Fraud Rings Run on Reused Documents, New Industry Data Shows
New identity fraud data shows 65.68% of linked fraud attempts reuse forged documents, with one ring running 70 identities on 13 devices. What that means.

Identity fraud is not a crime of individuals anymore. New industry data released this week makes the industrial structure explicit: in Shufti's Identity Fraud Report 2026, drawn from verification checks processed across eleven industries in the first half of 2026, 65.68 percent of linked fraudulent attempts involved reused forged identity documents. The same assets, deployed again and again, across businesses that each judged them in isolation.
The report's most vivid finding is a single cluster: one fraud ring linked 70 identities across 13 devices, with one device anchoring 16 separate verification events. Every one of those identities may have looked plausible on its own screen. The fleet was only visible to anyone watching the connections.
For fraud teams, the numbers confirm what forensic practitioners have argued all year: the unit of modern fraud is the ring, and defenses that score sessions one at a time are fighting the wrong shape.
The ring economy in four numbers
Beyond document reuse, the report maps the infrastructure that binds rings together. Shared IP addresses connected 17.67 percent of linked fraud, and shared devices another 16.64 percent. Cross-border operations made up 2.01 percent of network fraud, and they move fast: the average gap between the same identity assets appearing in different countries was 9 minutes and 33 seconds, with the fastest observed interval at 38 seconds. No passport moves that quickly. Credentials traded across a ring do.
On the AI side, deepfake documents dominated, accounting for 80.10 percent of AI-enabled attacks, ahead of synthetic identities at 12.31 percent, injected videos at 4.01 percent, and face swaps at 3.58 percent. The generative wave has concentrated on the artifact businesses check least rigorously: the document image itself.
Why single-session checks keep losing
A reused forged document is, by definition, a document that has already passed somewhere. Each business that verified it in isolation added a false clean record to the asset's history. The ring's economics depend on exactly this: manufacturing one convincing kit is expensive, but replaying it across dozens of targets is nearly free, and every target that judges sessions independently resets the attacker's odds.
The countermeasure is correlation. Document fingerprinting spots the same forged asset across attempts, device intelligence links the personas sharing hardware, and velocity analysis flags the 38-second country hop no human can perform. deepidv's provenance layer runs those checks against a continuously growing forensic index, so the 70th identity from a 13-device ring is met with the accumulated evidence of the previous 69. Luna then turns the cluster into a single case narrative instead of 70 unrelated files.
The sector spread tells its own story
The report's industry fraud rates rank digital assets first at 22.49 percent, then fintech at 18.36 percent, forex at 17.18 percent, lending and investment at 17.08 percent, and iGaming at 12.45 percent, with traditional banking lowest at 4.24 percent. The gradient is not random: it tracks how quickly value can be extracted and how young each sector's verification stack is. Rings are rational actors moving toward the softest well-funded targets.
The banking number carries the lesson. Decades of layered controls, shared intelligence, and regulatory pressure pushed banking's rate to a fifth of the digital asset sector's. Every younger vertical is now speedrunning the same curve, and the ones adopting fleet-level detection first will compress it fastest.
Fraud Ring FAQ
- What is an identity fraud ring?
- An identity fraud ring is an organized group that manufactures or acquires identity assets, forged documents, synthetic identities, deepfake media, and deploys them across many businesses using shared devices, infrastructure, and playbooks. Rings profit from reuse: one convincing identity kit is replayed against dozens of targets.
- How common is document reuse in fraud?
- Very. In identity checks processed across eleven industries in the first half of 2026, 65.68 percent of linked fraudulent attempts involved reused forged documents, making reuse the single strongest connector between related fraud events, ahead of shared IP addresses and shared devices.
- Which industries have the highest identity fraud rates?
- Per the 2026 data: digital assets at 22.49 percent, fintech at 18.36 percent, forex at 17.18 percent, lending and investment at 17.08 percent, and iGaming at 12.45 percent. Traditional banking sits at 4.24 percent, reflecting decades of layered defenses.
- How do businesses detect fraud rings rather than single attempts?
- By correlating across sessions: fingerprinting documents so a reused forgery is recognized on sight, linking personas that share devices or infrastructure, and flagging impossible velocity such as the same assets appearing in two countries minutes apart. Platforms with a persistent forensic index meet each new attempt with the ring's full history.
- Are deepfakes used more for documents or faces?
- Documents, by a wide margin. Deepfake documents accounted for 80.10 percent of AI-enabled fraud attacks in the 2026 data, versus 12.31 percent for synthetic identities, 4.01 percent for injected videos, and 3.58 percent for face swaps.
Relevant Articles
iGaming Fraud Hits 12.45% as Age Verification Lags
The ring economy's arrival in player verification.
Sep 11, 2026
Sub-150ms Attestation Moves Verification to the Client Edge
Device signals that expose shared hardware.
Sep 4, 2026
KPMG Buys Into Deepfake Detection as Testing Labs Multiply
The market maturation behind the fraud data.
Sep 14, 2026
What is deepidv?
Not everyone loves compliance — but we do. deepidv is the AI-native verification engine and agentic compliance suite built from scratch. No third-party APIs, no legacy stack. We verify users across 211+ countries in under 150 milliseconds, catch deepfakes that liveness checks miss, and let honest users through while keeping bad actors out.
Learn More