The 2026 deepfake statistics tell two stories at once. Deloitte’s Center for Financial Services projects that generative-AI-enabled fraud will cost the United States $40 billion by 2027, up from $12.3 billion in 2023, a compound annual growth rate of 32%. Entrust’s 2025 Identity Fraud Report found that a deepfake attempt occurred every five minutes in 2024, while the follow-up 2026 report links deepfakes to one in five biometric fraud attempts, with deepfaked selfies rising 58% in 2025.
Reading a decade of deepfake statistics research back-to-back, and against a growing body of primary-source cybersecurity threat data from 2025 and 2026, one pattern stands out: the loudest figures are the ones with no methodology attached. The deepfake statistics below all come from reports that publish sample sizes, cohorts, and dates. Where the picture is unflattering to a security vendor’s own product, we say so.
Key Takeaways
- Deloitte’s Center for Financial Services projects US generative-AI fraud losses will hit $40 billion by 2027, up from $12.3 billion in 2023, a 32% compound annual growth rate. Deloitte’s Center for Financial Services anchors the projection to a 2023 base of $12.3 billion.
- Sumsub’s Identity Fraud Report 2025-2026 measured +180% YoY growth in ‘sophisticated’ fraud, with the share of multi-step attacks rising from 10% (2024) to 28% (2025) of all identity fraud.
- The FBI’s Internet Crime Complaint Center, for the first time in its nearly 25-year history, features a section on artificial intelligence, which accounts for 22,364 complaints, costing Americans nearly $893 million.
- iProov’s Deepfake Blindspot Study found that only 0.1% of 2,000 surveyed consumers could accurately identify deepfake media.
- Regula’s Deepfake Trends 2024 survey found that in 2024, every second business globally reported deepfake fraud; 49% of companies experienced both audio and video deepfakes, up from 37% and 29% respectively in 2022.
- Injection attacks, the delivery vehicle for most enterprise deepfakes, targeted iOS devices with a 1,151% surge in H2 2025 alone. iProov reported injection attacks targeting iOS devices surged by 1,151% in the second half of 2025, contributing to a 741% annual increase.
- A September 2025 Gartner study found that 62% of organizations experienced a deepfake attack in the past year.
Editor’s Choice
- Entrust says its Onfido platform has prevented an estimated $5.5 billion in fraud while processing millions of verifications annually.
- The FBI’s IC3 receives nearly 3,000 complaints per day, escalating from 859,532 total complaints in 2024 to 1,008,597 in 2025.
- Sumsub analyzed 4,000,000+ fraud attempts between 2024 and 2025 across its verification network, blended with a 2025 Fraud Exposure Survey of 300+ risk professionals and 1,200+ end users.
- Digital document forgeries increased 244% year-over-year in 2024 and represent 57% of all document fraud, with national ID cards drawing 40.8% of document attacks globally.
- Native virtual-camera attacks, used to feed deepfakes into verification systems, surged 2,665% in a single year, alongside a 300% year-over-year rise in face-swap attempts.
- Cryptocurrency onboarding flows now account for 67% of fraud attempts targeting sign-up processes, a rate that dwarfs the SMB cybersecurity data baselines, with payments and digital-first banks seeing 82% and 55% respectively of authentication-stage account takeovers.
- iProov surpassed one million daily identity verifications in 2025, a scale that its founder attributes to enterprises reclassifying identity as their primary attack surface.
Deepfake-driven fraud losses at a glance
About This Data
The figures on this page come from ten primary-source studies published between November 2024 and April 2026. The publishers are the FBI, the World Economic Forum, Sumsub, Entrust, iProov, Regula, and the Deloitte Center for Financial Services. Every entry carries a publisher, a publication date, and, where possible, a sample size, and is refreshed when a new edition is published.
- Deloitte’s central projection puts US generative-AI-enabled fraud losses at $40 billion in 2027, up from $12.3 billion in 2023, a compound annual growth rate of 32%.
- The FBI’s IC3 reported nearly $21 billion in cyber-enabled fraud losses across 2025, with cryptocurrency and AI-related complaints among the costliest categories.
- Investment fraud remained the biggest single category, accounting for nearly 49% of all scam-related losses in 2025.
- Cryptocurrency complaints alone drove more than $11 billion in losses across 181,565 complaints in the IC3 dataset.
- Regula’s survey put average losses across industries at nearly $450,000 per company hit by deepfake fraud.
- Older Americans reported approximately $7.7 billion in losses to internet-enabled crime in 2025, up 37% from 2024, a demographic that maps closely onto voice-clone impersonation targets.
- Deloitte notes that generative-AI toolkits are now sold on dark-web marketplaces from $20 to thousands of dollars, collapsing the marginal cost of a deepfake attempt.
The Deloitte scenario is the only one that publishes a base year, a terminal year, and a 32% CAGR; every other figure below is a measured 2024 or 2025 observation, not a projection. Treat the $40 billion 2027 estimate as a scenario with clearly stated inputs, not a settled forecast; and the measured figures as the ground truth beneath it.
Attack volume and growth rates
- Entrust measured a deepfake attempt every five minutes in 2024 across the Entrust Onfido verification network.
- iProov’s 2026 Threat Intelligence Report recorded a 1,151% surge in injection attacks targeting iOS devices in the second half of 2025, contributing to a 741% annual increase.
- iProov’s prior 2025 report measured a 2,665% surge in native virtual-camera attacks and a 300% year-over-year rise in face-swap attempts across 2024.
- Sumsub reported +180% YoY growth in ‘sophisticated’ fraud, with the share of multi-step attacks rising from 10% to 28% of all identity fraud between 2024 and 2025.
- Regula’s global survey saw video-deepfake exposure rise from 29% of businesses in 2022 to 49% in 2024, a 20-point increase.
- Injection-attack volumes overall, the primary delivery vehicle for deepfakes into verification flows, rose 40% year-over-year in the Entrust 2026 dataset.
- Southeast Asia experienced a 720% spike in attacks in Q3 2025 per iProov, which the vendor characterises as a testing ground for emerging fraud techniques.
- Deloitte cites earlier vendor data that deepfake incidents increased 700% in fintech in 2023, an inflection year before the current wave of injection tooling matured.
| Attack vector or vendor cohort | Growth rate (% YoY) |
|---|---|
| iOS injection attacks, H2 2025 (iProov) | 1151 |
| Native virtual-camera attacks, 2024 (iProov) | 2665 |
| iOS injection attacks, annualized 2025 (iProov) | 741 |
| Southeast Asia attacks, Q3 2025 (iProov) | 720 |
| Fintech deepfake incidents, 2023 (Deloitte-cited) | 700 |
| Face-swap attempts, 2024 (iProov) | 300 |
| Digital document forgeries, 2024 (Entrust) | 244 |
| Sophisticated multi-step fraud, YoY 2024-2025 (Sumsub) | 180 |
| Injection attacks, YoY 2026 report (Entrust) | 40 |
Source: iProov Threat Intelligence Reports 2025 and 2026; Entrust 2025 and 2026 Identity Fraud Reports; Sumsub Identity Fraud Report 2025-2026; Deloitte Center for Financial Services
Why it matters: iProov’s 1,151% H2 2025 iOS injection surge matters less as a headline than as a directional signal, and the 741% annual figure is the durable one to plan against: the platform-as-safe-haven assumption is over. Attackers now industrialize deepfake delivery on whichever OS holds the identity, not whichever OS is easier to root.
Recent Developments
- April 2026: The FBI released its 2025 Internet Crime Report, adding artificial intelligence as a standalone tracked fraud category for the first time in the IC3’s nearly 25-year history.
- January 2026: The World Economic Forum published its Global Cybersecurity Outlook 2026.
- Entrust released its 2026 Identity Fraud Report.
- The FBI’s IC3 warned that scammers deploy fake social profiles, voice clones, identification documents, and believable videos depicting public figures or loved ones.
- A malicious deepfake video falsely depicting Irish presidential candidate Catherine Connolly announcing her withdrawal from the race sparked an official complaint to the Electoral Commission.
- Q4 2025: Sumsub reported the emergence of autonomous AI fraud agents.
Deepfake fraud by industry
- Sumsub’s 2025 verification-network data shows online media and dating at a 6.3% fraud rate, financial services at 2.7%, crypto at 2.2%, professional services at 1.6%, and video gaming at 1.6%.
- Entrust reports cryptocurrency sign-up flows face 67% of onboarding fraud attempts, the highest rate of any sector its network processes.
- Payments and digital-first banks see 82% and 55% respectively of account-takeover attempts targeting authentication.
- Regula’s cross-industry survey shows audio deepfakes dominate in Financial Services (51%), Aviation (52%), and Crypto (55%).
- Video deepfakes dominate in Law Enforcement (56%), Technology (57%), and FinTech (57%) per Regula’s cohort.
- The Sumsub top-five sector list reflects consumer-facing platforms with permissive KYC and high account-creation volume: dating, media, and financial services, in that order.
- 58% of businesses globally have experienced identity fraud in the form of fake or modified documents, a category that predates the deepfake wave but is now amplified by generative document tools.
Regional distribution of deepfake fraud
- Sumsub’s regional fraud rates over 2024-2025 show Europe down 14.6%, North America down 5.5%, Africa up 9.3%, APAC up 16.4%, and the Middle East up 19.8%.
- Country-level Sumsub rankings put Iraq at 9.7% (Middle East), Pakistan at 5.9% (APAC), Tanzania at 5.0% (Africa), Argentina at 3.8% (LatAm), Latvia at 3.7% (Europe), and the US at 1.4% (North America).
- Regula’s business-level survey highlights 56% of UAE businesses reporting video deepfakes and 56% of Singaporean businesses reporting audio deepfakes, well above the global mean.
- The lowest exposure in the Regula cohort was Mexico at 35% for video deepfakes and 38% for audio deepfakes.
- iProov identifies Southeast Asia as a testing ground for emerging fraud techniques, with a 720% attack spike in Q3 2025, a regional pattern echoed in the API breach statistics that vendors track alongside injection attacks.
- Money-mule recruitment is a broad exposure: one in four survey respondents were targeted for money-mule recruitment, with roughly 80% recognising the term but lacking clarity on its real legal and financial risks.
- Cambodia holds the highest ratio of approved applicants linked to fraud networks in APAC at 17% in Sumsub’s dataset.
Executive-targeted deepfake incidents
- Ponemon Institute data cited by iProov reports 41% of organizations have experienced deepfake attacks targeting executives.
- A September 2025 Gartner study found 37% of cybersecurity leaders have encountered deepfake incidents during video calls.
- A separate 2025 Gartner study cited by iProov measured 62% of organizations experiencing a deepfake attack in the past year, with attackers prioritising “stealth and identity compromise” over other exploits.
- Deloitte cites a 2024 incident in which an employee at a Hong Kong firm sent $25 million to fraudsters after being instructed by her chief financial officer on a video call that turned out to be a deepfake replication.
- iProov CSO Andrew Newell warned that Generative AI is allowing attackers to industrialize digital impersonation at scale in the same 2026 threat report.
- WEF’s 2026 respondents identified AI as the most significant driver of cybersecurity change ahead, according to 94% of survey respondents, and 87% flagged AI-related vulnerabilities as the fastest-growing cyber risk of 2025.
- Recent cyber incidents affecting Marks & Spencer and Jaguar Land Rover demonstrate how a single successful impersonation or social-engineering attack can disrupt systems and operations, per iProov’s 2026 report framing.
How deepfakes fit inside the wider fraud stack
- Sumsub’s first-party fraud breakdown puts synthetic identity at 21%, chargeback abuse at 16%, application fraud at 14%, deepfakes at 11%, and money mules at 11%.
- Third-party fraud schemes (external attackers exploiting genuine users) break down as identity theft 28%, account takeover 19%, card testing 17%, social engineering 16%, and bot attacks 12%.
- Deepfakes and synthetics rarely act alone: Sumsub reports a rising share of multi-step attacks over 2024-2025.
- 40% of surveyed companies and 52% of end users reported being victims of fraud in 2025, with 75% of respondents believing fraud will become increasingly AI-driven.
- Sumsub frames the next frontier of verification as the AI agents themselves, confirming not just who you are but who acts on your behalf.
- On the defensive side, Sumsub says defenders now gain behavior modeling, millisecond anomaly detection, and self-learning systems.
For broader context on how deepfakes plug into the wider Attackers landscape, third-party schemes still dominate the volume charts even as first-party deepfakes attract the headline coverage.
Document forgery and AI-generated identity documents
- Entrust reports that digital document forgery surpassed physical counterfeits as the leading method of fraud in 2024, with digital forgeries accounting for 57% of all document fraud, a 244% increase from 2023 and a 1,600% surge since 2021.
- National ID cards drew 40.8% of document attacks globally in the Entrust 2025 report cohort.
- Sumsub reports a brand-new AI-forgery signal: AI-assisted forgery rose from zero to 2% of fake documents in 2025, driven by tools such as ChatGPT, Grok, and Gemini.
- The share is small in absolute terms: roughly one in 50 forged documents is now AI-generated.
- Entrust characterizes the shift as bad actors leveraging AI to mount more sophisticated attacks on documents.
- According to Entrust, its Onfido stack processed millions of verifications annually and has prevented an estimated $5.5 billion in fraud cumulatively across its history.
Detection gap: humans and machines
- iProov’s Deepfake Blindspot Study found only 0.1% of 2,000 surveyed consumers could accurately identify deepfake media in a controlled test.
- WEF’s 2026 respondents said the share of organizations assessing the security of their AI tools has nearly doubled, from 37% in 2025 to 64% in 2026.
- Concern is shifting: data leaks associated with genAI (34%) and the advancement of adversarial capabilities (29%) stand out as leading concerns for 2026, a striking reversal from 2025 when adversarial capabilities topped the list at 47% versus only 22% for data leaks.
- 87% of WEF respondents identified AI-related vulnerabilities as the fastest-growing cyber risk over the course of 2025.
- Deloitte notes that generative-AI-enabled deepfakes incorporate a “self-learning” system that constantly checks and updates its ability to fool computer-based detection systems.
Key finding: The 0.1% consumer detection rate is the number every deepfake-awareness campaign has to price in. Even at the top end of pilot studies, humans do not clear the noise floor of a modern face-swap tool. The line of defense must be automated, and the checkpoint must be as close to the identity event as possible, not a follow-up email asking, “Was that really you?”
The Sophistication Shift: quality over volume
- Sumsub’s headline metric: the overall identity fraud rate decreased from 2.6% to 2.2% over 2024-2025, but remained above the 2.0% level of 2023.
- Within that flattening line, the share of multi-step attacks rose from 10% in 2024 to 28% in 2025 of all identity fraud, the metric the vendor calls the “Sophistication Shift”.
- The Sophistication Shift is about complexity: Sumsub logs +180% YoY growth in ‘sophisticated’ fraud over 2024-2025.
- Regional detail shows the same pattern: Europe’s fraud rate dropped 14.6%, and North America’s dropped 5.5% over 2024-2025.
- Sumsub CEO Andrew Sever framed the pivot as one of the Sophistication Shift marks a turning point, as businesses now face challenges tied to their velocity: the speed at which they can detect threats and adapt, in the report’s launch statement.
- The takeaway inverts the recycled “3000% surge” vendor narrative: the fraud rate fell in Europe and North America while the multi-step share nearly tripled, a harder problem to price into a detection budget than a straight-line growth rate.
| Sumsub metric | 2024 | 2025 |
|---|---|---|
| Multi-step attacks (share of identity fraud) | 10% | 28% |
| Overall identity fraud rate | 2.6% | 2.2% |
| Companies reporting fraud (surveyed) | not reported | 40% |
| End users reporting being victims of fraud | not reported | 52% |
| Respondents expecting fraud to become AI-driven | not reported | 75% |
Source: Sumsub Identity Fraud Report 2025-2026 (methodology: 4,000,000+ fraud attempts across the Sumsub verification network 2024-2025, plus a Fraud Exposure Survey of 300+ risk professionals and 1,200+ end users)
Deepfakes in politics and information warfare
- In Indonesia, a wave of deepfake scams featuring fabricated videos of President Prabowo Subianto promising financial aid has swindled Indonesians across 20 provinces, per the WEF Outlook 2026.
- In Ireland, a malicious deepfake video falsely depicting presidential candidate Catherine Connolly announcing her withdrawal from the race sparked outrage and an official complaint to the Electoral Commission.
- WEF frames the political-deepfake wave as AI accelerating the scale and sophistication of cyber-enabled harm, requiring stronger verification standards, cross-platform coordination, and safeguards for vulnerable groups.
- WEF’s respondents put AI as the most significant driver of change in cybersecurity in the year ahead, per 94% of survey respondents; the framework operators are trying to fit deepfake-driven disinformation into.
- The FBI’s IC3 has begun issuing PSAs about scammers deploying fake social profiles, voice clones, identification documents, and believable videos depicting public figures or loved ones in its 2025 annual write-up.
| Incident | Location |
|---|---|
| President Prabowo Subianto deepfake scams across 20 provinces | Indonesia |
| Presidential candidate Catherine Connolly deepfake withdrawal video | Ireland |
| IC3 leadership deepfake impersonation scheme | United States |
Source: World Economic Forum Global Cybersecurity Outlook 2026 (January 2026); FBI Internet Crime Complaint Center PSA
Political deepfakes overlap with the broader crime picture: the same generative-media toolkit that lets a fraudster clone a CFO on a video call is the one that lets a hostile actor put words into a presidential candidate’s mouth. The response, in both cases, ends up hinging on verification-of-origin systems rather than after-the-fact takedowns.
Are deepfakes actually illegal?
Deepfakes as a technology are not universally illegal. The legality turns on how the synthetic media is used and where the target is located.
In the United States, the FBI’s 2025 Internet Crime Report tracked 22,364 complaints and nearly $893 million in losses in its standalone AI category.
The UK’s Online Safety Act criminalised the sharing of non-consensual intimate deepfakes in 2023.
Multiple US states, including California, Texas, Minnesota, and Tennessee, have passed election-deepfake and intimate-image statutes since 2024.
The EU’s Artificial Intelligence Act, which entered into force in 2024, treats deepfakes as a transparency-obligation category rather than an outright ban, requiring clear labelling.
What is uniformly illegal across major jurisdictions: deepfakes deployed to defraud, extort, generate non-consensual intimate imagery, or interfere with elections. Every one of the growth-rate figures on this page belongs to that criminal-use tail, not to the far larger volume of consented entertainment or satirical deepfakes.
Conclusion
The 2026 deepfake statistics picture is not the linear surge that most vendor headlines still describe. Deloitte still projects a jump from $12.3 billion (2023) to $40 billion (2027) in US gen-AI-enabled fraud losses, and the FBI’s nearly $893 million in AI-enabled 2025 losses confirms the direction of travel; the underlying data from Sumsub, iProov, and Entrust shows the threat has industrialised into fewer, more sophisticated multi-step attacks.
For security leaders, the practical picture the 2026 deepfake statistics paint is straightforward: a deepfake attempt now happens every five minutes, roughly 1 in 5 biometric fraud attempts already carries a deepfake component, and iOS is no longer the platform attackers avoid. Human detection is effectively zero (0.1%), so the response has to be automated and layered across biometric, injection-detection, and telemetry checks. Detection tooling that assumes a human-in-the-loop as the final check helps reduce the risk of successful impersonation only when the model itself is watermark-agnostic and injection-aware.
































































