Fraud prevention service Cifas has just published its Fraudscape 2026 report, and the headline number is stark: 444,993 fraud cases were logged to the National Fraud Database in 2025, the highest total on record and up 6% on the year before. Members are now recording more than 1,200 cases a day, and nearly three-quarters of them trace back to identity fraud or account takeover. For UK SMEs, this isn’t just a bigger version of a familiar problem, it’s a signal that fraud has quietly become a cyber and identity issue as much as a finance one.
The detail that should worry small business owners most is what’s driving the growth. Loan and lending-related filings jumped 33%, much of it linked to falsified or altered documents, and Cifas explicitly points to AI-generated paperwork as a growing factor. Fake payslips, doctored bank statements, and synthetic ID documents that would once have taken real skill to fake convincingly can now be produced in minutes. The same tools your business might be using to write emails faster are being used by fraudsters to fabricate the paper trail behind a fraudulent application, invoice, or new supplier relationship.
Why this lands on your desk, not just your bank’s
Small businesses sit at both ends of this risk. You’re a target for identity fraud through your own accounts, banking, credit lines, and supplier onboarding, and you’re increasingly exposed through the people and businesses you deal with. A “new supplier” providing a convincing-looking company registration document, or a job applicant with a synthetic identity, are no longer edge cases. If your onboarding process for new suppliers, contractors, or customers still relies on eyeballing a PDF, this report is a reason to tighten it.
What actually reduces this risk
Verify identity documents through a proper check, not a visual glance. Companies House ID verification is becoming mandatory for directors this year, and that same discipline is worth applying to new suppliers and higher-value customers: a proper identity verification step, not just “does this document look real.”
Tighten your bank detail change process. A large share of fraud losses now trace back to a single changed bank account number on an invoice or payroll instruction. Any change to payment details should require a verified phone call to a known number, never confirmation via the same email thread that requested the change.
Put the right paperwork in place before you need it. Clear terms of business, supplier agreements, and verification clauses give you a legal footing if a fraudulent relationship turns into a dispute. Smallprint has ready-to-use UK legal templates that make this a same-day fix rather than a project for “when we have time.”
Treat a fraud attempt as a security incident, not just a finance write-off. If your business gets hit, understanding how the fraudster got your details in the first place, whether through a data breach, a compromised email account, or an unverified new contact, matters for stopping the next attempt. KeepSafe monitors for exactly this kind of exposure, so you know if your business details are already circulating before someone tries to use them against you.
The takeaway
Fraudscape 2026 isn’t describing a niche financial crime problem any more, it’s describing an identity crisis that any business handling payments, suppliers, or customer onboarding is exposed to. The fix isn’t expensive, it’s mostly about tightening a handful of verification steps that most small businesses have never formally written down. Do it before you’re the next case in next year’s report.