Third-Party Identity Fraud

Third-party identity fraud is the use of a real person’s identity, without their knowledge or consent, to obtain credit, open accounts or access services. The identity belongs to someone who exists, is not involved, and usually discovers what happened long afterward.

It is the category most people mean by “identity fraud,” and it is distinguished from the alternatives by a single question: whose identity is it, and is that person a participant?

Identity used A real person’s, without consent
Is there a victim Yes — a specific, identifiable person
Source data Breaches, phishing, skimming, stolen mail, dark web purchase
Typical products Credit cards, loans, phone contracts, government benefits
Detection lag Often months — the victim is not notified of the application
Where it is catchable Application, before the account exists

The three-way distinction

Third-party First-party Synthetic
Whose identity A real victim’s The fraudster’s own Fabricated, often part-real
Is there a victim Yes No individual victim Sometimes — if a real identifier was used
Who complains The victim, on discovery Nobody Nobody — there is no one to complain
How it is found Victim dispute Behavior and affordability Often only at charge-off
Recorded as Fraud Frequently miscoded as credit loss Frequently miscoded as credit loss

The last two rows carry the practical consequence. Third-party fraud is the category institutions measure best, because a real person eventually reports it. The other two are systematically undercounted — not because they are rarer, but because nobody raises a dispute. A portfolio’s fraud statistics are therefore skewed toward the type that has a complainant, which distorts where prevention gets funded.

How third-party identity fraud works

The identity data is obtained rather than invented — from a breach, a phishing campaign, stolen mail, a compromised mailbox, or purchased as a complete record. The completeness matters: a full record supports applications that a partial one does not, which is why fullz command a premium over loose card numbers.

The fraudster then applies as the victim. Where knowledge-based verification is used, they answer the questions correctly, because the answers are in the record they bought or derivable from public data. Where a document is required, they present a forged or altered one carrying the victim’s details. Where a credit check is run, it returns the victim’s genuine file, which is often good.

Delivery and contact details are the one place the fraudster must diverge, and it is handled by routing to an address or phone they control — which is why an application matching a credit file on every attribute except the contact details is a meaningful signal.

The account then runs until the victim discovers it: on a credit report, through a collections contact, or when a legitimate application is declined for reasons they do not recognize.

Why it matters for identity verification

Third-party fraud defeats the checks that ask what the applicant knows, and for a structural reason: everything a knowledge check can ask about the victim is in the record the fraudster is holding. Date of birth, previous addresses, mortgage lender, car payment — these were secrets when the controls were designed and are now data.

The check that does not degrade this way is the one that asks the applicant to be the person. A government document verified as authentic, plus a live face matched to its portrait, tests something no data purchase supplies. The fraudster holds the victim’s identity; they do not hold the victim’s face, and liveness is what keeps a photograph from standing in for one.

This is also the control with the clearest victim benefit on the project. In synthetic fraud the loss is financial and the institution absorbs it. In third-party fraud a real person spends months proving they did not do something, on a record they did not create, with an institution they never chose. Preventing the application prevents that entirely.

What third-party fraud controls cannot do

Knowledge-based authentication is largely spent. Decades of breaches have made the underlying answers widely available. It still deters casual attempts and should not be relied on against a prepared one.

Credit bureau checks confirm the identity exists. That is what they are for, and in third-party fraud the identity does exist, with a genuine file. A bureau match is evidence about the identity, not about the applicant.

Victim notification arrives too late to prevent. Alerts and freezes are valuable and operate after the data is already circulating. They shift the burden onto the victim to defend an identity somebody else is using.

It does not address first-party fraud at all. An applicant using their own identity passes every identity control correctly, because they are who they say they are. That is a different problem with different controls.

Frequently asked questions

What is the difference between identity theft and third-party identity fraud?

Identity theft is the acquisition of the data; third-party identity fraud is the use of it against an institution. They are separate events, often separated by months or years, and the organization that suffers the fraud is rarely the one that leaked the data.

How is third-party fraud different from synthetic identity fraud?

Third-party fraud uses a real person’s complete identity without consent, so there is a victim who eventually notices. Synthetic fraud fabricates an identity, often around one real identifier, so there is no person to notice and the loss is frequently miscoded as ordinary credit default.

Why does third-party identity fraud take so long to discover?

Because nobody tells the victim an application was made in their name. Discovery usually comes indirectly — a collections contact, an unexpected entry on a credit report, or a declined application — which can be months after the account was opened.

What stops third-party identity fraud at application?

Verifying the document is authentic and that the person presenting it is live and matches its portrait. The fraudster holds the victim’s data and cannot supply the victim, which is the one requirement no amount of stolen information satisfies.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data