Synthetic Identity Fraud: How to Detect and Stop One of the Fastest-Growing Financial Crimes
- 10Pearls Editorial Team
- 9 min read
Summary
Synthetic identity fraud is the fastest growing financial crime in the US. Understanding why that is and what its life cycle looks like is critical to successfully detect it. We have also shared synthetic identity fraud prevention playbook.
Synthetic identity fraud is among the fastest-growing financial crimes in the US and now represents about 11% of all reported fraud. The losses in the US tied to this fraud reached $2.94 billion in 2025. These synthetic identity fraud statistics should give you an idea of its prevalence and growth trajectory.
AI has been a significant factor behind the explosive growth of this fraud and, ironically, AI fraud detection is also critical to solving it.
This blog will take you through the lifecycle and factors behind the prevalence of synthetic identity fraud, its detection, and preventive measures.
What is synthetic identity fraud?
Synthetic identity fraud is the practice of combining at least one element of real Personally Identifiable Information (PII), usually a Social Security Number (SSN), with fake information
like name and date of birth (DOB), to create synthetic identities that can pass as real ones.
They are also called “Frankenstein” identities because they are stitched together with different identity elements.
There is one critical difference between this and traditional identity fraud, which is the practice of stealing someone’s entire identity and using it to access their bank accounts or take out loans in their name. In these cases, the victim usually becomes aware of the crime in a matter of weeks or months and may alert the authorities.
In synthetic identity fraud, the victims may not be aware of the crime for years because their SSN is used to build a separate identity, and because victims are often deliberately chosen from vulnerable population segments, including children, the elderly, and the deceased.
How it works: the synthetic identity lifecycle
The fraud’s lifecycle begins with synthetic identity theft or acquisition of real identity elements. Most often these are SSNs, which were exposed in roughly two-thirds of all data breaches in the US in 2025.
Identity fabrication
A synthetic identity is created by pairing a real SSN, preferably one with no credit history or minimal credit history (a thin file), with a fake name, DOB, address, and contact information like phone numbers and email addresses. More sophisticated IDs may also have a digital footprint with AI-generated profile photos. Some may even have an employment history, making them better suited for loans.
Planting or establishing a file
With this synthetic identity, fraudsters apply for a credit application, which is typically denied because of a lack of credit history. But this application serves a critical purpose, as it triggers the creation of the first credit file for the synthetic identity and marks the beginning of its credit history.
Nurturing or profile building
The credit profile is developed, often over several years. Fraudsters use the synthetic identity to get easy loans or access credit products that don't require significant scrutiny, like Buy Now Pay Later (BNPL) offerings. The payments are made on time to build a healthy profile. Other “credit grooming” techniques include piggybacking on legitimate credit card accounts, adding the synthetic identity as an authorized user. Fraudsters also connect multiple synthetic identities and exchange funds to build up the financial profile.
Bust out
Once a synthetic identity is sufficiently groomed and is viable for high-ticket purchases or higher-value loans, they max out all their available credit lines and take out significant loans at once, then disappear with the cash, abandoning the synthetic identity. One thing that makes these frauds hard to detect is that financial institutions often record the losses as credit defaults rather than fraud, because no real account-holder comes forward to dispute the debt, since the synthetic identity was never a whole, real person to begin with.
Why is it the fastest-growing financial crime?
Multiple factors have enhanced the appeal and accelerated the prevalence of synthetic identity fraud, including:
Data breaches with SSNs:
The number of data compromises including SSNs has doubled between 2021 and 2025 (Source: HIPAA Journal). One of the largest online databases of exposed personal information (including US citizens) had 2.7 billion records that included SSNs. The database most likely contained data obtained from breaches spanning at least a decade (Source: Upguard). Even if a fraction of these compromised SSNs is useable for synthetic identity fraud, it’s still a significant number.
SSN validation gap:
While there are methods to validate name, DOB, and address against an SSN, it’s time and resource-intensive. As a result, it’s often skipped for low-ticket credit products like BNPL. This gap allows synthetic identity fraud to thrive.
Growing digital onboarding:
Digital onboarding removes much of the manual friction and checkpoints where synthetic or fake identities might have been exposed. Automated document uploads, selfies, and typed-in information are all digital media that can be spoofed with enough dedication and the right tools.
Focus on the credit-thin population:
As per the latest estimates, about 7 million adults in the US are credit invisible and 25 million have a thin file – both are considered unscoreable (Source: Federal Reserve). Financial institutions, particularly community banks and credit unions, started identifying them as a significant underserved market segment, and with certain government reforms acting as a catalyst, made the process of accessing credit easier for thin-file candidates. While it benefited millions of legitimately underserved individuals, it also gave more breathing room to synthetic profiles with thin credit files.
Generative AI tools:
From fake profile pictures to fake documents, generative AI can be used to create synthetic documents and identifiers that may pass several automated checks. It can also be used to create plausible identities around legitimate SSNs, including DOB, address, name, pictures, etc. About 40% of the financial institutions surveyed already saw higher attack rates tied to AI (Sources: CFO Dive).
Abundant raw material, verification gaps, frictionless onboarding, a welcome credit environment, all super-charged with AI that can scale it all at an unprecedented rate. Together, these factors explain why multiple sources describe synthetic identity fraud as the fastest-growing financial crime in the US.
How to detect synthetic identity fraud
Synthetic identities are hard to detect because they are built to look legitimate. But they still leave traces. The mismatch between a real SSN and its fabricated wrapper, and the unnatural way these profiles behave, both create signals that trained teams and systems can catch.
Warning signs that can help with synthetic identity fraud detection include:
A thin or young credit file with adult-level activity:
A profile that surfaced only recently but is already applying for sizable credit lines, or a young file behaving like a seasoned borrower.
Mismatched or inconsistent PII:
A name, DOB, and address that don’t align with each other, or with what public records associate with the SSN.
An SSN that doesn’t fit the identity: An SSN that appears to have been issued only recently but is presented by someone claiming to be an adult, or one that SSA records tie to a different date of birth than the applicant states.
An unusual number of authorized-user tradelines:
Several recently added authorized-user accounts is a signature of piggybacking to build history quickly.
Application velocity:
The same identity, or clusters of similar identities sharing a phone number, device, or address, applying across many lenders in a short window.
How can systems detect synthetic identity fraud? Several layers work together for synthetic fraud detection:
Identity verification and KYC:
Document checks, selfie and liveness matching, and cross-referencing PII at onboarding, though these now have to account for AI-generated documents and images that pass older automated checks.
SSN validation with eCBSV:
The SSA’s Electronic, Consent-Based SSN Verification (eCBSV) confirms whether a name, DOB, and SSN match what’s in the SSA records. This closes the validation gap that’s often skipped in financial products with low scrutiny.
Device and behavioral signals: Device fingerprinting, IP patterns, and behavioral signals like typing cadence or hesitation on fields a genuine owner would answer instantly.
Data sharing among financial institutions:
Different financial institutions can share financial data among themselves and signal out identities that operate across many lenders that no single institution would see on its own.
ML-based anomaly detection and link analysis:
ML models can be trained to flag profiles with statistical inconsistencies and improbabilities, even if they aren’t defined (anomalies). They can also analyze and map the connections between identities, devices, and addresses to identify clusters and organized rings.
How to prevent synthetic identity theft: a playbook for institutions
There isn’t a single control that can accomplish synthetic identity fraud prevention on its own. These identities are designed and assembled to pass individual checks. So the reliable defense has to be a layered one. This will ensure that even if a fraud signal is missed at one stage, it can be caught in the next one. A good idea is to think of it as an in-depth, adaptive defense across the lifecycle of an account, instead of a single gate at onboarding.
Strengthen onboarding and KYC:
Move beyond static PII checks to document verification, liveness detection, and selfie matching, with the assumption that AI-generated documents and images will attempt to pass. The goal is to catch the fabricated identity before it ever gets a file.
Verify the SSN at the source with eCBSV:
The SSA’s Electronic Consent-Based SSN Verification service confirms whether the name, DOB, and SSN actually match SSA records, closing the exact gap that low-scrutiny products tend to skip. Enrolling in it is one of the highest-leverage single steps a lender can take.
Deploy multi-signal and ML-based detection:
Combine device fingerprinting, behavioral signals, and machine learning models, built as compliant AI systems, that flag statistically improbable profiles. No single signal is decisive, but together they expose identities that look wrong in aggregate.
Monitor portfolios for nurturing behavior:
Detection cannot stop at onboarding. Watch existing accounts for the seasoning pattern, sudden authorized-user additions, unusual credit-limit-increase requests, or coordinated behavior across accounts that signals an approaching bust-out.
Share consortium data:
An identity operating across dozens of lenders looks like an ordinary customer to each one of them. Cross-institution data sharing highlights the patterns that only appear at scale.
The primary trade-off here is friction. Each new check that’s added, runs the risk of turning away a legitimate credit-invisible applicant, so the aim is not to maximize friction but to introduce smart friction, applying heavier verification only where the risk justifies it.
Synthetic identity fraud examples and real-world impact
Synthetic identity fraud news, real-world examples, and studies can help us understand how prevalent and impactful this problem is.
In a Long Island case prosecuted by the Suffolk County District Attorney, investigators found that 13 individuals had created more than 20 synthetic identities to obtain loans and credit cards from 19 different financial institutions, stealing more than $1 million. (Source: ASIS online). In a separate, nationwide ring investigated by Homeland Security Investigations, a Georgia man was sentenced to more than seven years in federal prison for using stolen Social Security numbers, including those belonging to children, to create synthetic identities that opened credit lines and shell companies and stole nearly $2 million from financial institutions. (Source: ICE)
The pattern in both is the same: fabricated people, credit patiently nurtured, then a coordinated bust-out. The exposure also runs beyond credit cards into auto loans, digital lending, and, during the pandemic, government relief programs, where synthetic identities were used to fraudulently obtain millions in Paycheck Protection Program funds. (Source: Department of Justice)
The entity that absorbs the loss is another defining feature of this fraud. In most cases, it is the lenders who are the victims, since they extend credit to a person who never existed. There is no single defrauded consumer filing a complaint, which is precisely why the losses so often get recorded as ordinary credit defaults.
Conclusion
One core reason why synthetic identity fraud is difficult to detect and prevent is that the identity behaves like a real, creditworthy customer. Yet, when there are losses, there is no specific individual on the other end to raise the alarm. This combination, and the fact that
many children’s SSNs aren’t pulled for credit checks for years, even decades, lets these fabricated identities mature for long periods (often several years), with the losses being considered routine defaults.
So the solution naturally needs to be more sophisticated as well. Verify identities rigorously at the door, validate the SSN at its source, and monitor accounts for the seasoning behavior that comes before a bust-out. Generative AI raises the stakes on both sides, making fabricated identities cheaper to produce and, increasingly, giving defenders better anomaly detection to catch them.
Building that kind of layered detection takes fraud and risk analytics, AI/ML engineering, and financial-services domain expertise working together. If your team is strengthening its defenses against synthetic identity fraud, 10Pearls’ fintech software development services help financial institutions design and build AI-augmented fraud detection systems suited to exactly this challenge.
TABLE OF CONTENTS
Related blogs

Fintech
Synthetic Identity Fraud Detection and Prevention
Synthetic identity fraud is the fastest growing financial crime in the US. Understanding why that is and what its life...

Fintech
How AI creates value with open banking data
Every fintech company with an open banking license in Saudi Arabia must build the basic infrastructure to receive open banking...
Fintech
How AI fraud detection strengthens financial security and prevents real-time fraud
Discover how AI fraud detection outperforms traditional methods by identifying novel threats, boosting accuracy, and scaling with ease.
Fintech
Key strategies for navigating 1033 compliance in finance
In its final rule, implementing section 1033 of the Dodd-Frank Act, the Consumer Financial Protection Bureau (CFPB) defined requirements that...
Fintech
Explore common misconceptions of agile fatigue
Within the past few years, there has been relative fatigue in many organizations in adopting and implementing Agile practices, processes,...
Get in touch with us
Global digital transformation and product engineering partner.
