Home Cyber Security

National IDs Now Prime Targets as Entrust Report Reveals Shifting Global Fraud Patterns

Entrust’s 2026 Identity Fraud Report highlights growing regional disparities in fraud activity, with national ID cards emerging as the most exploited documents worldwide.

The newly released 2026 Identity Fraud Report from Entrust provides a comprehensive look at global identity fraud patterns, revealing which regions and industries face the most significant threats. Covering millions of identity verification checks conducted across 195 countries, the report uncovers a clear shift in fraudster behaviour, tactics, and preferred attack surfaces.

National ID Cards Make Up Nearly Half of All Global Document Fraud
The report shows that 46% of all fraudulent document submissions involve national ID cards, making them the most targeted identity document globally. The issue is particularly pronounced in the Asia-Pacific region, where fraudulent national IDs account for 60% of all document-based fraud.

By comparison:

EMEA recorded 45% fraudulent national IDs
AMER saw 37% fraudulent driver’s licences the most exploited document in that region
This trend reflects the ease with which national ID templates can be obtained online, combined with the growing availability of AI tools used to enhance digital forgeries.

Counterfeit vs Digital Forgery: Two Different Battles
While physical counterfeits remain more common (47%), Entrust reports that digital forgeries have grown significantly, now representing 35% of document fraud up from an average of 29% between 2022 and 2024.

Digital forgeries tend to be more sophisticated, enabled by increasingly powerful generative AI platforms that allow fraudsters to fabricate high-quality documents from scratch.

A 24/7 Global Fraud Operation
Entrust’s analysis reinforces the idea that modern fraud is not just opportunistic it’s industrialised. Fraud attempts peak between 2:00 am and 4:00 am UTC, a window that aligns with reduced staffing hours across several regions.

Fraud rings now operate with “rinse and repeat” methods, recycling details such as:

Common names (e.g., Jon Doe)
Reused document numbers
Frequently recycled birthdates
These recycled elements appear across multiple fraudulent identity submissions, indicating organised pipelines rather than isolated actors.

Industry-Specific Behaviour Shows Targeted Attacks
Different sectors are being hit in different ways:

Cryptocurrency providers see the highest onboarding fraud (67%) due to sign-up bonuses.
Payments providers and digital banks suffer high volumes of account takeover fraud, at 82% and 55% respectively.
These insights suggest attackers tailor their strategies to each industry, targeting whichever stage of the customer lifecycle delivers the highest payoff.

Identity Becomes the Primary Battlefield
“Generative AI and shared tactics fuel volumes and sophistication across global fraud networks,” said Simon Horswell of Entrust. “Identity is now the battlefield where businesses must be prepared to defend.”
“With more than one billion identity verifications conducted worldwide, our data gives us unparalleled visibility,” added Tony Ball, Incoming CEO at Entrust. “Layered, identity-centric security is the only way to stay ahead.”
The report reinforces that as fraud operations become more organised, businesses must adopt multi-layered defences spanning document verification, biometric security, behavioural analytics, and ongoing account monitoring.