Synthetic identity fraud is a financial crime where criminals combine real and fabricated personally identifiable information to create an entirely new, fictitious persona that doesn’t belong to any actual person. Unlike traditional identity theft, where a thief impersonates a real, living individual, synthetic identity fraud builds a brand-new profile from scratch. That distinction matters because there’s often no immediate victim to report the crime, which means fraudsters can operate undetected for months or even years.
You might hear the terms synthetic identity fraud and synthetic identity theft used interchangeably. They refer to the same thing. The fraud industry also shortens it to synthetic ID fraud or just synthetic fraud. Regardless of the label, the mechanics stay the same: real data gets mixed with fake data to create a person who exists only on paper.
How Synthetic Identity Fraud Works
The process behind synthetic identity fraud follows a predictable pattern, though the execution has grown more sophisticated over time. Fraudsters typically start by obtaining a real Social Security number (SSN), often belonging to someone unlikely to check their credit report anytime soon.
From there, the scheme unfolds in stages:
- Data sourcing: The fraudster acquires a legitimate SSN, frequently purchased on the dark web or harvested from data breaches
- Identity assembly: That real SSN gets paired with a fabricated name, date of birth, and address to create what fraud professionals call a Frankenstein identity.
- Credit file creation: The fraudster applies for credit, often starting with secured cards or retail accounts that have lower approval thresholds. Initial applications may be denied, but those denials actually create a credit file with the bureaus, which is exactly what the fraudster wants
- Credit cultivation: Over 12 to 24 months, the synthetic identity builds legitimate-looking credit history through small purchases and on-time payments
- The bust-out: Once credit limits climb high enough, the fraudster maxes out every available line and disappears
What makes this scheme particularly effective is patience. Traditional fraud happens fast, with a stolen card getting used immediately. Synthetic fraud plays out over years, which is why automated systems often treat these profiles as legitimate thin-file customers rather than threats.
Synthetic Identity Fraud vs. Traditional Identity Theft
Synthetic identity fraud creates a ghost, a person who exists only on paper. When the fraud finally surfaces, there’s no angry customer calling their bank because the customer never existed in the first place.
Traditional identity theft, by contrast, hijacks a real person’s existing identity. Their name, SSN, and credit history are all tied to someone who is very much alive and will eventually notice something is wrong. A fraudulent charge shows up on a statement, a collections call comes in, or a credit application gets denied, and the victim has both the standing and the motivation to report it. That built-in tripwire is exactly what synthetic identity fraud is designed to avoid.
Fraudsters blend a real SSN, often a child’s or someone who rarely checks credit, with fabricated personal details, building an identity with no living victim to sound the alarm. The fraud can go undetected for years, accumulating credit lines and payment history, until lenders are left holding losses with no one to chase.
Who Gets Targeted for Synthetic Identity Fraud
Fraudsters deliberately seek out SSNs from people unlikely to check their credit reports. This targeting strategy explains why certain groups face disproportionate risk.
1. Children and minors
Children represent prime targets because their SSNs sit dormant for years. A child’s credit file won’t be checked until they apply for student loans or their first credit card, potentially creating 18 years of undetected fraud opportunity. Parents rarely think to request a credit report for a minor, so the fraud often isn’t discovered until the young adult is denied credit of their own.
2. Elderly individuals
Seniors, particularly those in care facilities, may not actively monitor their credit. Cognitive decline can also make it harder to notice or report suspicious activity. Family members or caregivers handling finances may not think to check for a synthetic identity layered on top of a senior’s legitimate SSN.
3. Deceased persons
The deceased can’t check their credit reports. While the Social Security Administration maintains a Death Master File, gaps in reporting create windows where a deceased person’s SSN remains usable. Estates are rarely monitored for credit activity, so fraud built on a deceased person’s number can persist well after probate has closed.
4. Incarcerated individuals
People serving long prison sentences rarely have reason to monitor their credit, making their SSNs attractive for long-term synthetic identity schemes. Limited access to credit monitoring tools while incarcerated only widens the window fraudsters have to work with.
5. Recent immigrants
Individuals new to the U.S. credit system often have limited credit histories. This makes it easier for fraudsters to establish synthetic identities that blend in with other thin-file applicants. Unfamiliarity with U.S. credit monitoring practices can also delay how quickly suspicious activity gets flagged.
What ties these groups together is not vulnerability in the traditional sense, but invisibility. Each one shares a gap in oversight that fraudsters can exploit precisely because no one is watching closely enough, or for long enough, to catch the fraud early. Understanding these patterns matters less as a way to assign blame to victims and more as a roadmap for where credit monitoring, reporting requirements, and institutional safeguards need to be strengthened.
Why Synthetic Identity Fraud Is Hard to Detect
Traditional fraud detection relies on comparing applicant information against known identity records. When someone applies for credit, systems check whether the name, address, and SSN match what’s on file. Synthetic identities break this model because there’s no “real” identity to match against.
Several factors compound the detection challenge:
- No victim complaints: The cornerstone of fraud detection, customer reports, simply doesn’t exist for synthetic identities
- Legitimate-looking behavior: Synthetic identities often exhibit better payment behavior than real customers during the cultivation phase
- Fragmented data: Credit bureaus may create multiple files for the same synthetic identity, none of which raise red flags individually
- SSN randomization: Since 2011, the SSA has issued SSNs randomly rather than by geographic region, eliminating one traditional verification signal
Synthetic identity might pass standard verification checks with flying colors. The billing address matches, the SSN validates, and the credit history looks clean because the fraudster spent months making it look that way.
How Synthetic Identity Fraud Affects Merchants
While synthetic identity fraud often targets lenders and financial institutions, merchants face significant fraud exposure too. The impact shows up in several ways that directly affect your bottom line.
1. New account fraud
Fraudsters use synthetic identities to open accounts on your platform. They might exploit new-customer promotions, build purchase history for later bust-outs, or establish accounts for reselling stolen goods. Because these identities pass standard verification checks, they can sit dormant for months before ever being used maliciously.
2. Buy now, pay later abuse
BNPL services have become a prime target. A synthetic identity can open multiple BNPL accounts across different providers, make purchases, and default on all of them simultaneously. Since each provider typically checks credit independently, a single fabricated identity can rack up debt across several platforms before any of them notices a pattern.
3. Loyalty program exploitation
Synthetic identities can accumulate rewards points across multiple accounts, then consolidate or cash out before the fraud is discovered. These programs often have weaker identity verification than core financial products, making them an easy entry point for testing whether a synthetic identity will hold up.
4. Chargeback complications
When a synthetic identity eventually busts out, the resulting chargebacks hit your merchant account. Unlike traditional fraud where you might recover funds, synthetic fraud leaves no real person to pursue. Even law enforcement has little to work with, since there is no actual victim to file a police report or corroborate the theft.
The challenge for merchants is that synthetic identities often look like ideal customers during the cultivation phase. They pay on time, don’t dispute charges, and gradually increase their purchase volume. All of those behaviors would normally signal a valuable customer relationship.
How to Detect Synthetic Identity Fraud
Detection requires looking beyond traditional verification methods. Since synthetic identities are designed to pass standard checks, the focus shifts to signals that reveal inconsistencies in the identity’s history and behavior.
1. Identity element analysis
Look for mismatches between identity elements that wouldn’t occur naturally. An SSN issued in 2015 paired with a stated birth year of 1970 suggests the SSN was obtained recently, not at birth.
2. Credit history anomalies
Synthetic identities often show unusually rapid credit-building patterns. A thin file that suddenly adds multiple tradelines or shows authorized-user accounts across unrelated cardholders warrants scrutiny.
3. Device and behavioral signals
Device fingerprinting and behavioral analytics can reveal when multiple “different” customers share the same device, IP address, or behavioral patterns like typing speed and mouse movements.
4. Velocity monitoring
Track how quickly new accounts are being created with similar characteristics. Fraud rings often create synthetic identities in batches, which produces detectable patterns.
5. Network analysis
Cross-reference application data across your customer base and, if available, across merchant networks. Synthetic identities often share addresses, phone numbers, or devices with other suspicious accounts.
How to Prevent Synthetic Identity Fraud
Synthetic fraud prevention combines verification improvements with ongoing monitoring. No single tool catches everything, so a layered approach works best.
- Implement identity verification at onboarding: Go beyond basic SSN validation. Document verification, knowledge-based authentication, and biometric checks add friction that discourages fraudsters while remaining manageable for legitimate customers.
- Use device intelligence: Device fingerprinting identifies when the same device creates multiple accounts. This signal alone can flag fraud rings operating at scale.
- Monitor for authorized-user patterns: Synthetic identities often build credit by becoming authorized users on established accounts. Unusual authorized-user activity, especially across accounts with no apparent relationship, can indicate synthetic identity cultivation.
- Leverage consortium data: Shared fraud intelligence across merchants and financial institutions helps identify synthetic identities that have been flagged elsewhere. When a fraudster hits one merchant in the network, that signal can protect others.
- Establish velocity rules: Set thresholds for how quickly new accounts can be created from similar IP ranges, devices, or with overlapping identity elements. Legitimate customers rarely trigger velocity rules, while fraud rings frequently do.
The businesses that manage synthetic identity fraud most effectively treat prevention as an ongoing process rather than a one-time checkpoint, revisiting their verification standards and monitoring rules as new tactics emerge. Combined with the four measures above, that continuous approach turns synthetic identity fraud from a hidden, slow-building loss into a risk that gets caught early enough to matter.
Staying Ahead of a Fraud Type Built to Look Legitimate
Synthetic identity fraud succeeds precisely because it doesn’t look like fraud. That’s what makes it more dangerous than traditional identity theft: there’s no victim filing a complaint to tip you off, and by the time the bust-out happens, the loss is already locked in. As data breaches keep expanding the pool of usable SSNs, synthetic identity fraud isn’t going away, but a merchant that knows what to look for is far harder to turn into a target.
Frequently Asked Questions
How is synthetic identity fraud different from account takeover?
Account takeover involves gaining unauthorized access to an existing customer's account, while synthetic identity fraud creates entirely new accounts using fabricated identities. ATO exploits real relationships, whereas synthetic fraud manufactures fake ones.
Does synthetic identity fraud show up on a credit report?
Synthetic identity fraud creates its own credit report under the fabricated identity, not under any real person's name. This is why victims, often children or the deceased, may not discover the fraud for years.
How long does synthetic identity fraud typically take to discover?
Most synthetic identity fraud goes undetected for 12 to 24 months during the credit-building phase. Some schemes operate for three years or longer before the bust-out occurs.
Who bears the financial loss when synthetic identity fraud occurs?
Losses typically fall on the lender or merchant who extended credit to the synthetic identity. There's no real person whose account was compromised and no individual to pursue for recovery.
Is synthetic identity fraud increasing?
Synthetic identity fraud has grown significantly over the past decade. The growth is driven by data breaches that make SSNs widely available and by the shift to online account opening that reduces in-person verification.
Charity Amancio
Charity Amancio specializes in SaaS solutions for global eCommerce businesses, including payments and risk management applications. She bridges the gap between technology and merchant needs, offering practical perspectives on the tools shaping eCommerce. Her insights appear regularly in B2B publications covering the digital commerce space.












