Global Identity Fraud Report revealing eight-month ‘mega-attack’

March 2024 Editor's Choice, Security Services & Risk Management

AU10TIX recently released its Q4 Global Identity Fraud Report. Drawing insights from millions of transactions processed across 249 countries from October to December 2023, the report uncovers significant trends in large-scale organised identity fraud. This special edition of AU10TIX’s recurring report goes beyond Q4 to reveal an eight-month-long coordinated identity fraud mega-attack for the first time. Between May and December 2023, organised criminals executed 22 080 fraudulent onboarding attempts using AI-generated variations of a single passport.

AU10TIX researchers have subsequently identified two never-before-seen distinct patterns of ‘mega’ identity fraud attacks, which they have categorised as ‘sudden burst’ and ‘slow burn.’ The sudden burst is represented by the mega-attack involving 22 080 attacks, half of which took place over a short duration of 2-3 weeks. The slow burn refers to the average mega-attack, which involves around 2000 AI-generated IDs being used five to six times per day over a long duration, usually 12 months. The company detected more than ten slow-burn attacks in 2023.

Payments and cryptocurrency were the most targeted sectors in these mega-attacks, but in a surprising development, attacks targeting the social media sector increased by more than 21%. Data suggests that this trend might be tied to organised crime groups attempting to establish social credibility for fake accounts, which will later be used for money laundering and terrorism financing activities.

“We detected these mega-attacks by cross-referencing anonymised ID data against AU10TIX’s consortium of 60+ top-tier organisations, demonstrating the power of collective expertise in identifying complex fraud patterns that may evade individual entities,” said Dan Yerushalmi, CEO of AU10TIX. “Sophisticated AI and deep-fake technology are helping organised crime groups escalate their attack numbers exponentially, but we will continue working to make the world a safer and more secure place.”

Key Q4 trends

Bitcoin value surge led to increased cryptocurrency sector attacks

In Q3, AU10TIX reported a shift in attacks from the cryptocurrency sector to the payments industry, likely in response to the EU’s Markets in Crypto Assets (MiCA) regulations, which require stringent Know-Your-Customer (KYC), Know-Your-Business (KYB) and Anti-Money Laundering (AML) screening for trading platforms. Although this trend continued in Q4, it was impacted by the rising value of Bitcoin throughout the quarter, which attracted both legitimate traders and scammers. As a result, the percentage of global attacks targeting the cryptocurrency sector rose from 23% to 32%. Still, it remained far below the 47% spike of Q2.

Payments tops list as most heavily targeted industry

The payments sector remained responsible for nearly half of all global Q4 fraud attempts. This industry does not have a widespread and globally accepted regulatory framework, so it is crucial that payment organisations strengthen their security protocols to protect consumers from fraudulent transactions.

AU10TIX offers four actionable insights to help organisations protect against identity fraud:

1. Selfie-based biometrics are proven to be effective prevention against fake account onboarding.

2. Robust KYB, KYC, and AML screening are must-haves to protect the reputation of a business.

3. Consortium validation increases privacy and magnifies fraud detection.

4. Be aware that fraudsters are using social media platforms to establish fake ID credibility.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Who is to blame for autonomous mistakes?
Editor's Choice Security Services & Risk Management Industrial (Industry) Mining (Industry)
Most supply agreements for AI-integrated equipment still closely resemble plant hire contracts from ten years ago: bilateral, human-focused, and silent on who bears the risk when a machine makes a decision on its own.

Read more...
Beyond the checkpoint
Veracitech Editor's Choice
For decades, mining corporations have treated employee screening as a necessary friction point, an operational cost to be managed rather than a strategic capability to be optimised. A new generation of full-body X-ray technology, purpose-built for the realities of high-throughput precious-metals environments, is beginning to change that calculus.

Read more...
Persistent surveillance with rapid deployment
Editor's Choice
Sky Robots has introduced an aerial drone system designed to operate as a consistent layer within security environments, addressing long-standing challenges around visibility and response across large or complex sites.

Read more...
The control room problem that nobody wants to talk about
Technews Publishing Editor's Choice
WhatsApp has become the unofficial backbone of security communications across the mining and industrial sectors, but it was never designed to be a security tool.

Read more...
Controlling access for people and vehicles
IDEMIA STid Security Technews Publishing Editor's Choice Access Control & Identity Management Asset Management Industrial (Industry) Mining (Industry)
When it comes to access control, the security requirements of mines and the industrial sector are similar, requiring a layered approach that combines physical barriers, digital authentication, and continuous monitoring to protect personnel, assets, and operational continuity.

Read more...
957 women killed in three months
News & Events Security Services & Risk Management
Despite years of summits, task teams and public commitments, South Africa’s femicide rate remains around five times higher than the global average, and too few are using the legal lifelines available.

Read more...
Africa’s opportunity to shape the future of human-centred AI
AI & Data Analytics Security Services & Risk Management
Across the Global South, countries are not yet locked into decades of legacy AI systems, energy-intensive infrastructure, or governance frameworks designed for a different technological era. That creates something rare in technology development: a cleaner slate.

Read more...
AURA appoints Taryn Winer as global head of people
News & Events Security Services & Risk Management
Following its €13,5 million Series B funding round last year and accelerating international expansion, particularly across the United States, AURA has appointed Taryn Winer as global head of people.

Read more...
95% do not have full trust in cybersecurity vendors
Information Security Security Services & Risk Management
Trust in cybersecurity vendors is fragile, difficult to measure, and increasingly shaping risk posture at both operational and board levels. Lack of verifiable transparency undermines cybersecurity decision-making, according to Sophos-backed research.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.