Sign up
Subscribe
Home / news / FCA Crypto Authorisation Gateway Opens on 30 September 2026 as Identity Fraud Hits 22.49% in Crypto Onboarding
news

FCA Crypto Authorisation Gateway Opens on 30 September 2026 as Identity Fraud Hits 22.49% in Crypto Onboarding

FCA Crypto Authorisation Gateway Opens on 30 September 2026 as Identity Fraud Hits 22.49% in Crypto Onboarding

The UK Financial Conduct Authority (FCA) will open its new cryptoasset authorisation gateway on 30 September 2026, and firms applying under the new regime will have to show how their systems and controls handle financial crime and identity fraud. For PSPs, acquirers, and banks touching crypto, the message is simple: onboarding fraud is not a side issue, it is part of the licensing conversation.

  1. Shufti’s Identity Fraud Report 2026 found that identity fraud made up 22.49% of verification requests in the crypto sector in the first half of 2026, the highest rate across the 11 industries examined. Banking was at 4.24%, which is a useful reminder that “high risk” is not an abstract label here; it shows up in the onboarding queue.
  2. Crypto was followed by fintech at 18.36%, forex at 17.18%, and lending and investment at 17.08%. Payments recorded an identity fraud rate of 14.87%, e-commerce and marketplaces 13.29%, and telecom 8.07%. These figures represent confirmed fraudulent verification attempts as a share of each sector’s verification requests.
  3. That distinction matters: a higher rate means greater observed exposure to fraudulent attempts, not necessarily weaker fraud controls. But if controls at a specific firm are weak, sectors with more fraud attempts give cybercriminals more chances to compromise data and operations. In other words, the fraud rate is a stress test, not a verdict.
  4. Within crypto, altered documents accounted for 10.10% of verification attempts, the highest rate for this attack type across all sectors in the report. Shufti also found that fraud is increasingly coordinated rather than isolated, which makes one-by-one screening less effective.
  5. Across the verification data, 65.68% of matches between separate fraudulent attempts were linked to reuse of the same fraudulent identity document. The largest coordinated network identified by Shufti involved 70 identities connected through shared fraudulent documents, devices, and IP addresses. Those identities were associated with 13 devices, and one device was linked to 16 verification events.

The AI layer is part of the same picture: deepfake document fraud accounted for 80.10% of AI-enabled identity fraud in the first half of 2026, followed by synthetic identities at 12.31%, injected videos at 4.01%, and face swaps at 3.58%. Shufti also recorded a typical interval of 9 minutes and 33 seconds between cross-border fraudulent attempts, which is the sort of timing that matters when onboarding teams are looking only at the individual application in front of them.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!