Three years ago, deepfakes were a footnote in fraud statistics at 0.1% of attempts. Today, one in fifteen fraud attempts involves one, and in Germany, deepfake incidents grew 53% in 2025 alone, according to Sumsub.
Time for a sober stocktake. For this article, I compiled the fraud reports of the major identity verification providers, the FBI and BSI numbers, the detection studies, and the current state of legislation, and had every key figure cross-checked. Deliberately without how-to guides or tool tips, but with everything you should know about the risk.
- The deepfake share of fraud attempts rose from 0.1 to 6.5% in three years (Signicat), and in 2024 there was a deepfake attack every five minutes on average (Entrust). in Germany, deepfake incidents grew 53% in 2025 per Sumsub
- The damages are real: $25.6M in the Arup case, $893M in AI-related losses in the FBI's 2025 numbers alone, and Deloitte expects up to $40B in GenAI fraud losses in the US by 2027
- People massively overestimate themselves: only 0.1% reliably detect all deepfake types (iProov). Regulation is responding, with the EU labeling requirement applying from August 2, 2026
1. The Key Numbers at a Glance
These numbers come from different surveys with different methodologies. But they all point in the same direction, and steeply upward.
2. The Growth: From Footnote to Mass Phenomenon
The cleanest before-and-after measurement comes from Signicat, which surveyed 1,206 fraud decision-makers across seven European countries:
From 0.1 to 6.5% in three years. Signicat itself puts the growth of deepfake fraud attempts at 2,137%, and according to the study, deepfakes are now the most common form of digital identity fraud in Europe.
Other measurements confirm the pace:
Sumsub registered a tenfold increase in deepfake incidents worldwide from 2022 to 2023 alone. Entrust (then still operating as Entrust Onfido) counted a deepfake attack every five minutes on average across its verification platform in 2024, and in its latest report, one in five biometric fraud attempts is already a deepfake. Resemble AI's incident database recorded 1,567 verified individual incidents for 2025.
3. Country Comparison: Europe Is Catching Up on Fraud
The current Sumsub report shows how quickly deepfake attacks grew in the major European markets in 2025:
Germany gets off comparatively lightly at +53%, while France and the UK nearly doubled. The most curious value comes from the Maldives at +2,100%, an outlier most likely explained by a small baseline. Globally, the "sophisticated fraud" category (multi-step, coordinated attacks, including AI-generated identities) grew 180%.
4. Germany: Between Awareness and Helplessness
For Germany, the 2026 cybersecurity monitor by the BSI and the police crime prevention agency (3,060 respondents, April 2026) provides the first official numbers on how people handle AI-driven fraud. Only 19% of respondents verify the source of suspicious content, and 32% use none of the verification steps surveyed.
Just as interesting is what Germans think about deepfakes. The Bitkom survey from June 2026 (1,006 people aged 16+) shows a population caught between awareness and helplessness:
Nine in ten consider deepfakes dangerous, but only a third trust themselves to spot one. The next section shows how justified that skepticism is.
5. Detection: The Dangerous Overconfidence
The most uncomfortable number in all of deepfake research comes from an iProov study with 2,000 participants in the UK and US:
Only 0.1% of participants could reliably identify all deepfake types shown. Videos performed worst. Participants were 36% less likely to recognize synthetic videos than synthetic images.
The real problem is the gap between self-image and reality:
According to the BSI, 47% of Germans believe they can recognize AI-generated content, but only 28% have ever actively looked for inconsistencies in an image or video. This overconfidence is exactly the opening fraudsters exploit. Those who feel certain don't verify.
6. The Damages: From Single Case to Billion-Dollar Problem
The Arup case is more than an anecdote. A finance employee transferred $25.6 million after a video call in which both the "CFO" and several "colleagues" were deepfakes. The case shows the real risk. Deepfakes defeat exactly the verification mechanisms companies have relied on, namely the face and voice of familiar people.
The FBI's move is remarkable, too:
The Internet Crime Complaint Center reports a dedicated AI category for the first time in its 25-year history: 22,364 complaints with $893 million in damages for 2025, most of it investment fraud ($632 million).
7. Industries: Where Deepfake Fraud Strikes
Deepfake fraud concentrates massively on the financial world. When Sumsub first broke down incidents by industry in 2023, 88% of all deepfake cases hit crypto services and another 8% hit fintechs.
The logic is simple. Deepfakes pay off where a passed video identification means direct access to money. According to Signicat, AI-assisted fraud now accounts for 42.5% of all detected fraud attempts in the financial sector, while only 22% of financial institutions use AI-based fraud detection. That gap between attack and defense technology is the industry's real problem.
8. Politics and Elections: Two Documented Precedents
On election deepfakes, I deliberately separate documented incidents from speculation. Two cases are cleanly documented.
First, Slovakia in September 2023. Two days before the parliamentary election, a fake audio clip circulated showing the liberal frontrunner allegedly planning election manipulation, spread during the legal pre-election silence when media could barely issue corrections. Over 100,000 views on Facebook alone are documented. A causal effect on the election result is not.
Second, New Hampshire in January 2024. AI robocalls with a cloned Biden voice urged voters to skip the primary. The consequences were real: a $6 million FCC fine against the perpetrator, a $1 million settlement by the telecom carrier involved, and criminal charges for voter suppression (though a jury acquitted him on all counts in June 2025).
9. The Biggest Victim Problem: Non-Consensual Content
The fraud focus often obscures who deepfakes target most. The first systematic count by Deeptrace (now Sensity) in 2019 found that 96% of all deepfakes circulating online were non-consensual pornographic content, exclusively targeting women.
Newer data shows the pattern persists:
A widely cited analysis by Security Hero found around 95,800 deepfake videos online in 2023, 98% of them pornographic, again 99% targeting women. And in Resemble AI's 2025 incident database, 20% of all verified incidents involved non-consensual intimate content or abuse material. This is precisely where the toughest new laws focus, from the US TAKE IT DOWN Act to Germany's Section 184k.
10. Regulation: The Legal Framework Catches Up
2025 and 2026 are the years lawmakers worldwide are getting serious:
The most important date for Europe is August 2, 2026. From then on, the labeling requirement of Article 50 of the EU AI Act applies. Deepfakes must be disclosed as artificially generated, machine-readable and recognizable to humans. Violations carry penalties of up to €15 million or 3% of worldwide annual revenue. How enforceable that proves will be one of the most interesting regulatory questions of the coming years.
11. Milestones: From Reddit to the EU Labeling Requirement
What strikes me is the acceleration at the end of the timeline. Six years passed between the 2017 Reddit post and the first major fraud case. Between the Arup case and the first comprehensive labeling requirement, less than three.
12. Conclusion: A Fraud Problem, Not a Panic Topic
The data justifies neither downplaying nor panic. Deepfake fraud is growing at triple-digit rates, damages run into the billions, and human detection ability is demonstrably worse than our self-image. At the same time, the deepfake share of total fraud remains in the single digits, regulation is catching up at high speed, and documented election interference remains a set of isolated cases rather than a widespread phenomenon.
The practical takeaway for you and your company is unspectacular but effective. For money and identity matters, stop relying on face or voice alone; use callbacks via known numbers and second-channel confirmations. Exactly that would have prevented the Arup case.
For the technology behind generative image models, see my AI image statistics. And for the industry-wide picture, check my AI statistics.






