Synthetic Identity Fraud
Synthetic identity fraud uses an identity that was assembled rather than stolen — typically a real identifier such as a Social Security number paired with a fabricated name and date of birth. Also called synthetic identity theft, it is distinctive because there is no victim to notice, so the fraud can mature for years before anyone reports anything.
| Also called | Synthetic identity theft, synthetic ID fraud, Frankenstein identity |
| Construction | A genuine identifier combined with fabricated biographical details |
| Preferred identifiers | SSNs with no credit history — children, the deceased, the recently arrived |
| Defining property | No real victim, so no one disputes the accounts |
| Typical lifecycle | Create, nurture with small credit, build a file, then bust out |
| Time to maturity | Months to years of deliberately normal behavior |
| Why detection fails | The identity behaves like a genuine thin-file customer, because functionally it is one |
| Primary loss event | Bust-out — maximum credit drawn simultaneously, then abandonment |
How it works
The lifecycle is the reason this category is hard, and it is worth understanding as a sequence rather than an event.
Construction pairs a valid identifier with invented details. The most useful identifiers belong to people with no credit history — children, the deceased, recent immigrants — because nothing contradicts the fabricated biography attached to them. Nobody is monitoring a seven-year-old’s credit file.
Nurturing is the patient part. The synthetic applies for credit and is declined, and the inquiry itself creates a file. Small secured products are opened and repaid impeccably. Sometimes the identity is added as an authorized user on an established account, inheriting its history — the same mechanism as credit piggybacking. Over months the file thickens into something indistinguishable from a real person building credit.
Bust-out ends it. Every available line is drawn simultaneously and the identity disappears. There is no one to pursue, no one to dispute the charges, and often no clear point at which the account should have been flagged — the payment history was excellent right up to the last day.
The category is expanding beyond credit. Synthetics are used to open deposit accounts for laundering, to farm promotional offers at scale, and to hold marketplace seller accounts — anywhere an identity is required and no one will check it against a real person.
Why it matters for identity verification
Synthetic identities defeat data-based verification structurally rather than incidentally, and this is the part most explanations skip.
Verification that checks whether an identity exists in the bureaus returns a match, because the synthetic has been building a file deliberately. Knowledge-based questions drawn from that file are answerable, because the fraudster created the history the questions are drawn from. Every data check confirms an identity that the fraudster authored.
Document and biometric verification breaks that loop by asking a question the fabricated file cannot answer: is there a real person here, holding an authentic government-issued credential that matches their face? A synthetic identity has no genuine document, because no issuing authority ever met the person — there is no person. Where fraudsters obtain real documents for synthetics through corrupted issuance, the biometric check still constrains them to one face per identity, which breaks the economics of running hundreds.
Linking identity attributes across accounts surfaces the other tell: synthetics reuse elements, so the same SSN appearing under several names, or one device enrolling many identities, is visible in aggregate while invisible per application. Microblink’s synthetic and stolen identity detection combines both approaches.
Synthetic vs traditional identity theft
| Synthetic identity fraud | Traditional identity theft | |
|---|---|---|
| Identity used | Assembled from real and fabricated elements | A real person’s, used wholesale |
| Victim | None, or a child unaware for years | A real person who will notice |
| Discovery | At bust-out, often years later | Weeks — the victim reports it |
| Detection difficulty | High — behaves like a genuine thin file | Lower — disputes create a signal |
| Loss attribution | Often booked as credit loss, not fraud | Recorded as fraud |
| Countered by | Document plus biometric verification, cross-account linking | Authentication and monitoring |
The misattribution in the fifth row matters commercially. Because there is no victim to file a dispute, synthetic losses are frequently written off as ordinary credit defaults — which means the fraud never appears in fraud statistics and the institution systematically underestimates it.
What it can’t be caught by
Credit bureau checks confirm what the fraudster built. A synthetic with a nurtured file returns a positive match. The check is working correctly and validating a fiction.
Knowledge-based authentication is worse than useless here. The questions come from the file, and the fraudster created the file. They answer more reliably than genuine customers, who forget old addresses and former lenders.
Velocity rules miss the nurturing phase. The behavior is slow, small, and impeccable by design. Nothing about it triggers a threshold until the bust-out, at which point the loss has already happened.
Device signals help but do not settle it. Serious operations use clean devices and residential proxies per identity. Device reuse catches the careless and the industrial-scale, not the patient middle.
Frequently asked questions
What is the difference between synthetic identity fraud and identity theft?
Identity theft uses a real person’s complete identity, and that person eventually notices and disputes. Synthetic identity fraud assembles a new identity from real and fabricated pieces, so there is no one to dispute the accounts — which is why it survives so much longer.
Why are children’s Social Security numbers targeted?
Because they have no credit history to contradict a fabricated biography, and no one checks a child’s credit file for a decade or more. The fraud is frequently discovered when the child applies for their first loan as an adult.
Can identity verification stop synthetic identity fraud?
Document and biometric verification is the most effective single control, because a fabricated identity has no genuine government-issued document tied to a real face. Data-only verification does not work, since the synthetic’s data trail was built to pass exactly those checks.
How long does synthetic identity fraud take to detect?
Often years. The identity is nurtured deliberately, behaves impeccably, and produces no dispute. Discovery usually comes at bust-out, and the loss is frequently misclassified as credit default rather than fraud.
Related reading
- Credit piggybacking — the mechanism synthetics use to inherit credit history
- Fullz — the stolen data packages synthetic identities are assembled from
- Fraud ring — how synthetics get created and cashed out at scale
- Synthetic identity fraud in depth — the longer treatment of detection and loss patterns