Glossary

Synthetic identity fraud

Synthetic identity fraud is the use of a wholly invented identity, or a fabricated profile built from real and false personal data, to open accounts or obtain credit. The fraudster controls the identity even when some details belong to a real person.

Synthetic identity fraud combines information such as a real Social Security number, name, date of birth, address, or phone number with invented or altered details. Criminals commonly use the resulting profile to pass account-opening checks and build a credit history before taking money or goods.

It differs from traditional identity theft because the victim whose data is used may not be directly impersonated. A lender or service provider can instead see what appears to be a new customer with a plausible, but false, identity.

How the fraud typically develops

  • A fraudster obtains a real identifier through a data breach, theft, public records, or other sources, then pairs it with fabricated details.
  • They apply for low-risk products or accounts, sometimes using authorized-user relationships or other methods to create an apparent credit record.
  • After building account history and increasing limits, they may rapidly draw down available credit, transfer funds, or make purchases before abandoning the identity. This final stage is often called a bust-out.

Why it is difficult to detect

Synthetic identities can produce records that look internally consistent across credit, telecommunications, device, and address data. They may also have limited negative history, particularly when first created. Automated checks that only confirm whether submitted data exists can therefore miss fabricated combinations of genuine and false information.

Identity-verification implications

Organizations reduce exposure by validating that a person, document, device, contact point, and claimed identity have credible links to one another. Relevant controls can include document and biometric checks where appropriate, database and credit-header analysis, phone and email intelligence, device-risk signals, and ongoing account monitoring. No single check reliably identifies every synthetic identity.