← Work Output Research Report

Research Report · Document Fraud

Forged ID & proof of address: a global review

Identity fraud volume fell in 2025. That is not good news. The rate dropped because the cheap attacks stopped working — and the actors who remain are considerably better at this than the ones who left.

Prepared by Jeremy Martin Tapia Period 2023 – 2026 Type Secondary research / desk review
The headline, in four numbers
2.2%
Global identity fraud rate, 2025 — down from 2.6%
180%
Rise in sophisticated fraud vs. 2024
$50B+
Projected global cost of identity fraud, 2025
30%
Of ID fraud cases now synthetic identity

01Executive summary

Across the reporting period, the global identity fraud rate moved from 2.0% (2023) to a peak of 2.6% (2024), then eased to 2.2% in 2025. Read alone, the 2025 decline looks like a win for the control environment. Read alongside the quality data, it reads very differently: sophisticated fraud rose 180% year over year as stronger verification made low-skill attempts uneconomic.

The pattern is a market being priced out at the bottom, not shut down. Fewer attempts, each costing the attacker more and carrying a higher expected payout. For review teams, that means the same headline pass rate now conceals a meaningfully harder caseload.

The rate fell. The difficulty didn't.

2.0%
2023 fraud rate
2.6%
2024 — the peak
2.2%
2025 — looks like a win
+180%
…but sophistication rose this much

Rings are scaled for comparison, not to a shared axis — the first three show the fraud rate ×10; the fourth shows the sophistication increase.

Key finding

A falling fraud rate paired with a rising fraud quality is the signature of effective controls, not diminishing risk. Teams that report only the rate will read this period as improvement and under-resource review capacity going into the next one.

02Methodology & limitations

This is a desk review of published industry and institutional reporting, not primary research. Figures are drawn from vendor fraud reports (Sumsub, Regula, Entrust), institutional analysis (World Economic Forum), and regulatory enforcement records.

Three limitations are worth stating plainly, because they shape how far these numbers can be pushed:

03Sector exposure

Exposure concentrates where the payoff justifies the effort. Financial services and mobility lead — both combine an account or asset worth taking with a mandatory identity gate at onboarding.

Financial Services 24.6%
Mobility & Transportation 23.5%
Gaming 18.6%
Employee background screening 10.6%

Share of identity documents found tampered or counterfeit, by sector. Source: Regula.

04Proof of address: the soft underbelly

Identity documents get the attention and the security engineering. Proof of address gets neither — and that asymmetry is now the story. A passport is a hardened artefact with optical security, encoded data, and an issuing authority. A utility bill is a PDF.

Sumsub tracked a 73% year-over-year rise in document forgery, with utility bills and bank statements accounting for the majority of detected fakes. Proof-of-address fraud attempts rose a further 18% year over year in H1 2025, with synthetic addresses making up 42% of all high-risk cases.

73%
YoY rise in document forgery — mostly bills & statements
18%
YoY rise in POA fraud attempts, H1 2025
42%
Of high-risk cases are synthetic addresses
$5–20
Cost to buy a forged bill — the attacker's entire outlay

A passport is a hardened artefact with optical security, encoded data, and an issuing authority behind it. A utility bill is a PDF.

The economics, plainly

Template-spoofing services price a custom-filled PDF utility bill or bank statement at roughly $5–$20. Against an account worth four or five figures, the attacker's cost of entry rounds to zero. No amount of ID hardening compensates for an address gate that cheap to clear.

Attack path How it works Why it clears review
Template spoofing Purpose-built PDF generated from a cloned issuer template Visually correct; no issuer to call and verify against
Genuine-document reuse Real bills obtained via phishing, breach, or theft, submitted by another party The document is authentic — only the claimant is wrong
Edited originals A real bill with name or address fields altered Genuine substrate and layout; only the edited field betrays it
AI-generated statements Wholly synthetic bank statements or tax letters Internally consistent; defeats plausibility-only review
Synthetic address Address that does not correspond to a real serviceable residence Passes format validation; fails only against a real address dataset

The regulatory consequence is not theoretical. The UK's Financial Conduct Authority fined Monzo £21m for KYC failures that included accepting implausible customer addresses — among them Buckingham Palace, 10 Downing Street, and Monzo's own London headquarters. The controls didn't fail to catch a sophisticated forgery. They failed to check whether an address was real.

05The AI inflection

AI-assisted document forgery went from effectively 0% of detected fakes in 2024 to 2% in 2025. Two percent is small. The trajectory is not — this is the first period in which the category registers at all.

The biometric channel is further along. Deepfakes now account for roughly one in five biometric fraud attempts, and deepfake selfies rose 58% in 2025. The implication for document review is direct: liveness and selfie-match checks can no longer be treated as the backstop that catches what document review misses.

AI-forged docs — 2024 ~0%
AI-forged docs — 2025 2%
Deepfake share of biometric attempts ~20%

Note: bars are scaled relative to the largest value shown, not to a common 100% axis.

06Implications for review operations

Reading the period end to end, five things follow for anyone actually running a review function:

Stop reporting rate without quality

A falling fraud rate alongside a 180% rise in sophistication is not improvement. Pair every rate figure with a difficulty or category mix, or leadership will read the trend backwards and cut capacity.

Fund proof of address like it's the weak gate — because it is

ID documents are hardened; POA is a PDF that costs $5–$20 to fake. Verification investment that goes entirely into ID hardening leaves the cheaper door open.

Validate addresses against reality, not format

Synthetic addresses account for 42% of high-risk POA cases and pass format checks by construction. Only a real serviceable-address dataset catches them. Monzo's fine is what the alternative costs.

Treat "genuine document, wrong person" as a first-class case

Reuse of authentic documents defeats every authenticity check by design, because the document isn't the thing that's false. Reconciliation against the record has to be a required step, not the one skipped under volume pressure.

Retrain on the moving edge, continuously

A category went from 0% to 2% in twelve months. Any training program on an annual refresh cycle is, by construction, a year behind the attack surface.

Bottom line

The organisations most exposed in the next period are the ones that read 2025's falling rate as permission to relax. The volume left because the controls worked. It will come back the moment they don't.

Sources

  1. Sumsub — Identity Fraud Report 2025–2026 (global fraud rate, sophistication increase, AI-assisted forgery share, document forgery rise)
  2. Regula — Identity Fraud by Numbers: Trends, Insights & Threats (sector exposure figures)
  3. World Economic Forum — How identity fraud is changing in the age of AI
  4. Resistant AI — How to spot a fake proof of address (POA attack paths, template-spoofing pricing)
  5. Sumsub — Proof of Address: Accepted Documents, Verification Methods, and KYC Best Practices
  6. Entrust — 2026 Identity Fraud Report
About this piece: A portfolio sample demonstrating desk research, data interpretation, and executive-summary writing. All figures are from the published sources cited above and are reproduced as reported; the analysis, framing, and operational recommendations are my own. No employer data is included.