KYCKART
KYCKART Intel · June 2026Newsletter

The Same Fraudster, Ten Different Names

A fraudster rejected at one institution can walk to the next one the same afternoon with the same documents and a different name. No one in the system connects the dots. Not because anyone is careless. Because no institution can see past its own front door.

calendar_monthJune 2026
schedule~8 min read
library_books18 Cited Sources

At KYCKART[1], the question we keep returning to isn’t how fast we can catch fraud. It’s what it would take to make this fraud impossible to repeat. Reduction is a KPI you report on quarterly. Elimination is a design problem, and design problems are worth thinking about years ahead of the next big loss, not in the week after it.

One pattern keeps surfacing in that thinking, across nearly every conversation we have with banks, NBFCs, fintechs, and insurers: a fraudster rejected at one institution can walk to the next one the same afternoon with the same documents, the same face, and a different name, and nobody in the system will connect the dots. Not because any one institution is careless. Because no institution can see past its own front door, and today, none of them are supposed to.

lightbulb

A fraudster you reject today isn’t gone. They’re just walking to whichever door doesn’t know them yet. That’s a systems problem, not a client problem.

You’re reading this because you’re part of the KYCKART Intel community: BFSI leaders who think seriously about identity risk. If this was forwarded to you, subscribe for future editions on our website.

01

The Blind Spot in India's KYC Infrastructure

Three existing systems that each solve a slice of the problem, but none cover it end-to-end

India has three pieces of shared infrastructure that sound like they should solve this. None of them do, individually.

CKYCR (CERSAI)
Lets a regulated entity check whether a KYC record already exists for a PAN or Aadhaar. Built for de-duplication, saving customers from repeating paperwork [3], not for flagging that the same document set has surfaced under five different names across five different lenders.
RBI Central Fraud Registry
Has tracked bank fraud above ₹1 lakh since 2016, but access is restricted to banks. NBFCs, who now co-lend heavily with banks, carry real exposure to the same fraud rings and are petitioning for access, which may require amending the RBI Act itself. [6][7]
DPIP (RBI & NPCI)
A newer real-time intelligence layer doing genuinely good work flagging mule accounts: 524,000+ flagged in March 2026 alone [4][5]. But its lens is payment and transaction fraud, not onboarding-stage identity fraud.

“We spend enormous effort verifying a customer once, in isolation, and almost none connecting what we learn to what the rest of the industry already knows. A shared fraud intelligence layer across regulated and non-regulated entities isn’t a nice-to-have anymore. It’s the only way individual due diligence keeps pace with organised, repeat fraud.”

Lokesh Chaudhary

Founder & CEO, KYCKART

02

The Scale of What Falls Through the Gap

RBI FY26 Annual Report figures: what they actually reveal

The numbers deserve a closer look than the headline gives them. RBI’s annual report[2] shows fraud value reported by banks rose 46.4% to ₹48,021 crore in FY26. But ₹30,199 crore of that, nearly two-thirds, came from 314 legacy cases reclassified after re-examination under a 2023 Supreme Court judgment. The case count actually fell sharply, from 23,722 to 10,114.

That doesn’t make the underlying problem smaller. It makes it harder to see: institutions are catching fewer cases, but each one is larger and takes years to surface. Layer in that industry research suggests 33%of BFSI fraudsters are repeat offenders, and the picture is less “fraud is exploding” and more “fraud is compounding quietly, and we’re only finding it long after the fact.”

This is what loan stacking and identity reuse look like in practice: a rejected applicant reapplies elsewhere before any of us has time to share what we’ve learned. Without cross-institution signal-sharing at the speed of origination, a rejection at one door is not a barrier anywhere else.

FY26 Fraud Value

+46.4%

Year-over-year growth in bank-reported fraud value

RBI FY26 Annual Report [2]

Reclassified Share

63%

Of FY26 value came from reclassified legacy cases, not new-year fraud

RBI FY26 Annual Report [2]

Fraud Case Count

-57.4%

Year-over-year decline in reported case count (23,722 to 10,114)

RBI FY26 Annual Report [2]

Repeat Offenders

33%

Share of BFSI fraud attributed to repeat individuals or rings

Industry research estimates

Mule Accounts

524K+

Flagged by DPIP in March 2026 alone (payment fraud lens only)

RBIH DPIP [4] · The 420 [5]

Source: RBI FY26 Annual Report. Figures reflect reported fraud value, not confirmed new-year occurrence.

Every fraud rejection your institution issues today is intelligence someone else needs tomorrow. Sitting on it doesn't protect you. It just delays the next institution's loss.
03

What a Shared Fraud Intelligence Layer Should Look Like

The credit bureau model, purpose-built for identity and document reuse

The model already exists in an adjacent industry: credit bureaus. Every lender contributes data. Every lender benefits from the pooled signal. A KYC fraud intelligence layer needs the same logic, purpose-built for identity and document reuse rather than repayment history.

01

Document and biometric fingerprinting

Not storing raw documents, but hashed signals that flag when the same Aadhaar, PAN, face, or device has appeared under a different name at a different institution.

02

Coverage beyond banks

Fintechs, NBFCs, and insurers included from day one, since today's fraud rings deliberately target the least-connected parts of the ecosystem first.

03

Real-time query at origination

The check has to happen during onboarding, not in a monthly batch report, or the fraud has already moved on by the time anyone reads it.

Importantly, what comes back from a query should never be another institution’s customer record. It should be a limited, actionable signal:

Potential match to a previously reported suspicious identity pattern

Associated risk signal reported by multiple participating institutions

Enhanced verification recommended

No known network-level risk signal

policy

No underlying record, no other institution’s decision, no raw PII. Just enough to decide whether this application deserves a closer look.

The question the industry actually needs to answer isn’t who gets to build the database. It’s what narrowly defined fraud signals regulated institutions should be allowed, and required, to share, under what safeguards, and through which trusted governance model. Get that question right first, and the technology choice becomes straightforward.

04

Where the Gaps Show Up Today

Four vectors exploiting the absence of cross-institution signal sharing

The absence of a shared intelligence layer isn’t theoretical. Here is where it creates exploitable gaps in practice:

sync_alt

Loan Stacking

Rejected applicants reapply elsewhere within hours. No shared signal exists to stop them. Each institution evaluates in isolation, and the fraudster simply works down the list until one approves.

videocam_off

Deepfake Video KYC

AI-generated faces and forged documents already cost one NBFC ₹15-20 crore in a single ring. Without cross-institution biometric hashing, the same deepfake can be reused against every institution independently.

person_search

Synthetic Identity Reuse

Same face, same documents, different name: invisible without cross-institution matching. A synthetic identity that fails once can be resubmitted with a name variation the same afternoon.

account_tree

Regulatory Fragmentation

CFR, CKYCR, and DPIP each solve a slice of the problem. None cover fintech or NBFC KYC fraud end-to-end. Fraud rings specifically map and exploit the boundaries between these systems.

05

Start With a Sandbox, Not a Mandate

A structured feasibility exercise before committing to nationwide infrastructure

India doesn’t need to commit to a nationwide registry on day one. It needs a structured feasibility exercise: a controlled pilot with a small group of banks, NBFCs, insurers, fintechs, privacy experts, and relevant public agencies, testing only defined, high-confidence scenarios such as confirmed document forgery or mule-account-linked onboarding attempts.

A pilot like this should be judged on five things:

shield_check

Fraud prevention value

rule

False positive rate

speed

Query latency

lock

Privacy risk

person_check

Customer-impact outcomes

The goal isn’t to prove that surveillance works. It’s to find out whether a limited, accountable, privacy-preserving network can reduce repeat fraud without becoming a new source of exclusion or misuse. That’s a smaller ask than it sounds, and it’s the one worth making first.

Frequently Asked Questions

KYCKART Intelligence

Ready to share what you know before the next door opens?

KYCKART is building the infrastructure for shared fraud intelligence across India’s BFSI ecosystem. If you want to be part of the conversation, talk to us.

Start the Conversationarrow_forward