessions based on the geography factor

EU

  • France has the second-highest volume of flagged sessions in the EU (4,412) and a 15% suspicion rate, almost double Germany’s 8%
  • Denmark (20%) and Hungary (19%) have the highest suspicion rates among EU countries, with 2,000+ verifications
  • Czechia has a 14% fraud suspicion rate, with 2,132 flagged sessions

-> Personal code mismatches appear in 7.8% of flagged EU sessions (4,735). This signal is specific to EU national ID numbering systems.

UK

  • Document information mismatches are the most common UK signal (23%).
  • AML suspicion appears in 14% of flagged UK sessions. That’s about 7× the EU share (2%) and 2× the US share (7%)
  • Proof of Address screenshots make up 352 flagged sessions (10%) where a screenshot was used instead of a real PoA document
  • Virtual camera flags appear in 2% of UK flagged sessions, twice the EU share
  • Underage attempts make up 6%, almost 3× the EU share

USA

  • Duplicate document faces appear in 12% of flagged US sessions (1,865).
  • Blocklist alerts reached about 1,080 in the US alone (across faces, document faces and personal data)
  • Printed document spoofs made up 287 flagged sessions (1.8%), more than 2× the EU share (0.7%)

Asia

  • China has the highest volume of flagged sessions in Asia (2,330), with an 8% suspicion rate
  • Vietnam (21%) and Indonesia (20%) have high suspicion rates. South Korea (33%) and Taiwan (29%) are already in the post
  • India had 2,063 flagged sessions and a 13% suspicion rate
  • Screen photos of documents appear in 13% of flagged sessions, about 3× the share in the EU, UK and US
  • Underage attempts reached 7%, the second highest of the four regions

Africa

  • Africa has the highest share of any region for duplicate faces, with duplicate document faces accounting for 24% of flagged sessions and duplicate selfie faces for 21%
  • Egypt alone accounts for about 25% of Africa’s flagged sessions (2,713)
  • Ethiopia (28%) and Cameroon (22%) have high suspicion rates, but on smaller samples (about 1,200 ID verifications each)
  • Underage attempts made up 9% of all flagged KYC sessions, which is the highest number compared to other regions
Related: OSINT-Based KYB: How to Verify East African Businesses 

Can You Use Lightweight KYC Checks for All Types of Identity Fraud?

The short answer is no. Lightweight, simple ID checks are an option in low-risk cases, where simplified due diligence is enough. In high-risk industries, such as banking, you can’t employ only one ID verification check, as both layers are mandatory and considered to be a standard onboarding process for the account opening stage. That’s because identity fraud is serious and can later be linked to even bigger crimes, such as money laundering. 

Reasons why a multi-layered approach to KYC compliance is more suitable in high-risk industries that are prone to identity fraud.

There are criminal groups that specialize in this sort of matter, creating new identities and finding new ways to bypass KYC, no matter which country or geography they come from. Sometimes, they target niche jurisdictions on purpose with the hope that an automated KYC system or a human analyst won’t recognize that particular ID document, approving it and shining a green light to access sensitive information.

Related: What is the Difference Between CDD and EDD?

How iDenfy Can Help

iDenfy has the full stack to protect your platform from identity fraud and related risks, such as duplicates, underage users, fake and altered documents, users storming in from sanctioned jurisdictions, and other risks that can be flagged efficiently, based on parameters such as country- or industry-specific risks. 

On our KYC and KYB/AML platform, we offer:

-> Doc-based identity verification service

-> Non-doc digital IDs (such as Smart-ID, Sweden BankID, and other eIDs)

-> Biometric verification w/ passive or active liveness

-> Database cross-matching (including special checks, such as criminal background checks in the US)

-> Automated proof of address checks

-> Bank card verification and bank account API

-> Transaction monitoring

-> Automated risk assessment and risk-scoring 

-> Other fraud prevention services, such as phone verification, SMS/email verification, IP address detection

-> AML screening (PEPs & sanctions, watchlist screening and adverse media checks)

-> KYB verification for corporate entities

Get started via a simple self-onboarding process and try out iDenfy for free. For extra info and a more detailed dashboard tour, book a quick demo. 

Frequently asked questions

1

Can Businesses Block Identity Fraud by Country?

Arrow

Partly. Some identity verification service providers like iDenfy use custom workflows, offering built-in no-code options to create internal blocklists and rules to detect and prevent certain countries and their users from onboarding entirely. For example, you can reject users from sanctioned jurisdictions due to geography-specific risk.

2

How Do Users Try to Bypass Liveness Checks Using Screens?

Arrow
3

How Do Industry-Specific Risks Affect the Geography of Identity Fraud?

Arrow
4

Which Region Has the Highest Rate of Identity Fraud?

Arrow
5

What are the Most Common Identity Fraud Indicators in the US vs. EU?

Arrow

Save costs by onboarding more verified users

Join hundreds of businesses that successfully integrated iDenfy in their processes and saved money on failed verifications.

Image of salesmens
X