WristPay
Regulation

Fraud Rings Reuse Documents to Evade KYC, Report Finds

Lu-Hai Liang 29.09.2026

Document Reuse Drives Coordinated Fraud

A new identity‑fraud study released in 2026 shows that organized criminal groups are increasingly reusing the same identity documents, devices, and IP addresses to slip past Know‑Your‑Customer (KYC) checks. The findings come from a comprehensive analysis of thousands of fraudulent attempts across the globe, revealing a growing trend in coordinated identity theft.

The report highlights that 65.68 percent of matched fraudulent attempts involve the reuse of a single identity document. This figure is the strongest indicator of coordinated activity. The study also found that many fraudsters share the same IP addresses and devices, creating a networked approach that bypasses typical verification systems.

The data shows that fraudsters are not creating new documents each time. Instead, they recycle the same passports, driver's licences, or national IDs across multiple accounts. This reuse makes detection harder because the documents appear legitimate at first glance. The report indicates that when a document is flagged, it is often linked to dozens of other fraudulent applications. This pattern points to organized rings that operate with a shared pool of stolen documents.

The high match rate suggests that fraudsters are deliberately targeting documents that have already proven effective in previous attempts. By reusing these documents, they reduce the risk of detection and increase the speed of account creation. The study also notes that many of these documents have been tampered with, yet still pass initial verification checks.

How Fraud Rings Exploit Shared Infrastructure

Beyond document reuse, the report identifies shared IP addresses as another key tactic. Over 40 percent of fraudulent attempts share the same IP, indicating that fraudsters use a common network or proxy service. This shared infrastructure allows them to mask their true location and avoid geographic restrictions that many KYC systems enforce.

Devices are also commonly reused. Fraudsters employ the same smartphones or computers across multiple accounts, leaving digital fingerprints that are difficult to trace. The combination of shared IPs and devices creates a robust framework that supports large‑scale identity theft operations.

The report warns that these coordinated efforts are becoming more sophisticated. Fraudsters now use cloud services and encrypted channels to coordinate document sharing and device usage. This evolution makes it harder for traditional KYC solutions to keep pace.

Frequently Asked Questions

The findings underscore the need for identity verification providers to adopt advanced analytics and cross‑reference checks. By monitoring document reuse patterns and shared IP addresses, companies can spot coordinated fraud earlier and reduce the risk of financial loss.

What is the most common method used by fraud rings to bypass KYC? Fraudsters primarily reuse stolen identity documents across multiple accounts, a tactic that accounts for about two thirds of coordinated fraud cases.

How can businesses protect themselves against this type of fraud? Implementing real‑time document verification, monitoring for repeated IP addresses, and using device fingerprinting can help detect and prevent coordinated fraud attempts.

Will new regulations help curb this trend? Stricter KYC guidelines and mandatory sharing of fraud intelligence between institutions could reduce the success rate of coordinated identity theft.

Share:

More stories: