Fraud Article
Your verification has amnesia. Fraud remembers.
Fraud remembers. Verification often doesn’t. The full numbers arrive in the Identity Fraud Report 2027. But the pattern is already visible in the data we have.
Some identities never really disappear. They keep coming back to apply again and again. The same stolen document, the same face, the same device; rejected on one platform, then recycled on the next. And the next. We call them zombie identities. And traditional onboarding checks weren’t built to recognize a fraudster coming back for another attempt.
That’s the problem this piece opens up. The full numbers arrive in the Identity Fraud Report 2027, but the pattern is already visible in the data we have.
Fraud isn’t new. It’s persistent.
According to the Veriff Identity Fraud Report 2026, 4.18% of all verification attempts in 2025 were flagged as fraudulent: roughly 1 in every 25, and the rate has held above 4% for the third year in a row. Impersonation accounted for more than 85% of those attempts. E-commerce marketplaces hit a 19.2% net fraud rate. Financial services crossed 5.5%.
These aren’t isolated incidents. And a steady rate hides something our fraud teams see every day: the same identities, documents, and faces cycling through verification, again and again, across platforms and time.
These figures represent two years of year-over-year data, with full regional and industry coverage from the previous report. The 2027 report will go deeper.
Why zombie identities keep working
A verified identity is a proven asset. Once a document clears a check somewhere, it has value. That value gets reused. The same document template comes back with a new name and date of birth. The same selfie appears across different accounts. The same device runs dozens, sometimes hundreds, of sessions. And a rejection isn’t the end, either. It’s feedback: fraudsters adjust the lighting, swap the document, change the device, and try again.
This is the zombie identity mechanic: not a one-time fraud attempt, but an identity that keeps coming back because the check it faces has no memory of where it’s been.
Single-session KYC can confirm a document is genuine and a face is live. But a stolen document is genuine, and a mule’s face is live. What the check cannot do is recognize that this document may have already failed three applications last month, or that this face has been flagged at two other platforms. Every attempt looks like the first – even when it isn’t. That’s how so much new account fraud gets through.
Coming this November
Learn how verified credentials are stolen, rented, and reused across platforms, and how to stop the cycle.
What verification with memory looks like
Closing this gap means looking beyond the current session. That means biometric blocklists that flag a face tied to confirmed fraud. CrossLinks that connect the same document, device, IP or network appearing under different names. And intelligence that spans organizations. So a repeat offender blocked at one platform is recognized at the next. Just as important, it has to tell a fraudster’s fifth attempt apart from an honest customer’s second try after a blurry photo.
That’s what Veriff’s Fraud Prevention suite is built to do: give onboarding a memory, so genuine customers move through quickly while zombie identities get recognized and stopped.
The 2027 report goes further
The Identity Fraud Report 2027 arrives in November. It will quantify what this piece introduces: how often the same identity, document, face, or device returns across attempts and platforms – and how much of the fraud Veriff detects is repeat activity, not new.
Reserve your copy to be the first to read the report this November.