Fraud & identity·Jul 3, 2026·10 min read

First-Party Fraud: When the Applicant Is Real and Lying

First party fraud lending losses come from real applicants misstating income and intent. What the data shows, and what source verification settles.

Alfred BEditorial Reviews
Oil painting of a harbour slip where a tallyman turns from a consignee's sealed crate to call down to the arriving crew

The document match is clean. The selfie matches the licence, the phone number carries four years of tenure, the name belongs to a person who has been alive for thirty-eight years and can prove it. Nothing in the identity stack has anything to say about this file. The problem is a single figure on the income page, and the applicant knows it is wrong.

First-party fraud in lending is misrepresentation by an applicant using their own genuine identity, most often about income, employment or intent to occupy. Identity verification cannot detect it, because the identity is real. Detection depends on corroborating the claim against a record the applicant does not control, and on watching what the loan does afterwards.

That is a different problem from the ones most fraud budgets were built for, and the controls that solve it sit somewhere else entirely.

What separates first-party fraud from third-party fraud?

The separation is whose identity is on the application. In third-party fraud, an applicant uses somebody else's identity or one assembled from parts. In first-party fraud, the applicant is the person they claim to be, and the false element is a claim about their circumstances.

The Federal Reserve built that distinction into its FraudClassifier model, announced on 18 June 2020, which starts by asking who initiated a payment in order to separate authorized from unauthorized parties. The Federal Reserve's guidance on the model states that fraud initiated by an authorized party is often overlooked and underreported. Cifas, the UK not-for-profit that operates the National Fraud Database, defines first-party fraud as fraud committed by customers, meaning not by employees and not by people using stolen or fake identities.

Two neighbouring problems sit outside that definition. A fabricated person who never existed is a synthetic identity, and an altered pay statement is a document tampering problem. Neither describes the applicant who passes every check because every check is asking about someone who genuinely exists.

Is first-party fraud in lending actually growing faster than identity fraud?

In several markets, yes, though the picture is uneven. In vendor research published on 15 April 2026, Equifax Canada reported first-party fraud up 31% year over year between the fourth quarter of 2024 and the fourth quarter of 2025, drawn from its Market Pulse fraud data.

The composition inside that release matters more than the headline. Equifax Canada reported that in banking and deposits, first-party fraud rose from 0.51% to 0.68% while third-party fraud fell from 0.45% to 0.32% over the same period, and that credit card first-party fraud nearly doubled, from 0.08% to 0.15%. Contradictory or mismatched applicant data became the dominant form of first-party fraud in credit cards, moving from 59% to 77% of first-party credit card cases. Equifax Canada put Ontario's credit card fraud-related credit loss as high as $123 million.

British filing data points the same way for one category and the opposite way for another. Cifas reported in Fraudscape 2026, published on 12 March 2026, that 444,993 cases were filed to the National Fraud Database in 2025, up 6%. Identity fraud fell 3%, to 242,003 cases. Misuse of facility, which covers an account used fraudulently by its genuine holder, rose 43% to 106,497 cases. False application filings, the first-party category sitting at the front door, fell 24% to 16,431.

So the fair summary is narrower than the growth rate suggests. First-party behaviour is rising, but the rise concentrates after the account opens rather than uniformly at application. A single number for first-party fraud growth is compressing several separate trends.

What do income and employment misrepresentation look like in the data?

Income and employment claims are where the misstatement usually sits. Fannie Mae's Mortgage Fraud Investigative Findings series for 2005 to 2021 puts occupancy misrepresentation at a peak of 40% of confirmed findings in 2014 and 11% in 2020, while income and employment misrepresentation rose steadily across the same years.

The size of that rise, and what it says about documents, belongs to the document tampering story. Employer existence is a separate question from the applicant's. Fannie Mae issued a fraud alert, updated in July 2021, listing businesses that had appeared on loan applications as places of employment but whose existence Fannie Mae could not confirm, and told lenders to exercise due diligence in reviewing the entire loan file where one of them appears.

Income overstatement is harder to see, because there is rarely a second copy of the number. Atif Mian and Amir Sufi, in work published in the Review of Financial Studies in 2017 and circulated as an NBER working paper in February 2015, measured it by subtracting IRS-reported income growth from the income growth reported on home-purchase mortgage applications in the same zip codes. Across 1991 to 2007 the two series moved together everywhere, with one exception. In the non-GSE market between 2002 and 2005 the correlation went to zero, and the zip codes with the largest gap later showed high default, falling income and rising unemployment.

The method is the part worth keeping. Inside the application, the misstatement was invisible. Beside an independent record of the same fact, it was obvious.

What does source verification actually settle?

It settles what was paid and by whom, and almost nothing about what happens next. Source verification retrieves a record from the institution holding it, which removes the applicant from the chain of custody for that one fact. Forecasts, intentions and events after the pull all sit outside its reach.

Freddie Mac's automated income assessment using direct deposit data, described in a fact sheet dated June 2025, shows both halves. The service assesses income from direct deposit data supplied by third-party providers and offers relief from enforcement of selling representations and warranties covering the accuracy of the income calculation, the integrity of the verification report data and the borrower's current employment status. It also requires 2 to 24 months of deposit history depending on income type, and that the lender have no knowledge contradicting a reasonable expectation of the income continuing for at least the next three years. The record proves the deposits. The three-year expectation is still a judgement someone has to make.

The tax authority route has the same shape and a different limit. The US Internal Revenue Service's Income Verification Express Service, described on an IRS page last reviewed on 19 April 2026, returns tax return, W-2 and 1099 transcripts to a lender. Transcripts describe what was filed, so their coverage ends at the last filing.

Then there is the population with no payroll record at all. Statistics Canada, in a study released on 3 June 2024, reported an average of 2,652,600 self-employed people in Canada in 2023, making up 13.2% of the employed population. Connected-account data still shows deposits landing for that group. What it cannot show is a payer confirming what it paid.

What a source-verified check settles about a genuine applicant, and what it leaves open.

Claim on the applicationWhat source verification settlesWhat stays open
EmploymentThat a payroll or deposit record exists in the applicant's nameConfirmation of the employer itself, which Fannie Mae treats as a separate check (fraud alert, July 2021)
Income amountWhat was actually paid, from the payer's record (Freddie Mac AIM fact sheet, June 2025)Whether that income continues; the same programme requires a reasonable expectation of continuance for three years
Historic incomeWhat was filed, via tax return, W-2 and 1099 transcripts (IRS IVES)The period since the last filing
Self-employed incomeDeposits arriving in a connected accountCoverage stops at the deposits themselves
LiabilitiesWhat was reported to the bureau as of the pullObligations taken on between verification and funding
Occupancy and intentNothing at all; intent is a statement about the futureObservable only afterwards; Elul, Payne and Tilson identified it by tracking residence four quarters post-origination (Philadelphia Fed, January 2023)

What does first-party fraud cost a lending book after funding?

It costs a default rate around 75% higher than a comparable declared investor's, and it lands inside the credit line rather than the fraud line. Ronel Elul, Aaron Payne and Sebastian Tilson measured that gap in Federal Reserve Bank of Philadelphia working paper 23-01, dated January 2023, across 584,499 mortgages originated between 2005 and 2017.

They identified undisclosed investors by checking whether self-declared owner-occupants held multiple first liens and had not moved four quarters after closing. Their loss concentration figure is the one to keep. Those loans were under 4% of originations and accounted for more than 11% of dollars in default. The same paper found fraudulent investors defaulting at nearly twice the rate of comparable declared investors, a gap of 6.4 percentage points in the 2005 to 2007 cohorts and 2.3 percentage points from 2008 to 2017.

Two other studies land in the same range on different data. Tomasz Piskorski, Amit Seru and James Witkin, in the Journal of Finance in 2015, found about 9.1% of roughly 1.9 million securitized loans originated between 2005 and 2007 carried misreported owner-occupancy or an undisclosed second lien, defaulting about 60% and 70% more often respectively. John Griffin and Gonzalo Maturana, in the Review of Financial Studies in 2016, found around 48% of securitized non-agency loans showed at least one misreporting indicator, associated with a 51% higher likelihood of delinquency.

Where the money goes after that is the part lenders discuss least. A misrepresented file does not announce itself. It performs, then it stops, and it reaches the collections queue booked as an ordinary credit loss. The Bank of Canada's staff analytical note 2026-3, published on 26 February 2026 by Laura Zhao, Aidan Witts and Jia Qi Xiao using TransUnion credit bureau data covering more than nine million Canadian mortgage holders, found revolving credit utilisation begins rising roughly two years before a first mortgage delinquency, with non-mortgage delinquency climbing 12 to 24 months ahead of it. The runway is long. By the time the account is worked, the application is three years old and nobody re-reads it.

Recovery is where the arithmetic gets short. The US Federal Trade Commission's study of the debt buying industry, published on 30 January 2013, examined more than 5,000 portfolios covering roughly 90 million consumer accounts with $143 billion in face value across nine of the largest debt buyers, and found they paid an average of about 4 cents per dollar of face value. That is the market price of a charged-off unsecured balance. A file that was wrong at intake ends up worth a few cents, having consumed underwriting, funding, servicing and collections on the way. That gradient is the whole case for catching it at the front of the process.

How much of this is people under pressure?

A meaningful share of it, and pretending otherwise makes for worse controls. Cifas published its Fraud Behaviours Survey 2025 on 12 May 2026, reporting that half of UK adults surveyed considered first-party fraud reasonable and that 8% said they had committed it, a figure unchanged since 2021.

The same survey put the figure at 33% among adults aged 25 to 34. Those numbers describe a spread, not a criminal class. Some applicants inside a first-party fraud population are running organised schemes. Others rounded a variable income up to whatever cleared the threshold, in a month when the alternative was losing something.

The distinction matters enormously for how a borrower is treated and hardly at all for how a portfolio performs, because a loan sized against income that is not there fails at the same rate whatever the sympathy attached to it. Getting the figure right is the kinder outcome on both sides of the table. It is a measurement job before it is a moral one.

What we couldn't verify

Four gaps, named rather than papered over. One concerns Canadian first-party fraud data published as rates without denominators, one a survey whose method is not stated, one a findings series that measures composition rather than incidence, and one a number nobody appears to publish at all.

No published Canadian total for first-party fraud losses exists. No Canadian first-party fraud figure we found publishes its methodology, denominators or sample, so none of them can be independently reconstructed, including the 31% growth rate quoted above.

The behaviours survey quoted above does not state its sample size or fieldwork dates in the release we could open, so those percentages are reported here as published.

Fannie Mae's investigative findings series counts confirmed findings rather than applications, so it measures the composition of what its investigators found rather than incidence in the market. No equivalent series exists for Canadian mortgage, auto or consumer lending.

We found no published estimate, from any regulator or statistical agency in Canada or the United States, of what share of charged-off consumer loans involved misrepresentation at application. That number may not be recoverable from existing records.

Common questions

What is first-party fraud in lending?
First-party fraud in lending is misrepresentation by an applicant using their own real identity, typically overstating income, misstating employment, or misstating intent to occupy a property. Cifas, which runs the UK National Fraud Database, defines it as fraud committed by customers rather than by employees or people using stolen or fake identities.

How is first-party fraud different from identity fraud?
Identity fraud uses someone else's identity or a fabricated one, so identity checks can catch it. First-party fraud uses a genuine identity, so every identity control returns a clean result. The Federal Reserve's FraudClassifier model, announced in June 2020, separates the two by asking whether the initiating party was authorized.

Does income verification stop first-party fraud?
It settles the income figure and little else. Freddie Mac's June 2025 fact sheet on income assessment using direct deposits describes relief tied to the accuracy of the calculation, while still requiring a lender judgement that the income continues for three years. Intent, future liabilities and self-employed earnings stay open.

What does first-party fraud cost a lender?
A default rate around 75% higher than a comparable declared investor's, itself an elevated-risk group rather than a clean file. Federal Reserve Bank of Philadelphia working paper 23-01, dated January 2023, found undisclosed-investor loans were under 4% of originations but more than 11% of dollars in default.

Is first-party fraud growing in Canada?
Equifax Canada reported on 15 April 2026, in vendor research whose methodology is not published, that first-party fraud rose 31% between the fourth quarter of 2024 and the fourth quarter of 2025, with banking first-party fraud up from 0.51% to 0.68% while third-party fraud fell from 0.45% to 0.32%.


Carousel collects applicant income and employment from the institutions that hold the record, so the figure in the file is the figure the payer reported. See how verification fits your flow

Fraud & identityfirst-party-fraudincome-verificationemployment-verificationcredit-loss