Deepfake Statistics 2026: Growth, Fraud and Detection Rates
By AI Detector 360 Editorial Team · · 6 min read

Deepfake numbers get inflated as reliably as deepfakes themselves. Plenty of viral statistics trace back to vendor guesses compounded by rewrites. This roundup takes the opposite approach: every figure below comes from a named report, study or confirmed incident, with dates attached, and where the honest answer is "nobody knows," we say so.
The most consequential deepfake statistics in 2026: Deloitte projects US generative-AI-enabled fraud losses of $40 billion by 2027; Entrust recorded a deepfake attack attempt every five minutes in 2024; Sumsub measured a 4x year-over-year jump in detected deepfakes; and in iProov's testing, just 0.1% of people caught every fake shown to them.
Key takeaways
- Deloitte's aggressive scenario puts US gen-AI-enabled fraud losses at $40B by 2027, up from $12.3B in 2023 — a 32% compound annual growth rate.
- Detected deepfake volume roughly quadrupled from 2023 to 2024 and reached about 7% of all fraud attempts in identity verification (Sumsub).
- Humans are near-hopeless as detectors: 0.1% of 2,000 iProov participants sorted every real from fake, while 57% were sure they could.
- Two major legal deadlines now apply: the US TAKE IT DOWN Act's platform rules (May 2026) and the EU AI Act's deepfake disclosure duty (August 2026).
The deepfake statistics that matter in 2026
If you only keep six numbers from this page, keep these.
| Statistic | Figure | Source, year |
|---|---|---|
| Projected US gen-AI fraud losses by 2027 | $40B (aggressive) / ~$22B (conservative) | Deloitte, 2024 |
| Frequency of deepfake attack attempts | One every 5 minutes | Entrust, 2024 data |
| Growth in detected deepfakes, 2023→2024 | ~4x | Sumsub, 2024 |
| Deepfakes as share of fraud attempts | ~7% | Sumsub, 2024 |
| People who caught every fake in testing | 0.1% of 2,000 | iProov, Feb 2025 |
| Largest confirmed single loss | US$25.6M (Arup) | CNN, May 2024 |
Everything below unpacks where these come from and what they do — and don't — prove. One reading note first: most attack-volume data comes from identity-verification vendors, measured inside their own onboarding flows. That's telemetry, not a census — it counts attempts against companies that bought detection, and sees nothing of scam ads, fake war footage or voice calls to grandparents. Directionally reliable, absolutely incomplete.
Fraud: the money numbers
The Deloitte Center for Financial Services produced the most-cited forecast in this space by scoring each fraud type the FBI tracks for its exposure to generative AI. Its aggressive-adoption scenario has US fraud losses enabled by gen-AI reaching $40 billion by 2027, up from $12.3 billion in 2023 — a 32% compound annual growth rate. Even the conservative scenario lands around $22 billion, and within the total, Deloitte pegs AI-assisted email fraud alone at up to $11.5 billion by 2027. The same report noted a 700% increase in deepfake incidents in fintech during 2023 alone.
Treat the forecast as a range with reasoning attached, not a prophecy — but notice that reality has been cooperating with the aggressive scenario, not the conservative one.
Forecasts are forecasts; the confirmed incidents are what make them believable. The benchmark case remains Arup: in early 2024 an employee in the firm's Hong Kong office wired HK$200 million (about US$25.6 million) across 15 transfers after a video call where the CFO and every other participant was synthetic. The employee suspected the initial email was phishing — the deepfaked call is what overrode the doubt. That failure mode (video as trust anchor) is exactly what our deepfake spotting checklist is built to break.
Volume: how often attacks actually happen
Two independent identity-verification providers publish attack telemetry, and their 2024 numbers agree on direction:
- Entrust (2025 Identity Fraud Report, covering September 2023–August 2024): a deepfake attempt occurred every five minutes, while digital document forgeries jumped 244% year over year — reaching 57% of all document fraud and marking a 1,600% surge since 2021, the first year digital forgeries overtook physical counterfeits.
- Sumsub (Identity Fraud Report 2024–2025): detected deepfakes grew ~4x from 2023 to 2024, reaching about 7% of all fraud attempts, with regional spikes of 643% in the Middle East, 393% in Africa and 255% in Latin America and the Caribbean.
The two datasets don't share methodology or customer bases, which is what makes their agreement meaningful: whichever vendor's lens you look through, synthetic media went from exotic to routine attack tooling in under two years.
Worth stating plainly: these figures measure attempts caught by verification vendors, so they undercount everything that got through and everything outside onboarding flows — the fake war footage, the celebrity scam ads, the synthetic voices calling grandparents. Treat them as the visible part of the curve.
Scan videos for AI, frame by frame
Our video detector samples frames across the timeline and shows you exactly where AI signals spike.
Try the AI video detectorDetection: humans vs. machines
The starkest number in this roundup comes from iProov's February 2025 study. Of 2,000 UK and US participants who knew they were being tested, only 0.1% correctly classified every real and fake sample. Meanwhile 57% believed they could spot a deepfake, and awareness collapses with age — 30% of 55–64s and 39% of over-65s had never heard the term. Still images show the same pattern: in the ARIA benchmark, people caught just 61.58% of AI-generated images.
Sit with the pairing for a second: the honest human baseline is near zero, and the perceived baseline is a comfortable majority. Every fraud script exploits the space between those two numbers — victims aren't careless, they're miscalibrated, primed by years of "obvious" fakes to assume the fakes stay obvious.
Machines do better, with caveats we'd rather state than hide. Detection models catch compositing artifacts and statistical fingerprints humans can't perceive, but accuracy drops on compressed, re-encoded social media copies — Bellingcat demonstrated back in 2023 that compression alone flipped 7 of 10 AI images past a leading detector. That's why the AI Detector 360 video detector samples frames across the entire timeline and reports per-frame results with a confidence level, and why we tell users a score is evidence, not proof. For fully synthetic clips — the Sora and Veo variety rather than face swaps — see our guide to detecting AI-generated video, because the artifact classes differ.
The law catches up
Two legal regimes moved from proposal to enforcement in the last eighteen months:
- United States. The TAKE IT DOWN Act, signed May 19, 2025, made publishing nonconsensual intimate imagery — explicitly including AI-generated "digital forgeries" — a federal crime, and gave covered platforms until May 19, 2026 to stand up a 48-hour notice-and-removal process. It's the first federal statute to name deepfakes directly.
- European Union. The EU AI Act's Article 50 transparency obligations became applicable on August 2, 2026: AI-generated content must be marked in a machine-readable way, and deepfakes must be disclosed as such. We've broken down the compliance details in our Article 50 explainer.
Neither law stops a fraudster mid-call. What they change is the infrastructure: mandatory machine-readable marking pushes generators toward embedded provenance, which makes automated verification progressively more reliable.
What the numbers add up to
Read together, the statistics describe a specific asymmetry. Attack volume is compounding (4x year over year), per-incident stakes are proven at eight figures (Arup), and the human baseline for detection is near zero (0.1%). The response that scales isn't better squinting — it's layered verification: provenance checks, source tracing and statistical detection, the workflow we walk through across this series. A first pass on any suspicious still or thumbnail through AI Detector 360's image detector takes seconds; flagging a video for frame-level analysis takes about a minute.
A citation-hygiene note, since this page will get quoted: keep the qualifiers attached. "$40 billion" is a projection for 2027 under Deloitte's aggressive scenario, not a measured loss; "every five minutes" describes attempts inside Entrust's customer telemetry, not the whole internet; and the 0.1% figure comes from one 2,000-person study, not a global census. The numbers are strong enough without exaggeration — stripping their context is exactly the kind of distortion a statistics page about synthetic media shouldn't commit.
We'll update this page as 2026 reports land. If a number here later gets revised by its source, the revision ships here too — that's the standard we'd want from anyone else's statistics page.
Scan videos for AI, frame by frame
Our video detector samples frames across the timeline and shows you exactly where AI signals spike.
Try the AI video detectorFrequently asked questions
How many deepfakes are on the internet in total?
Nobody can credibly say, and any precise global count you see is a projection, not a measurement. What can be measured is growth in detected attempts: Sumsub logged a fourfold increase in deepfakes caught during identity verification from 2023 to 2024, and Entrust recorded an attempt every five minutes across the year to August 2024. The trend lines are solid even where totals are guesswork.
What's the largest confirmed loss from a single deepfake attack?
The Arup case remains the benchmark. In early 2024, a finance employee in the engineering firm's Hong Kong office transferred about US$25.6 million across 15 transactions after a video call in which the CFO and several colleagues were all deepfakes. The company confirmed the incident publicly in May 2024.
What share of fraud attempts involve deepfakes?
In Sumsub's 2024 identity-verification data, deepfakes accounted for roughly 7% of all fraud attempts, up fourfold from the prior year. Forged documents still dominate overall fraud, but deepfakes are the fastest-growing category — and unlike a bad photocopy, each one targets the verification step that's supposed to be the strong link.
Are deepfakes illegal in the United States?
Creating a deepfake isn't broadly illegal, but specific uses now are. The federal TAKE IT DOWN Act, signed May 19, 2025, criminalizes publishing nonconsensual intimate images, explicitly including AI-generated ones, and requires covered platforms to remove them within 48 hours of a valid request. Fraud, defamation and impersonation laws also apply to deepfakes the same as any other medium.
Sources & further reading
- Deloitte Center for Financial Services — Deepfake banking fraud risk (2024)
- Entrust — 2025 Identity Fraud Report announcement (Nov 2024)
- Sumsub — Identity Fraud Report 2024–2025
- iProov — Deepfake blindspot study (Feb 2025)
- CNN — Arup confirmed as victim of $25M deepfake scam (May 2024)
- Congress.gov — S.146, TAKE IT DOWN Act (2025)
Fair-use note: AI detection scores — from any tool, including ours — are probabilistic estimates, not proof. Never make academic, employment or legal decisions on a score alone.
Related reading

How to Detect AI-Generated Video (Sora, Veo, Kling and Beyond)
Sora and Veo made fake video effortless. How to detect AI generated video in 2026: temporal glitches, physics slips, watermarks and frame-by-frame analysis.
Jul 17, 2026 · 6 min read

How to Spot a Deepfake Video in 2026: A Practical Checklist
99.9% of people failed a deepfake spotting test. How to spot a deepfake video in 2026: face boundary glitches, lip-sync drift, lighting mismatch, audio tells.
Jul 6, 2026 · 7 min read

The EU AI Act's Transparency Rules Are Live: What Article 50 Means
EU AI Act Article 50 is now in effect: machine-readable marking of synthetic content, deepfake disclosure, who must comply, and the fines for ignoring it.
Aug 17, 2026 · 6 min read