What is synthetic identity fraud? | Transmit Security

Glossary

What is synthetic identity fraud?

Synthetic identity fraud combines real and fake data to create a fictitious identity used to open accounts and commit fraud. Learn why it’s so hard to detect.
by Transmit Security

Synthetic identity fraud is the creation of a fictitious identity by combining real information (such as a genuine but misused Social Security number) with fabricated details (a fake name, date of birth, or address), then using that "synthetic" identity to open accounts and commit fraud. It’s widely considered the fastest-growing and one of the costliest forms of financial crime, precisely because the identity doesn’t fully belong to any real person.

Unlike stolen-identity fraud, where a criminal impersonates a real victim, a synthetic identity is a Frankenstein construct (partly real, partly invented) that exists only on paper and in databases. That hybrid nature is the source of both its power and its stubbornness against detection.

How synthetic identities are built

Fraudsters typically start with a real identifier that lacks an established credit history (historically often a child’s or an elderly person’s Social Security number, or one that’s simply unused) and attach fabricated personal details to it. They then nurture the synthetic identity, applying for credit (and being declined at first, which paradoxically helps establish a credit file), getting added as an authorized user, and slowly building a legitimate-looking history. Over time the synthetic identity accrues real credit, real accounts, and the appearance of a real person.

Why it’s so hard to detect

Synthetic identity fraud defeats most controls because there’s no clean signal of impersonation. Identity verification may pass: the SSN is real, the documents may be fabricated convincingly, and there’s no actual victim to notice or report misuse. The identity behaves normally, often for months or years, so point-in-time onboarding checks see nothing wrong. And because it isn’t a real person, traditional identity-theft alerts and victim reports never fire. The fraud only becomes visible when the synthetic identity acts fraudulently, usually far too late to prevent the loss.

The bust-out

The classic monetization is the bust-out: after building trust and credit over an extended period, the fraudster maxes out every available line at once and abandons the identity. Because there’s no real person behind it, there’s no one to pursue, and the losses fall on the lenders. Some synthetic identities are also used more (as mule accounts to launder funds, or to abuse services and benefits) but the patient credit bust-out is the signature play.

How synthetic identity fraud is detected

Because a single check won’t catch it, detection combines several approaches: deep data validation to spot the subtle inconsistencies of a fabricated identity (mismatched or thin data footprints, an SSN that doesn’t align with the claimed age or history), device and behavioral signals that reveal automation or coordinated creation, cross-referencing to detect the same fabricated elements reused across many applications, and machine-learning models trained on known synthetic patterns. Crucially, lifecycle monitoring matters as much as onboarding, watching for the behavioral shift that precedes a bust-out on an account that opened cleanly.

Preventing synthetic identity fraud

Prevention is strongest when identity, fraud, and lifecycle signals work together. Rigorous identity verification (document plus biometric with liveness) raises the bar at onboarding; data validation catches fabricated-identity markers; ML detection flags synthetic patterns; and continuous monitoring remembers how an account began so a marginal one is watched afterward. No single control is sufficient (the whole point of a synthetic identity is that it slips past isolated checks) which is why fusing identity verification with ongoing fraud detection is the most effective defense against it.

The scale and cost

Synthetic identity fraud is consistently cited as the fastest-growing financial crime, with losses running into the billions annually and rising. Part of what makes it so expensive is the delay: a synthetic identity can sit and mature for a year or more before busting out, so losses recognized today reflect fraud seeded long ago, and the true exposure is often larger than reported figures capture. It’s also frequently misclassified, a synthetic-identity bust-out can be booked as a credit loss (an unpaid loan) rather than fraud, which hides the real scope and starves the problem of attention and investment. The generative-AI era compounds the threat further, making the fabricated documents and personas behind synthetic identities cheaper and more convincing to produce at scale.

Frequently asked questions

Is synthetic identity fraud growing?

Yes: it’s widely cited as the fastest-growing financial crime, with billions in annual losses, and it’s often under-reported because it can be misclassified as credit loss.

What is synthetic identity fraud?

Creating a fictitious identity by blending real data (like a real SSN) with fake details, then using it to open accounts and commit fraud.

How is it different from identity theft?

Identity theft impersonates a real victim; synthetic identity fraud creates a partly-fabricated person with no single real owner.

Why is synthetic identity fraud so hard to detect?

The identity often passes verification, behaves normally for months, and has no real victim to report misuse.

What is a bust-out?

Building credit and trust over time on a synthetic identity, then maxing out all credit at once and abandoning it.

How do you prevent synthetic identity fraud?

Combine identity verification, data validation, ML detection of synthetic patterns, and lifecycle monitoring, no single check suffices.

Related: New Account Fraud · Identity Theft · Identity Verification (IDV) · Data Validation · Money Mule · Machine Learning for Fraud

Request a Demo

By clicking the button, you agree to the Terms and Conditions