/

/

What Is Synthetic Identity Fraud? How It Works and How to Stop It

What Is Synthetic Identity Fraud? How It Works and How to Stop It

Synthetic identity fraud is the fastest-growing financial crime in the United States, and it is quietly becoming the defining fraud threat of 2026. Instead of stealing one real person's identity, criminals stitch together real and fabricated data to build a person who does not exist, a so-called Frankenstein identity, then use it to open accounts, borrow money, and disappear. Because there is no real victim to raise the alarm, these identities can hide in plain sight for years.

The scale is significant and rising. Synthetic identity fraud already accounts for billions in lender exposure each year, and generative AI has poured fuel on the fire: deepfake fraud attempts in North America surged more than 1,100 percent in early 2025, and synthetic document fraud rose around 300 percent.

This guide explains what synthetic identity fraud is, how it differs from ordinary identity theft, how the scheme works step by step, why it slips past traditional checks, and how modern identity verification stops it at the front door.


What Is Synthetic Identity Fraud?


Synthetic identity fraud is the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for financial gain. The result is an identity that looks real on paper but corresponds to no actual human being. Fraudsters build it by blending two kinds of data:

  • Real, stolen elements: a genuine Social Security number or national ID number, and sometimes a real address, often taken from a child, an elderly person, or someone deceased.

  • Fabricated elements: an invented name, date of birth, email, and phone number layered on top to complete the persona.

Combined, these pieces pass the checks that confirm a piece of data is valid, even though the person they describe was never born.


Synthetic Identity Fraud vs. Traditional Identity Theft


People often confuse the two, but they are fundamentally different crimes, and the difference is exactly why synthetic fraud is so hard to catch. Traditional identity theft hijacks a real person, who eventually notices and reports it. Synthetic fraud invents a person nobody will ever miss:

Aspect

Traditional identity theft

Synthetic identity fraud

What is used

A real person's complete identity

Real data fragments blended with fabricated details

Is there a victim?

Yes, a real person who is harmed

Often none, so no one reports it

How it surfaces

The victim spots and disputes activity

Stays hidden for months or years

How losses are logged

Recorded as fraud

Often miswritten off as bad debt


How Synthetic Identity Fraud Works: The Lifecycle


A synthetic identity is a long con, not a smash-and-grab. It usually moves through five stages, patiently building credibility before cashing out, and each stage leaves a trace a business can catch:

Stage

What happens

Where it can be caught

Data acquisition

Criminals gather real PII from breaches, the dark web, or scams.

Breach and data monitoring

Identity creation

Real and fake details are blended into a new persona, often with AI-generated faces and documents.

Document and biometric verification

Credit file establishment

The fraudster applies for credit; even a rejected application can create a bureau file.

Identity proofing at onboarding

Credit building

Small purchases are paid on time to raise limits and trust over months.

Behavioral and transaction monitoring

Bust-out

The identity maxes out every line of credit and vanishes.

Anomaly detection and velocity checks


Two Types: Manipulated and Fabricated Synthetics


Not all synthetic identities are built the same way, and the distinction matters for detection. Some are lightly altered versions of a real identity, while others are assembled almost entirely from scratch, which makes them far harder to spot:

Type

How it is built

Detectability

Manipulated synthetic

A real identity with small changes to the SSN or other details, often to hide bad credit.

Easier; it collides with the real identity and fails validity checks

Fabricated synthetic

A Frankenstein persona assembled from PII across many people or invented outright.

Very hard; the PII matches no single real consumer


Why Synthetic Identities Evade Traditional Checks


The uncomfortable truth is that most legacy fraud controls were never designed to catch a person who does not exist. Several structural gaps let synthetics slip through:

  • SSN randomization. Since the US moved to randomized Social Security numbers in 2011, numbers are no longer geographically predictable, so a fabricated one is harder to flag as fake.

  • Credit-file bootstrapping. The first application creates a credit file, so the very act of applying makes the fake identity look real to the next lender.

  • Existence is not identity. A database check confirms that an SSN or document number is valid, not that the person presenting it is real.

  • No victim, no alarm. With no real person to notice and dispute the activity, nothing triggers a traditional fraud review.


How AI Is Supercharging Synthetic Fraud


Generative AI has turned a slow, manual craft into an industrial process. Criminals now use AI to parse enormous breach datasets, assemble non-duplicated identities at scale, and generate the media needed to pass verification. That includes deepfake faces and voices and counterfeit identity documents convincing enough to fool basic onboarding.

The impact is already measurable: deepfake fraud in North America jumped more than 1,100 percent in the first quarter of 2025, synthetic document fraud climbed roughly 300 percent, and a majority of fraud teams now name AI-driven fraud as a top concern. The good news is that the same technology powers the defense, because AI-based verification can detect the subtle artifacts these fakes leave behind.


Red Flags: How to Detect a Synthetic Identity

Synthetic identities are designed to look ordinary, so detection relies on spotting subtle inconsistencies rather than obvious fraud. Individually these signals may be harmless, but together they warrant a closer look:

  • A thin or brand-new digital footprint, such as an email, phone, or social profile created only days ago.

  • A mismatch between the date an identity number was issued and the applicant's stated age.

  • A first credit inquiry that returns no existing file, resembling a genuinely new-to-credit consumer.

  • Unusually rapid credit building followed by sudden maximum utilization.

  • The same address, phone, or device shared across multiple supposedly separate identities.


How to Prevent Synthetic Identity Fraud at Onboarding

Because a synthetic identity is built to defeat data-only checks, the most effective place to stop it is at account opening, by proving that a real, live, unique human is behind the application. Layering the following controls closes the gaps that legacy checks leave open:

A common myth is that biometrics do not help against synthetic identities. They do, when applied at onboarding to bind a real, live face to a verified document, rather than only as a login step later on.


The EU and Regulatory Angle

Most coverage of synthetic identity fraud is US-centric, but European firms face the same threat under a distinct set of rules that make strong identity proofing a legal expectation, not just good practice:

  • AML directives require customer due diligence and beneficial-ownership checks that a synthetic identity is designed to defeat.

  • eIDAS 2.0 and the EU Digital Identity Wallet, discussed in our guide to eIDAS 2.0, push toward high-assurance identity proofing that raises the bar for fraudsters.

  • GDPR governs the personal data that both fuels synthetic fraud and must be protected during verification, making privacy-respecting digital identity essential.


Stop Synthetic Identities at the Front Door with Qoobiss

Qoobiss helps banks, fintechs, and platforms block synthetic identities before they ever open an account. Its identity verification combines document authentication, biometric face match, and liveness detection to prove a real person is present, while fraud prevention and Omnicheck add screening and ongoing monitoring. See how Qoobiss stops synthetic identity fraud at onboarding, or get in touch to see it in action.

Frequently Asked Questions

What is synthetic identity fraud?

How is synthetic identity fraud different from identity theft?

How do criminals create synthetic identities?

Who are the most common victims?

How can businesses detect synthetic identity fraud?

Is synthetic identity fraud growing?

Why Qoobiss

Book a 30-minute KYC verification demo → sales@qoobiss.com



Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved

Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved

Expo Business Park

54A Av. Popisteanu Street, 1st floor

Bucharest, Romania

© Qoobiss 2026. All rights reserved