A digital bank account can be opened in minutes. While human review still exists in digital onboarding, it is only for applications flagged as unusual. Most everyone else gets an automated decision.
Fraudsters have noticed that shift, and advanced technology now lets them build fake identities that look like the real deal. They manufacture entire personas and slip past the basic checks that used to be enough.
Checking that a name, date of birth, or document exists on paper is the easy part. What you need to know is if the person applying, the identity they're claiming, and the evidence behind it all belong to the same human being.
Fraud prevention solutions for detecting fake identities during bank account applications include, for example, GBG. In this article, we’ll show you how it works.
Fake identities are built in different ways, and no single check catches all of them. Here are the main types:
Each of these layers answers a different question about the applicant before you grant access to banking services.
A fake identity rarely fails on one obviously false field. A fraudster can submit a real-looking name, address, and date of birth and what gives it away is how those fields fit together. Identity data checks compare the application against trusted databases to see whether the identity can be corroborated.
Take a synthetic persona built from a legitimate Social Security number and a fabricated name. Each field looks plausible, but the financial history behind it won't make sense: a 45-year-old applicant with an extremely new or sparse credit record warrants a closer look. The same record on a very young applicant would be normal.
These checks happen in the background using information the applicant has already entered. You can gather additional evidence about the identity before asking a genuine customer to take a selfie, photograph an ID or wait for manual review.
Document capture only proves that an applicant supplied an image. Document authentication tells you whether the credential is genuine and unaltered. It checks whether the layout matches the issuing authority's standards, if expected security features and machine-readable zones are present, whether the text fields agree with each other, and if the photo was changed after issuance.
Say a fraudster gets an image of a legitimate driver's license and swaps in their own portrait, leaving the text intact. A basic upload flow reads the real name, birth date, and license number and marks the document as verified. Document authentication inspects the image layers, fonts and microprint and finds the tampering.
Comparing document data against the rest of the application matters, too. A credential can look authentic on its own but contain details that conflict with the address, date of birth or identity data submitted elsewhere.
Data checks confirm an identity exists, documents confirm the credential is genuine, and biometrics establish that the applicant is the rightful owner of both.
Facial biometrics compare the portrait on the verified ID with a live capture taken during sign-up. If the two are similar enough, that supports the applicant's claim to the identity.
A match alone isn't enough, though, because fraudsters try to get around the camera. Presentation attacks put a printed photo, a video on a screen or a physical mask in front of it. Passive liveness testing catches these by analyzing a single selfie for signs that a real person is physically present. Customers don't have to blink, smile or turn their head.
Injection attacks skip the camera entirely and feed manipulated or AI-generated media straight into the verification system. Generative AI has made synthetic faces and deepfake videos cheap to produce, so verification has to confirm that the media really came from a camera, as well as whether the faces match.
An application can look completely reasonable on its own and still turn out to be fraud once you compare it with everything else coming in. That's why identity verification works best alongside broader fraud intelligence.
Network and behavioral signals answer questions the applicant's own details can't: whether a single device is associated with multiple identities, if high application volumes are coming from the same IP address or whether contact details repeat across unrelated accounts.
Velocity measures how often a specific identity element, device or technical identifier appears within a given timeframe. A single new account application from a mobile device looks normal. Ten applications under different identities from the same device within two hours is a red flag.
Fraud rings often change the names they use but reuse the same background infrastructure, like device fingerprints or email domains. Linking those shared signals exposes relationships no single application would show. It also means an applicant with valid details and a clean document can still be high risk if their device or contact details tie back to other applications.
Read more: How to build smarter and faster onboarding flows
When comparing fraud prevention solutions for bank account applications, look at how each option handles these seven things:
A fake identity usually gets caught when the evidence stops agreeing with itself. GBG brings identity data, forensic document checks, biometrics and fraud intelligence together in one orchestration platform, GBG Go, so you can look at an applicant's full story before deciding whether to onboard them.
When the data, the document, and the face don't line up, you have a clear reason to investigate before approving the account.
Stolen identity fraud is when a criminal uses real information belonging to an existing person without their permission. Synthetic identity fraud is when a fraudster combines real details, like a Social Security number, with fake ones to create a persona that doesn't belong to any living person.
It looks at a single selfie for depth, skin texture, reflections and light patterns to tell whether a live person is in front of the camera. The applicant doesn't have to smile, blink, or move their head.
Basic data checks only confirm that a name, address and birth date exist on official databases. They can't tell you whether the ID was altered after issuance or whether the person applying actually owns the identity.