Trend #11 · Risk & Identity · 2027

Fraud & Identity: identity can no longer be verified once and forgotten

Synthetic identities, deepfakes, forged documents, account takeover and automated fraud networks are turning identity protection from a one-off KYC step into continuous control across the customer journey.

Trend: Fraud & IdentityImpact: very highStatus: already hereHorizon: 2027Updated: 11.09.2026
Executive summary
In 2027, a strong fraud-prevention system needs to answer not only the question “who registered?”, but also “who is controlling the account right now?”.
01

Continuity

Identity is checked not only at registration, but also at login, during payments, profile changes and withdrawals.

02

Multiple signals

Documents, face, device, network, payments and behaviour should be assessed together.

03

AI resilience

Defences need to account for deepfakes, injection attacks and automated creation of false data.

04

Recovery

A good fraud system should not only block suspicious activity, but also return legitimate customers to their accounts safely.

Why now

AI is strengthening both attack and defence

Generative AI lowers the cost of creating fake documents and video, while fraud-as-a-service helps attackers scale campaigns around the clock and across many accounts at once.

1 in 5
of biometric fraud attempts are deepfakes

According to the Entrust Identity Fraud Report 2026, deepfakes have become a mainstream component of biometric identity fraud.

Entrust · 2026
+58%
growth in deepfake selfies

Entrust reports year-on-year growth in attempts to use AI-generated selfies to bypass identity verification.

Entrust · 2026
+40%
growth in injection attacks

The attacker tries to feed a prepared image or video directly into the verification process.

Entrust · 2026
83%
of iGaming operators saw fraud increase

Sumsub's 2025 industry survey illustrates how widespread the fraud problem has become.

Sumsub · industry survey 2025
Identity lifecycle

Registration → Verification → Authentication → Transactions → Re-verification

The most dangerous assumption is that successful KYC permanently proves the same person will always control the account.

01REGISTRATION

Create

Establish the baseline signals for a new user and device.

  • Phone / email
  • Device
  • IP / geography
  • Linked accounts
02VERIFICATION

Prove

Verify documents, face and additional identity attributes.

  • Documents
  • Liveness check
  • Face matching
  • Age
03AUTHENTICATION

Recognise again

Determine whether the genuine owner is returning to the account.

  • Login
  • New device
  • Behavioural signals
  • Step-up verification
04TRANSACTIONS

Observe

Identity risk changes alongside payment and gambling behaviour.

  • Deposit
  • Withdrawal
  • Payment method
  • Transaction velocity
05RE-VERIFICATION

Confirm

A material change in the risk profile triggers additional verification.

  • Data change
  • ATO signal
  • Risk threshold
  • High-impact action
Fraud threat map

Fraud targets different parts of the customer journey

Fraud cannot be reduced to a fake document. A single customer account may face several attacks, from synthetic identity at registration to account takeover after months of normal activity.

The identity layer therefore needs to connect onboarding verification, payments, device intelligence and account behaviour.

Fraud Map · 20276 main vectors
RegistrationSynthetic identitya mix of real and fabricated identity attributes
VerificationDeepfake / face swapbypassing face matching and liveness checks
DocumentsDigital forgeryAI-assisted editing and document generation
AccountAccount takeoverphishing, credentials and social engineering
PaymentsMule / linked accountslinked accounts and movement of funds
PromotionsBonus abusescaling repeated registrations and schemes
Key attack types

How fraud is changing in 2027

Different attacks require different signals. A generic fraud score without context is not enough.

Synthetic identity

An identity can look credible and still never have existed

An attacker combines real and fabricated data to create a profile that passes individual checks but does not correspond to a real person.

  • Phone / email / device links
  • Consistency of identity attributes
  • Document history
  • Reuse of identity details
  • Link analysis
Core principle

Check relationships, not just fields

The more an identity graph connects accounts, devices, documents, payment methods and network signals, the harder it becomes to scale synthetic-identity fraud.

Deepfakes

Video is no longer automatic proof of presence

Deepfake and face-swap tools can imitate the face of a real or synthetic user.

  • Advanced liveness checks
  • Injection-attack detection
  • Motion and challenge checks
  • Device integrity
  • Repeat biometrics
Market signal
Deepfake fraud1 in 5 biometric attempts
Deepfake selfie+58%
Injection attacks+40%
SourceEntrust 2026
Document fraud

Forgery is becoming digital

Modern tools make it easy to alter existing images, generate new documents and create many variants of the same scheme.

  • Document forensics
  • Template validation
  • Metadata
  • Cross-checking identity data
  • Duplicate detection
2025 → 2026

Digital forgery is becoming mainstream

Entrust reports that digital forgeries accounted for 35% of detected document fraud in its 2025 data.

Account takeover

Successful KYC does not protect an account from being stolen a month later

Account takeover can use phishing, stolen credentials, social engineering or malware, after which the attacker acts as an already verified customer.

  • Device change
  • Impossible travel
  • Credential reset
  • Behaviour change
  • Withdrawal change
Signal

+37% suspected account takeover

TransUnion reports that the global suspected digital fraud rate for account takeover rose 37% from 2024 to 2025.

Mule and linked accounts

One person can look like dozens of independent customers

Shared devices, payment methods, IPs, documents and behavioural patterns can reveal fraud networks.

  • Device graph
  • Shared payment instrument
  • IP / network overlap
  • Shared identity attributes
  • Coordinated transaction patterns
Regulatory signal

Linked accounts — high risk

In 2026, the UK Gambling Commission specifically identifies inadequate control of linked and duplicate accounts as a high ML/TF risk for remote casino.

Bonus abuse

Automation lowers the cost of creating accounts at scale

Bonus abuse can combine multiple identities, linked devices, payment-method reuse and coordinated account networks.

  • Repeated identity patterns
  • Device reuse
  • Payment-method reuse
  • Promotion clustering
  • Fast cash-out patterns
Balance

Fraud controls should not break onboarding

Controls that are too strict create false positives and drive legitimate users away. Friction should be risk-based.

AI vs AI

Fraud is becoming a machine-to-machine contest

One side uses AI to create identities and bypass controls; the other uses it to detect inconsistencies, anomalies and network connections.

ATTACK

AI-assisted fraud

Automation lowers the cost of creating and scaling convincing fraud scenarios.

AI-generated documents
Deepfake video
Face swaps
Synthetic identities
Automated account creation
VS
DEFENCE

AI-assisted defence

The defensive layer analyses many weak signals that may not look suspicious on their own.

Liveness check
Document forensics
Device intelligence
Behavioural analytics
Network graph analysis
Continuous identity

KYC becomes an identity risk engine

Each new signal can change the level of confidence the system assigns to the person currently using the account.

01 · IDENTITY

Who?

Documents, face, age and core identity attributes.

02 · DEVICE

From where?

Device, IP, browser, geography and network relationships.

03 · BEHAVIOUR

How?

Behavioural profile and deviations from the account's normal usage pattern.

04 · MONEY

What is happening?

Deposits, withdrawals, payment methods and transaction velocity.

05 · DECISION

What next?

Allow, request step-up verification, restrict or route to an analyst.

Devices and behaviour

Fraud often appears not in a document, but in a sequence of events

Device intelligence and behavioural signals help detect account takeover, multi-accounting and coordinated networks without forcing every customer through full KYC repeatedly.

Example signal stream

An account changes its risk profile in four minutes

Illustrative example: each signal may be normal on its own, but the combination calls for step-up authentication.

02:14:03Login from a new device+ risk
02:14:44Password changed+ risk
02:15:31New payment method added+ risk
02:17:02Large withdrawal requestedhigh risk
02:17:05Re-verification triggeredstep-up verification
Key principle

Risk-based friction

Most legitimate customers should not face the highest level of verification for every action.

Additional verification should appear when a combination of signals genuinely increases risk.

DeviceBehaviourPaymentsStep-up verification
Deposits and withdrawals

Fraud often becomes visible after onboarding

A common weakness is strong onboarding control followed by much weaker monitoring after successful registration.

WHAT TO MONITOR

Transaction identity

A financial action should be consistent with the identity and history of the account.

  • Payment-holder match
  • New payment method
  • Deposit / withdrawal velocity
  • Closed-loop payment logic
  • Linked accounts
RED FLAGS

When identity confidence falls

A combination of new devices, payment changes and fast withdrawals may indicate account takeover or mule-account activity.

  • New device + new withdrawal method
  • Payer-name mismatch
  • Multiple payment methods
  • Fast withdrawals
  • Payment reuse across accounts
Human review

Not every suspicion should end in a block

A good fraud-control system distinguishes low-risk automated actions from decisions that require human investigation.

ALLOW

Low risk

Continue the customer journey without additional friction.

AUTHORISE

Step-up verification

Request an additional authentication factor or re-verification.

CHECK

Human review

Route a high-impact case to an analyst with a prepared evidence pack.

RESTRICT

High risk

Temporarily restrict a critical action while preserving the decision log.

Customer recovery

Fraud prevention needs a way to correct its own mistakes

A false positive becomes a customer-experience problem if a legitimate customer cannot restore access quickly and safely.

01

Detect

Identify that an account may have been taken over or incorrectly blocked.

02

Protect

Temporarily stop critical operations without destroying evidence.

03

Verify

Use an independent route for repeat identity verification.

04

Restore

Restore the verified owner and credentials.

05

Learn

Feed the outcome back into fraud rules, models and training data.

Fraud operations

Detection without an operating system does not solve the problem

Even a strong model is of limited value if alerts pile up, evidence is gathered manually and false-positive outcomes never feed back into the system.

01

Prioritisation

Combine related signals and route the most important cases to analysts.

02

Evidence pack

Automatically assemble identity, device, payment and behavioural context.

03

Connections

Show the relationship graph between accounts, devices and payments.

04

SLA

High-risk events should have a defined response time.

05

Feedback

Analyst outcomes should update rules and models.

06

Audit trail

Every material decision should leave an auditable history.

Identity & Fraud Stack

From document checks to continuous risk

The goal is not one verification system, but an architecture connecting identity proofing, authentication, devices, payments and fraud operations.

Layer 01 · Identity

Documents, face and core attributes

KYC · age · liveness · face matching
Layer 02 · Device

Device, network and session intelligence

device ID · IP · geography · emulator
Layer 03 · Graph

Relationships between entities

accounts · payments · documents · devices
Layer 04 · Behaviour

Behavioural profile and anomalies

login · navigation · timing · velocity
Layer 05 · Decisioning

Risk score and step-up actions

allow · verify · review · restrict
Layer 06 · Operations

Cases, recovery and governance

analyst · SLA · feedback · audit
KPI Matrix

What to measure beyond the number of blocked accounts

A fraud programme should balance prevented losses, false positives, conversion and customer recovery.

MetricWhy it mattersPurposeRisk if ignored
Fraud loss rateShows actual financial losses↓ LowerDirect financial loss
False-positive rateShows the cost of incorrect blocks↓ LowerLoss of legitimate customers
KYC pass rateMeasures the balance between protection and onboarding UXBalanceConversion loss
Account-takeover detectionTests protection after onboarding↑ HigherTheft of funds / loss of trust
Time to decisionShows the speed of operational response↓ FasterHigher losses
Recovery successShows the ability to restore a legitimate customer↑ HigherChurn after a fraud event
Linked-account detectionTests fraud controls at network levelMonitorScaling of fraud schemes
Build or buy

What to source from specialist providers and what to keep in-house

Biometric and document-verification technology is often best sourced externally, while the identity graph, business rules and risk orchestration should reflect the operator's own product.

PARTNER / BUY

Specialist technology

Layers where value comes from data scale, specialist research and global fraud intelligence.

  • Document verification
  • Liveness check
  • Biometric matching
  • Device intelligence
  • External fraud-consortium data
BUILD / CONTROL

Risk orchestration

Capabilities that depend on the operator's product, customer journey, promotional mechanics and risk appetite.

  • Identity graph
  • Linked-account logic
  • Decision rules
  • Step-up policy
  • Customer recovery workflow
2027 scenarios

Three directions for identity fraud

These are Betting Trends editorial scenarios, not guaranteed forecasts.

SCENARIO A

Continuous identity

One-time KYC gives way to a continuous trust assessment that changes across the full customer lifecycle.

Identity lifecycleStep-up verificationBehaviour
SCENARIO B

Fraud networks

The main unit of analysis shifts from a single account to a network of linked identities, devices and payments.

Relationship graphLinked accountsMule accounts
SCENARIO C

AI arms race

Fraudsters and operators are both automating attack generation and detection at increasing speed.

DeepfakesAI defenceAutomation
90-day plan

How to move from onboarding KYC to continuous identity

Start not with new biometrics, but with a map of the fraud journey and the weak points after onboarding.

Days 1–30

Map

Understand where identity risk appears today.

  • Fraud journey map
  • Linked-account review
  • Account-takeover incidents
  • False-positive baseline
Days 31–60

Connect

Connect identity, device, payment and behavioural data.

  • Unified risk profile
  • Device graph
  • Transaction signals
  • Step-up triggers
Days 61–90

Automate

Launch risk-based decisioning and a feedback loop.

  • Risk engine
  • Case prioritisation
  • Recovery workflow
  • Model governance
Board questions

7 questions before scaling the fraud stack

If the team can only talk about its KYC provider, the identity strategy does not yet cover the full customer lifecycle.

01
Where is identity checked after registration?

Which events trigger step-up authentication or re-verification?

02
Can we see linked accounts?

Are devices, payments, documents, IPs and customer attributes connected?

03
How resilient are the controls to deepfakes?

Do we have injection detection, advanced liveness and device-integrity controls?

04
How is account takeover detected?

Are behavioural and device signals monitored after successful KYC?

05
How many legitimate customers are blocked incorrectly?

Is the false-positive rate measured for every fraud control?

06
Can a legitimate customer be restored quickly?

Is there a safe recovery flow after account takeover or an incorrect restriction?

07
Does the system learn from closed cases?

Do analyst outcomes feed back into rules, models and network intelligence?

Sources & Methodology

Sources and methodology

This page combines regulatory sources, identity-fraud research and the Betting Trends editorial framework. Vendor statistics are clearly identified and are not treated as universal figures for the betting industry.

Regulator · 2026UK Gambling Commission — ML/TF Risk Assessment 2026

The growing complexity of AI-assisted fraud, fake identities, altered documents and technology-driven ML/TF threats.

Open source →
Remote casino · 2026UK Gambling Commission — Remote Casino

False / stolen identities, AI-generated documents, deepfake video, face swaps, linked accounts and mule-account risk.

Open source →
Identity fraud · 2026Entrust — Identity Fraud Report 2026

More than 1 billion identity verifications: deepfake biometric fraud, injection attacks, digital document forgery and lifecycle identity protection.

Open source →
Digital fraud · 2026TransUnion — Top Fraud Trends 2026

Account-creation fraud, account takeover, identity-based attacks and fraud across the customer lifecycle.

Open source →
iGaming researchSumsub — State of Identity Verification in iGaming

Vendor industry report covering AI-generated document fraud, deposit-stage attacks, identity fraud and bonus abuse.

Open source →