One in 100: How Deepfakes Are Breaking ID Checks at Scale
LexisNexis: 1 in 100 failed identity checks involves a deepfake. At 100 billion annual checks, the math makes this a systemic infrastructure crisis.

On July 14, 2026, LexisNexis Risk Solutions published a finding that should recalibrate how the identity verification industry talks about deepfake fraud: one in every 100 failed identity checks now involves a deepfake document, image, or liveness video.
That statistic is alarming on its own. It becomes catastrophic when you add the denominator.
Juniper Research estimates that 100.4 billion identity verification checks will be carried out globally in 2026 — a 16 percent increase over 2025. If the overall failure rate across platforms averages even 2 percent, the industry is absorbing approximately 2 billion failed checks per year. One percent of those involve deepfakes. At scale, that translates to tens of millions of deepfake-assisted fraud attempts surfacing through the failure stack annually — and the volume is growing at 180 percent year on year.
This is no longer a KYC problem. It is an infrastructure problem.
What "1 in 100" Actually Means at Scale
Statistics make better headlines than boardroom calculations. Let us do the math properly.
100.4 billion identity verification checks per year amounts to roughly 275 million checks per day, or 3,200 checks per second, globally. The majority of these will pass. But every verification system that applies genuine anti-fraud controls will reject a proportion of attempts. The total universe of failed checks is enormous.
LexisNexis did not publish the aggregate failure rate across its platform. But consider: if even 1 percent of 100 billion annual checks fail, that is 1 billion failed verifications. One percent of those involve deepfakes. That is 10 million deepfake-assisted fraud attempts surfacing through the catch layer alone — before accounting for attacks that are not caught.
The LexisNexis figure reflects detected attempts. The caught-to-slipped ratio is unknown, and that is the more important number.
The 180 percent year-on-year increase in deepfake attacks that LexisNexis recorded does not represent linear growth in a known threat. It represents the market expansion of commercially available AI fraud tooling — specifically the emergence of packaged attack kits that can be assembled for as little as $60 per month and deployed against multiple verification systems without requiring any technical expertise.
Three Forces Making the Problem Structural
The identity verification industry has faced fraud acceleration before. What makes the 2026 deepfake problem structurally different from previous waves is the convergence of three forces simultaneously.
Accessibility. Until 2024, deepfake creation required significant technical skill, compute, and time. The democratization of generative AI tools has changed this completely. A convincing document deepfake can now be created in minutes by an operator with no computer science background. Shufti's Identity Fraud Index projects a 3,892 percent growth in document deepfakes alone in 2026 — a 40-fold increase over 2025 levels driven entirely by accessibility, not by new underlying technology.
Distribution. The market structure of AI-assisted identity fraud has shifted from bespoke attacks by skilled actors to packaged fraud-as-a-service operations. As documented in our analysis of KYC bypass-as-a-service operations, these services are actively maintained, pre-configured for specific verification platforms, and priced for high-volume deployment. The attacker is no longer a specialist — it is a subscription service with customer support.
Vector expansion. The attack surface is no longer limited to face liveness. Injection attacks on liveness detection now represent the dominant threat vector, bypassing sensor-level detection entirely by feeding synthetic video directly into application pipelines. Document deepfakes are rising faster than biometric deepfakes. And stolen genuine biometrics — from breaches like the Mercor incident — enable impersonation attacks that no liveness algorithm can catch, because the biometric data is authentic.
The convergence of accessible tooling, commercial distribution, and vector diversification means that addressing one layer of the problem does not address the system. You cannot fix the deepfake problem by improving your face liveness algorithm. The attack has already moved.
The Gartner Prediction Has Arrived
In February 2024, Gartner published a prediction: by 2026, 30 percent of enterprises would no longer consider identity verification and authentication solutions reliable in isolation due to AI-generated deepfakes.
We are now in August 2026. The LexisNexis data confirms the prediction is not theoretical — it is operational. One in 100 failed checks involves a deepfake. Deepfakes drive 1 in 5 biometric fraud attempts globally. More than half of organizations cannot fully verify that biometric data was captured live, according to Biometric Update's July 2026 analysis.
The implication Gartner pointed toward in 2024 was not that biometric verification should be abandoned. It was that biometric verification cannot be the only signal. A single biometric check at onboarding — even a sophisticated, multimodal one — cannot maintain identity assurance across a customer relationship whose risk profile may change, whose credentials may be compromised, and whose behavior may diverge from the baseline established at onboarding.
This is the architectural gap that perpetual KYC and continuous monitoring addresses — and the gap that Gartner saw coming two years before the data arrived to confirm it.
Why "Better Biometrics" Is Not the Answer
The instinct when fraud accelerates is to upgrade the check. Better liveness detection. More sophisticated face matching. Behavioral biometrics layered on top of facial recognition.
These improvements matter. The layered biometric verification approach that Regula and AU10TIX pivoted to in July 2026 is a necessary evolution. But layered biometrics at the onboarding gate still represents a point-in-time check. It is a more defensible check, but it answers the same question: "Who is this person at this moment?"
At 100 billion checks per year and 180 percent annual growth in deepfake attacks, the problem is not only about the quality of the point-in-time check. It is about what happens in the gap between that check and everything that follows.
A customer who passes a five-layer biometric verification at onboarding in January may have their credentials compromised by April. Their device fingerprint changes. Their transaction velocity increases. Their login geography shifts. None of these signals trigger a re-verification under a point-in-time model. Under a continuous intelligence model, every anomaly is a signal — and the response is calibrated, not binary.
The Wolfsberg Group, whose correspondent banking guidelines shape how major financial institutions assess counterparty risk, has begun updating its guidance to reflect identity assurance failures as a source of systemic de-risking pressure. The concern is not that individual institutions are failing their KYC checks — it is that the aggregate failure rate across the verification ecosystem is creating a trust deficit that affects correspondent banking relationships at the macro level.
The Architecture That Scales
Manual review cannot scale to the threat. A human reviewer working efficiently can evaluate perhaps 40 identity verification cases per hour. At even 100 million deepfake-assisted attempts surfacing per year — a conservative estimate given the data — addressing the threat through manual review would require approximately 68,000 full-time reviewers working year-round on deepfake cases alone, before accounting for any other fraud vector.
This is not a staffing problem with a staffing solution. It is an architecture problem with an architecture solution.
Joinble's AI agents operate continuously across the customer lifecycle, evaluating behavioral signals that emerge after a clean onboarding: changes in device fingerprint, shifts in transaction velocity, geographic anomalies, session behavior divergence, and cross-system risk signal correlation. The agent does not wait for a periodic review cycle — it monitors in real time and acts in real time, whether that means flagging for human review, triggering a step-up verification challenge, or applying a temporary restriction while the anomaly is assessed.
At the scale of 100 billion annual checks and 180 percent annual deepfake growth, the operational model that fails is one built around human reviewers and periodic re-verification. The model that scales is one where autonomous agents handle continuous monitoring and humans handle exceptions.
What Compliance Teams Must Do Now
The LexisNexis data is not a warning about a future problem. It is a measurement of a current one. Compliance teams still relying on a single-signal biometric check at onboarding, with no continuous monitoring layer, are already behind the threat curve.
The priority actions:
Audit your check architecture. How many independent signals does your verification process evaluate at onboarding? If the answer is one (a selfie against a document) or two (selfie plus liveness), the attack surface is too narrow. Correlating multiple independent signals — document authenticity, biometric matching, liveness, device trust, behavioral baseline — collapses the window for single-vector attacks.
Implement continuous behavioral monitoring. Onboarding is the beginning of a relationship, not the conclusion of a risk assessment. Your verification architecture should include behavioral signals that persist across the full customer lifecycle: transaction patterns, session characteristics, device consistency, and geographic behavior.
Quantify your deepfake exposure. How many verification failures did your platform record in the last 12 months? What percentage involved document anomalies, biometric rejection, or liveness failure? If you cannot answer this question with current tooling, your monitoring stack is not providing the visibility the LexisNexis benchmark makes necessary to measure against.
Assess your vendor's injection attack detection. Ask specifically about injection attack detection, not just liveness detection. Camera injection attacks bypass liveness algorithms by feeding synthetic data at the pipeline level. A vendor that cannot detect injection attacks is vulnerable to what is now the dominant threat vector.
The 1-in-100 figure from LexisNexis is a baseline measurement taken in mid-2026. Given the 180 percent annual growth rate, the figure in mid-2027 will be materially higher. The question for compliance teams is not whether the problem will worsen — it will. The question is whether the verification architecture in place today was designed for that volume, and whether it will still be adequate when the number doubles again.
FAQ
What did the LexisNexis July 2026 report find? LexisNexis Risk Solutions reported that one in every 100 failed identity verification checks now involves a deepfake document, image, or liveness video. The company also recorded a 180 percent year-on-year increase in deepfake attacks. The report was published on July 14, 2026.
Why is 1 in 100 failed checks a systemic problem rather than a manageable fraud rate? Because the denominator is 100 billion. At 100.4 billion identity verification checks expected globally in 2026, even a small failure-rate percentage involving deepfakes translates to tens of millions of deepfake-assisted fraud attempts annually. The absolute volume, not the percentage, is what strains verification infrastructure and makes human review economically unviable.
What is the difference between deepfake fraud and traditional document fraud? Traditional document fraud involves physically altered or forged materials. Deepfake attacks use generative AI to produce synthetic images, video, or documents that pass automated verification systems. The 2026 attack surface has expanded to include injection attacks — where synthetic video is fed directly into verification APIs at the pipeline level, bypassing camera sensors entirely.
Why can biometric verification alone no longer be trusted? Biometric verification answers a point-in-time question: "Is this person who they claim to be right now?" It cannot address credential compromise that occurs after onboarding, behavioral anomalies that emerge over time, or vector diversification like injection attacks that bypass the biometric layer entirely. Gartner's 2024 prediction that 30 percent of enterprises would consider biometric verification unreliable in isolation by 2026 is now confirmed by the operational fraud data.
What is the role of AI agents in responding to deepfake fraud at this scale? AI agents provide continuous monitoring across the full customer lifecycle, identifying behavioral anomalies that emerge after onboarding and acting in real time before human reviewers are involved. At the scale of tens of millions of deepfake attempts annually, human-only review cannot keep pace. Autonomous agents that flag, challenge, and escalate provide the operational throughput the threat volume demands.
What should compliance teams do first? Audit how many independent signals your current verification process evaluates. If you rely on a single biometric check, your attack surface is too narrow. Add behavioral monitoring that persists after onboarding, assess your vendor's injection attack detection capabilities specifically, and establish a baseline metric for what share of your current verification failures involve synthetic content — so you can track whether that share grows.
Related Articles

No Single Signal Wins: Layered Biometric Verification
Deepfakes now drive 1 in 5 biometric fraud attempts. Regula and AU10TIX pivoted to layered multimodal verification in July 2026. Here's what changed and why.

1 in 26: AI Fraud Has Overtaken Physical Forgery
AU10TIX's Q1 2026 data confirms AI-generated fraud surpassed physical forgery for the first time. What the 3.89% confirmed fraud rate means for KYC teams.

Account Takeover Fraud Up 250%: Why Static KYC Fails
Account takeover fraud spiked 250% and cost $16B in 2024. Discover why one-time KYC verification is structurally powerless against post-onboarding attacks.