Most fraud has a victim who eventually notices something is wrong. A stolen card gets used, a statement looks off, a credit report shows an unfamiliar account. Synthetic identity fraud is built to avoid exactly that moment. The identity behind the fraud does not belong to a real person, so there is no one to file a complaint, dispute a charge, or flag suspicious activity. The loss simply lands on the lender, often months or years after the fraudulent account was first opened.
This open accounts for new customers, synthetic identity fraud represents a category of risk that traditional identity verification was never designed to catch.
What Is Synthetic Identity Fraud?
Synthetic identity fraud is a form of fraud in which a criminal combines real personal information, most often a genuine Social Security number, with fabricated details such as a false name, date of birth, or address, to construct a composite identity that does not correspond to any real person.
According to TransUnion, which tracks synthetic identity risk across the credit ecosystem, these identities are carefully constructed to mimic legitimate consumer behavior closely enough that they pass standard identity verification checks.
Unlike traditional identity theft, where a criminal impersonates a real, existing person, synthetic identity fraud creates someone who has never existed. That distinction is what makes it so difficult to detect using conventional fraud controls built around verifying whether a person is who they claim to be.
How Does Synthetic Identity Fraud Work?
Synthetic identity fraud typically unfolds over an extended period, following pattern fraud teams often call the bust-out.
- Identity construction : A fraudster obtains a real Social Security number, frequently belonging to a child, an elderly person, or someone with little or no credit history, and pairs it with a fabricated name, address, and date of birth.
- Credit file creation : The fabricated identity is used to apply for credit, often starting with products that require minimal verification, such as a secured credit card or a retail store card.
- Patient credit building : The fraudster makes small purchases and pays bills on time, sometimes for a year or more, allowing the synthetic identity to build a legitimate-looking credit history and credit score.
- Credit limit expansion : As the credit file matures, the fraudster applies for additional credit products and requests limit increases, expanding the total credit exposure tied to the synthetic identity.
- The bust-out : Once available credit reaches its peak, the fraudster maxes out every account simultaneously and disappears, leaving lenders with losses tied to an identity that was never real.
Why Is Synthetic Identity Fraud So Difficult to Detect?
Traditional fraud detection is built around verifying that a person is who they claim to be. Synthetic identity fraud sidesteps that model entirely, because there is no real identity being impersonated for a verification check to catch. The fabricated identity often behaves exactly like a legitimate customer for months or years, making on-time payments and gradually building credit, which is precisely the behavior most scoring models are designed to reward.
The scale of the problem reflects this detection gap. According to TransUnion’s research, U.S. lenders faced more than 3.3 billion dollars in exposure to synthetic identities tied to newly opened accounts for the year ending 2024, an all-time high in the firm’s tracking. Industry researchers describe synthetic identity fraud as one of the fastest-growing categories of financial crime, driven in part by the increasing availability of stolen personal data and, more recently, by generative AI tools that make fabricating convincing identity documents and behavioral patterns significantly easier.
What Makes Someone Vulnerable to Synthetic Identity Fraud?
Certain populations are disproportionately targeted for the Social Security number component of a synthetic identity, precisely because they are unlikely to notice the misuse quickly.
- Children rarely have credit files of their own, so a Social Security number used fraudulently may go unnoticed for years, often until the child applies for their first loan or credit card.
- Elderly individuals, particularly those who are not actively monitoring credit activity, provide numbers that can be paired with fabricated details without triggering the account holder’s own attention.
- Recent immigrants with limited credit history in the country present a similar profile: a valid Social Security number with little existing credit activity to conflict with a fabricated identity.
- Incarcerated individuals are another commonly exploited group, since their ability to monitor and dispute credit activity is limited during incarceration.
Where Does Synthetic Identity Fraud Show Up in the Enterprise?
Synthetic identity risk concentrates at the point of account creation, since that is the single moment when an organization has the best opportunity to catch a fabricated identity before it can build a credit history. Digital onboarding is now considered the highest risk point of exposure by most financial institutions, since remote verification processes rely heavily on document checks and data matching that synthetic identities are specifically constructed to pass. The risk extends beyond traditional lending into deposit accounts, checking and payment products, and increasingly into fintech and buy-now-pay-later platforms, wherever a new account can be opened with limited friction. Third-party identity verification vendors also sit squarely in this risk chain, which is why evaluating a vendor’s synthetic identity detection capability has become a standard part of third-party risk management for organizations that outsource onboarding checks.
How Can Organizations Detect and Prevent Synthetic Identity Fraud?
Effective defense requires moving beyond identity verification alone toward identity resolution, confirming not just that supplied data is internally consistent, but that it corresponds to a real, continuous person.
- Cross-reference public and alternative data sources to check whether a Social Security number, name, and address combination has a plausible, consistent history rather than appearing together for the first time.
- Apply velocity and behavioral analytics to detect patterns common to synthetic identities, such as a thin credit file that suddenly accelerates toward the credit limits typical of a bust-out.
- Extend identity governance to the onboarding process, treating new account creation with the same scrutiny identity and access management programs apply to internal privileged access, since a synthetic identity that passes onboarding effectively becomes a trusted account inside the organization’s systems.
- Monitor for known synthetic identity indicators on an ongoing basis, not only at account opening, since fraudsters deliberately build credit slowly to avoid triggering point-in-time review thresholds.
- Feed onboarding and account activity signals into centralized monitoring, so that unusual patterns across accounts can be correlated through existing SIEM infrastructure rather than sitting isolated within a fraud team’s own tooling.
Final Thoughts
Synthetic identity fraud succeeds precisely because it does not look like fraud for most of its lifecycle. It looks like a new customer paying bills on time. That makes it fundamentally different from the identity theft scenarios most fraud controls were built to catch, and it requires organizations to shift from asking whether a person is who they claim to be, toward asking whether that person exists at all in any verifiable, continuous way.
As synthetic identity losses continue climbing and generative AI lowers the barrier to fabricating convincing documentation, the organizations best positioned to limit exposure will be those that treat onboarding as a continuous risk surface, not a one-time checkpoint.
Synthetic identities are built to pass a single verification check, not sustained scrutiny.
| Talk to Ampcus Cyber to assess whether your onboarding and identity governance controls can catch what a point-in-time check misses. |
Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.









