Research Report · Document Fraud
Forged ID & proof of address: a global review
Identity fraud volume fell in 2025. That is not good news. The rate dropped because the cheap attacks stopped working — and the actors who remain are considerably better at this than the ones who left.
01Executive summary
Across the reporting period, the global identity fraud rate moved from 2.0% (2023) to a peak of 2.6% (2024), then eased to 2.2% in 2025. Read alone, the 2025 decline looks like a win for the control environment. Read alongside the quality data, it reads very differently: sophisticated fraud rose 180% year over year as stronger verification made low-skill attempts uneconomic.
The pattern is a market being priced out at the bottom, not shut down. Fewer attempts, each costing the attacker more and carrying a higher expected payout. For review teams, that means the same headline pass rate now conceals a meaningfully harder caseload.
The rate fell. The difficulty didn't.
Rings are scaled for comparison, not to a shared axis — the first three show the fraud rate ×10; the fourth shows the sophistication increase.
A falling fraud rate paired with a rising fraud quality is the signature of effective controls, not diminishing risk. Teams that report only the rate will read this period as improvement and under-resource review capacity going into the next one.
02Methodology & limitations
This is a desk review of published industry and institutional reporting, not primary research. Figures are drawn from vendor fraud reports (Sumsub, Regula, Entrust), institutional analysis (World Economic Forum), and regulatory enforcement records.
Three limitations are worth stating plainly, because they shape how far these numbers can be pushed:
- Detection bias. Every figure here measures detected fraud. Undetected forgeries are, by definition, absent from the dataset. Rates therefore track detection capability as much as attacker activity.
- Vendor sampling. Much of the data originates with verification vendors, whose customer mix skews toward sectors that already invest in verification. Under-controlled sectors are likely under-represented.
- Definitional drift. "Sophisticated," "synthetic," and "AI-assisted" are not standardised across publishers. Cross-vendor comparison is directional, not exact.
03Sector exposure
Exposure concentrates where the payoff justifies the effort. Financial services and mobility lead — both combine an account or asset worth taking with a mandatory identity gate at onboarding.
Share of identity documents found tampered or counterfeit, by sector. Source: Regula.
04Proof of address: the soft underbelly
Identity documents get the attention and the security engineering. Proof of address gets neither — and that asymmetry is now the story. A passport is a hardened artefact with optical security, encoded data, and an issuing authority. A utility bill is a PDF.
Sumsub tracked a 73% year-over-year rise in document forgery, with utility bills and bank statements accounting for the majority of detected fakes. Proof-of-address fraud attempts rose a further 18% year over year in H1 2025, with synthetic addresses making up 42% of all high-risk cases.
A passport is a hardened artefact with optical security, encoded data, and an issuing authority behind it. A utility bill is a PDF.
Template-spoofing services price a custom-filled PDF utility bill or bank statement at roughly $5–$20. Against an account worth four or five figures, the attacker's cost of entry rounds to zero. No amount of ID hardening compensates for an address gate that cheap to clear.
| Attack path | How it works | Why it clears review |
|---|---|---|
| Template spoofing | Purpose-built PDF generated from a cloned issuer template | Visually correct; no issuer to call and verify against |
| Genuine-document reuse | Real bills obtained via phishing, breach, or theft, submitted by another party | The document is authentic — only the claimant is wrong |
| Edited originals | A real bill with name or address fields altered | Genuine substrate and layout; only the edited field betrays it |
| AI-generated statements | Wholly synthetic bank statements or tax letters | Internally consistent; defeats plausibility-only review |
| Synthetic address | Address that does not correspond to a real serviceable residence | Passes format validation; fails only against a real address dataset |
The regulatory consequence is not theoretical. The UK's Financial Conduct Authority fined Monzo £21m for KYC failures that included accepting implausible customer addresses — among them Buckingham Palace, 10 Downing Street, and Monzo's own London headquarters. The controls didn't fail to catch a sophisticated forgery. They failed to check whether an address was real.
05The AI inflection
AI-assisted document forgery went from effectively 0% of detected fakes in 2024 to 2% in 2025. Two percent is small. The trajectory is not — this is the first period in which the category registers at all.
The biometric channel is further along. Deepfakes now account for roughly one in five biometric fraud attempts, and deepfake selfies rose 58% in 2025. The implication for document review is direct: liveness and selfie-match checks can no longer be treated as the backstop that catches what document review misses.
Note: bars are scaled relative to the largest value shown, not to a common 100% axis.
06Implications for review operations
Reading the period end to end, five things follow for anyone actually running a review function:
Stop reporting rate without quality
A falling fraud rate alongside a 180% rise in sophistication is not improvement. Pair every rate figure with a difficulty or category mix, or leadership will read the trend backwards and cut capacity.
Fund proof of address like it's the weak gate — because it is
ID documents are hardened; POA is a PDF that costs $5–$20 to fake. Verification investment that goes entirely into ID hardening leaves the cheaper door open.
Validate addresses against reality, not format
Synthetic addresses account for 42% of high-risk POA cases and pass format checks by construction. Only a real serviceable-address dataset catches them. Monzo's fine is what the alternative costs.
Treat "genuine document, wrong person" as a first-class case
Reuse of authentic documents defeats every authenticity check by design, because the document isn't the thing that's false. Reconciliation against the record has to be a required step, not the one skipped under volume pressure.
Retrain on the moving edge, continuously
A category went from 0% to 2% in twelve months. Any training program on an annual refresh cycle is, by construction, a year behind the attack surface.
The organisations most exposed in the next period are the ones that read 2025's falling rate as permission to relax. The volume left because the controls worked. It will come back the moment they don't.
Sources
- Sumsub — Identity Fraud Report 2025–2026 (global fraud rate, sophistication increase, AI-assisted forgery share, document forgery rise)
- Regula — Identity Fraud by Numbers: Trends, Insights & Threats (sector exposure figures)
- World Economic Forum — How identity fraud is changing in the age of AI
- Resistant AI — How to spot a fake proof of address (POA attack paths, template-spoofing pricing)
- Sumsub — Proof of Address: Accepted Documents, Verification Methods, and KYC Best Practices
- Entrust — 2026 Identity Fraud Report