A customer applies for a bank account. Their Social Security number is valid. Their address exists. Their driver's license passes inspection. Even their selfie matches the photo on the document.
Months later, the account is linked to fraud, and you discover the customer never existed.
That's what makes synthetic identity fraud so difficult to detect: fraudsters combine real identity elements with fabricated information to create identities that can pass onboarding checks and build credibility before being used for fraud.
In this guide, we'll explain how synthetic identity fraud works, how it differs from traditional identity theft, and the strategies you can use to detect and stop synthetic identities earlier.
We’ll cover:
Ready to improve your organization’s synthetic identity fraud detection capabilities? Get in touch with GBG to discover how our identity verification and fraud prevention solutions can help.
Synthetic identity fraud occurs when criminals create a new identity using a mix of legitimate and fabricated information. Rather than stealing and impersonating a real person, they assemble an identity that appears genuine but doesn't actually belong to anyone.
This creates quite a unique challenge for financial institutions: in cases of identity theft (when criminals steal and use a real person's information to impersonate them), the victim may notice unauthorized activity and report the fraud. Where synthetic identity fraud is concerned, there is no real victim.
This means no one reports suspicious activity or disputes transactions. As a result, synthetic identities can remain active for long periods before they’re discovered.
Making things even more complex, AI technology now gives fraudsters new tools to create convincing documents, digital personas and deepfake content.
Fraudsters typically begin with a legitimate identity element, such as a Social Security number obtained through data breaches or dark web marketplaces. They then combine it with fabricated details, including names, addresses, phone numbers or emails, to create a profile that appears consistent across verification checks.
The goal is to create a believable digital footprint. A phone number that receives verification codes or an address tied to existing utility records can make the identity appear more credible during onboarding.
Synthetic identity fraud is often a long-term scheme. Rather than immediately applying for large loans or high-value financial products, fraudsters typically begin with accounts that are easier to open, such as a basic checking account or entry-level credit product.
Over time, they create a history of legitimate-looking activity. Small deposits, on-time payments, and routine account usage help build trust with financial institutions. As the identity develops a stronger financial profile, it may begin to appear legitimate to traditional credit and risk models, opening the door to larger credit lines and more valuable products.
Once the synthetic identity has accumulated enough trust, the fraudster shifts from building credibility to extracting value. This often involves drawing down available credit, taking cash advances, or securing loans with no intention of repayment. This part of the process is sometimes referred to as bust-out fraud.
Synthetic identities are frequently used to commit loan fraud, exploit Buy Now, Pay Later programs, open mule accounts, and facilitate money laundering. Because the identity appears legitimate, these activities may go unnoticed until significant losses have already occurred.
Additionally, the same synthetic identity is often reused across multiple institutions. This is how fraudsters maximize its value before it’s detected and abandoned.
Here are two scenarios that show how synthetic identities are used to gain access to financial services:
A fraudster applies for a new digital checking account using a real Social Security number tied to a child or dormant record, then pairs it with a fabricated name, address, phone number and email that all appear consistent during onboarding.
Once the account is open, the fraudster may let it sit for a few weeks, adding small deposits and building a pattern of normal-looking activity before using it to receive stolen funds, move money for a mule network or cash out through transfers and withdrawals.
Digital onboarding makes it easier for fraudsters to test multiple synthetic identities at scale while organizations balance fraud prevention with customer conversion.
A fraudster signs up for a digital wallet using synthetic identity details, then repeats the process across several other wallets or money transfer accounts to create a network of seemingly unrelated users.
Each account may be used to send small transfers back and forth, which creates the appearance of normal consumer activity while actually layering funds to obscure where the money originated.
Because these platforms are built for speed and convenience, fraudsters often exploit the fact that onboarding is designed to be quick and low-friction, especially when the business is trying to reduce drop-offs during sign-up.
This creates a constant balancing act for providers: if controls are too strict, genuine customers could abandon the process, but if controls are too loose, synthetic identities can slip through and be used for laundering or fraud.
Verifying that an identity attribute exists doesn't necessarily prove that an identity is genuine. After all, fraudsters can use legitimate data points to create fake profiles that appear credible during onboarding.
Instead, you should ideally compare applicant information against authoritative source-of-record databases and use multiple trusted data sources to determine whether identity attributes belong together.
Looking across multiple sources helps uncover inconsistencies that may indicate a synthetic identity, such as conflicting identity records or information that lacks a meaningful historical connection to the broader identity profile.
Identity documents are often used to reinforce the credibility of a synthetic identity. However, the risk of AI-generated or digitally manipulated documents that appear authentic to the human eye is ever-increasing.
The best layer of defense is to use document verification technology that can evaluate security features, embedded metadata and signs of manipulation that may not be visible during manual review.
This also includes detecting indicators of forgery or fabrication, such as altered text, mismatched fonts, inconsistent formatting or image tampering.
Another challenge is that a legitimate-looking identity document doesn't necessarily prove that the person presenting it is its rightful owner. Biometric verification helps establish that connection by comparing a user's selfie against the photo on their identity document.
Unfortunately, modern fraud attacks increasingly rely on deepfakes, face swaps and other AI-generated content designed to bypass traditional verification methods.
For this reason, you should combine facial matching with liveness detection to confirm that a real person is present during the verification process. Advanced liveness checks can help identify presentation attacks, deepfake videos and injected media before fraudulent applicants gain access to accounts or financial products.
Synthetic identities often lack the digital history and behavioral patterns associated with genuine consumers. Examining phone numbers, email addresses and other digital identity signals can reveal inconsistencies that warrant additional scrutiny.
For example, you can assess whether a phone number was recently activated or if it’s a Voice over Internet Protocol (VoIP) number or whether an email address was created shortly before an application was submitted.
Synthetic identity fraud is rarely limited to a single application, leaving behind digital patterns that can help expose suspicious activity.
Device, IP and behavioral intelligence can help you identify these patterns by detecting unusual geolocation activity, device anomalies or velocity attacks involving multiple applications from the same device or network.
Behavioral signals can also provide valuable context. For example, unusually fast form completion or excessive copy-and-paste activity could indicate that an identity is being manufactured rather than submitted by a genuine customer.
Address verification should go beyond confirming that an address exists. You should also assess if the address aligns with the applicant's broader identity profile and whether it makes sense in the context of other available information.
For instance, unusual combinations of information, such as an applicant claiming to reside in one state while consistently accessing services from another region, might indicate that additional investigation is needed.
A document may appear authentic, a phone number might be active and an address could be valid, yet the overall identity may still be fraudulent.
That’s why the most effective detection approach is to evaluate identity, document, biometric, device, and digital intelligence signals together to determine whether an applicant's information forms a coherent and trustworthy profile.
When these signals are viewed in context, patterns and inconsistencies become easier to identify, which allows you to make more informed onboarding decisions and detect synthetic identities before they establish trust.
We’ll explain how we do that in the next section.
Synthetic identity fraud is difficult to prevent because it doesn’t rely on a single point of failure. Fraudsters exploit gaps between systems – they combine stolen, fabricated and manipulated information to create identities that can appear genuine during onboarding.
Detecting these threats requires more than individual verification checks: you need connected identity, document, biometric and fraud intelligence signals that provide a complete view of risk.
With more than 30 years of experience in identity verification and customers including HSBC, Santander, and Metro Bank, we help organizations bring these signals together and stay ahead of evolving fraud threats while maintaining a seamless customer experience.
Here are three ways we help detect synthetic identity fraud:
To determine if identity attributes genuinely belong together, we use multi-source identity verification to fill in data gaps and source-of-record data. This helps you build a more comprehensive profile of each customer.
You can also use our document authentication services to analyze identity documents for signs of manipulation or fraud, while selfie matching and liveness detection help confirm that the person presenting the document is its rightful owner. When combined, these controls also help defend against deepfake injection attacks and face-swap technologies used in modern onboarding fraud, contributing to identity fraud detection accuracy rates of up to 96%.
Our global data coverage includes 8,500+ identity document types across 195 countries and local data sources in 50 countries, which helps you verify identities accurately across regions and customer segments.
Many synthetic identities appear genuine during onboarding because traditional verification checks only evaluate part of the risk picture.
We help you identify risk at the point of onboarding by combining fraud intelligence, digital identity signals, synthetic identity scoring and adaptive verification.
Our GBG Trust product leverages millions of identity insights across more than 28 industries. By drawing on cross-industry intelligence and transaction patterns, you can identify risk signals that may not be visible within your own customer data.
Email intelligence, mobile intelligence and other digital signals help identify suspicious patterns associated with synthetic identities, while automated scoring evaluates identity quality and activity to surface potential risk.
In addition to fraud prevention, our GBG Go platform also supports compliance workflows with access to more than 450 PEP, sanctions and adverse media watchlists.
With our risk-based verification workflows, you can apply additional scrutiny when risk indicators are present while reducing unnecessary friction for genuine customers.
Many organizations rely on separate solutions for identity verification, document authentication, biometrics, fraud scoring and device intelligence. And while each solution may provide valuable insights, disconnected tools can create blind spots and increase operational complexity.
That’s why GBG Go unifies these capabilities through a single API. Instead of switching between systems and manually reconciling results, fraud teams can manage verification, fraud checks, decisioning and case management within a single workflow.
This unified approach helps accelerate onboarding decisions and identify synthetic identities earlier in the customer lifecycle.
Detect synthetic identity fraud before it progresses further down the onboarding funnel: Book a demo to learn how we can help.
Common indicators of synthetic identity fraud include inconsistencies in personal information, unusual address or phone number changes, limited credit file or credit profile history, suspicious document details and multiple identities linked to the same device, contact information or digital footprint.
Fraudsters often create a fictitious identity by combining real and fake information, which makes these inconsistencies especially important to detect.
Banks detect synthetic identity fraud by combining Know Your Customer (KYC) identity verification, document checks, biometric analysis and fraud intelligence during onboarding.
They may also compare identity information against trusted data sources, including credit bureaus, where appropriate. By analyzing identity data alongside behavioral and digital signals, banks can identify suspicious patterns, support AML (Anti-Money Laundering) compliance and assess risk before opening new accounts.
Generative AI can make synthetic identity fraud harder to detect by creating convincing fake documents and profiles. However, layered KYC approaches that combine document verification, biometrics, identity intelligence and behavioral analysis can help identify inconsistencies and prevent fraudulent accounts. Many organizations also use artificial intelligence to detect anomalies that indicate financial fraud.
Synthetic identity fraud and account takeover are distinct types of fraud, but they can occur alongside one another as part of a broader financial crime strategy. Synthetic identity fraud involves creating a new fictitious identity using a mix of real and fabricated information, while account takeover involves gaining unauthorized access to an existing customer's account.
Financial institutions should use layered identity verification, authentication, and ongoing fraud monitoring to help detect and prevent both.