← Back to blog May 22, 2026

The deepfake economy: what changed in 2026

How much has deepfake fraud grown?

Sumsub measured a 4× year-over-year rise in deepfakes on its verification platform, reaching 7% of all fraud attempts and creeping toward 11% by 2026. Pindrop recorded a 1,300% surge across contact centers. Gartner found 62% of organizations had faced a deepfake attack. Humans score 0.07 at detecting them, where 0 is guessing.

In February 2024, an engineer at Arup's Hong Kong office joined what looked like a routine video call with the company's UK-based CFO and a handful of senior colleagues. Every face on the call was synthetic. Every voice. By the time he had wired funds across fifteen transactions, Arup was out roughly $25 million.

The story is more than two years old. What has changed since is that the playbook is no longer novel. The tools that made it possible are now consumer products, the price has collapsed, and the volume has reached numbers that make detection a different kind of problem than it was when the Arup case happened.

The numbers

A few data points worth holding in your head, because they get cited in regulator briefings and they should:

You can argue with any one of those numbers. The shape is consistent across the reports: the volume is up sharply, human detection is at the level of a coin flip, and most defenders have not caught up.

What actually changed

Four shifts in the last twelve months, in roughly the order they hit the threat model:

Real-time, not pre-rendered. The Arup-style attack required a rendered video. Today's tooling drives a synthetic face onto a live video stream, with audio, on consumer hardware. That changes the defender problem from "spot the fake in a recording" to "spot the fake during a live exchange."

Off-the-shelf, not custom. What needed a researcher with GPU time in 2023 is now a SaaS subscription. The barrier to entry collapsed from "build a model" to "buy a seat." Most of the attempts hitting KYC platforms in 2026 are not novel attacks; they are the output of three or four widely-circulating tools.

Cross-modal. The interesting attacks now stack. A synthetic document, a matching deepfake selfie, a virtual camera feeding the browser, a device fingerprint farm presenting clean machines, and a behavioral profile that looks plausible. Each layer alone is detectable. Each layer combined is what catches single-signal defenders.

Voice has caught up with video. Voice cloning is now a few seconds of source audio for a usable result. Pindrop's contact-center numbers are not theoretical. The attacks happen during account-recovery calls, refund-authorization calls, and high-net-worth client interactions. The 2026 social-engineering playbook assumes the caller can sound exactly like the customer.

Where this is hitting hardest

Five surfaces are taking most of the volume:

  1. KYC onboarding. Synthetic ID + matching synthetic selfie + virtual camera. The classic combination, and the one most KYC vendors are measured against.
  2. Contact center. Voice clones authenticating against name-and-DOB challenges or even older passive-voiceprint systems.
  3. Video meetings and wire authorization. The Arup pattern, now generalized. CFO impersonation, board-member impersonation, vendor-CEO impersonation. Wire-fraud teams treat any video-only authorization as suspicious.
  4. Age verification. Particularly the UK Online Safety Act surface. Synthetic faces aging up or down to clear thresholds. The certification regime in the UK (HEAA) is partly a response to this.
  5. Real-time impersonation of platform users. Synthetic faces on dating sites, on creator platforms, in remote-employment fraud. Not strictly an identity-verification problem, but the same defenders end up holding the bag.

What the defender response actually looks like

The honest read is that no single signal is enough and most platforms are in the middle of figuring out which signal stack to commit to. The categories that are doing real work:

Multi-modal liveness. Random pose sequences, motion challenges, color-sequence anti-replay, depth data where the camera supports it. The current crop of consumer deepfake tools still trips on at least one of these, particularly anything that asks the device to respond to a server-issued challenge mid-capture.

Multi-provider deepfake detection. Industry consensus has converged on the position that no single model wins. Running two or more APIs in parallel and combining their scores beats any of them alone. The major commercial detectors (Hive, Azure AI Content Safety, Sensity, Reality Defender) have different blind spots. Combining is the work.

Device, network, and behavioral signals. The same device fingerprint trying a hundred attempts is a stronger signal than analyzing any one of the frames. So is keystroke biometrics, paste detection, mouse movement, time-on-task. Behavioral analytics on the capture flow are doing more lifting in 2026 than they were in 2024, partly because the deepfakes themselves got better.

Identity graph and cross-attempt linkage. Same person, different document, different selfie, different country. The clue is rarely in a single submission. It is in the fifth, when a cluster of attributes overlaps with submissions one through four.

Continuous verification. Not just at onboarding. Re-verify before high-value transactions, on device change, on anomalous behavior. The "verify once, trust forever" model is what the Arup attackers exploited and what no platform should still be running for high-value flows.

What is not working

Three patterns that look like solutions and aren't:

A "deepfake check" sold as a single binary signal. Vendor evaluation decks show 99% lab accuracy. Real-world catch rate on a 2026 synthesis pipeline is lower, often substantially so. The 99% number is on the vendor's training and evaluation distribution. Your traffic is not that distribution.

Static thresholds from 2024. The base rate of deepfake submissions has risen sharply. If you calibrated your false-positive rate against the 2024 baseline, you are letting through cases now that you would have flagged then, or you are flagging too many of the legitimate ones. Re-calibrate quarterly at minimum.

Opaque risk scores. When a regulator asks why you flagged or didn't flag a specific submission, "the model said so" is not an acceptable answer. The reasoning chain has to be inspectable. This is the part of the response landscape that is changing fastest, partly because the EU AI Act gives it teeth and partly because the larger customers are starting to require it in procurement.

The regulatory dimension

The 2024 deepfake conversation was mostly about reputational risk and election interference. The 2026 conversation has compliance attached to it.

The EU AI Act is in force. Biometric and identification systems have specific obligations, including human oversight on automated decisioning and documentation of training data sources. The UK Online Safety Act has driven age-assurance specifications (ACCS-certified estimation, HEAA-compliant flows) that explicitly account for synthetic-media bypass attempts. US state-level deepfake laws, particularly around financial impersonation and election interference, have expanded enough that defenders need a per-jurisdiction view.

None of this is settled. The interesting fights over the next twelve months will be over what counts as "reasonable" detection effort, how much human review is required, and what disclosure obligations attach to flagging decisions.

What the next twelve months actually look like

Three predictions worth holding loosely:

Multi-modal liveness becomes the default rather than a premium SKU. Vendors that gate it behind enterprise pricing will lose mid-market deals to vendors that bundle it.

Multi-provider deepfake detection becomes table stakes. Single-vendor stacks read as 2024 architecture in 2026 procurement.

The disclosure floor rises. The combination of EU AI Act, US state-level rules, and customer pressure pushes toward named, inspectable fraud signals over composite risk scores. Vendors that can show their work win the contracts.

How Verifa thinks about this

The way Verifa is built reflects most of the above. Deepfake detection runs against multiple commercial providers because we agree with the industry consensus that no single model is enough, and we say so plainly rather than pretending we have a magic in-house detector. The signals we surface in the dashboard are named: liveness_no_blinks, liveness_robotic_timing, liveness_impossible_reaction, flashmark for color-sequence anti-replay, plus device, behavioral, and network signals. Reviewers and regulators see the actual reasons a session was flagged, not a 0-to-100 number.

The face-match and OCR models we trained ourselves; the deepfake detectors we did not. Drawing that line clearly matters more in 2026 than it did two years ago, because customers ask. They should keep asking.

Ready to get started?

Start verifying identities in minutes with Verifa's free plan. No credit card required.

Create Free Account