What Is Synthetic Identity Fraud?
Synthetic identity fraud is the use of a combination of personally identifiable information (PII) to fabricate a person or entity to commit a dishonest act for personal or financial gain. This industry-recommended definition (opens in new tab) is echoed verbatim in NIST SP 800-63-4 (opens in new tab).
Unlike traditional identity theft, where a criminal steals and assumes a real person's identity, synthetic identity fraud builds an identity that belongs to no one, typically by pairing a legitimate Social Security number with a fabricated name, date of birth, and address.
How synthetic identity fraud works
Fraudsters usually start with a real Social Security number belonging to someone unlikely to notice its misuse: a child, an elderly person, or someone deceased. Children are especially valuable because their credit histories are clean, and thieves can misuse their records (opens in new tab) for years before anyone checks.
After the June 2011 randomization of SSN issuance (opens in new tab) removed the geographic and chronological structure from new numbers, a fabricated but plausible number no longer stands out from a legitimate unissued one, so fraudsters also generate numbers algorithmically and test them until one attaches to a credit file.
The scheme then follows a predictable lifecycle. The fraudster applies for credit and is denied, but the application itself opens a credit file at the bureaus and gives the fake person a paper existence.
Over months or years, the fraudster cultivates the identity with small loans repaid on time and steadily rising credit limits, often renting tradelines from real cardholders who add the synthetic identity as an authorized user.
Then comes the credit bust-out (opens in new tab): every available line is maxed out with no intention to repay. Because the borrower never existed, investigators have limited recourse (opens in new tab) to trace anyone or recover the debt. One prosecuted ring (opens in new tab) paid cardholders with excellent credit to add synthetic identities as authorized users, then detached the seasoned identities and used them to open credit cards and bank accounts.
Why synthetic identity fraud is hard to stop
No complete person exists to report the crime. The real holder of the borrowed SSN rarely notices the activity or disputes a charge, so the detection burden falls (opens in new tab) first on institutions. A real SSN paired with a plausible name and valid address looks legitimate, and credit-bureau checks and knowledge-based questions can pass the identity straight through onboarding.
Behavioral models struggle too, because a synthetic identity sets its own baseline and never deviates from a genuine normal. When the bust-out finally lands, institutions routinely misclassify (opens in new tab) the loss as a credit default rather than fraud. And because fraudsters reuse the same data points across lenders, one Social Security number surfacing at several banks at once is a signal no single institution (opens in new tab) can see from its own data.
Generative AI has industrialized the work. The underground service OnlyFake used neural networks to churn out IDs (opens in new tab) for about $15 each, one of which cleared identity verification at a cryptocurrency exchange. Injection attacks feed a synthetic video stream directly into the verification pipeline (opens in new tab) behind the camera, and fraud agents retry the check (opens in new tab) with small variations until one clears.
Microsoft reports that the use of AI-generated IDs grew 195% globally (opens in new tab), with forgeries now convincing enough to defeat many selfie and liveness checks.
Types of synthetic identities
The Federal Reserve groups synthetic identities (opens in new tab) by how they are built, and the construction method drives both the damage an identity can do and how easily fraud teams catch it.
- Identity manipulation: slightly modified real PII, such as a genuine name and date of birth attached to an altered Social Security number, creating an identity close enough to a real person to pass loose matching.
- Identity compilation: real and fabricated data combined, most often a real Social Security number paired with a fake name, address, and date of birth. This is the classic child-SSN synthetic.
- Identity fabrication: entirely invented identifiers with no real PII anchor. Fraudsters find this the hardest to season past credit checks, because nothing ties it to an existing record.
Synthetic identities do more than bust out credit lines. Fraud rings enroll them at colleges as ghost students (opens in new tab) to drain federal student aid, a pattern documented in a July 2026 FinCEN alert, and use synthetic accounts to anchor money-mule networks.
The same fabricated personas drive romance scams and deepfaked job candidates (opens in new tab), including the North Korean IT-worker operations that place fabricated hires inside real companies.
How to defend against synthetic identity fraud
No single check confirms that a name and date of birth truly belong to the holder of an SSN, so effective programs use a multi-layered approach (opens in new tab) that combines manual and technical controls.
- Verify SSNs against SSA records. The eCBSV service (opens in new tab) returns a yes-or-no match on an SSN, name, and date of birth combination, plus an indication of death. A match confirms the combination exists in SSA records, not that the applicant is its rightful owner.
- Layer identity proofing. NIST SP 800-63A (opens in new tab) separates evidence collection and validation from verification, and prohibits knowledge-based verification for identity proofing, since the security-question answers it relies on are exactly what data breaches expose.
- Pair document checks with liveness and injection defenses. Presentation attack detection and injection-attack protections are complementary requirements (opens in new tab) under NIST SP 800-63-4, and neither alone closes every gap.
- Apply machine learning and behavioral analytics. Machine-learning models (opens in new tab) can process the volume of signals needed to surface synthetic indicators. Static rules go stale, so retraining discipline matters as much as initial accuracy.
- Share signals across institutions. The Section 314(b) (opens in new tab) safe harbor under the USA PATRIOT Act lets financial institutions exchange information on suspected fraud tied to money laundering, closing the cross-institution blind spot no single firm can see alone.
How Doppel helps
Synthetic identities rarely stop at credit files. Those personas also populate fake social profiles, fraudulent job listings, and impersonation campaigns aimed at employees and customers.
Doppel, the AI-native Social Engineering Defense (SED) platform unifying Digital Risk Protection and Human Risk Management, detects and dismantles the impersonation infrastructure behind those threats across domains, social platforms, paid ads, app stores, and messaging channels.
The Doppel Threat Graph links a fake profile or fraudulent listing to the lookalike domains and executive impersonation around it, building campaign-level views instead of isolated alerts. Doppel's agentic AI correlates and prioritizes those signals and runs takedowns at scale, leaving analysts the complex escalations.
The platform reports a 95% takedown success rate (opens in new tab). Its Simulation and Security Awareness Training then rehearse employees against the same deepfake-enabled impersonations across email, voice, SMS, and collaboration channels.
Request a demo to watch the Threat Graph map a live impersonation campaign back to the infrastructure behind a synthetic persona.
Frequently asked questions about synthetic identity fraud
What is synthetic identity fraud?
Synthetic identity fraud is the use of a combination of personally identifiable information to fabricate a person or entity to commit a dishonest act for personal or financial gain. A typical synthetic identity pairs a real Social Security number, often a child's or an elderly person's, with a fabricated name, date of birth, and address. The fake person builds a credit history over months or years, then maxes out every available credit line. Financial institutions are the primary victims and absorb the charge-offs.
What is the difference between synthetic identity fraud and identity theft?
In traditional identity theft, a criminal assumes a real person's existing identity, and that person eventually notices the fraud, disputes the charges, and triggers an investigation. In synthetic identity fraud, the criminal builds a new identity from a mix of real and fabricated data, so no complete real person exists to complain. The loss lands first on the institutions that extend credit to the fake person, and later on the real owner of the borrowed Social Security number, who often discovers the damage years afterward.
What is an example of synthetic identity fraud?
A fraudster pairs a child's unused Social Security number with a fabricated name, date of birth, and address, then opens small accounts and pays them off on time. Over a year or two the invented person earns a solid credit score and rising limits, until the fraudster maxes out every line at once and disappears. The bank writes the balance off as a default, and the child discovers the damaged record years later when applying for a first loan.
What is synthetic identity fraud in cybersecurity?
In security terms, synthetic identity fraud is the identity layer of social engineering: fabricated personas open accounts, apply for remote jobs, and run impersonation campaigns against employees and customers, and because no real victim files a complaint, discovery usually falls to the targeted organization. Deepfaked job candidates are the clearest case, including North Korean IT-worker operations that use AI-generated resumes and live face swaps to clear hiring checks. Fraudsters also use synthetic personas to open money-mule accounts and move scam proceeds through institutions that believe they onboarded a real customer.


