More than 220,000 fraud-risk cases were recorded in the UK National Fraud Database during the first half of 2026, with identity fraud accounting for 59% of the total, according to fraud-prevention service Cifas.
The figures put identity compromise at the centre of several linked risks for banks, card issuers, retailers and telecom providers. Cifas said identity-fraud cases increased 9% from the first half of 2025 to nearly 130,000. Bank accounts and plastic cards were the main targets, together accounting for 68% of those cases.
These are records submitted to the Cifas database, not a count of every fraud committed in the UK, unique victims or confirmed financial losses. Changes in reporting, membership and detection can also affect recorded volumes. Even with those limits, the category mix points to control pressure at onboarding, account recovery, authentication and transaction monitoring.
Money muling rose 69%
Cifas reported more than 13,000 cases linked to money muling, a 69% increase from the first six months of 2025. Mule activity represented 30% of all “misuse of facility” cases, a category in which a genuine account or product holder misuses the facility.
People under 30 accounted for 57% of recorded muling cases, including 17% involving people under 21. That distribution matters to payment providers because mule controls cannot end with identity verification. A customer may pass onboarding using genuine credentials and later receive and forward criminal proceeds.
Practical controls therefore need to connect onboarding signals with post-opening behaviour: rapid inbound-and-outbound movement, abrupt changes in counterparties, unusual use of newly opened accounts and clusters of accounts linked by devices or beneficiaries. Providers also need a process for distinguishing complicit account use from customers who have been manipulated, particularly where younger users are targeted through social media or false job and investment offers.
Account takeover and SIM swaps test authentication
Facility-takeover reports increased 5% to nearly 40,000 cases. Within that category, Cifas said online-retail account takeovers rose 84% and plastic-card account takeovers rose 59% from the same period a year earlier.
The most striking percentage change was in unauthorised SIM-swap cases, which Cifas said increased 402%. The organisation linked SIM swapping to interception of security codes and the bypass of account protections. Cifas did not disclose the underlying number of SIM-swap cases in its public release, so the percentage should not be read as evidence that SIM swapping is the largest fraud category.
For payment firms, the trend is a warning against treating possession of a phone number as conclusive proof of customer control. Recent SIM changes, device changes, password resets and payee creation can be combined as risk signals. Higher-risk activity may justify stronger reauthentication or a temporary hold, provided controls are calibrated to avoid unnecessarily blocking legitimate customers.
Identity controls face synthetic and manipulated evidence
Cifas said criminals are increasingly using synthetic identities, AI-enabled impersonation and digitally manipulated documents. It also reported that people aged 61 and over made up the largest group of identity-fraud victims, while the sharpest increase was among people aged 21 to 30, where cases rose 32%.
The combination broadens the responsibility across the payment chain. Identity-verification vendors must test whether document and liveness controls resist manipulated evidence. Banks and issuers need to examine whether apparently valid identities are connected to reused devices, addresses or funding sources. Retailers and wallet providers need account-recovery controls that do not allow a compromised email address or phone number to become the sole route back into an account.
No single control addresses the full sequence. Identity fraud can open an account, account takeover can seize an existing facility, and mule networks can move the proceeds through accounts held in genuine names. The Cifas data support treating those events as connected signals rather than separate fraud queues.
The operational priority is not simply adding friction everywhere. It is placing stronger checks at moments where multiple risk signals converge, while preserving clear escalation and recovery paths for legitimate customers. Cross-sector sharing among financial institutions, retailers, telecom companies and fraud databases can help expose activity that appears ordinary when viewed by only one provider.