Cifas recorded 220,041 fraud-risk cases in the first half of 2026, just 1% up on the same period last year. While it may look like a story of stabilising fraud levels, identity fraud is up 9%, money muling is up 69%, and SIM swap has risen 402%, all while misuse of facility fell 15%. The flat headline number is hiding a fast-moving reshuffle of where fraud is actually happening, and firms reading only the top-line figure will miss where the real risk has moved to.

Here are the six trends worth your attention, and what to do about each one.
|
Key insights:
|
1. Identity fraud is climbing again, and cards are driving it

Identity fraud is now the largest single case type by some distance, up from 55% of filings a year ago. Plastic cards (mainly personal credit cards) are behind most of the growth, rising 33% and adding almost 15,000 cases, largely tied to personal credit cards. Plastic cards and bank accounts combined now make up 68% of all identity fraud cases, up from 64%.
Identity fraud isn't a problem any one firm's data can solve. Federated learning is the mechanism worth backing here: firms sharing fraud application data and intelligence catch attackers who've already been flagged elsewhere before they reach the next lender.
What this means for firms: most lenders already use external data at application. The credit bureaux cross-match application details across lenders to flag inconsistencies, such as a salary that changes between applications, and are adding AI models that score how likely an identity is to be synthetic. Fraud databases like Cifas add confirmed cases filed by other members.
But all of this relies on an identity having left a trace somewhere. A synthetic identity built slowly, with a clean credit file, can pass every check until the bust-out. Federated learning goes further by training detection models on fraud data from many firms without that data leaving each one. In other words, a lender can spot how a new attack behaves even when the identity itself has no history.
2. Account takeover is moving away from telecoms

Telecoms is still the single largest sector for account takeover, but its share dropped from 69% to 51% of all cases. Online retail and plastic cards picked up the difference, and SIM swap is a reason why, because cases in that category alone rose 402%, now making up 10% of all takeover filings, up from 2%.
Mobile providers need to get this under control. The vulnerability is largely outside a bank's own systems, in how easily a SIM can be transferred to an attacker's device. Firms shouldn't be relying solely on SMS-based verification in the first place, and a 402% rise makes that case harder to argue against. It's also why businesses have moved staff MFA from SMS codes to authenticator apps, and consumers are likely to follow. Many banks already ask customers to approve payments in their banking app, so the groundwork is in place.
What this means for firms: if SMS is still the only second factor on any customer journey, this is the number that should move it up the priority list.
3. First-party fraud is rising alongside pressure on household finances

Misuse of facility filings fell 15% overall, but this one figure cuts against the trend, and it points to something beyond normal fluctuation. Economic pressure on household finances is the most likely driver. Under financial strain, opportunistic, first-party fraud becomes more attractive, even to those who wouldn't otherwise consider it.
This is individuals making a decision under pressure, not organised fraud, which calls for detection tuned to that specific behaviour rather than the patterns most controls are built around.
What this means for firms: a rise in falsely reporting a loss is worth tracking against economic indicators like household debt and cost-of-living pressure. In other words, the data needs joining up. Fraud teams see the false claim, while credit risk and collections see the same customer falling behind on payments. Few firms bring those two views together, so the early warning goes unnoticed until the losses are booked.
Education has a part to play too. Many customers don't see a false loss claim as fraud, or know it can lead to a Cifas marker that affects their access to credit for up to six years. Making that consequence visible at the point of the claim is a low-cost deterrent.
4. AI is scaling fraud faster than legacy detection can keep up

Cifas flagged growing concern around synthetic identities, AI-enabled impersonation, and digitally manipulated documents throughout the report. False application filings for loans rose 33%, largely where altered or false documents were supplied, and Cifas members link the growing quality of those documents directly to AI. Whether a lender's process would catch a digitally altered passport depends on the tools it's running. Some document verification systems will spot the manipulation and some won't. Meanwhile, both detection and forgery techniques are getting smarter, which makes this an arms race.
The tools used to catch fraud five years ago were built for a far less sophisticated threat. Spotting synthetic fraud at the level Cifas is describing needs more advanced ML algorithms and detection tools than most current stacks are running.
What this means for firms: document and identity verification tooling bought even two or three years ago should be re-tested against current synthetic fraud techniques, not assumed to still be keeping pace.
5. Money mule activity is rising, and it needs to stop being treated as a lesser crime

The new "funds received – money muling" filing category is showing the full scale of a problem that was previously undercounted, up from 15% of misuse of facility cases a year ago. The 21–30 age group remains the largest share of subjects at 40%, unchanged from 2025.
Prevention comes down to education, specifically what misuse of facility actually costs the people recruited into it. Many have never heard the term money muling, let alone realised that letting someone move money through their account is money laundering, which carries a prison sentence of up to 14 years. Even without a prosecution, a mule can have their bank account closed and a Cifas marker filed against them, making it hard to open a new account or get credit for up to six years.
That message needs to land hardest at university age, where recruitment tends to start. Plenty of organisations already run awareness campaigns there, but young people still see muling as harmless, and that belief is exactly why it keeps growing.
What this means for firms: prevention happens upstream of the transaction, in education and outreach, not only in the detection layer.
6. This is the busiest first half on record, and the second half is unlikely to slow down

More than 220,000 cases were filed to the National Fraud Database in the first six months of 2026, the highest total Cifas has recorded for the first half of any year. The overall rise looks modest at 1%, but that figure hides the real movement underneath it. Misuse of facility fell 15%, while identity fraud, money muling, and SIM swap all rose sharply enough to push the total to a new record regardless.
What this means for firms: budget conversations for next year should start from the assumption that overall volume keeps climbing, with identity fraud, mule activity, and SIM swap accounting for a growing share of it.
Building fraud models that keep pace
These figures show where fraud is moving, and detection has to keep pace, or firms fall behind. That's exactly what we built our fraud models around. Archetype, our proprietary predictive modelling software, is trained to catch the non-linear patterns typical of fraudulent applications, adapting as the data does rather than needing to be rebuilt every time fraudsters change tactics.
The results back that up. Firms using Archetype are seeing detection rates climb while false positives fall, so fewer genuine applicants get caught in unnecessary friction, and actual fraud gets flagged faster.
So if any of the trends above sound familiar, identity fraud slipping past static checks, SIM swap exposure through SMS-only verification, synthetic applications outpacing legacy detection, get in touch. We'd like to talk you through what a review of your own controls could look like.
Further reading. You may also like: