Skip to content
Back to Blog
Synthetic Identity FraudIdentity TheftFraud PreventionAMLKYCFinancial Crime

Synthetic Identity Fraud: What It Is, How It Works, and Why It Is So Hard to Detect

Marco Beranzoni · · 13 min read

Reading time: ~13 minutes · For AML, fraud, KYC and credit risk professionals

Synthetic identity fraud is one of the most difficult forms of financial crime to detect, because in many cases the person being flagged does not actually exist.

Unlike traditional identity theft, where a criminal takes over the identity of a real person, synthetic identity fraud involves creating a new, fictitious identity by combining real and fabricated personal information. That difference matters more than it first appears.

In short: a fraudster pairs a genuine identifier (in the US, usually a Social Security number) with an invented name, date of birth and address. Because the identity is fabricated, there is no real victim to notice the fraud early and complain. The profile can be cultivated quietly for months or years, building a clean credit history, before the fraudster maximises every available credit line and disappears. Catching it depends on looking across accounts and devices, not on verifying one applicant’s paperwork in isolation.

In traditional identity theft, there is usually a victim who notices something is wrong. They see a credit account they did not open, a transaction they did not authorise, or a bill they do not recognise. They complain, dispute the activity, and create a paper trail investigators can follow.

With synthetic identity fraud, there is often no obvious victim in that conventional sense. The identity is fake. The profile is built slowly over time. The credit history can look genuinely clean. By the time the fraud is detected, the criminal may already have borrowed as much as possible and moved on.

I recently covered this topic on my YouTube channel. You can watch the full video here: Synthetic Identity Fraud, explained.

What Is Synthetic Identity Fraud?

Synthetic identity fraud is the creation of a fictitious identity using a combination of real and fabricated data.

A common pattern is a criminal taking a real Social Security number, often belonging to someone with little or no credit history, and combining it with a fake name, date of birth, address, phone number or email address. The result is an identity that looks plausible enough to enter the financial system, but does not correspond to any real person.

This is what makes synthetic identity fraud so difficult to catch. The underlying identifier can be technically valid. The identity built around it is not.

In the United States, Social Security numbers are particularly attractive to criminals because they are used so widely across financial services as identity anchors. An SSN does not inherently encode a date of birth the way some national ID numbers elsewhere do. The correct name, date of birth and SSN relationship sits in authoritative records, but not every institution verifies that relationship consistently, or in real time.

So the fraudster is not altering the date of birth attached to the SSN at the Social Security Administration. They are presenting a real SSN together with fabricated biographical details to lenders, credit providers or other institutions. Where those details are not properly verified, a new profile can start to take shape around that combination.

The Federal Reserve has described synthetic identity fraud as the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain (see Federal Reserve, Synthetic Identity Fraud in the U.S. Payment System, 2019).

FATF has also flagged synthetic identities as part of the wider risk landscape linked to digital identity, onboarding, verification and financial inclusion (see FATF, Guidance on Digital Identity).

How Synthetic Identity Fraud Works

Most synthetic identity fraud schemes do not happen overnight. They are built gradually, which is exactly why they can be so effective. A simplified version of the process has four stages.

1. Acquiring the seed data

The fraudster starts with a real identifier, in the US context often a Social Security number. It may belong to a child, a recent immigrant, an elderly person, or even a deceased person. These are attractive because they may have little or no active credit history, making inconsistencies harder to notice.

The data may come from breaches, dark web marketplaces, or identity data circulating within criminal networks. Large data breaches have made this worse. Once names, dates of birth, addresses and SSNs are exposed, criminals can reuse that information in different combinations for years after the breach was first reported.

2. Building the profile

The criminal pairs the real identifier with fabricated biographical information: a real SSN, a fake name, a fake date of birth, a controlled address, a new phone number, a new email address.

This creates a profile that does not fully match a real person, but may still pass weak or incomplete checks. Synthetic fraud often exploits gaps between systems. One institution may check whether the SSN exists. Another checks whether the address is formatted correctly. Another leans heavily on documentary evidence or credit bureau data. If nobody performs a strong, authoritative match across the full identity, the fabricated profile can start to survive.

3. Cultivating the identity

This is where synthetic identity fraud diverges from most other fraud typologies. The identity is not usually exploited for a large loss right away. Instead it is cultivated.

The fraudster may apply for a secured card, become an authorised user, open small credit lines, make regular payments, and gradually build a clean-looking credit history. From the outside the profile looks low risk: stable behaviour, no missed payments, increasing creditworthiness. That is exactly the point. The fraudster is building trust with the financial system, and this stage can last months or years.

4. The bust-out

Once the synthetic identity has built enough credibility, the criminal moves to exploitation, often called the bust-out. They apply for multiple credit products, loans or lines of credit across different lenders within a short window, maximise available credit, and disappear.

By the time one institution realises something is wrong, other institutions may already have been exposed to the same synthetic identity, or to linked synthetic identities built from the same seed data. This is why synthetic identity fraud is not only an onboarding problem. It is a monitoring problem, a credit risk problem, a fraud problem, and often an AML problem as well.

Why Static Document Checks Are Not Enough

One of the most common misunderstandings in financial crime controls is the assumption that valid data equals a valid person. It does not.

A document may look genuine. An SSN may be technically valid. An address may exist. A phone number may work. An email address may be active. A credit file may appear clean. None of that necessarily proves the applicant is a real person with a genuine identity history.

Static document checks at onboarding can miss synthetic identity fraud because the foundational data may not be obviously false. The problem is rarely fake documents. It is the artificial combination of real and fabricated data. That is why institutions need to move beyond isolated checks and look at the wider network around an identity, not just the identity itself.

Warning Signs for Individuals

For individuals, synthetic identity fraud can be hard to spot directly, especially where the identity is built using the SSN of a child or someone with limited credit activity. A few signals are worth acting on:

  • Mail arriving for unfamiliar names at your address
  • Credit offers addressed to someone who does not live there
  • A child unexpectedly having a credit file
  • Inquiries or accounts that do not make sense
  • Contact about debts linked to information you do not recognise

Parents should pay particular attention to children’s credit files. A child’s SSN is attractive to criminals precisely because it may go unused for years, giving a synthetic profile time to grow before anyone notices.

One of the strongest protective steps available in the US is freezing credit with the major credit bureaus, including for children where possible. A credit freeze makes it harder for new accounts to be opened using that identity. Checking credit reports regularly, and treating unfamiliar activity as something to investigate promptly rather than dismiss, is a habit worth building early.

Warning Signs for Financial Institutions

For financial institutions, the signals look different. Synthetic identity fraud is usually not detected by looking at one account in isolation. It is detected by looking across accounts, devices, addresses, contact details and behavioural patterns. Some of the more reliable indicators:

  • Multiple identities linked to the same device
  • Different applicants sharing overlapping addresses
  • Several profiles reusing the same phone number or email pattern
  • Thin credit files paired with unusually clean behaviour
  • SSN and date of birth combinations that do not make sense together
  • Recently created digital footprints
  • Repeated use of the same employer or income information
  • Clusters of accounts building credit and then busting out together
  • Third-party beneficiaries reused across multiple accounts

This is where network analytics becomes critical. A single account may look reasonable on its own. Connected to ten other accounts through devices, addresses, phone numbers or payment flows, the picture can change quickly.

Why Synthetic Identity Fraud Sits Between Fraud and AML

Synthetic identity fraud often exposes a structural gap between fraud and AML teams.

Fraud teams tend to focus on the immediate loss: the loan, the credit card, the application, the account takeover, the bust-out itself. AML teams tend to focus on the movement of funds, suspicious activity reporting, proceeds of crime and wider network behaviour. Synthetic identity fraud usually involves both. The fraud generates proceeds, and those proceeds are then moved, layered or dispersed through accounts, money mules, businesses, or crypto platforms.

From a compliance perspective, this means SAR or suspicious activity narratives should describe the network, not only the individual account: shared identifiers, linked addresses, common devices, repeated phone numbers, connected beneficiaries, and coordinated timing across multiple applications or accounts. If the suspicious activity is network-based, the reporting should reflect that network.

What Financial Institutions Should Be Doing

Financial institutions should treat synthetic identity fraud as more than a document verification issue. A stronger approach layers several things together.

First, identity verification should assess whether the identity makes sense as a whole, not only whether individual data points are technically valid. Second, institutions should use authoritative verification where appropriate, particularly when checking whether key identity attributes genuinely belong together. Third, thin-file applicants deserve structured scrutiny; a clean thin file is not automatically a low-risk file, and in synthetic identity fraud it may be exactly what the criminal has carefully built. Fourth, network-level controls matter: shared devices, addresses, phone numbers, emails, beneficiaries and behavioural patterns can reveal connections invisible at single-account level. Fifth, fraud, AML, credit risk and onboarding teams should share intelligence, because a typology this cross-functional is easy to miss if each team only sees its own part of the picture.

In the US, FinCEN’s Section 314(b) information-sharing mechanism can support institutions sharing information related to money laundering or terrorist financing, subject to the relevant requirements (see FinCEN, Section 314(b) Information Sharing).

For teams building this out, our FinCrime Career Accelerator works through exactly this kind of cross-functional judgement, sanctions, FIU, MI reporting, QA and CDD, so analysts can spot a typology like this rather than just following a checklist.

Frequently Asked Questions

What is synthetic identity fraud? It is the creation of a fictitious identity by combining a real identifier, usually a Social Security number, with fabricated biographical details such as a fake name, date of birth or address. The resulting identity does not correspond to a real person.

How is synthetic identity fraud different from identity theft? Identity theft takes over an existing person’s identity, and that person usually notices and disputes the activity. Synthetic identity fraud fabricates a new identity, so there is typically no real victim watching their own credit file for something to go wrong.

Why is synthetic identity fraud so hard to detect? Because the underlying data can be technically valid even though the identity built around it is not, and because institutions often check individual data points in isolation rather than whether the full identity makes sense as a whole. Detection usually requires looking across accounts, devices and behavioural patterns rather than at a single application.

What is a bust-out in synthetic identity fraud? The bust-out is the final stage, where a cultivated synthetic identity applies for multiple credit products across lenders in a short window, maximises the available credit, and disappears, often before any single institution has noticed.

Can freezing a child’s credit prevent synthetic identity fraud? A credit freeze makes it harder to open new accounts using that identity, which is one of the more effective protective steps available to parents in the US. It does not eliminate the risk, but it closes a route criminals rely on precisely because children’s SSNs go unused for years.

Is synthetic identity fraud a fraud problem or an AML problem? Both. The fraud generates proceeds; those proceeds are then moved, layered or dispersed through the financial system. Institutions that keep fraud and AML analysis siloed are more likely to miss the full pattern.

Why This Typology Will Continue to Matter

Synthetic identity fraud is likely to remain a serious challenge because it exploits several weaknesses at once. It exploits the availability of breached personal data. It exploits overreliance on static identifiers. It exploits gaps between institutions. It exploits siloed fraud and AML teams. And it exploits the fact that a synthetic victim never complains.

That is also why no single control solves it. Better document checks help, but are not enough on their own. Better identity verification helps, but is not enough on its own. Better transaction monitoring, better fraud models, same story. The strongest response is layered: identity verification, behavioural analytics, network detection, fraud intelligence, AML investigation, credit risk insight and information sharing, working together rather than in sequence.

Final Thoughts

Synthetic identity fraud is dangerous because it challenges one of the basic assumptions of financial services: that the customer being assessed actually exists. A valid identifier does not always mean a valid identity.

For individuals, the practical message is simple: monitor your credit, freeze it where appropriate, and do not ignore unfamiliar activity. For financial institutions, the message is more complex but just as important: move beyond static onboarding checks and start looking at the network.

Synthetic identity fraud is not just a fake ID problem. It is a system problem. And where fraud and AML teams are not working from the same picture, criminals will keep exploiting the gap between them.

References

This material is for general information only and does not constitute legal advice. Sources include the Federal Reserve, FATF and FinCEN publications cited above.

Share: