Skip to main content

Deepfake Statistics 2026: Fraud, Detection & Laws

Current deepfake statistics for 2026: fraud cases, financial damages, detection rates, and the state of regulation. With verified sources.

FHFinn Hillebrandt
AI Basics
Deepfake Statistics 2026: Fraud, Detection & Laws
Links marked with * are affiliate links. If a purchase is made through such links, we receive a commission.

Three years ago, deepfakes were a footnote in fraud statistics at 0.1% of attempts. Today, one in fifteen fraud attempts involves one, and in Germany, deepfake incidents grew 53% in 2025 alone, according to Sumsub.

Time for a sober stocktake. For this article, I compiled the fraud reports of the major identity verification providers, the FBI and BSI numbers, the detection studies, and the current state of legislation, and had every key figure cross-checked. Deliberately without how-to guides or tool tips, but with everything you should know about the risk.

TL;DRKey Takeaways
  • The deepfake share of fraud attempts rose from 0.1 to 6.5% in three years (Signicat), and in 2024 there was a deepfake attack every five minutes on average (Entrust). in Germany, deepfake incidents grew 53% in 2025 per Sumsub
  • The damages are real: $25.6M in the Arup case, $893M in AI-related losses in the FBI's 2025 numbers alone, and Deloitte expects up to $40B in GenAI fraud losses in the US by 2027
  • People massively overestimate themselves: only 0.1% reliably detect all deepfake types (iProov). Regulation is responding, with the EU labeling requirement applying from August 2, 2026

1. The Key Numbers at a Glance

MetricDeepfake share of fraud attempts (Europe)
Value (as of)6.5%, or 1 in 15 attempts (Signicat, 2024)
MetricFrequency of deepfake attacks
Value (as of)Every 5 minutes (Entrust Onfido, 2024)
MetricShare of biometric fraud attempts
Value (as of)1 in 5 (Entrust, Nov 2025)
MetricDeepfake incidents in Germany (annual growth)
Value (as of)+53% (Sumsub, 2025)
MetricShare of deepfake cases: crypto industry
Value (as of)88% (Sumsub, 2023)
MetricDocumented damages 2025
Value (as of)~$1.3B (Resemble AI)
MetricPeople who reliably detect deepfakes
Value (as of)0.1% (iProov, Feb 2025)

These numbers come from different surveys with different methodologies. But they all point in the same direction, and steeply upward.

2. The Growth: From Footnote to Mass Phenomenon

The cleanest before-and-after measurement comes from Signicat, which surveyed 1,206 fraud decision-makers across seven European countries:

20222024Share of fraud attempts0.1%6.5%+6.4pp
Source: Signicat (2024 survey, published Feb 2025)
|
CC BY 4.0
gradually.ai

From 0.1 to 6.5% in three years. Signicat itself puts the growth of deepfake fraud attempts at 2,137%, and according to the study, deepfakes are now the most common form of digital identity fraud in Europe.

Other measurements confirm the pace:

Sumsub registered a tenfold increase in deepfake incidents worldwide from 2022 to 2023 alone. Entrust (then still operating as Entrust Onfido) counted a deepfake attack every five minutes on average across its verification platform in 2024, and in its latest report, one in five biometric fraud attempts is already a deepfake. Resemble AI's incident database recorded 1,567 verified individual incidents for 2025.

3. Country Comparison: Europe Is Catching Up on Fraud

The current Sumsub report shows how quickly deepfake attacks grew in the major European markets in 2025:

France
+96%
United Kingdom
+94%
Spain
+84%
Germany
+53%
Source: Sumsub Identity Fraud Report (Nov 2025)
|
CC BY 4.0
gradually.ai

Germany gets off comparatively lightly at +53%, while France and the UK nearly doubled. The most curious value comes from the Maldives at +2,100%, an outlier most likely explained by a small baseline. Globally, the "sophisticated fraud" category (multi-step, coordinated attacks, including AI-generated identities) grew 180%.

4. Germany: Between Awareness and Helplessness

For Germany, the 2026 cybersecurity monitor by the BSI and the police crime prevention agency (3,060 respondents, April 2026) provides the first official numbers on how people handle AI-driven fraud. Only 19% of respondents verify the source of suspicious content, and 32% use none of the verification steps surveyed.

Just as interesting is what Germans think about deepfakes. The Bitkom survey from June 2026 (1,006 people aged 16+) shows a population caught between awareness and helplessness:

StatementKnow the term deepfake (2024: 56%)
Share75%
StatementConsider deepfakes dangerous
Share89%
StatementHave already encountered a deepfake (certain or suspected)
Share61%
StatementConfident they can reliably detect deepfakes
Share34%

Nine in ten consider deepfakes dangerous, but only a third trust themselves to spot one. The next section shows how justified that skepticism is.

5. Detection: The Dangerous Overconfidence

The most uncomfortable number in all of deepfake research comes from an iProov study with 2,000 participants in the UK and US:

Germans confident they can spot deepfakes (Bitkom)
34%
Reliably detect all deepfake types (iProov)
0.1%
Sources: iProov (Feb 2025), Bitkom (Jun 2026)
|
CC BY 4.0
gradually.ai

Only 0.1% of participants could reliably identify all deepfake types shown. Videos performed worst. Participants were 36% less likely to recognize synthetic videos than synthetic images.

The real problem is the gap between self-image and reality:

According to the BSI, 47% of Germans believe they can recognize AI-generated content, but only 28% have ever actively looked for inconsistencies in an image or video. This overconfidence is exactly the opening fraudsters exploit. Those who feel certain don't verify.

6. The Damages: From Single Case to Billion-Dollar Problem

Case/SurveyArup (Hong Kong)
Damage$25.6M
DetailVideo call with deepfake CFO and colleagues, 15 transfers (Jan 2024)
Case/SurveyFBI IC3: AI-related cases 2025
Damage$893.35M
Detail22,364 complaints, first dedicated AI category (report Apr 2026)
Case/SurveyResemble AI: documented deepfake losses 2025
Damage~$1.3B
Detail1,567 verified incidents; headline figure $1.28B, category sum $1.42B; no loss figure for over 80% of them
Case/SurveyDeloitte forecast: GenAI fraud, US
Damageup to $40B (2027)
DetailAggressive scenario, up from $12.3B in 2023 (forecast May 2024)

The Arup case is more than an anecdote. A finance employee transferred $25.6 million after a video call in which both the "CFO" and several "colleagues" were deepfakes. The case shows the real risk. Deepfakes defeat exactly the verification mechanisms companies have relied on, namely the face and voice of familiar people.

The FBI's move is remarkable, too:

The Internet Crime Complaint Center reports a dedicated AI category for the first time in its 25-year history: 22,364 complaints with $893 million in damages for 2025, most of it investment fraud ($632 million).

7. Industries: Where Deepfake Fraud Strikes

Deepfake fraud concentrates massively on the financial world. When Sumsub first broke down incidents by industry in 2023, 88% of all deepfake cases hit crypto services and another 8% hit fintechs.

The logic is simple. Deepfakes pay off where a passed video identification means direct access to money. According to Signicat, AI-assisted fraud now accounts for 42.5% of all detected fraud attempts in the financial sector, while only 22% of financial institutions use AI-based fraud detection. That gap between attack and defense technology is the industry's real problem.

8. Politics and Elections: Two Documented Precedents

On election deepfakes, I deliberately separate documented incidents from speculation. Two cases are cleanly documented.

First, Slovakia in September 2023. Two days before the parliamentary election, a fake audio clip circulated showing the liberal frontrunner allegedly planning election manipulation, spread during the legal pre-election silence when media could barely issue corrections. Over 100,000 views on Facebook alone are documented. A causal effect on the election result is not.

Second, New Hampshire in January 2024. AI robocalls with a cloned Biden voice urged voters to skip the primary. The consequences were real: a $6 million FCC fine against the perpetrator, a $1 million settlement by the telecom carrier involved, and criminal charges for voter suppression (though a jury acquitted him on all counts in June 2025).

9. The Biggest Victim Problem: Non-Consensual Content

The fraud focus often obscures who deepfakes target most. The first systematic count by Deeptrace (now Sensity) in 2019 found that 96% of all deepfakes circulating online were non-consensual pornographic content, exclusively targeting women.

Newer data shows the pattern persists:

A widely cited analysis by Security Hero found around 95,800 deepfake videos online in 2023, 98% of them pornographic, again 99% targeting women. And in Resemble AI's 2025 incident database, 20% of all verified incidents involved non-consensual intimate content or abuse material. This is precisely where the toughest new laws focus, from the US TAKE IT DOWN Act to Germany's Section 184k.

10. Regulation: The Legal Framework Catches Up

2025 and 2026 are the years lawmakers worldwide are getting serious:

RegionEU
LawAI Act, Art. 50 (labeling requirement)
Status (as of July 2026)Core obligations apply from Aug 2, 2026; penalties up to €15M or 3% of global revenue
RegionUSA
LawTAKE IT DOWN Act
Status (as of July 2026)In force since May 2025; 48-hour platform takedown duty applies since May 2026
RegionUSA
LawNO FAKES Act
Status (as of July 2026)Reintroduced May 2026, passed the Senate Judiciary Committee unanimously in June 2026
RegionGermany
LawNew Section 201b Criminal Code (draft)
Status (as of July 2026)Up to 2 years' imprisonment for deceptive deepfakes; stuck in committee for months, not yet passed
RegionDenmark
LawCopyright approach (face/voice)
Status (as of July 2026)Draft since June 2025, no final passage documented as of mid-July 2026
RegionUK
LawOnline Safety Act
Status (as of July 2026)Sharing sexualized deepfakes a priority offence since Sept 2024

The most important date for Europe is August 2, 2026. From then on, the labeling requirement of Article 50 of the EU AI Act applies. Deepfakes must be disclosed as artificially generated, machine-readable and recognizable to humans. Violations carry penalties of up to €15 million or 3% of worldwide annual revenue. How enforceable that proves will be one of the most interesting regulatory questions of the coming years.

11. Milestones: From Reddit to the EU Labeling Requirement

Dec 2017
The term is born
A Reddit user named “deepfakes” posts the first AI face-swap videos. The name sticks.
2019
First inventory
Deeptrace (now Sensity AI) systematically counts deepfakes online: 96% are non-consensual pornography, exclusively targeting women.
Sep 2023
Election deepfake in Slovakia
A fake audio clip discredits a leading candidate two days before the election, during the pre-election silence period.
Nov 2023
Tenfold increase
Sumsub reports a 10x rise in deepfake incidents compared to 2022.
Jan 2024
Arup fraud and Biden robocall
A deepfake video call costs engineering firm Arup $25.6M; in New Hampshire, robocalls imitate Biden's voice.
Sep 2024
$6M fine
The FCC fines the creator of the Biden robocalls $6 million.
Feb 2025
The detection shock
iProov shows that only 0.1% of people reliably detect all deepfake types.
May 2025
TAKE IT DOWN Act
The US makes non-consensual intimate deepfakes a federal crime.
Jul 2025
Germany follows
The Bundesrat introduces the new Section 201b of the Criminal Code against deceptive deepfakes.
Apr 2026
FBI adds an AI category
The IC3 reports AI-related fraud separately for the first time: $893M in damages in 2025.
Apr 2026
Germany's BSI measures verification habits
The cybersecurity monitor by the BSI and police shows that only 19% of Germans verify the source of suspected AI content, and 32% run no checks at all.
Aug 2026
EU labeling requirement
The transparency obligations of Article 50 of the AI Act become applicable. Deepfakes must be labeled as such.

What strikes me is the acceleration at the end of the timeline. Six years passed between the 2017 Reddit post and the first major fraud case. Between the Arup case and the first comprehensive labeling requirement, less than three.

12. Conclusion: A Fraud Problem, Not a Panic Topic

The data justifies neither downplaying nor panic. Deepfake fraud is growing at triple-digit rates, damages run into the billions, and human detection ability is demonstrably worse than our self-image. At the same time, the deepfake share of total fraud remains in the single digits, regulation is catching up at high speed, and documented election interference remains a set of isolated cases rather than a widespread phenomenon.

The practical takeaway for you and your company is unspectacular but effective. For money and identity matters, stop relying on face or voice alone; use callbacks via known numbers and second-channel confirmations. Exactly that would have prevented the Arup case.

For the technology behind generative image models, see my AI image statistics. And for the industry-wide picture, check my AI statistics.

Frequently Asked Questions

FH

Finn Hillebrandt

AI Expert & Blogger

Finn Hillebrandt is the founder of Gradually AI, an SEO and AI expert. He helps online entrepreneurs simplify and automate their processes and marketing with AI. Finn shares his knowledge here on the blog in 50+ articles as well as through his ChatGPT Course and the AI Business Club.

Learn more about Finn and the team, follow Finn on LinkedIn, join his Facebook group for ChatGPT, OpenAI & AI Tools or do like 17,500+ others and subscribe to his AI Newsletter with tips, news and offers about AI tools and online business. Also visit his other blog, Blogmojo, which is about WordPress, blogging and SEO.