A new intelligence report from Unico and Liminal warns that identity fraud is not only growing in scale, but moving rapidly up the sophistication ladder, with simple injection attacks now representing the largest share of classified fraud attempts observed in Unico’s network.

The report, Identity Fraud Intelligence: Trends & Insights, draws on Unico network-scale data gathered from June 2025 to April 2026, as well as Liminal market intelligence, to argue that fraud has moved beyond isolated incidents and predictable loss patterns. The central finding is that attackers are shifting away from crude presentation attacks and toward more scalable, AI-enabled techniques that can be deployed across institutions and markets.
Unico’s data sorts classified attacks into three tiers. Physical presentation attacks, such as a printed photo or a face held up to a camera, accounted for 30.9 percent of classified attacks. Simple injection attacks, in which a manipulated image or video stream is fed directly into the verification pipeline, made up the largest share at 45.8 percent. Sophisticated fraud, including deepfakes, injection, and physical manipulations involving curved monitors or mirrors, already represented 23.3 percent.
The report characterizes the middle tier as a “waiting room” for more advanced fraud, noting that attackers using simple injection methods are only “one cheap step” away from moving into the sophisticated fraud category. It also says monthly classified injection cases grew by roughly 9x over the observation window, while the cost of executing a sophisticated attack has fallen by more than 100x compared with a few years ago.
That shift has major implications for identity verification providers and the organizations that depend on them. According to the report, modern liveness detection has made the crudest forms of fraud easier to contain, but the lower cost of advanced tooling is pushing attackers toward injection, synthetic identities, and deepfake-enabled fraud. The result is a threat environment in which fraud is becoming more technically capable at the same time that the economics of attack are improving.
The report also highlights the networked nature of the threat. Unico found that a single evaluation entity in its global base had been tied to 949 distinct identity documents, while the top five entities each carried more than 850. One observed fraud actor targeted as many as 30 different businesses, according to the report.
The findings point to a structural weakness in isolated fraud defences. A company that sees only its own verification data may treat a repeat offender as a first-time visitor, even if that same actor has already been blocked elsewhere. The report argues that fraud now operates as a network, and that defences must evolve in the same direction.
The authors are careful to address the privacy and data-sharing implications of that argument. The report says connected fraud defense does not require institutions to pool customer records, but instead to exchange fraud signals that can indicate whether an identity or actor has previously been seen, flagged, or rejected elsewhere. “What travels is the fact of the fraud, not the identity of the customer,” the report says.
The report places those findings within a broader market shift away from static, point-in-time identity checks. Liminal’s research cited in the report indicates that buyers are moving toward continuous, behavioral, and device-based defenses that adapt in real time, with 76 percent ranking device fingerprinting as their most effective defense against AI-enabled fraud.
The report’s conclusion is that identity verification has become a core business risk function rather than a compliance checkbox. As AI-enabled fraud becomes more sophisticated, synthetic, and cross-institutional, the authors argue that static and isolated defenses will be poorly matched to the threat.
Unico provides identity verification and fraud prevention technology combining biometric verification, deepfake and spoofing detection, and fraud risk classification. The company says its platform has processed more than three billion verifications and prevents fraud across onboarding, account recovery, high-value transactions, payment authorization, and multi-account detection.
–
By the ID Tech Editorial Team






Follow Us