Identity fraud continues to account for the largest share of cases, representing 54% of all filings, followed by misuse of facility at 24% and facility takeover at 18%.
Together these are the driving forces behind the latest overall rise, with particularly high levels of account takeovers against telco products and the growing misuse of bank accounts.
While the overall increase was modest (+1%), the underlying movements and filing patterns point to continued changes in criminal tactics and focus against different products and sectors.
Sustained increases in identity fraud (+9%) and account (facility) takeover (+5%) are likely to be key drivers of another record year for fraud risk filings in 2026. Growth in both categories was particularly evident across online retail and plastic card products, highlighting the continued exploitation of compromised personal and account data.
Criminals are also using increasingly sophisticated social engineering techniques to target UK individuals and businesses, harvest personal information and gain access to accounts. One example is SIM swap fraud, which reached record levels in the first half of 2026, increasing by 402%.
Although identity fraud fell overall, five sectors reported increases compared with 2024. The biggest rises were in bank accounts (+5,372 cases, +10%) and insurance (+3,355 cases, +26%). Within banking, personal instant and easy-access accounts saw a dramatic 455% rise (+7,131 cases), suggesting threat actors are shifting towards the targeting of basic banking products using stolen or synthetic identities. In insurance, increases continue to be driven by motor insurance, which is up 26% year-on-year.
Plastic cards remain the most affected sector, accounting for 36% of all identity fraud. Personal credit cards are overwhelmingly the main target of these, representing 92% of filings. Communications and online retail are also significant, together making up 33% of all identity fraud cases.
Victims of impersonation are older with those over 61 most commonly targeted. Filings in relation to this age group rose by 13%, representing 29% of all cases. Those aged 51–60 follow at 21%. Identity fraud involving victims under 21 increased by 8%, linked to the greater willingness among younger people to share personal information online.
Our assessment indicates that online fraud will continue to become more sophisticated, supercharged by AI-powered impersonation, synthetic media, and accessible fraud‑as‑a‑service tools that are likely to ensure identity fraud and account takeover remain major threats. The use of synthetic identities is becoming industrialised, with criminals building convincing long-term profiles that blur the lines between real users and AI-generated imposters. At the same time, more individuals are selling or sharing their identity documents under financial strain, creating increased opportunities for misuse.
Plastic cards and bank accounts continue to account for the majority of identity fraud filings, collectively representing 68% (88,129) of cases (previously 64%).
The loans sector saw a 49% (+3,484) increase in filings and now accounts for 8% of identity fraud cases (previously 6%). This uplift was largely driven by personal loans with deferred credit (+133%), which allow customers to access credit immediately while delaying repayments until a later date.
Telecoms sector filings decreased by 28%, down to 9,055 cases, primarily due to lower volumes recorded against mobile phone products. However, previous analysis suggests reductions in telecoms filings may, in part, reflect a shift towards account takeover activity rather than a genuine reduction in the threat.
Impersonation, using the victim’s current address, remains the leading filing reason and increased by 12% compared to the same period in 2025. This aligns with wider intelligence showing that criminals have access to large volumes of personal information and are using increasingly convincing social engineering tactics to exploit targets.
False identity filings decreased by 35%, largely across telecoms and bank account sectors. Despite this, intelligence continues to indicate growing concerns around synthetic identities, AI-enabled impersonation and digitally manipulated documentation.
Victims aged 21–30 recorded the largest increase in identity fraud cases (+32%), largely linked to personal credit cards.
The bank account sector continues to be the main source of misuse filings (82% of cases), rising 44% in 2025 - driven largely by a 35% increase in filings in relation to personal current accounts. Payment fraud is now the largest category in this sector, accounting for 31% of filings, up from 20% in 2024.
Increasing bank account misuse reflects the evolving recruitment tactics of fraudsters, with victims encouraged to pass on funds or share banking details. In some cases, personal information is being sold to criminal networks to support account opening and misuse.
Overall, payment fraud rose 239% during 2025 and now makes up 40% of all misuse filings, mainly driven by personal current accounts and credit cards. Evasion of payment is also up 22%, linked to high volumes of loan, asset, and credit card applications with no intent to repay.
Additionally, misuse cases in the communications (which includes telecoms) sector rose 106% in 2025, mainly due to mobile phone filings linked to evasion of payment. Although driven by a small number of members, this may signal a shift towards customers avoiding payment for everyday items.
1 Cifas’ research points to an increasing societal acceptance of first-party fraud, this is reflected in member data which also shows increases in both payment evasion and broader account misuse. Misuse of personal money transfer accounts also increased +43%, suggesting criminals are expanding into other account types to avoid detection.
The bank account sector continues to represent the highest proportion of filings (77%, previously 82%). However, when combined with payment fraud, these categories still declined by 28% overall.
Despite the overall reduction in bank account filings, this product had noteworthy increases in ‘falsely reporting a loss’ (+189%) and ‘fraudulent direct debit guarantee claims’. Against a backdrop of growing evidence1 around the normalisation of first-party fraud, these increases may indicate a rising willingness to misuse banking products.
Misuse of company accounts increased by 20%, with several members reporting heightened levels of behaviours indicative of money muling (+85%) and payment fraud (+223%). Members continue to express concern around the use of corporate structures to obtain business banking facilities which can then be misused.
Around one in twelve (8%) misuse of facility cases now relate to the plastic card sector which recorded more than 3,500 filings (+13%). The vast majority (90%) involved personal credit cards, with volumes increasing by over a third. This growth was driven by higher levels of payment fraud, evasion of payment, and 'funds received – money muling’.
Increases in ‘theft of asset’ filings (+35%) were apparent, relating to asset finance products (+35%). These trends raise concerns of an enduring threat of individuals intentionally acquiring high-value products (for example mobile phones and vehicles), with no intention of paying. This presents a major challenge for institutions to predict when a product is likely to be misused.
Cases primarily involved personal bank accounts, which accounted for 89% of money muling filings, as well as business bank accounts, which comprised 4% in 2025. This newly introduced Cifas filing category now enables muling activity to be more reliably tracked across an expanding range of facilities, such as personal credit cards, pre-paid cards and money transfer accounts.
The rising misuse of bank accounts reflects some of the many ways individuals receive fraudulent funds or give away their banking details.
Intelligence indicates that some people are actively selling their personal information to criminal networks, allowing them to construct credit profiles using some or all of that data and open accounts for illicit use.
Concerningly, 35% of Gen-Zs surveyed by Cifas have said they would transfer money to a stranger for a fee1. Although this group poses a risk, a high proportion of offboarded customers are aged 30–39, with increases also seen in those aged under 16, highlighting the need for impactful messaging to all. Separately, Cifas research also shows a fifth of individuals don’t believe that money muling is illegal, highlighting a lack of knowledge and understanding of the significant risks involved.2
intelligence from Cifas members highlights muling as a persistent threat, with diverse recruitment tactics ranging from job scams to customers receiving overpayments when selling items via online marketplaces. Social media is a key channel for luring new mules and advertising ‘quick money’ schemes. Although greater awareness might lead to criminals changing fraudulent techniques, recruitment tactics are predicted to remain focused on mimicking employment or business opportunities.
This increase is likely to reflect greater adoption of the newly introduced filing reason released in 2025 – ‘funds received – money muling’, alongside members using enhanced detection capabilities. Both have led to greater visibility and tracking of mule activity with over 14 different products filed by members. Overall, this helps to demonstrate that money muling is not confined to traditional bank accounts and is increasingly impacting a wider range of financial facilities.
Notable increases also occurred in company current accounts (+67%) and personal credit cards (+146%). There were also consistent volumes across pre-paid cards, personal money transfer accounts and savings accounts.
Further increases in mule-related cases are expected throughout 2026 as adoption of the new filing category continues to grow. This enhanced visibility will also enable a more accurate assessment of how the threat is evolving, and which age groups are most susceptible to recruitment.
Overall, the highest proportion of subjects fell within the 21–30yrs age category, accounting for 40% of filings, unchanged from 2025. This age group also recorded the largest rise in volume (+73%), followed by 31-40yrs (+75%) which accounts for one-quarter of cases (24%) overall.
These trends highlight the continued vulnerability of younger individuals to exploitation by criminal networks engaged in money mule activity. Importantly, increases in filings were observed across all age groups, showing the threat is not confined to younger demographics alone.
The telecommunications sector recorded the greatest volume of account takeover cases. It now accounts for the majority of such cases (62%, previously 48%), driven by the sustained rise in mobile phone-related filings.
The leading filing reason for account takeover in 2025 was ‘unauthorised addition of facility’ and ‘unauthorised security/personal details change’, with filings predominantly relating to mobile phones, online retail, and personal credit cards.
There has been a notable rise in unauthorised SIM swaps (+38%). This increase appears to be driven by the growing availability of stolen personal data, and the use of more automated methods for compromising accounts.
Victims aged 61 and above are the most frequently targeted age range, accounting for 31% of cases, with filings in relation to this age group up 10% compared with 2024.
Criminals are exploiting AI to enhance malicious communications and automate large-scale credential attacks, contributing to the rising threat of takeovers. Techniques such as hyper-personalised scams, deepfake audio targeting call centres and SIM hijacking are becoming more prevalent, enabling attackers to bypass authentication processes and mimic legitimate login behaviour, making unauthorised access harder to detect.
As methods become more advanced, SIM swap attacks are expected to continue rising, fuelled by widespread reliance on mobile-based authentication. Account takeovers are also becoming more integrated into multichannel operations, where criminals combine and enrich stolen data to maximise impact and financial return. As organisations strengthen their defences, attackers are increasingly focusing on stealth – disabling customer alerts, flooding inboxes, spoofing devices, and slowly altering profile details to blend malicious behaviour with normal user activity.
Despite the reduction in filings, the telecoms sector continues to account for 51% (20,214) of all account takeover cases. Previous analysis assessed that mobile phone-related takeover activity remains a significant threat, particularly through organised mobile dealer fraud and SIM swap activity. The reduction may reflect changes in reporting patterns, prevention controls, or focus into other targeted products rather than a substantive reduction in threat.
Online retail filings now account for 24% of all cases (previously 14%). This increase is consistent with intelligence highlighting the growing value of compromised online retail accounts.
The plastic cards sector rise is driven largely by personal credit cards (+66%). This supports wider intelligence that threat actors continue to prioritise products such as credit cards offering immediate spending power, with compromised card accounts remaining a valuable commodity for organised groups.
‘Unauthorised SIM swap’ cases increased by 402% (+4,109) and now represent 10% of all filings (previously 2%). This reflects a trend repeatedly identified where SIM swaps are used to intercept authentication codes, bypass security measures, and facilitate wider account compromise.
'Unauthorised facility delivery instruction’ filings increased by 111% (+3,948), driven primarily by the online retail sector (+114%). This increase may indicate the continued targeting of customer accounts to redirect deliveries and obtain high-value goods.
Individuals aged 61+ remained the most targeted, accounting for 29% of cases despite a 7% decline overall. Increases in online retail (+93%), plastic cards (+29%) and bank accounts (+11%) suggest older consumers remain particularly vulnerable to social engineering attacks and account compromise. The 41–50 age group rose following a 17% increase in filings, driven by growth in online retail (+104%), plastic cards (+85%).
In 2025, 65% of false applications were received through online channels, down from 80% in 2024. This reduction is mainly due to a rise in false mobile app applications. The trend indicates a shift towards app‑based application methods, particularly in banking.
The bank account sector was the largest source of false applications (38% in 2025), though numbers have still fallen. Undisclosed adverse addresses were the most common filing reason, accounting for 46% of cases (up from 40%). In contrast, false document filings for personal current accounts decreased by 41%, reflecting reports from members around improved controls and greater investment in fraud detection tools.
The insurance sector recorded a 30% drop in filings, following unusually high volumes in 2024. This was mostly driven by the reporting of fewer cases from a small number of members.
Members reported that false applications are still a major concern. Although often seen as a ‘victimless’ crime, first-party frauds such as these are becoming more common, contributing to rising prices and premiums. Independent Cifas research1 also shows a growing social acceptance of this behaviour. An example of this is the increase in filings relating to tenant referencing which increased by 263% driven by false and altered documents.
Those aged 25–342 are most likely to engage in first-party fraud, with behaviour driven by cost-of-living pressures, uncertainty at what constitutes fraud, and greater exposure to advertising and malicious content offering unrealistically attractive deals and rates.
Cifas members also reported widespread income and affordability manipulation, supported by realistic fake document websites. Risks are further heightened by AI-enabled document forgery and unregulated brokers posing as ‘application helpers’, with some fake documents reused repeatedly across multiple applications.
Those aged 21–30 accounted for the majority of false application filings (34%, previously 36%), followed by those aged 31–40 (33%, previously 32%). Changes within these age groups are linked to reductions in motor insurance filings, although ‘personal unsecured loan’ cases increased.
Most sectors saw a decrease, including insurance (down 58%), bank accounts (down 23%) and asset finance (down 28%). Altered or false documents accounted for the largest reductions across these sectors.
Despite the decreases, bank accounts, loans and asset finance continue to experience issues involving false documents, including false bank statements, wage slips and identity documents that support applications.
‘Dishonest action by staff to obtain a benefit by theft or deception’ is the most common case type and again accounts for the largest share of filings made to the ITD. Volumes increased by 28%, rising from 116 to 148. It now accounts for 48% of all cases. The most frequent filing reasons were abuse of company time or privilege (15%), false expenses submissions (13%), and theft of IT equipment (11%).
Internal controls and audits uncovered 45% of dishonest behaviour, with staff reporting responsible for a further 21%, highlighting the critical role of employee awareness and speak-up cultures.
‘False employment application – unsuccessful’ was the next highest volume and saw a notable increase on 2024 (+25%). As fraudulent job applications continue to rise, this underscores the need for strong pre-employment screening to stop unsuitable or high-risk individuals entering organisations. The most common issues were hidden adverse credit history (40%), followed by concealed employment history (20%) and concealed employment records (15%). Although formal filings remained steady, intelligence reports on false references increased, often driven by reference houses selling fake work histories or training certificates —allowing candidates to bypass vetting and gain access to sensitive data.
Employee dishonesty is increasingly centred on abuse of company time and privilege. Although multiple/dual working is a growing risk area, interest in tackling it – especially in the private sector – is also growing. The rise of such social media-driven ‘overemployment’ contributes to performance issues, conflicts of interest, and potential data security risks.
Employees are also seeking to supplement income through a wide range of dishonest methods. This is reflected in more than 24 categories of filings – from inflated expenses to manipulation of reward schemes. As some organisations broaden staff benefits with only limited controls, there is a high likelihood these perks –such as staff discounts or loyalty rewards – will be exploited or resold for financial gain.
Online insider approaches, often disguised as legitimate networking on platforms like LinkedIn, are a growing blind spot for organisations. Those holding large volumes of personal data, including telecoms and banks, may be particularly exposed.
Within the ‘dishonest action’ case type, there are a variety of filing reasons, including abuse of company time/privilege, false expenses, false overtime, falsifying documents, account manipulation and theft-related behaviours. This supports the wider assessment that employees may be seeking to supplement their income through dishonest conduct.
Cases of ‘false employment application – successful’ more than doubled, increasing from nine cases in 2025 to 19 in 2026 (+111%). Although volumes remain lower than unsuccessful applications, this rise is important as it indicates a greater number of individuals with concealed or false information may have progressed into employment, before being identified.
‘False employment application – unsuccessful’ cases decreased from 49 in 2025 to 36 in 2026 (-27%). This could be an indication of improved pre-employment detection or lower reporting volumes. However, it should not be interpreted as a reduced threat given the increase in successful false employment application cases overall.




















The Fraudscape six-month update is a comprehensive analysis of cases recorded by Cifas members to the National Fraud Database (NFD) and Insider Threat Database (ITD) in the first half of 2026, with comparisons to the same period in 2025.
More than 220,000 cases were filed to the NFD between January and June 2026. While this represents a modest 1% increase (+2,624 cases), it is the highest number ever recorded during the first six months of a year and suggests filing levels are on track to surpass the record volumes seen in 2025.

The increase was primarily driven by the plastic cards sector, which saw a 33% rise in filings (+14,955), largely linked to personal credit cards.

Despite this decline, misuse of facility remains a significant contributor to the NFD, accounting for around one-fifth of all cases filed, meaning it ranks in second place behind identity fraud.

Between January and June 2026, over 13,000 cases were filed to the NFD indicative of money mule activity – a rise of 69% compared to 2025.
Money mule cases now account for 30% of all misuse of facility cases (previously 15%) with over 40 unique members filing cases.

Filings relating to account takeover increased by 5% (+1,729) to 39,878 cases compared to the same period in 2025.
Together, the telecom and online retail sectors account for 75% of recorded account takeover cases – though levels of telecoms filings dropped by 23% compared to the same period in 2025. Online retail filings and plastic card filings increased by 84% (+4,350) and 59% (+2,188), respectively.

The first six months of 2026 saw a 26% decrease in false application filings compared with the same period in 2025, with just over 6,300 cases reported.
Loan filings increased by 33%, driven by rises in 'personal unsecured loans’ and ‘company unsecured loans’, particularly where altered or false documents were supplied. This correlates with reports from members who highlight the increasing sophistication and quality of documents submitted that support applications and are facilitated by AI.

Cases filed to the ITD dropped by 3% to 143 cases in 2026, compared to 148 in the same period in 2025.
‘Dishonest action by staff to obtain a benefit by theft or deception’ is the dominant case type, increasing from 68 cases to 76 in 2026 (+12%). It now accounts for 53% of all filings, up from 46% in 2025.
Welcome to Fraudscape 2026. It provides a comprehensive assessment of fraud risk in the UK, drawing on data filed by Cifas members to the National Fraud Database (NFD) and Insider Threat Database (ITD) in the twelve months to December 2025, alongside intelligence from members, partners and law enforcement.
Taken together, the data from these sources present a clear and compelling picture of the scale, complexity and evolving nature of the fraud threat. They highlight both the pressures facing the fraud prevention community today and the emerging threat vectors that demand sustained focus and collective action.
The headlines are sobering. In 2025, a record 444,993 cases were filed to the NFD, including more than 242,000 cases of identity fraud. Although identity fraud filings fell by 3% year-on-year, it is still the most common case type, accounting for over half of all reports. This modest reduction is accounted for by a shift in criminal tactics rather than a reduction in harm, with fraudsters increasingly targeting account takeovers, particularly via mobile phones.
The threat from fraud is also global and organised, with criminal gangs now mimicking the size and structures of large corporations. Scam factories in West Africa and South-East Asia house thousands of enslaved workers in appalling conditions, criminalising the vulnerable and economically insecure, forcing them to build and operate a sophisticated infrastructure of call centres and websites intended for the sole purpose of stealing people’s money.
Fraud now accounts for almost 44%1 of all crime reported in England and Wales and is estimated to cost the UK economy £219 billion2 each year, including up to £81 billion in losses to the public sector. Consumers lost £9.4 billion3 to scams in 2024 alone, with those aged 61 and over remaining most at risk of identity fraud and account takeover.
Fraud is also increasingly digital. Four in five scams are now digitally enabled, with criminals moving seamlessly across platforms, services and technologies. It is global and highly organised, with networks operating at scale and exploiting both technology and human vulnerability.
Our assessment suggests that online fraud will become ever more sophisticated, supercharged by AI-powered impersonation, synthetic media, and accessible fraud-as-a-service tools that are likely to ensure that identity fraud and account takeover remain major threats. Synthetic identities are becoming industrialised, with criminals building convincing long-term profiles that blur the lines between real users and AI-generated imposters. At the same time, more individuals are selling or sharing their identity documents under financial strain, creating increased opportunities for misuse.
While this year’s Fraudscape report shows that progress is being made, it also underlines the scale of the challenge that remains. Through the use of Cifas’ products and services, our members prevented more than £2.4 billion in fraud losses last year. But no organisation can tackle fraud alone. It is only through effective collaboration and the sharing of data and intelligence that we can stay ahead of increasingly sophisticated criminals. This is why Cifas exists.
We hope this report provides valuable insight into the evolving fraud landscape. By working together, I hope we can use this report as the catalyst for action, to strengthen defences, deepen collaboration and collectively take the fight to the criminals.

In 2025, over 444,000 cases were filed to the National Fraud Database. This is a record number of cases (+6%) and continues the upward trend seen in 2024.

Identity fraud fell by 3% compared to 2024, with the largest drop in cases seen in the telecoms sector (-24%). However, this decline reflects a shift in criminal tactics rather than a genuine reduction in harm, as threat actors increasingly move towards account takeovers, particularly targeting mobile phone accounts. Despite the decrease, identity fraud is the most common filed case type, making up 54% of all NFD filings.

In 2025, over 106,000 cases of misuse of facility were recorded to the NFD – a 43% increase on 2024. Of the members that filed in both 2024 and 2025, 54% observed a rise. The majority of these filings involve significant incidents of bank account misuse.

In 2025, more than 22,000 incidents of money muling were reported to the NFD, following the introduction of a new money mule filing category ‘Funds received - money muling’.
In 2025 Cifas introduced a more specific filing category to simplify recording practices for our members and improve insight on this threat.

Over 78,000 account (facility) takeover cases were reported in 2025, a rise of 6% compared to 2024. This has been driven primarily by a significant increase in filings from the telecommunications sector (+38%).
Cases linked to mobile phone products dominate, followed by online retail and personal credit cards. Collectively, these products account for 90% of all account takeover filings. Nearly 1 in 5 (18%) of all fraud-risk cases reported to the NFD are now account takeovers.

Over 16,000 cases of false application were recorded to the National Fraud Database in 2025, a 24% fall on 2024.
Reductions were observed across many sectors, with the largest decline in relation to bank account cases (‑27%). Among those Cifas members who submitted cases in both 2024 and 2025, the majority (55%) reported a decrease. Filings continue to be concentrated in motor insurance and personal bank accounts, which together account for 62% of all cases.

In 2025, 288 subjects were filed to the Insider Threat Database (ITD)– a 21% increase on 2024.
‘Dishonest action by staff to obtain a benefit by theft or deception’ is most common case type and again accounts for the largest share of filings made to the ITD.
We protect individuals and organisations from fraud and financial crime
We are a not-for-profit membership organisation that brings different sectors together for the common goal of eliminating fraud and financial crime. Over 775 organisations work with us, all benefiting from each other's data, intelligence and learning - using the cutting edge financial crime prevention systems and tools we develop and deliver. For over 35 years we have been trusted by our partners to provide them with the systems and tools they need to detect and prevent fraud and financial crime, saving them billions of pounds in prevented losses.