CIFAS markers in 2026: what Fraudscape data reveals and how to challenge an unfair marker

Jun 11 2026

White Collar Crime

CIFAS’s Fraudscape 2026 findings show a UK fraud environment operating at record scale. More than 444,000 cases were recorded in the National Fraud Database in 2025, which is the highest annual figure and a 6% increase on 2024. It means that CIFAS members logged more than 1,200 cases per day.

These figures demonstrate that financial institutions, telecoms providers, retailers and other CIFAS members increasingly rely on data-sharing and fraud-prevention tools. However, the extensive use of fraud databases may also result in significant consequences for individuals, particularly where a CIFAS Marker has been applied unfairly or incorrectly.

What is a CIFAS marker?

A CIFAS marker is applied against an individual by a financial institution that suspects fraudulent activity. It is intended to warn other financial institutions about that individual. Markers are registered on a database and can remain in place for up to six years.

The consequences can be serious. A CIFAS Marker may affect an individual’s ability to open or maintain a bank account and may also affect employment opportunities in certain professions, including the civil service. Importantly, individuals can also find themselves subject to a marker where they have been victims of fraud.

Can you get a CIFAS marker if you have done nothing wrong?

Yes. In some cases, individuals who have been victims of fraud, identity theft or account misuse may find themselves subject to a CIFAS marker. Whether a marker has been applied correctly depends on the evidence available and the circumstances of the case.

Fraud risk is becoming more complex

According to CIFAS, identity fraud and facility takeover accounted for 72% of all cases reported in 2025. Identity fraud remained the most prevalent fraud type, with more than 242,000 cases filed, representing 54% of all fraud-risk cases recorded in the National Fraud Database.

Facility or account takeover also continued to rise. More than 78,000 cases were reported in 2025, accounting for 18% of all filings and representing a 6% increase on 2024. Mobile phone products, online retail and personal credit cards accounted for around 90% of all takeover cases. Unauthorised SIM swaps rose by 38%.

CIFAS also recorded more than 106,000 misuse of facility cases in 2025, a 43% increase on 2024. More than 22,000 cases were recorded under a new money mule filing category. Recruitment tactics included social media approaches, job scams, purported business opportunities and overpayments through online marketplaces.

AI is increasing the pressure on fraud controls

CIFAS identifies AI and generative technologies as factors enabling convincing impersonations, fake documents and synthetic identities to be created quickly and at scale. Individuals are also using more subtle techniques, including credential stuffing, SIM swaps and gradual profile changes designed to avoid detection.

In that environment, firms are under substantial pressure to act quickly when they suspect fraud. The operational imperative is obvious: fraud is becoming increasingly digital, organised and international.

However, speed and automation can also increase the risk that individuals are wrongly treated as fraud risks.

Challenging an unfair marker

Where a CIFAS marker has been wrongly applied, the first step is commonly to make a Data Subject Access Request (DSAR) to CIFAS. This can help identify the marker and the institution that requested it. A further request to the relevant financial institution may then assist in understanding the evidence relied upon. This may be by way of making a DSAR to the financial institution.

The next stage is to make targeted representations to the financial institution seeking removal of the marker. If removal is refused, there is a right of appeal through CIFAS. Where that process does not resolve the matter, a complaint to the Financial Ombudsman Service (FOS), and in appropriate cases onward litigation, may be considered.

The balance between prevention and fairness

The CIFAS Fraudscape 2026 suggests that there is a need for robust fraud prevention and cross-sector intelligence sharing. At the same time, CIFAS needs to recognise that markers can have far-reaching consequences for individuals, in particular, where they are imposed unfairly and/or wrongfully. With CIFAS’s focus on robust fraud prevention and cross-sector intelligence sharing, there is a need for sufficient evidence gathering prior to imposing any marker to fight the growing number of cases where such markers are applied unfairly and/or wrongfully.

Gherson insight: why Fraudscape 2026 matters

We have noticed that correlation between the use of automated fraud detection systems and adverse customer outcomes is getting stronger. As financial institutions face growing pressure to identify fraud quickly, decisions are often made using increasingly complex risk-scoring systems.

While these tools play an important role in preventing financial crime, they can also lead to situations where legitimate customers face bank account closures, payment restrictions or CIFAS markers based on incomplete or inaccurate information. In our experience, obtaining the underlying evidence and challenging assumptions early can be critical to achieving a successful outcome.

Frequently asked questions about CIFAS markers

How long does a CIFAS marker stay on your record?

Up to six years depending on marker type.

Can a CIFAS marker affect employment?

Yes. Certain employers may conduct checks.

Can I challenge a CIFAS marker?

Yes.

How do I find out if I have a CIFAS marker?

Usually via a DSAR.

Can a CIFAS marker be removed prior to the expiry of a six year period?

Potentially yes, if imposed unfairly or without sufficient evidence.

How Gherson can assist

Gherson’s Regulatory, White-Collar Crime and Investigations team are highly experienced in assisting clients in situations where a bank has frozen or closed their accounts. This includes submitting a request under data protection legislation, otherwise known as a Data Subject Access Request, to ascertain the information banks and other financial institutions may hold on the person concerned and to understand their decision making. After that we analyse the response received from the financial institution and, based on that, assist with any appropriate challenge.

If you would like to speak to us in respect of any of the issues raised in this blog or about your specific circumstances, do not hesitate to contact us for advice, send us an e-mail, or alternatively, follow us on XFacebook, or LinkedIn to stay-up-to-date.

The information in this blog is for general information purposes only and does not purport to be comprehensive or to provide legal advice.  Whilst every effort is made to ensure the information and law is current as of the date of publication it should be stressed that, due to the passage of time, this does not necessarily reflect the present legal position.  Gherson accepts no responsibility for loss which may arise from accessing or reliance on information contained in this blog.  For formal advice on the current law please do not hesitate to contact Gherson.  Legal advice is only provided pursuant to a written agreement, identified as such, and signed by the client and by or on behalf of Gherson.

This article was first published in 2025 and has been updated in June 2026. 

©Gherson 2026

View all news & Insights
Make an enquiry

Related Posts

Request Legal Advice

If you require legal assistance please get in touch
Contact us