An IDfy analysis of Video-KYC onboarding data suggests that district-level fraud risk can emerge, recede and reappear across locations faster than conventional enforcement maps may capture. The findings place Bareilly, Lakhimpur Kheri and Varanasi among 10 districts showing elevated early signals, while also indicating that the geography of digital fraud is dynamic rather than fixed.
The analysis is based on V-KYC onboarding data collected between April 2025 and June 2026 across around 130 districts. It examined monthly onboarding attempts and rejection patterns, applying statistical tests and minimum fraud-volume thresholds before ranking districts. The objective was to identify concentrations of suspicious activity rather than treat every increase in rejection rates as evidence of an established fraud network.
That distinction is central. The districts listed in the analysis are described as showing current V-KYC risk signals. Some may already be active fraud hotspots, while others may be emerging clusters. A high rejection rate is therefore an early-warning indicator, not by itself proof that fraud has been committed in a particular district or that residents of that district are responsible for fraudulent activity.
The data places Lakhimpur Kheri at the top of the listed risk signals, with a V-KYC rejection rate of 14.03%. Bareilly followed at 13.37%, while Varanasi recorded 12.32%. Saharanpur stood at 10.32%, Muzaffarnagar at 9.77%, Panipat at 9.52%, Firozabad at 8.81%, Jodhpur at 7.61%, Lucknow at 6% and Ghaziabad at 5.91%.
The spread of locations matters because it shows that digital fraud risk is not confined to one type of settlement or one administrative region. The list includes districts in Uttar Pradesh, Haryana and Rajasthan, ranging from major urban centres such as Lucknow and Ghaziabad to districts that may be connected to wider regional networks through transport, communications and financial channels. The supplied analysis does not establish the precise operational links between these locations, but it does show that risk signals can appear across a broad geography.
The more significant finding concerns duration. In IDfy’s 15-month analysis, 81% of elevated-risk spikes in a district lasted only one month. Just 6.5% continued for three months or more. This suggests that a monitoring system focused only on persistent, already-known hotspots could miss shorter episodes of concentrated risk.
The pattern also complicates the idea of a permanent fraud map. When the risk in one district falls, another location may begin to show elevated signals. In 39% of the cases examined, the next hotspot was in the same state, while the average movement between linked hotspot observations was around 190 kilometres. These figures describe the movement of observed risk, not the physical movement of the same fraud operators. IDfy explicitly cautions that the data does not establish that operators moved from one district to another.
That limitation is important for public administration. A district-level signal can help institutions decide where to increase scrutiny, but it cannot replace investigation. It also should not be used to stigmatise a district, its residents or legitimate businesses. The value of the data lies in identifying where institutions may need to ask more questions, not in assigning collective blame.
What the V-KYC data reveals
The analysis argues that V-KYC data can provide an earlier warning than public reporting. Across financial year 2026, IDfy identified around 16 district-level fraud hotspots every quarter. The company said that between 85% and 90% of these were later confirmed through law-enforcement action or news reports. In the verified cases, it said V-KYC signals appeared up to two months before public reporting.
The larger whitepaper cited in the report gives a somewhat wider time range, saying that V-KYC rejection data flagged high-risk districts between two weeks and two months before police or media reporting in the cases studied. It also said V-KYC data identified 33% more active fraud locations than official daily reporting, while the company’s forecast came earlier than I4C reporting in 33% of regions.
These findings point to a gap between the emergence of suspicious digital activity and the moment when that activity becomes visible through formal enforcement or news coverage. Traditional reporting systems often depend on complaints, investigations, arrests, seizures or official disclosures. Onboarding data, by contrast, can register unusual patterns while a customer or account is still being assessed.
That does not make automated or statistical detection self-sufficient. The analysis itself relies on statistical validity and minimum fraud-volume thresholds, and it uses a Z-score to distinguish concentrated risk from fluctuations caused by small samples. Such methods are designed to reduce the possibility that a few unusual cases will create an inflated alert. Even so, a signal requires human review and independent confirmation before it can support enforcement action.
The examples cited by IDfy illustrate how the pattern may spread across adjoining areas. In the case of Nuh in Haryana, the report says fraud activity later expanded into adjoining districts of western Uttar Pradesh. In Gujarat, it describes a cluster that originated in Surat and progressively spread towards Botad, Amreli and Jamnagar. The source does not establish whether these examples involved the same individuals or organisations, and the geographic sequence should therefore be read as a pattern of observed activity rather than a proven chain of responsibility.
The governance challenge is coordination
The urban and administrative issue raised by the analysis is not simply whether one district has a higher rejection rate. It is whether financial institutions, law-enforcement agencies and digital-risk teams can share enough information to respond when risk crosses administrative boundaries.
District administration is structured geographically, while digital fraud networks can operate through accounts, devices, communications and transactions that do not respect district borders. A district may show a declining signal just as a nearby district begins to show a new one. If institutions treat each location as an isolated unit, the response may remain reactive and fragmented.
IDfy’s recommendation is for financial institutions to monitor neighbouring districts and pre-alert nearby areas when a high-risk district is identified. It also recommends identifying high-risk districts while the risk is active, rather than waiting for a hotspot to become established through enforcement or public reporting.
This is a shift from a static watchlist to a moving risk system. A static list asks which locations are known to be risky. A dynamic system asks where the next concentration may appear, how long the signal persists and whether nearby districts are showing related changes. The supplied material does not establish that such a system has been adopted by public authorities, but it identifies the operational problem that institutions would need to solve.
The approach also has implications for accountability. If V-KYC signals are used to intensify scrutiny, institutions must be able to distinguish a risk-based review from an automatic rejection based solely on location. The source does not provide details of how individual customers are treated, what safeguards apply or how false positives are resolved. Those unanswered questions matter because district-level indicators are aggregate signals and cannot determine the conduct or intent of an individual applicant.
A changing map of digital risk
The numbers in the analysis describe a highly uneven and short-lived pattern. Of the elevated-risk spikes studied, more than four out of five lasted only one month, while fewer than one in 15 continued for at least three months. This makes timing a major factor in fraud monitoring. A delayed response may miss the period in which the signal is most useful, while an extended response based on an outdated signal could create unnecessary scrutiny.
The repeated reappearance of locations adds another layer. IDfy said that 11 active hotspots in the current quarter had already been flagged earlier in financial year 2026. This indicates that a district can leave the immediate risk picture and later return to it. The finding challenges the assumption that a hotspot becomes irrelevant once its reported activity falls.
At the same time, the analysis does not provide enough evidence to explain why risk rises in one district and falls in another. It does not establish whether the changes are driven by organised networks, local account recruitment, shifts in enforcement, differences in onboarding volumes, reporting practices or other factors. Those causes would require investigation beyond the V-KYC patterns described in the report.
That boundary between detection and explanation is essential. Data can identify an unusual concentration, estimate its duration and track its geographical relationship with other signals. It cannot, without supporting evidence, establish the identity of perpetrators, the causes of the pattern or the exact route through which activity spreads.
For cities and districts increasingly connected through digital financial services, this distinction is part of the wider governance challenge. Urban economies depend on fast onboarding, remote verification and interoperable financial systems. The same systems can also create new surfaces for fraud, making the quality and speed of monitoring a public-interest concern.
The IDfy analysis confirms that district-level fraud risk can be detected before it becomes fully visible through law-enforcement action or media reporting in the cases studied. It also shows that risk signals are often brief, can recur and may appear in nearby locations. What remains uncertain is how these signals should be integrated with official investigations, what safeguards should govern location-based scrutiny and whether the reported patterns hold across a wider set of districts and independent datasets.

