The Entrust 2026 Identity Fraud Report paints a detailed picture of a fast-shifting global fraud ecosystem where attackers are scaling operations, diversifying techniques, and capitalising on weaknesses in identity systems. The data reveals a sharp rise in injection attacks, increasingly sophisticated document forgeries, and an intense focus on national identity cards as the primary target for fraudsters worldwide.
According to the report, national IDs now account for 46% of fraudulent document submissions globally, and the proportions are even higher in regions such as APAC (60%) and EMEA (45%). For AMER, fraudulent driver’s licences dominate at 37%. The surge reflects how national identity documents serve as the gateway to financial services, telecommunications, government benefits, and digital-first services making them the highest-value assets for identity criminals.
Document forgeries, both digital and physical, continue to rise. While physical counterfeits remain more common at 47%, the sophistication of digital forgeries is rapidly increasing, fuelled by the availability of AI editing tools and online forgery services. Digital manipulation now represents 35% of total document fraud, up significantly from the previous three-year average.
One of the fastest-growing threats highlighted in the report is the rise of injection attacks, which have surged 40% YoY. Unlike traditional spoofs, injection attacks bypass the camera feed entirely, allowing manipulated images or videos often enhanced using generative AI to be inserted directly into verification workflows. These attacks make it far more difficult for systems to distinguish legitimate users from synthetic or altered identities.
Globally, fraud rates vary significantly: APAC averages 2.1%, AMER sits higher at 4.3%, and EMEA reports the lowest at 1.4%. Entrust attributes these variations to differing regulatory environments, identity infrastructures, and regional fraud appetites.
The overall picture is one of increasingly organised and industrialised fraud operations operating around the clock. Entrust’s data shows attack activity spikes in the early hours of the morning UTC when many organisations’ operational defences are at their weakest. Combined with identity recycling tactics and the use of generative AI, fraudsters are pushing identity systems to their limits.
The report concludes that organisations must invest in layered, identity-centric verification strategies, using AI not just as a target of fraud, but as a defensive mechanism. With more than a billion identity verifications analysed across 195 countries, Entrust’s findings signal a clear warning: identity has become one of the most contested battlegrounds in cybersecurity, and the tactics used to compromise it are only becoming more advanced.








