Impostor Fraud in 2025-26: Key Figures & B2B Onboarding Protection
6
Min
•
29.06.2026
$3.5 billion.
What the 2025 impostor fraud data reveals about your onboarding process
In June 2026, the US Federal Trade Commission published a figure that should have made headlines in every trade publication: $3.5 billion lost to identity impostor fraud in the United States in 2025. That is a threefold increase in five years. Impostor fraud now accounts for one in three reported frauds in the country.
In France, identity theft already generates over €6 billion in estimated economic losses, with 210,000 recorded victims.
Across Europe, scams have nearly doubled in a year. And deepfake fraud attempts jumped by 700% between Q1 2024 and Q1 2025.
What this data reveals is not just a cybersecurity problem.It is an onboarding problem. Every impostor who enters your customer portfolio did so through your onboarding process. They passed your identity verification. They convinced your controls. And they got what they were after before you realised anything was wrong.
What the FTC's 2025 data reveals, and why it matters for Europe
The FTC report, published on 15 June 2026, details a reality that European risk teams will recognise immediately.
Impostor scams are the most reported fraud category for the fifth year running. Nearly $1 billion was lost to fake businesses (banks, insurers, telecoms providers), and $920 million to government impersonation fraud.
The central vector: brand impersonation.A fraudster poses as a legitimate business, earns the target's trust, and pushes them to act: transfer funds, share data, sign up for a service.
This pattern knows no borders.
In Europe, the European Payments Council reported a similar surge in impersonation scams in late 2025, with vishing (voice phishing) cases doubling and growing pressure on financial institutions to reimburse victims, following the UK model, where the reimbursement rate for impersonation scams already stands at 78%.
The trend is clear: the faster digital journeys move, the wider the attack surface for impostors becomes.
The B2B angle: the blind spot of impostor fraud
Most reports on impostor fraud focus on individual victims. But for companies running B2B onboarding processes, the risk cuts both ways, and is often underestimated.
The impostor can be your prospect :
- A fictitious or hijacked company signing up for financing, leasing or insurance.
- An impersonated executive opening a business account.
- A fraudulent supplier joining your network by posing as a legitimate business.
This type of fraud takes several forms in B2B onboarding.
1. Fake companies and impersonated director identities (KYB)
Fraud involving vehicle registration documents, company registration extracts (Kbis in France) or incorporation certificates has exploded with generative AI.Fully AI generated synthetic documents, visually flawless, with consistent data, now allow fraudsters to "create" a fictitious company in minutes.
The risk is no longer just dealing with a financially struggling company. It is dealing with an entity that simply does not exist, or whose real directors have no idea someone is acting in their name.
2. Identity theft of directors and legal representatives
In onboarding processes that involve identity verification (KYC) of the legal representative, the impostor does not try to falsify company documents. They directly steal the identity of a real person.
With AI generated ID documents or video deepfakes, some basic liveness check systems can be bypassed.
Deepfake attempts on KYC processes have risen by +700% globally in a year, and by +281% in France specifically.
3. Cross-company synthetic identity fraud
A particularly sophisticated variant: the creation of "synthetic" company identities, combining real elements (the company registration number of a dormant business, a legitimate address, an authentic registration extract) with fabricated data (a fictitious legal representative, fraudulent bank details).
These profiles pass basic document checks but do not correspond to any real economic entity.
What it actually costs
Direct losses are the visible part. A fraudulent customer who obtains financing, signs a leasing contract or accesses a service generally does not honour it, and recovering debt from a fictitious entity is, by definition, impossible.
But the indirect costs are often heavier.
- Regulatory cost. An impostor who passes your KYC/KYB checks and is later identified as linked to fraud or money laundering directly exposes your anti-money-laundering responsibility. Regulators do not distinguish between "we were victims" and "we did not have adequate controls".
- Reputational cost. In sectors where trust is central (banking, insurance, financing), being known as a business whose processes were bypassed by impostors sends a negative signal to your own customers and partners.
- Opportunity cost. Internal investigations triggered after a confirmed fraud tie up risk, compliance and legal teams for weeks. That time is not spent on growth.
How impostors get through, and how to detect them without friction
The question risk teams should be asking is not "how do we block every impostor?"
It is "how do we detect them without slowing down the 95% of legitimate applications?"
The answer lies in a multi-layered approach, applied in real time from the very first contact.
Advanced document verification. Beyond OCR reading and visual checks, this means detecting anomalies in file metadata, font consistency, and inconsistencies between digital and declared data. A visually flawless document can still betray its synthetic origin through non-visual signals.
Automated document verification
Passive liveness check. Confirming that the person signing up really is who their documents say they are, without a blocking step for legitimate users. Passive systems analyse this in the background while the user completes their journey.
KYC and identity verification
Company trust score (KYB). Cross-checking the declared company's identity against official registers, financial data, director history, ownership links and behavioural signals from the journey. A synthetic entity will always show detectable inconsistencies, provided you have the right cross-referenced sources.
Behavioural analysis of the journey. Time of the request, device used, form-filling speed, consistency between IP location and declared address. These signals, combined with the document score, significantly improve detection with no visible friction for legitimate users.
The goal is not to add more checks. It is to industrialise checks that run in parallel, in the background, in a matter of seconds.
What the 2025 data really tells us
The FTC figure, $3.5 billion, is striking. But the most important data point is not the amount: it is the trend.
A threefold increase in five years. A 25% rise in a year across all fraud types. Deepfakes up 700%.
The industrialisation of fraud as Fraud-as-a-Service.
This trajectory does not stop at the US border. It describes a structural, global risk, accelerated by generative AI, and one that hits hardest the companies whose onboarding processes were optimised for conversion but not for detection.
The question is not whether an impostor will try to get through your onboarding journey. It is whether your journey is designed to catch them before they enter your portfolio.
FAQ
Does impostor fraud affect B2B companies, or only individuals?
Both. In B2B, the risk is often higher per case: the amounts involved in business onboarding are structurally larger than in B2C. And B2B verification processes have historically been less automated.
What is the difference between document fraud and impostor fraud?
Document fraud is a method (falsifying or creating a fake document). Impostor fraud is a goal (posing as someone you are not). In practice, impostor fraud very often uses document fraud as its main tool.
Is a liveness check enough to detect an impostor?
No. A liveness check confirms the person is physically present and alive, but it does not confirm that this person is actually the company's authorised legal representative. A complete approach combines KYC liveness, KYB verification of the entity, and behavioural scoring of the journey.
How long does it take to integrate an anti-impostor solution into an existing journey?Deploying Meelo takes four weeks on average. Integration happens via API, with unified documentation covering KYC, KYB and fraud scoring within a single case record.
Find out how exposed your onboarding process is to fraud
In 20 minutes, we review your current journey and identify the blind spots.
.jpg)


