New account fraud is the opening of an account using stolen or fabricated identity information to commit a crime: laundering money, defaulting on credit, abusing promotions, or accessing services the applicant would never qualify for under a real identity.
It also goes by account opening fraud, account origination fraud, and account creation fraud, and it is distinct from account takeover (opens in new tab), which compromises an existing account rather than creating a new one.
How new account fraud works
The attack runs in four stages, and the first one happens long before attackers submit an application.
1. Identity acquisition
Attackers buy fullz identity packages with name, address, Social Security number, date of birth, and financial details on dark web markets (opens in new tab), or build synthetic identities by pairing a real Social Security number, often a child's, with a fabricated name, address, and date of birth.
Attackers source the raw data from spoofed websites (opens in new tab) on lookalike domains and run smishing campaigns (opens in new tab) from mass-registered fake toll-payment domains. They also use fake job postings (opens in new tab) to collect Social Security and bank account numbers as "employment paperwork."
2. Account opening
They submit that identity to a bank, fintech, exchange, carrier, or platform. Where onboarding requires a document and selfie, attackers deploy AI-generated identity documents (opens in new tab), deepfaked selfies (opens in new tab), and injection attacks (opens in new tab) that feed a synthetic video stream directly into the verification pipeline, so the liveness check receives a synthetic feed instead of footage from a physical camera.
Attackers have used deepfake documents to circumvent identity verification (opens in new tab) often enough to prompt a dedicated FinCEN alert (opens in new tab) based on suspicious activity reports.
3. Account aging
The attacker cultivates each approved account with small purchases, diligent repayments (often funded by other schemes), and credit-limit requests, running several identities in parallel until each profile looks like a model customer.
4. Monetization
Attackers drain cultivated accounts through bust-outs, launder funds through funnel accounts, and run industrial-scale promotion abuse. In one documented bust-out case (opens in new tab), recruits paid off credit cards with bad checks, received immediate credit, and charged the cards to their limits again before the checks bounced, then filed for bankruptcy on the recruiter's advice to discharge the debts.
Why new account fraud is hard to stop
The central detection gap is the absence of a victim. When the identity is synthetic, the scheme touches no real person's account and no customer calls to report a loss, so it matures for months or years and surfaces in collections as a credit default rather than in a fraud queue.
Many fraud models assume a real applicant, which is the gap the synthetic identity mitigation toolkit (opens in new tab) addresses for synthetic identities.
Onboarding controls also address a different threat. Point-in-time checks miss cross-session anomalies, and liveness detection can earn certification against presentation attacks (things shown to a camera) while offering little protection against injection attacks, which bypass the camera entirely.
A test that confirms a real face is in front of a real lens cannot validate the feed when attackers replace it with synthetic video.
Generative AI (opens in new tab) has collapsed the attacker's cost curve on top of both gaps. Attackers cheaply produce convincing fake documents, cloned voices (opens in new tab), and real-time face swaps (opens in new tab), and buy ready-made KYC bypass (opens in new tab) tooling from Telegram sellers.
The same deepfakes defeat the customer due diligence controls that anti-money-laundering programs depend on.
Types of new account fraud
The variants differ in the identity attackers use and the way they monetize the account:
- Stolen-identity (true-name) fraud: Attackers use a real person's genuine details without their knowledge. Victims typically must correct their credit reports and dispute the charges with individual creditors.
- Synthetic identity fraud: Pairs a real Social Security number with an invented name, address, and date of birth to build a person who does not exist. With no consumer victim to report it, it is harder to detect and prosecute than traditional identity theft.
- Bust-out fraud: The terminal monetization event for a cultivated account: attackers draw down credit lines built over months through cash advances, purchases, and balance transfers, then abandon the identity.
- Mule account fraud: Criminals open accounts with genuine documents that pass KYC checks, then use them to receive and layer illicit funds. In the funnel-account pattern, criminals deposit cash in cities where the customer does not live and withdraw it the same day.
- Promotion abuse and multi-accounting: Attackers create fake accounts at scale, often with emulators and app-cloning tools, to farm signup bonuses, free trials, and referral payouts while rotating emails, phone numbers, and IP addresses.
How to defend against new account fraud
Document checks miss device reuse, synthetic-video injection, and coordinated retries, so institutions need controls across identity, capture, device, and network signals:
- Identity and document verification: Financial institutions must collect and verify a customer's name, date of birth, address, and identification number through risk-based documentary and non-documentary methods under the Customer Identification Program rule at 31 CFR 1020.220 (opens in new tab). Treat it as the floor of the program.
- Liveness plus injection-attack detection: Pair presentation attack detection with controls that verify the capture pipeline itself. Look for virtual camera and driver signatures, emulator fingerprints, and metadata inconsistent with a physical sensor.
- Device intelligence and behavioral biometrics (opens in new tab): Repeat device fingerprints across multiple accounts, automated data entry, and non-human navigation expose account farming that document checks miss.
- Velocity and link analysis: Multiple identities sharing one SSN, address, phone number, or IP, and failure-then-success retry patterns with slight variations, are classic signatures of coordinated rings.
- Consortium data sharing: The Section 314(b) safe harbor (opens in new tab) lets institutions exchange information about fraud and mule activity, combining their visibility to map networks no single firm sees alone.
Defense also extends upstream of the application. Spoofed login pages (opens in new tab) and lookalike domains (opens in new tab) supply the fullz packages and credentials that attackers harvest (opens in new tab) through impersonation that fuel new account fraud. Fake recruiter portals (opens in new tab) are another source.
How Doppel helps
Doppel is the AI-native Social Engineering Defense (opens in new tab) (SED) platform that unifies Digital Risk Protection (DRP) (opens in new tab) and Human Risk Management (HRM) (opens in new tab) to detect and dismantle the impersonation infrastructure (opens in new tab) that feeds application forms. Its Brand Protection (opens in new tab) covers spoofed domains, fake social profiles, scam ads, and fraudulent job pages before customers hand over the personal data that becomes a fullz package.
The Doppel Threat Graph links domains, phone numbers, ads, and fake profiles into campaign-level views (opens in new tab), so fraud and Trust and Safety teams see the whole harvesting network instead of isolated alerts. Its agentic AI correlates, prioritizes, and executes takedowns at scale (opens in new tab), so analysts focus on the complex escalations that require human judgment. This workflow dismantles linked domains, ads, phone numbers, and fake profiles while increasing the cost of rebuilding the harvesting funnel.
Request a Demo (opens in new tab) to watch the Threat Graph map a live impersonation campaign by linking a lookalike domain to the full attacker infrastructure.
Frequently asked questions about new account fraud
What is new account fraud?
New account fraud occurs when a criminal opens an account using stolen or fabricated identity information to commit a crime, such as laundering money, defaulting on loans, or abusing promotional offers. Other names include account opening fraud, account origination fraud, and account creation fraud. Targets include banks, fintechs, crypto exchanges, telecom carriers, online marketplaces, and any business that provisions customer accounts.
What is new account fraud in cybersecurity?
It is the identity-layer attack that security and fraud teams see at onboarding rather than at login. Attackers now clear document-and-selfie checks with AI-generated identity documents and deepfaked selfies. Injection attacks feed a synthetic video stream into the verification pipeline. Synthetic identity fraud, one method behind new account fraud, uses a combination of personally identifiable information (opens in new tab) (PII) to fabricate a person or entity to commit a dishonest act for personal or financial gain. Attackers harvest the credentials and personal data that fuel it upstream through spoofed sites and smishing domains. Fake job postings provide another source.
What is the difference between new account fraud and account takeover?
New account fraud creates a fresh account under a stolen or synthetic identity, and the primary loser is usually the institution extending credit or services. Account takeover compromises an existing legitimate account, and the primary target is the account holder's own funds. The two share a supply chain, since the same phished credentials and personal data can feed either attack, but defenders address them at different control points: onboarding versus authentication.
