UK businesses face a growing threat from identity fraud during the transaction phase.
According to Signicat’s The Battle in the Dark report, 35% of UK identity fraud attempts occur during transactions. Logins account for a further 29%.
While AI-generated deepfakes dominate cybersecurity headlines, Signicat urges businesses to look beyond the hype.
Traditional identity fraud forms remain the primary threat. These include stolen credentials, phishing, smishing, and account takeovers. Criminals now use artificial intelligence to execute these attacks faster and on a massive scale.
The transaction stage is the new battleground
The UK mirrors a wider global trend highlighted in the report. Across the studied markets, the transaction phase is the most exposed point in the customer journey. It represents 40% of all identity fraud attempts. The challenge no longer lies just in identifying a new customer. Fraudsters actively target existing consumers. They attack when people log in, access accounts, or authorise transactions.
“Today we talk a lot about deepfakes, and for good reasons. But we must not forget that classic forms of identity fraud are still growing,” says Thomas Osinga, Head of Identity Proofing at Signicat.
“This includes social engineering, where vulnerable people are targeted. It also covers phishing, smishing, and basic copies of ID documents. Fraudsters are not changing their approach. They use AI to industrialise the classic art of deception at scale.”
This shift means businesses must rethink digital trust. “Identity fraud prevention must move towards continuous verified trust. Checks must run silently in the background throughout the entire customer journey,” Osinga adds.
One in five transactions and onboarding processes linked to fraud
The financial and operational impact is substantial. Businesses estimate that 19% of the transactions they process and customers they onboard are fraudulent.
External industry statistics confirm this alarming trend. Smishing now accounts for 35% of all mobile phishing attempts, according to SentinelOne.
Meanwhile, AI-generated spear-phishing campaigns achieve a 54% click-through rate. This is over four times higher than traditional emails, Harvard Business Review reports.
Recommended reading
- Too Authentic to be Synthetic: The Psychology Behind AI Voice Scams
- Identity Fraud Set to Explode in 2026, Warn Security Pros
- Is It Now Practically Impossible To Identify Deepfakes?
- Report: More Than 50% of Fraud Is Now Driven by AI
To fight this, adding more visible friction or passwords is not the answer. Businesses must apply invisible security with continuous background checks. Companies can use real-time data like geolocation, IP analysis, and device metrics. This helps them spot anomalies without making the process harder for genuine customers.
New requirements for digital trust
The need for continuous identity verification will only grow. European Digital Identity (EUDI) Wallets will be available to European consumers by December 2027. At the same time, autonomous AI agents will increasingly perform actions for humans.
“As we transition to an era dominated by agentic AI, we move towards a relentless AI-to-AI battle,” concludes Osinga. “Fraudsters will weaponise AI. Autonomous AI agents will execute tasks for consumers. We will use AI technology to defend everything in the middle.”





