Identity fraud reached 242,003 recorded cases in 2025 — more than half of every fraud logged to the UK National Fraud Database — and the people most often targeted are those over 61, the same group most likely to be drawing on pensions and savings they cannot replace. A single stolen detail can drain a pension pot or redirect a State Pension payment before you notice anything wrong. Here is how it actually happens and what it means for anyone living on retirement income.
Disclosure: Some links on this page are affiliate links. If you make a purchase through them, Britwealth may earn a commission at no extra cost to you. We only include products and services that are relevant to the topic.
This article is general information only and does not constitute professional advice. For your specific situation, consult a qualified professional.
These numbers come from two different counting systems. CIFAS records cases filed to its prevention database by member organisations — banks, insurers, telecoms — so it captures what gets detected and reported. The Crime Survey for England and Wales asks individuals what they experienced, including incidents never reported to anyone. Both tell the same story: identity abuse is the centre of gravity of UK fraud, and it is getting harder to spot as fraudsters adopt AI tools.
For someone in or near retirement, the stakes are higher than for a younger worker. A pension pot takes decades to build and can be emptied in days. A State Pension claim redirected to a fraudster’s account might not be noticed until the first missed payment. Understanding the mechanics — not just the warnings — is the only practical defence. Here is what you actually need to know.
What I tend to notice is that most people think identity theft means someone steals their wallet and uses their credit card. That still happens, but the bigger threat in 2026 is invisible: your details are already out there from a data breach years ago, and fraudsters are using AI to weaponise them at scale.
The numbers that actually govern identity fraud risk in the UK
The headline figures matter less than what they reveal about where the danger sits. Identity fraud against bank accounts rose 10% to more than 63,000 cases in 2025, according to CIFAS Fraudscape 2026. Insurance product fraud jumped 26% to over 16,000 cases. Facility takeover — where someone hijacks an account you already hold — reached more than 78,000 cases, up 6% year on year. Misuse of facility, which includes money-mule accounts, surged 43% to over 106,000 cases.
→ Scroll right to see all columns
| Fraud type | Cases in 2025 | Year-on-year change |
|---|---|---|
| Identity fraud (total) | 242,003 | -3% |
| Identity fraud — bank accounts | 63,000+ | +10% |
| Identity fraud — insurance | 16,000+ | +26% |
| Facility (account) takeover | 78,000+ | +6% |
| Misuse of facility | 106,000+ | +43% |
| Unauthorised SIM swaps | Not separately reported | +38% |
The dip in headline identity fraud cases — down 3% from nearly 250,000 in 2024 — looks like good news until you see that total fraud hit a record 444,000 cases. Identity fraud shrank as a share of a bigger pie because other categories grew faster, not because identity crime went away. The CIFAS six-month update recorded more than 118,000 identity fraud cases in the first half of 2025 alone, fuelled partly by AI-generated synthetic identities.
Card ID theft — a narrower slice of identity fraud involving stolen details used to obtain or use a card — actually fell 26% in value to £58.7 million in 2024, according to the UK Finance Annual Fraud Report 2025. That is one of the few improving measures, but it is offset by the rise in account takeover and SIM-swap fraud, which bypass card protections entirely.
What this means for someone in retirement: 72% of all recorded fraud involves identity abuse in some form. The odds that a fraud attempt will target your identity or your existing accounts are not remote — they are the norm. And because fraudsters increasingly use stolen personal data from breaches, having good digital habits matters as much as locking your front door.
Errors and gaps in how people understand identity theft
Thinking identity theft only happens after a stolen wallet
The old image of a pickpocket using your credit card still exists, but 86% of identity fraud cases are committed through online channels, per CIFAS data. Your details are more likely to be harvested from a data breach or a phishing email than taken from your physical post. The mechanical consequence: you never see it coming, and by the time a fraudulent application succeeds, the fraudster has already moved the money. Checking your credit report regularly — not just when something feels wrong — is the only way to catch applications made in your name before they cause damage.
Believing SMS codes are safe enough
Unauthorised SIM swaps rose 38% in 2025, driven by stolen personal data and automated attacks. A fraudster calls your mobile provider, impersonates you using details from a breach, and ports your number to a SIM they control. Every one-time passcode sent by text then goes to them, not you. The telecoms sector accounted for 69% of all account takeovers in the first half of 2025, up from 40% in 2024. If your bank or pension provider relies on SMS for multi-factor authentication, that single layer is increasingly vulnerable. Using an authenticator app or a hardware security key instead of SMS is a practical shift that closes this gap.
Ignoring synthetic identity fraud
Synthetic identity fraud uses a mixture of real and invented information — a genuine National Insurance number with a false name and address, for example. These combinations can pass basic database checks because the NI number is real. The fraudster builds a credit profile over months, then maxes it out and disappears. Detection requires cross-checking against trusted data sources and flagging profiles that lack a credible digital footprint. For someone in retirement, the risk is indirect: a synthetic identity using fragments of your data can damage your credit file or trigger fraud flags that take months to resolve.
Assuming pension providers will catch it
Pension pots are attractive targets because they are large and often checked infrequently. A fraudster who gains access to your online pension account can change payment details, request a transfer, or even cash out a small pot entirely. Providers have fraud detection systems, but they rely on the same identity verification methods used by banks — and those methods are being tested by AI-generated deepfakes and synthetic documents. Checking your pension accounts quarterly, not annually, is a simple habit that limits the window of undetected access.
How identity theft actually happens — the mechanics
Document fraud and forged identity documents
Fraudsters use forged, tampered, or stolen identity documents to open accounts or apply for credit. Modern document verification technology analyses security features and subtle alterations that manual review would miss, but not every organisation uses the same level of checking. A fraudster submitting a high-quality fake passport to a provider with basic verification can succeed. The warning signs for the victim often come months later, when a credit application they never made appears on their file. Checking your statutory credit report from each of the three main credit reference agencies — Experian, Equifax, and TransUnion — once a year is the most reliable way to catch document-based fraud early.
Biometric spoofing and deepfake attacks
Fraudsters increasingly use replay videos, printed photos, and AI-generated synthetic faces to bypass biometric verification. Passive liveness checks alone are often insufficient. Active liveness testing — where the user must blink, turn their head, or respond to a prompt — confirms the person is real and physically present. For someone managing a pension online, the risk is that a fraudster uses a deepfake of your face to pass a video verification check. Providers are investing in injection attack detection to counter this, but the technology is in an arms race. If your pension provider offers app-based authentication with biometric checks, enable it — it is harder to spoof remotely than a password.
Synthetic identity fraud and account takeover
Synthetic identities are built over time: a real NI number, a fabricated name, a rented address. The fraudster uses this hybrid identity to open a bank account, build a thin credit file, then apply for loans or credit cards. Account takeover, by contrast, targets an account you already hold. The fraudster gains access through stolen credentials — often from a phishing email or a data breach — then changes the password, adds a new payee, and transfers money out. The UK Finance fraud report recorded more than £1.1 billion stolen through fraud in 2024 across 3.3 million cases. For a retiree, a single account takeover can drain a current account that holds pension income for the month.
SIM-swap fraud as an enabler
A SIM swap gives the fraudster control of your mobile number. They port it to a handset they hold, intercepting the one-time passcodes that protect your banking, email, and pension accounts. The attack relies on the mobile provider’s customer service being convinced to issue a replacement SIM. Once the swap happens, the fraudster can reset passwords on any account that uses SMS verification. The practical defence: contact your mobile provider and ask them to add a dedicated PIN or password to your account that must be provided before any SIM change. Report a suddenly dead SIM immediately — do not assume it is a network fault.
The emerging threat of AI-generated fraud
AI tools make impersonation cheaper and faster. Fraudsters use generative AI to create realistic fake documents, synthetic faces for biometric checks, and convincing phishing messages that mimic your bank or pension provider. The Experian UK Fraud and FinCrime Report notes that 73% of UK businesses expect fraud management budgets to increase in 2026, reflecting the scale of the AI arms race. For individuals, the practical response is not to try to outsmart AI but to build habits that slow a fraudster down: unique passwords for every account, two-factor authentication via an authenticator app rather than SMS, and regular credit report checks.
Frequently asked questions about UK identity theft
What is the difference between identity theft and identity fraud? ▾
How do I check if my identity has been used fraudulently? ▾
What should I do if I discover identity fraud? ▾
Can identity fraud affect my State Pension? ▾
How do fraudsters get my personal details in the first place? ▾
Is it worth paying for identity protection services? ▾
Why the threat is not going away
The UK recorded more than 444,000 fraud cases in 2025 — over 1,200 a day — and every indicator points upward. AI-generated synthetic identities, deepfake biometric attacks, and automated SIM swaps are making fraud cheaper to execute and harder to detect. The ID-Pal identity fraud trends report notes that 98% of businesses have adopted or plan to adopt AI and machine learning for financial crime screening by 2026, but fraudsters are adopting the same tools. The arms race is real, and for individuals the margin for error is shrinking.
Remember: this article is general information only. For advice on your specific situation, speak to a qualified professional.
If this was useful, you might also want to read Beyond the Pension: Alternative Income Streams for a Comfortable UK Retirement.
Sources and Further Reading
What Happens to UK Pension Pots During a Divorce? — Pension division is a complex area where identity verification matters; this article covers the process.
CIFAS (2026). Fraudscape 2026. 🔗
Experian (2026). UK Fraud and FinCrime Report. 🔗
ID-Pal (2026). Identity Fraud Trends in 2026: AI, Deepfakes, Synthetic Identities. 🔗
UK Finance (2025). Annual Fraud Report 2025. 🔗
ONS (2026). Crime in England and Wales: year ending December 2025. 🔗


