Onboarding fraud is India's fastest-growing silent threat

September 7, 2026

India's banking sector lost ₹36,014 crore to fraud in FY 2024-25 — a staggering 194% jump from the previous year, according to RBI data. That number demands attention. But what demands even greater attention is where a significant portion of that fraud begins: not in the transaction layer, not in the collections stage, but at the very first touchpoint a customer has with a bank — onboarding.

Fraud has moved upstream. And most institutions are still building their defences downstream.

_____________________________________________________________________________________________________________

The Front Door Is Now the Most Dangerous Door

For decades, banking fraud controls were designed around transactions — monitoring account activity, flagging unusual transfers, reviewing credit behaviour over time. That logic made sense when fraud was largely opportunistic and reactive. It no longer does.

In 2025, identity became the main entry point for fraud in India's digital economy, with fragmented and reusable identity data being misused at scale. — Bureau Fraud Report / RBI Annual Report 2024-25.

Fraudsters have realised something that many bank risk teams are still catching up to: it is far easier — and far more profitable — to enter the system with a fraudulent identity at the onboarding stage than to manipulate an account once it is live and monitored.

The three primary vectors of onboarding fraud in India's BFSI sector today are synthetic identity fraud, document forgery, and mule account creation. Each is distinct. Each is growing. And each is largely invisible until the damage is done.

Synthetic Identity Fraud: The Enemy That Looks Like a Real Customer

Synthetic identity fraud is the creation of a fictitious identity using a combination of real and fabricated information. A fraudster might pair a valid Aadhaar number with a fabricated PAN, or use a genuine mobile number linked to a non-existent address. Individually, each data point can pass a basic check. Together, they represent a person who does not exist.

According to TransUnion's H1 2026 fraud trends data, 7.1% of consumer-facing transactions in India were suspected fraud in 2025 — nearly double the global average — with identity-centric fraud a significant driver.

The scale of this threat is accelerating. NASSCOM-DSCI research found that fake identities compiled using both genuine and made-up information have increased by 450% since 2022. A fraud ring in Bengaluru was found to have created over 200 synthetic identities using AI-generated PAN cards and Aadhaar details — each built carefully over time to establish apparent creditworthiness before defaulting on large loans.

This is not opportunistic fraud. It is organised, patient, and industrialised.

Document Forgery: Now Powered by AI

Document forgery at the onboarding stage has existed for as long as paper-based verification has. What has changed is the sophistication of the tools available to fraudsters.

Digital document forgeries have surged by approximately 244% year-on-year, while deepfakes constitute roughly 40% of biometric fraud attempts — a material shift from transactional fraud to application fraud at the point of onboarding. — AuthBridge, 2025.

Generative AI tools now allow bad actors to produce doctored bank statements, fabricated income proofs, and manipulated identity documents that pass basic OCR and visual inspection. Industry forecasts suggest that by 2026, one in four digital onboarding attempts may involve some form of synthetic media manipulation.

For Indian banks and NBFCs that rely on manual document review or basic digital checks, this represents an existential gap in their first line of defence. A forged identity at onboarding becomes a delinquent loan in collections — and the fraudster has often disappeared by then.

Mule Accounts: The Infrastructure of Financial Crime

If synthetic identities are the entry point, mule accounts are the pipeline. A mule account is a legitimate-looking bank account opened using a real or fabricated identity, then used to receive and rapidly move proceeds of cybercrime — making the funds difficult to trace and recover.

The CBI identified nearly 8.5 lakh mule accounts opened across 700 bank branches nationwide in 2025. The Indian Cyber Crime Coordination Centre identified 26.5 lakh layer-1 mule accounts by December 2025, with cybercriminals siphoning off nearly ₹20,000 crore through these networks.

The RBI has responded with urgency. Its Reserve Bank Innovation Hub developed MuleHunter.AI — an AI/ML tool analysing nineteen distinct patterns of mule account behaviour, capable of detecting approximately 20,000 mule accounts per month. As of December 2025, 23 banks have implemented the platform, with the Ministry of Home Affairs directing all financial institutions to integrate with MuleHunter by December 2026.

But here is the critical gap: MuleHunter detects mule accounts after they are opened. The more fundamental question is — why are these accounts being successfully opened in the first place?

The Reactive Trap — and Why It Is So Costly

58% of organisations identified false positives as their primary risk — indicating that risk teams spend a significant portion of their time investigating legitimate users while sophisticated threats slip through undetected. — Bureau India Fraud Report 2026.

This is the reactive trap. Banks invest heavily in transaction monitoring, fraud analytics, and post-disbursement surveillance — all of which activate after the fraudulent identity is already inside the system. The cost of catching fraud at this stage is dramatically higher than preventing it at entry.

The RBI has imposed penalties on multiple banks for weak KYC compliance during online onboarding — reflecting growing concern over identity theft and mule accounts that have surged alongside digital payments. Regulatory risk is now layered on top of financial risk.

The RBI Annual Report 2025-26 makes the supervisory intent unambiguous: future assessments will increasingly focus on demonstrable outcomes, data quality, risk intelligence, and operational effectiveness — not checkbox compliance.

Prevention Starts at Onboarding — Not After It

The shift from reactive to preventive fraud control requires moving verification intelligence to the front of the customer journey. This means treating every onboarding touchpoint — identity submission, document upload, video verification, AML screening — not as a compliance step to be completed, but as an active fraud signal to be analysed.

Aadhaar-based eKYC is one of the most powerful fraud prevention tools available to Indian banks and NBFCs — not just because it verifies identity, but because it does so against a biometric source that cannot be replicated without direct compromise of the original credential. When Aadhaar verification is embedded natively into the onboarding journey rather than run as a manual offline check, the risk of synthetic identity fraud drops significantly.

Video KYC (V-CIP) adds a real-time human and AI layer that document checks alone cannot provide. A live video interaction allows liveness detection — confirming that the person completing onboarding is physically present, not a deepfake or a pre-recorded video submission. A built-in Video KYC module that flags anomalies in real time is a critical line of defence for institutions onboarding thousands of customers remotely.

AML screening integrated at onboarding — rather than applied as a periodic batch process post-onboarding — means that a customer whose name, address, or identity attributes appear on watchlists, PEP databases, or adverse media is flagged before the account is opened, not weeks later.

CKYC/KRA cross-verification allows institutions to check whether the identity being presented at onboarding matches an existing verified record in the Central KYC Registry — catching synthetic identities that combine real and fictitious attributes, because the combination will not match any legitimate registered profile.

Together, these are not compliance checkboxes. They are the architecture of a fraud-resistant onboarding system — one where bad actors are stopped at the door rather than discovered inside the building months later.

The Strategic Imperative

62% of banks globally say digital onboarding is the highest risk point for synthetic identity fraud exposure. — BIIA, 2026.

India, with its combination of high-volume digital onboarding, expanding MSME lending, and rapidly scaling fintech infrastructure, is particularly exposed. The institutions that will emerge from this decade with strong books and clean compliance records are those that treat onboarding fraud prevention not as a risk function's problem, but as a board-level strategic priority — embedded into the onboarding journey itself, not bolted on after the fact.

The technology exists. The regulatory direction is clear. What remains is the willingness to move from reacting to preventing.

_____________________________________________________________________________________________________________

Celusion helps Indian banks and NBFCs build fraud-resistant onboarding journeys — with integrated Aadhaar eKYC, CKYC/KRA verification, AML screening, Video KYC, and DigiLocker, all within a single compliant, no-code-configurable platform.

www.celusion.com/onboard

Onboarding in 2025: Strategies for a standout banking experience
Mar 10, 2025

In 2025, Indian banks must prioritize speed, simplicity, and security in digital onboarding to deliver seamless, AI-driven, and customer-first experiences.

Identity with India's National Single Sign On, Meri Pehchaan
Sep 4, 2024

Learn how to seamlessly integrate India's National Single Sign On, Meri Pehchaan as an Identity Provider with Identity and promote digital inclusion.

Reimagine lending to MSME sector in India
Jun 10, 2024

Banks need to reimagine their lending strategies by leveraging technology and personalized approaches in the MSME sector.