A customer with a spotless application, a valid Social Security number (SSN), and a name that doesn’t exist anywhere else; that’s synthetic identity fraud, and it’s quietly become one of retail’s harder risk problems. Traditional identity fraud losses in the U.S. remained steady at $27.3 billion in 2025, affecting 18 million victims, according to Javelin Strategy & Research.
Unlike stolen-identity fraud, synthetic fraud stitches a real SSN (often a child’s or an infrequent credit-checker’s) to a fabricated name and address. No real victim exists to flag it, so the account appears to be a new customer.
For retailers, that shows up as fraudulent buy-now-pay-later approvals, fake loyalty accounts, and chargebacks nobody claims. Generative AI now speeds up every step—fake IDs, profile photos, and automated application testing—making these identities cheaper to produce and harder to catch.
Let’s dive in to learn how the fraud works, the warning signs to watch for, and what stops it.
- Synthetic identity fraud involves the use of authentic and fictional identity details to build fake identities that seem legitimate throughout the enrollment process and initial account reviews.
- Synthetic identity fraud typically occurs gradually. Fraudsters establish themselves by creating accounts with valid credentials, establishing positive account histories and reputations prior to engaging in any large-scale or high-value fraud.
- Combating synthetic identity fraud involves several factors, such as identity graphing technology, behavioral analytics, document authentication, device intelligence, and biometric or live identity verification.
- Risk-based strategies allow organizations to respond appropriately based on their assessment of risks and threats to the business. Stronger verification processes and real-time interventions become necessary when dealing.
What Is Synthetic Identity Fraud?
Synthetic identity fraud is a form of identity (ID) theft. It involves creating so-called synthetic identities, using real data (like an SSN) and fabricated data.
This is happening increasingly in the U.S., because U.S. identity verification systems tend to rely on personally identifiable information. This can include driver’s license ID numbers, passport numbers, your social security number, or date of birth. This data is then combined with other real and fake data to create difficult-to-trace fraudulent identities.
With these identities, criminals can open bank and credit accounts, conduct business with governmental agencies, or commit other forms of identity fraud.
According to research from Regula, nearly half (46%) of businesses globally
have experienced synthetic identity fraud.
What If My Identity Is Used in Fraud?
Ultimately, if your data has been used to create a synthetic identity, some of the implications include:
- Credit Risk: A synthetic identity tied to you could harm your credit score, e.g., the criminal misses payments, making it tougher for you to get loans later.
- Legal Hazards: A fake identity could engage in illegal activities that put you at risk for legal troubles, like tax evasion or financial crime.
- False Accusations: You could be wrongly linked to criminal activities if authorities confuse the synthetic identity with you, leading to legal issues.
- Resolution Hurdles: Fixing the fallout from synthetic identity fraud can be complex and time-consuming, involving law enforcement and credit agencies.
- Emotional Toll: Dealing with synthetic identity issues can cause stress and anxiety.
- Legal Entanglement: You could face legal action wrongly based on the actions of the synthetic identity, requiring evidence to clear your name.
Protect yourself. Learn about the latest fraud risks that target individuals and businesses.

How Are Synthetic Identities Created?
Like traditional fraud, synthetic ID fraud involves gathering or stealing personal ID information. Once stolen, this information can be fed into fraud tools to create hundreds of synthetic IDs.
Here’s a step-by-step guide to how fraudsters create and use synthetic identities:
Step 1: Gather Information
Fraudsters gather personal information they need to build a synthetic identity—including name, date of birth, address, phone number, etc. In some cases, this can be done by purchasing stolen data online or from dark web providers. In other cases, fraudsters may use “data scraping” technology to gather data from public sources.
An estimated 95% of synthetic identities go undetected during the onboarding process, according to Thomson Reuters.
Step 2: Create the Synthetic Identity
Once the information has been gathered, it’s time to create a new synthetic identity—often using a tool called an “identity mill.” An identity mill is an automated system that can generate hundreds or even thousands of fake identities. This tool allows fraudsters to combine pieces of real data with fictitious information to create a unique identity.
Step 3: Use the Synthetic Identity
Fraudsters can use a synthetic identity for various purposes. This could include opening new accounts, taking out loans, or even applying for credit cards. In some cases, a criminal may even use the identity to create false medical records or obtain government benefits.
Step 4: Monitor the Identity
Finally, the fraudster will monitor the synthetic identity over time to ensure that it is not detected. This could include using automated “bot” technology to search for any signs of suspicious activity associated with the identity. If anything looks out of place, the fraudster can take steps to cover their tracks before law enforcement can catch up.
Synthetic Identity Fraud Lifecycle
Synthetic identity fraud develops over multiple stages, allowing a fabricated identity to gain credibility before it is used for fraudulent activity. The following matrix shows what happens at each stage, the signals businesses may encounter, and the controls that can help identify or mitigate the risk.
| Stage | Key Signals | How to Detect | How to Mitigate |
|---|---|---|---|
| Identity Creation | Consistent but artificial, unusual identity combinations | AI-assisted document checks, identity graphing | Risk-based identity checks |
| Identity Establishment | Minimal file history, limited identity footprint, reused information | Device and identity graphing, cross-institution signals | Network analysis and identity linkage |
| Trust Building | Gradual activity, consistent account behavior, growing transaction history | Behavioral analysis, ongoing identity monitoring | Continuous risk monitoring |
| Identity Expansion | Identity reuse patterns, shared devices or networks across accounts | Identity graphing, network analysis, consortium signals | Cross-institution linkage and account monitoring |
| Fraud Exploitation | Sudden behavior changes, unusual transactions, transaction anomalies | Behavioral anomaly detection, risk scoring, transaction-level checks | Real-time intervention and step-up controls |
| Abandonment | Sudden account inactivity, disconnected devices, or payment patterns | Ongoing behavioral and transaction monitoring | Continuous monitoring and investigation controls |
Types of Synthetic Identity Theft
Synthetic identity theft primarily occurs in two forms: manipulated and manufactured identities. Let’s explore them one by one.
1. Manipulated Synthetics
As the name suggests, this type of theft is done by manipulating a few details or elements into real data. These fraudulent identities are based on real people’s personal information with minor modifications like altered addresses or date of birth.
These manipulated identities are created by fraudsters to cover up financial history and gain access to new credit with an intent to repay it. Organizations have easy ways to detect these manipulated identities, and the major giveaway is that they often do not pass the validity checks.
2. Manufactured Synthetics
Manufactured synthetic ID fraud is usually done by fabricating data put together from multiple identities. It is generally referred to as “Frankenstein Fraud,” as fraudsters create these identities by mixing real elements.
For example, a fraudster may create a fake name, date of birth, and address while keeping a genuine SSN. Such frauds are often seen nowadays, as they pick the same range of SSNs randomly issued by the SSA (Social Security Administration). This is why identity verification for fraud detection is crucial, since manufactured synthetic ID fraud is hard to detect with current techniques.
Common Examples of Synthetic Identity Fraud
Fraudsters use synthetic identities for different purposes, depending on which system they’re trying to exploit. Common examples include:
Fake Credit Profile Fraud
Credit card fraud schemes operate through a simple method known as bust-out fraud. It begins with a fraudster building up a positive credit history, beginning with a minor credit limit and consistently making timely payments. As soon as their credibility becomes established, the fraudster opens bigger lines of credit or maxes out several cards before running off with the money.
Fake Customer Accounts
Synthetic identity fraudsters use a combination of legitimate and fake personal information to open an account. By logging into the account regularly, making purchases, or initiating payments, the fraudster can establish legitimacy and successfully pass future screening attempts.
Synthetic Identities Used for Money Laundering
Synthetic identities allow fraudsters to create an account and then move illegal funds through it. Using a synthetic identity allows transactions to be disconnected from the individual who controls the account.

Retail and Ecommerce Fraud
Fraudsters create synthetic identities to commit fraud through buy-now, pay-later apps, reward program accounts, and sham online merchant accounts. They can steal products, reward points, and payment funds from orders that were never placed or delivered.
Warning Signs of Synthetic Identity Fraud
Synthetic fraud does not have a glaring indicator like other types of scams. In order to detect it, retailers must look for inconsistencies between identity elements, account usage patterns, and digital behavior.
Identity Inconsistencies
Every piece of information might seem real on its own. But when you look at the bigger picture, it doesn’t make sense. You see addresses linked to different names or different birthdates for the same person. Some personal details don’t match those provided in the application. All these signs together point to identity fraud.
Suspicious Account Behavior
Look out for patterns in which the account develops gradually, then abruptly changes. An individual who builds a reputation until they make large purchases, seek financing, or earn cash reward points requires careful consideration.
Digital Identity Signals
A person’s digital footprint can show the difference between how they appear online and who they really are. When multiple accounts are used from the same IP address, with strange login locations or always using the same network, it becomes obvious that the accounts are connected.
Document Verification Issues
A submitted ID might pass a visual check but still show signs of being altered. Even if the document looks valid at a glance, inconsistencies can arise when comparing the name, date, photo, or other details with the information entered during onboarding. These differences may not be obvious at first but become clear with a closer review.
How to Detect Synthetic Identity Fraud
Detecting synthetic identity fraud requires more than checking whether the name, address, or ID looks valid. Businesses can combine identity, behavioral, device, biometric, and external data to identify connections and inconsistencies that are difficult to spot through a single verification check.
Identity Graph Analysis
Identity graphs connect pieces of information, like names, addresses, phone numbers, devices, accounts, and payment methods. An identity graph can determine that several identities use the same data, even though each profile seems real on its own.
AI-Driven Fraud Detection
AI-driven fraud detection looks at amounts of identity and transaction data to spot patterns that match suspicious activity. It does not rely on fixed rules but rather evaluates many signals simultaneously and highlights strange combinations for deeper investigation.
Behavioral Anomaly Detection
Unlike a real consumer, a synthetic identity behaves in a different way during interactions. Monitoring changes in buying habits, login frequency, account usage, and transaction volume helps flag anomalies that deviate from normal user behavior.
Biometric and Liveness Verification
Biometric verification compares a person’s facial or other biometric characteristics with the identity being presented, while liveness checks help determine whether the person is physically present. Together, these checks can make it harder to use fabricated identities, stolen credentials, or presentation attacks during verification.

Credit File and Data Consistency Checks
Comparing information across credit files, public records, and other trusted data sources can expose gaps or conflicting details. A recently established credit history, mismatched addresses, or personal information that does not align across records can require additional verification.
Cross-Platform Identity Correlation
Fraudsters may use the same synthetic identity across multiple websites, accounts, or services. Correlating identity attributes, devices, contact information, and activity across platforms can help businesses identify linked profiles that would otherwise appear unrelated.
How to Prevent Synthetic Identity Theft: 7 Essential Tips

Synthetic identity fraud can hurt businesses and individuals. After you understand how this threat works, you can take these steps to boost personal data security:
1. Keep a Close Eye on Your Accounts
The best course of action is to monitor your accounts and/or use account monitoring tools:
- Stay Alert: Check your business accounts and transactions often. If you catch any strange things happening early, you can stop them from becoming big problems and costing you a lot of money.
- Activate Alerts: Use the special tools your bank provides to keep an eye on your accounts. These tools can send you quick messages if they see anything suspicious, so you can take action right away to keep your business safe.
2. Safeguard Confidential Information
- Prevention starts with data security: Centralize Sensitive Data: Keep important business information, like bank statements and private employee details, in one safe place that’s locked up.
- Implement Access Control: Make sure only the people who are allowed can get to the private information. This way, you lower the chances of someone who shouldn’t be seeing it and causing problems.
Start with digital identity verification solutions to eliminate threats, improve security, and increase trust.
3. Implement Strong Password Practices
Improving your password security is one of the easiest (and most effective) strategies to protect yourself:
- Establish Password Policies: Make some rules for your employees about passwords. Tell them to create passwords that are really strong and to change them often.
- Educate on Password Security: Teach your team how to keep their passwords safe. Tell them to use different passwords for different things and never to tell anyone their passwords. This helps keep your business information safe from criminals.
4. Activate Two-Factor Authentication (2FA)
Use dual-factor authentication and other enhanced verification tactics:
- Strengthen Authentication: Require the use of two-factor authentication for accessing sensitive business accounts. This adds an extra layer of security beyond passwords.
- Choose Strong Authentication Methods: Opt for authentication methods such as authentication apps or hardware tokens for added security.
5. Regularly Review Credit Reports
You can set up monitoring with a credit report agency like Equifax:
- Routine Audits: Regularly obtain and review your business credit report to identify any unauthorized accounts or suspicious activities.
- Immediate Reporting: If you notice any inaccuracies or unfamiliar accounts, report them to the credit bureaus immediately to prevent further damage.
6. Be Skeptical of Unsolicited Communications
Take precautions to avoid phishing attempts:
- Train Your Team: Educate your employees about the risks of sharing business information in response to unsolicited requests. Encourage them to verify such requests through official channels.
- Phishing Awareness: Conduct phishing awareness training to help employees recognize and avoid phishing attempts, which often lead to identity fraud.
7. Educate Your Team on Synthetic Identity Fraud
Grow awareness among your team:
- Provide Comprehensive Training: Organize workshops or training sessions to familiarize your team with synthetic identity fraud and the specific tactics used by fraudsters.
- Promote a Culture of Vigilance: Create an environment where employees feel comfortable reporting anything suspicious they notice. By working together to stop fraud, we can prevent problems from happening.
Learn more ways businesses can protect themselves from digital identity fraud.
Synthetic Identity Fraud Trends
Synthetic identity fraud is evolving as fraudsters gain access to more advanced technology and organized fraud services. The following trends show how AI, deepfakes, fraud-as-a-service, and fake ID marketplaces are making these schemes easier to create and harder to detect.
Generative AI-Powered Identity Fraud
Fraudsters use generative AI to manufacture credible information, IDs, documentation, and other identity components faster than ever before. It has become increasingly difficult to differentiate between synthetic identities and real customers.
Deepfake Identity Attacks
Deepfake frauds are carried out using realistic images and footage of a fabricated individual using deepfake technology. These methods can fool traditional forms of identification verification by providing false evidence.
Fraud-as-a-Service (FaaS) Growth
Fraudsters can now buy tools, stolen data, fake identities, and other services through fraud-as-a-service instead of developing them themselves. This lowers the barrier to entry and helps organized fraud operations scale.
Fake ID Marketplace Expansion
Online marketplaces make counterfeit documents and synthetic identity resources easier to obtain. As a result, businesses need to look beyond the document itself and assess multiple identity signals.
Final Thoughts
Integrating these strategies into your business practices will elevate your resilience against synthetic identity fraud. By concentrating on proactive prevention and fostering a company-wide commitment to security, you can elevate your business’s protection, preserve its reputation, and cultivate trust among customers and partners.
Remember, safeguarding your business from synthetic identity fraud is not just a duty— it’s an essential investment in securing its enduring success.
Protect Your Business From Synthetic Fraud
Safeguard your customers and strengthen your defenses against the growing threat