What is new account fraud? | Transmit Security

Glossary

What is new account fraud?

New account fraud is opening accounts with stolen or fabricated identities to commit fraud.
by Transmit Security

New account fraud (also called new account opening fraud) is the creation of accounts using stolen, fake, or synthetic identities in order to commit fraud: accessing credit, laundering money, absorbing stolen funds, or exploiting sign-up offers. It attacks the very start of the customer relationship, before any legitimate history exists, which is what makes it both damaging and hard to catch.

Unlike account takeover, which hijacks an existing customer, new account fraud manufactures a fraudulent customer from the outset. The account looks new because it is, there’s no behavioral history to compare against, so detection has to work from the identity and the signals present at opening.

How new account fraud works

Fraudsters open accounts using one of a few identity strategies: stolen identities (real people’s data from breaches), fabricated identities (entirely fake), or synthetic identities (a blend of real and fake data, the hardest to detect). They often automate the process with bots to open accounts en masse, using stolen or generated documents, throwaway emails and phone numbers, and spoofed devices to appear legitimate. The accounts are then used to draw credit they never repay, receive stolen funds as mule accounts, or exploit promotions and bonuses.

Why it’s so damaging

New account fraud is a top driver of losses in financial services, and synthetic identities in particular are notoriously costly because they can behave normally for months (building credit and trust) before "busting out" and disappearing with the proceeds. Because there’s no real victim to report the fraud (the identity may be partly or wholly fabricated), it often goes undetected longer than takeover of a real person’s account. It also feeds downstream crime: mule accounts opened this way power money laundering and scam cash-out.

How to stop new account fraud

Prevention concentrates at onboarding, layered:

  • Identity verification (document plus biometric with liveness) to confirm a real, specific person and block fabricated identities and deepfakes.
  • Data validation to catch the inconsistencies (mismatched phone, brand-new email, unresolvable address) that betray synthetic identities.
  • Device and bot intelligence to spot automation, emulators, and mass account creation.
  • Machine-learning detection tuned to new-account patterns, which can flag subtle synthetic-identity signals rules miss.

The strongest defense treats opening as the first data point in a continuous risk picture, so an account that opened with marginal signals is watched more closely afterward, catching the synthetic identity that behaves normally at first and turns fraudulent later.

The synthetic identity bust-out

The most costly form of new account fraud follows a patient pattern called the bust-out. A fraudster creates a synthetic identity (often a real (sometimes stolen, sometimes fabricated) Social Security number paired with a fake name and history) and uses it to open accounts. Then they wait, behaving like a model customer: making small purchases, paying bills on time, requesting modest credit-limit increases. Over months, the synthetic identity accumulates trust and rising credit. Then comes the bust-out: the fraudster maxes out every line of credit at once and vanishes. There’s no real person to pursue, and the losses land on the lenders.

This patience is exactly why point-in-time onboarding checks miss synthetic identities: at opening, the identity looks fine, and the fraud only reveals itself much later. Catching it requires two things: strong data validation and ML detection at onboarding to spot the subtle inconsistencies of a fabricated identity, and lifecycle monitoring that remembers how an account began and watches for the behavioral shift that precedes a bust-out. It’s the clearest case for treating fraud detection as continuous rather than a single gate.

New account fraud across industries

While financial services feels new account fraud most acutely (credit and money laundering) the problem spans sectors. In e-commerce and retail, fake accounts drive promo and loyalty abuse and fraudulent orders. In marketplaces and gig platforms, they enable scams and policy evasion. In telecom and utilities, they access services and devices on credit. Anywhere accounts unlock value (money, credit, rewards, services, or reach) new account fraud follows. The defenses are consistent across industries even as the payoff differs: verify the identity, validate the data, detect the bots and synthetic markers, and keep watching after the account opens.

Frequently asked questions

What is a synthetic identity bust-out?

A patient scheme where a fabricated identity builds credit and trust over months, then maxes out all credit at once and disappears.

Which industries are affected by new account fraud?

All that unlock value through accounts (banking, e-commerce, marketplaces, gig platforms, telecom) though the payoff differs.

What is new account fraud?

Opening accounts with stolen, fake, or synthetic identities to commit fraud such as credit abuse, money laundering, or promo abuse.

How is new account fraud different from account takeover?

New account fraud creates a fraudulent new customer; account takeover hijacks an existing legitimate account.

Why are synthetic identities so hard to detect?

They blend real and fake data and can behave normally for months before committing fraud, with no real victim to report it.

How do you prevent new account fraud?

Layer identity verification, data validation, device/bot intelligence, and ML detection at onboarding, and keep monitoring afterward.

Related: Synthetic Identity Fraud · Account Opening Fraud · Identity Verification (IDV) · Data Validation · Money Mule · Bot Detection

Request a Demo

By clicking the button, you agree to the Terms and Conditions