Cifas members filed over 220,000 UK fraud risk cases in the first half of 2026. Identity fraud hit 59% of them, SIM swap filings rose 402% and muling rose 69%.
Table of contents
Identity fraud accounted for 59% of the fraud risk cases filed to the UK National Fraud Database in the first half of 2026, the highest January to June total recorded by Cifas. Cifas is the UK not for profit fraud prevention service. Cases rose 9% to nearly 130,000. Unauthorised SIM swap filings climbed 402%, and muling cases rose 69%.
- Cifas members filed more than 220,000 fraud risk cases to the National Fraud Database between January and June 2026, the highest January to June total recorded. Cifas is the UK not for profit fraud prevention service, with nearly 800 members.
- Nearly 130,000 of those were identity fraud, up 9% year on year, with bank accounts and plastic cards making up 68% of the total.
- Unauthorised SIM swap cases rose 402% against the same six months of 2025, which puts pressure on any control that leans on an SMS one time code.
- Money muling cases rose 69% to more than 13,000 and now make up 30% of misuse of facility filings, with 57% of mule cases involving people under 30.
- Cifas flags synthetic identities, AI enabled impersonation and digitally manipulated documents as the growing intelligence concerns behind the numbers.
What did the Cifas half year data find?
Cifas released the Fraudscape 2026 six month update on 5 August 2026. It covers cases filed by members to the UK National Fraud Database, the shared fraud database Cifas operates for its members, between January and June. More than 220,000 fraud risk cases were recorded, and identity fraud was the largest single category at 59%.
The detail matters more than the headline. Identity fraud cases rose 9% to nearly 130,000, and bank accounts and plastic cards accounted for 68% of them. Most victims were aged 61 and over, but the sharpest rise fell on people aged 21 to 30, where cases increased by almost a third. Mike Haley, chief executive of Cifas, said that "stolen personal data often provides the entry point".
| Metric, January to June 2026 | Figure | Change on H1 2025 |
|---|---|---|
| Fraud risk cases filed to the National Fraud Database | More than 220,000 | Roughly flat, highest January to June total |
| Identity fraud cases | Nearly 130,000, or 59% of all filings | Up 9% |
| Facility (account) takeover cases | Nearly 40,000 | Up 5% |
| Money muling cases | More than 13,000 | Up 69% |
| Unauthorised SIM swap cases | Not disclosed | Up 402% |
Two sub trends sit underneath. Online retail account takeovers rose 84% and plastic card takeovers rose 59%, which underlines the value of compromised accounts and payment facilities. And Cifas records criminal use of synthetic identities, AI enabled impersonation and digitally manipulated documentation as a growing intelligence concern, not a fringe technique.
Why does a 402% rise in SIM swap matter?
A SIM swap moves a victim's mobile number onto a device the attacker controls. Every code, reset link and push prompt sent to that number then lands with the attacker. A 402% rise in unauthorised SIM swap filings in six months is therefore not a telecoms problem. It is an authentication problem.
The attacker collects enough personal data to pass a mobile operator's account checks, ports the number, then uses it to intercept security codes and defeat account protections. Cifas describes exactly this chain: the swap is the means, and further fraud is the objective. This is why account takeover and identity fraud numbers move together rather than independently.
For anyone relying on SMS codes as the possession factor in strong customer authentication, that chain breaks the assumption. The factor is supposed to prove the customer holds a specific device. After a swap it proves only that someone holds the number. Device bound credentials, app based authenticators and chip verified identity remove the SIM swap exposure, because the secret never travels over a mobile network. They do not remove real time phishing, which needs separate handling.
What does this change for your compliance obligations?
The Cifas data does not create new law, but it changes what a supervisor will treat as reasonable under existing UK duties. Four areas move first: customer due diligence, suspicious activity reporting, authentication design, and the corporate failure to prevent fraud offence. Each has a specific statutory hook rather than a general instruction to be careful.
| Duty | Source | What the H1 2026 data changes |
|---|---|---|
| Customer due diligence and ongoing monitoring | Money Laundering Regulations 2017, regulation 28(18) | Weaker basis under the reliable, independent source test in regulation 28(18) |
| Suspicious activity reporting | Proceeds of Crime Act 2002, section 330 | More mule accounts meeting the suspicion or reasonable grounds test, skewed young |
| Authentication and step up | Payment Services Regulations 2017, regulation 100, and the SCA technical standards | SMS possession factors degraded by a 402% rise in number porting attacks |
| Failure to prevent fraud | Economic Crime and Corporate Transparency Act 2023, sections 199 and 201 | Insider and staff facilitated fraud is the exposure, not being defrauded |
Customer due diligence and ongoing monitoring
Under regulation 28(18) of the Money Laundering Regulations 2017, customer due diligence has to verify identity from a reliable source that is independent of the person being verified. Where nearly 130,000 filings a half year involve stolen or fabricated identities, and manipulated documents are a named concern, an uploaded image of a document is a weaker evidence base than a chip read.
The chip is signed by the issuing authority and the signature can be checked, which an edited image cannot match. Monitoring also has to account for a genuine record being taken over after onboarding.
Suspicious activity reporting
Money muling is where fraud data becomes an anti money laundering duty. A 69% rise in mule filings means more accounts meeting the test in section 330 of the Proceeds of Crime Act 2002, which catches reasonable grounds for suspicion as well as actual suspicion, and triggers a suspicious activity report to the UK Financial Intelligence Unit, part of the National Crime Agency.
With 57% of mule cases involving people under 30 and 17% under 21, expect a higher share of reports on young, thin file customers whose accounts look ordinary until the flow starts.
Authentication and step up
Regulation 100 of the Payment Services Regulations 2017 requires strong customer authentication where a user accesses a payment account online or initiates an electronic payment transaction, subject to the exemptions in the technical standards. Online account access is exactly the takeover surface in this data. The SIM swap trend argues for treating a recent number port as a risk signal in its own right, and for demoting SMS in high value or high risk journeys. Multi factor authentication that leans on one intercepted channel is a single factor with extra steps.
Failure to prevent fraud
This one is often misread, so be precise about direction. The offence in the Economic Crime and Corporate Transparency Act 2023 came into effect on 1 September 2025. It bites where an employee, agent or other associated person commits fraud intending to benefit the organisation or, in some circumstances, its clients.
A fraud committed against the organisation does not trigger it, because the offence turns on intent to benefit. Section 199(3) is narrower than it is often described. It removes liability only where the organisation is the victim or intended victim of a fraud intended to benefit its clients, and the guidance confirms that indirect harm such as reputational damage does not make an organisation a victim.
Section 201 defines a large organisation as meeting, in the guidance wording, "two or three out of the following criteria", that is two or more: more than 250 employees, more than £36 million turnover, and more than £18 million in total assets. The Cifas relevance runs through the insider side of the dataset, since Fraudscape combines the National Fraud Database with the Insider Threat Database. The scenario most likely to be in scope is staff bypassing customer due diligence to hit onboarding targets, where the benefit runs to the firm and the conduct amounts to a base fraud offence listed in Schedule 13. An insider paid by criminals to open mule accounts generally falls outside this offence, because the benefit runs the wrong way, though it remains a money laundering and insider threat matter.
What is still uncertain in the identity fraud figures?
The main limit is that the National Fraud Database is a filing dataset, not a census. It measures what nearly 800 Cifas members recorded, so a rise can reflect better detection, wider membership or changed filing behaviour as well as more crime. Cifas itself credits greater reporting and stronger detection for part of the clearer picture.
That cuts both ways. If part of the increase is detection, the volume in earlier years was higher than recorded, and any internal baseline built on prior filings understates the threat. If part of it is real growth, controls tuned two years ago are calibrated to the wrong volume. Neither reading supports leaving thresholds alone.
The headline percentage needs the same care. Cifas published the SIM swap change as a percentage only. Without a base count the 402% cannot be sized against the 220,000 total, and a low starting volume would produce a large percentage from a modest absolute rise.
Three further questions are open. The report does not resolve how much of the identity fraud growth is fully synthetic versus stolen real identities, and the two need different countermeasures. Liability for a SIM swap chain is unsettled, sitting between the mobile operator that approved the port and the firm that accepted the code. And there is a cost question: chip based verification and device bound credentials reduce the attack surface, but they exclude customers without a compatible document or handset, which is a real inclusion risk.
How does this compare with the first half of 2025?
Year on year, the totals moved modestly while the composition shifted sharply. Overall filings rose from more than 217,000 to more than 220,000, a plateau at a high level. Identity fraud, however, went from a little over half of all filings to nearly three in five, which is the change worth acting on.
| Measure | H1 2025 | H1 2026 |
|---|---|---|
| Total fraud risk cases filed | More than 217,000 | More than 220,000 |
| Identity fraud cases | More than 118,000 | Nearly 130,000 |
| Identity fraud share of all filings | Around 54% (Zyphe calculation) | 59% (Cifas) |
| Facility (account) takeover cases | More than 38,000 | Nearly 40,000 |
| Headline intelligence theme | AI generated documents and identity selling | Synthetic identities, AI impersonation, muling |
Two notes on the arithmetic. Cifas states the identity fraud rise as 9%, while the rounded values above imply closer to 10%, which points to the percentage being calculated on unrounded figures. And Cifas billed H1 2025 as a record six month total too, so two consecutive record halves reinforce the risks section: records track filing behaviour as much as offending.
The 2025 update described criminals using AI to forge documents and bypass verification. The 2026 update adds distribution: muling to move the proceeds and SIM swap to defeat the checks. The threat has completed its supply chain.
How should compliance teams respond?
UK firms should act on three controls after this data. Re-run the onboarding risk assessment against document manipulation and synthetic identity specifically, not fraud in general. Remove SMS one time codes from the highest risk journeys, and treat a recent SIM change as a step up trigger. Review mule typologies for young account holders.
Then check the reporting path. A 69% rise in mule filings across the sector means your route to the UK Financial Intelligence Unit has to absorb more volume. One design point we plan for at Zyphe: any chip verification rollout still needs a path for documents without a readable chip. That image based fallback is the route an attacker will choose, so it needs its own controls. Our earlier coverage of deepfake identity fraud in verification data goes further on that point.
Then look at the data you hold. Every copy of a passport image, address and date of birth in your systems is raw material for the fraud recorded in this report. Zyphe reads the document chip over NFC to the ICAO Doc 9303 standard, with two step liveness and no image upload. The personal data is then sharded across a decentralised network so no single node holds a complete record, and the customer holds a reusable credential. If that is the direction you are moving, see KYC software, decentralised PII storage, or book a demo.
The bottom line
The signal in this release is not the record total, it is the mix. Identity is now the entry point for the majority of fraud risk cases recorded in the UK, and the techniques around it have industrialised: manipulated documents to get in, SIM swaps to defeat the check, mule accounts to move the money.
Controls designed when identity fraud was one category among several now face the dominant one. The practical response is to verify identity against something an attacker cannot fabricate or intercept, and to hold less of the personal data that fuels the next round of attacks.
Cited sources
- Cifas, Nearly three in five (59%) fraud-risk cases linked to identity fraud, newsroom item dated 4 August 2026, report released 5 August 2026
- Cifas, AI fuels surge in identity fraud, Fraudscape six-month report, 5 August 2025
- Cifas, Fraudscape 2026 6 Month Update, full report (registration required)
- GOV.UK, Guidance to organisations on the offence of failure to prevent fraud (ECCTA 2023)
- Money Laundering Regulations 2017, regulation 28 (customer due diligence measures)
- Proceeds of Crime Act 2002, section 330 (failure to disclose: regulated sector)
- Payment Services Regulations 2017, regulation 100 (strong customer authentication)
- National Crime Agency, Suspicious Activity Reports
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.