Identity Verification News: The Biggest IDV Failures of Q1 2026

Identity Verification News The Biggest IDV Failures of Q1 2026

It’s fair to say Q1 2026 didn’t lack variety when it came to identity verification failures. In less than three months, a crypto exchange was hit with 6.65 million KYC violations, a major bank’s onboarding was compromised using deepfake technology, and several online platforms struggled with age verification.

If there’s one common thread, it’s this: each case exposed a different weak spot in remote identity checks, and none of them were minor. The consequences ranged from fines and court cases to delayed rollouts and public criticism.

In this identity verification news report, we break down five of the biggest incidents from Q1 2026 and highlight what they reveal about where identity systems are still falling short, and what companies need to fix before those gaps turn into their own headline.

1. Bithumb’s 6.65 million KYC violations

On March 17, South Korea’s Financial Intelligence Unit (FIU) took action against Bithumb, reporting a staggering 6.65 million compliance violations. These included around 3.55 million failures in customer verification and 3.04 million cases where trading wasn’t blocked despite incomplete checks. The regulator also found that Bithumb supported over 45,000 transactions involving 18 unregistered foreign virtual asset operators.

The issues were wide-ranging:

  • Blurred or partially hidden IDs were still accepted
  • Customers with missing or incomplete address data were approved
  • Reverification reused old documents instead of collecting new IDs
  • Deadlines for reverification were missed
  • High-risk users were allowed to keep trading without additional checks
  • Driver’s licenses were verified without required encrypted serial numbers
  • Around 16,000 cases lacked stored ID document copies

The penalties reflected the scale. Bithumb received a six-month partial business suspension (March 27 to September 26, 2026) and a fine totaling 36.8 billion won. The CEO was formally reprimanded, and the reporting officer was suspended for six months.

One detail worth noting: existing users could continue trading, while newly registered users were only restricted from external transfers, not all activity.

2. ABN AMRO onboarding bypassed with deepfakes

One of the clearest examples of deepfake-assisted fraud this quarter came from the Netherlands. On March 18, DutchNews reported that a man had opened 46 bank accounts at ABN AMRO using deepfake technology to bypass facial recognition checks.

According to prosecutors:

  • The onboarding process required an ID and a selfie, but the suspect used manipulated images of his own face
  • Some victim IDs were sourced from social media, others from a classifieds site under the pretense of “verification”
  • In one case, a woman’s ID was paired with a selfie clearly showing a man helping uncover the scheme

Authorities reportedly found debit cards, PINs, fake IDs, and even chat logs where the suspect asked ChatGPT how to bypass the bank’s security. CCTV footage showed cash deposits into multiple accounts, suggesting possible money laundering.

Prosecutors are seeking a 30-month prison sentence (six months suspended) and €6,240 in damages.

3. Roblox’s age checks face real-world spoofing

Roblox made a bold move in early January, rolling out facial age checks globally for chat access. The goal was to limit interactions between adults and minors and introduce parental controls for younger users.

But within days, the system ran into trouble.

Users, parents, and developers quickly reported incorrect age classifications. Soon after, examples of spoofing started circulating, some creative, some concerning.

Key issues reported:

  • Adults being classified as teenagers, and vice versa
  • Users bypassing checks with avatars, makeup, or even photos (including one of Kurt Cobain)

Roblox responded in February by introducing:

  • One-time age reset options for adults
  • Parental correction tools
  • Additional verification prompts if user behavior didn’t match their recorded age

The company also stated that 45% of its 144 million daily active users had completed roblox age verification.

Still, the situation highlighted an important reality: at global scale, users judge these systems not by lab accuracy but by how reliably they work in everyday conditions.

4. Discord delays rollout after spoofing concerns

Discord followed a similar path, announcing stricter age assurance measures in early February. The plan included teen-by-default settings and additional verification for users accessing restricted content.

The platform relied on a mix of signals, account history, payment data, and behavioral patterns, and offered facial age estimation or ID verification when needed. It also emphasized that facial analysis would happen on-device, with only age group data shared.

But just two days after the announcement, reports surfaced of a browser tool capable of bypassing the system using a synthetic 3D face.

By February 24, Discord postponed the global rollout to the second half of 2026.

The company acknowledged communication issues, said most users (around 90%) wouldn’t need verification, and promised additional methods, including credit card checks. Future implementations would also prioritize fully on-device verification.

5. Reddit fined for relying on self-declared age

While others struggled with imperfect systems, Reddit faced the opposite issue: not having one at all.

On February 24, the UK’s Information Commissioner’s Office (ICO) fined Reddit £14.47 million for failing to implement proper age assurance.

Despite prohibiting users under 13, Reddit relied solely on self-declared age during sign-up until mid-2025. Regulators pointed out how easily this can be bypassed and noted that Reddit lacked a lawful basis for processing children’s data.

The ICO also found that the platform had not conducted a data protection impact assessment on risks to children before January 2025.

In a follow-up letter on March 12, the regulator urged platforms to move beyond self-declaration and adopt robust age verification technologies, using the Reddit case as a clear example.

What these cases tell us

At first glance, these incidents may seem unrelated. But together, they point to a deeper issue: identity verification doesn’t fail because of one weak control, it fails when the overall system isn’t strong enough for the level of risk.

Modern fraud doesn’t rely on a single trick. It’s iterative, fast, and designed to probe systems until it finds the easiest way through.

That’s why layered verification matters.

Solutions like Regula IDV Platform are built around this principle, combining document, biometric, and age verification into a single system while maintaining full visibility and control over the process.

In practice, that means the ability to:

  • Cross-check document data (VIZ, MRZ, barcode, RFID) and detect tampering using liveness and security feature analysis
  • Match selfies against document and chip images while blocking spoofing attempts with liveness detection
  • Verify age within the same workflow instead of relying on weak or standalone checks
  • Route high-risk cases to stricter flows or manual review
  • Use device, IP, and behavioral data to strengthen identity profiles
  • Maintain full verification history for returning users
  • Control access and actions across teams with role-based permissions
  • Keep detailed logs for compliance and audits
  • Integrate seamlessly with AML, PEP, and sanctions screening systems

In short, staying ahead of both attackers and regulators means treating identity verification as a system, not a single checkpoint.

UNLOCK THIS FREE DOWNLOAD

DOWNLOAD NOW

Fill Your E-mail to Receive this Download Directly in Your Inbox.

RECEIVE OUR UPDATES

The Biz Model Club

Get daily, no-fluff insights on the latest business models, startup strategies, and trends delivered straight to your inbox.