Zenoo
Learn/Synthetic identity fraud explained
AI threat and defence

Synthetic identity fraud explained

What synthetic identity fraud is, how it differs from ordinary identity theft, how criminals pull it off, how big it is now, and how banks detect and stop it.

Last reviewed 3 June 202614 min read
In shortThe answer, first

Synthetic identity fraud combines real and fabricated personal data, often a genuine Social Security number paired with a made-up name and date of birth, to build a person who does not exist. Criminals nurture that fictional identity until it holds real credit, then draw it all down and vanish. Because no real victim complains, it hides for months.

Key facts
  • It manufactures a new person rather than impersonating a real one, so for a long time there is no victim to raise the alarm.
  • The dangerous type pairs a real, unused SSN (often a child's) with a fabricated name and date of birth, so the number validates cleanly.
  • The lifecycle runs create, get declined, incubate, piggyback on aged tradelines, then bust out.
  • TransUnion measured USD 3.3 billion of US lender exposure to suspected synthetics as of end-2024.
  • Deloitte estimates synthetic identity fraud could drive at least USD 23 billion in US losses by 2030.
  • Generative AI now pairs the classic synthetic file with an AI face and document, merging synthetic identity and deepfake threats.

What is synthetic identity fraud?

Synthetic identity fraud is the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain. That wording is the first common industry definition, published in 2021 by a Federal Reserve led group of fraud experts, because until then institutions classified these cases inconsistently and could not size the problem.

The Federal Reserve framework splits the data into two tiers. Primary elements are identifiers usually unique to one person: name, date of birth, Social Security number, and government-issued ID numbers. Supplemental elements are supporting data that adds plausibility but cannot establish identity on its own: address, phone, email, and digital footprint. A synthetic is built by mixing a few real primary elements with fabricated ones, then wrapping them in supplemental data.

Common misconception
It is not just identity theft
Synthetic identity fraud is a form of identity theft, so the same fraud models catch it.
Traditional identity theft impersonates a real victim who eventually notices and disputes. Synthetic identity fraud manufactures a new person, so for a long time there is no human victim to raise the alarm. That is exactly why it evades conventional fraud models.

Synthetic identity fraud vs traditional identity theft

The two crimes look similar on paper and behave nothing alike in practice. The distinction below is the single most important thing to understand, because it explains why detection is hard and why losses are so badly measured.

Traditional identity theftSynthetic identity fraud
Is there a real victim?Yes, a real person is impersonatedNo real person exists to impersonate
Who raises the alarm?The victim, once they spot activityNobody, so it hides for months
Detection difficultyModerate, disputes surface itHigh, it behaves like a thin-file customer
How the loss is codedUsually flagged as fraudOften miscoded as ordinary credit charge-off
Main defenceVictim alerts, dispute handlingLink analysis, SSN verification, behavioural signals

The three ways a synthetic is built

The Federal Reserve describes three construction methods. The difference between them decides how easy the identity is to catch.

  • Identity fabrication uses entirely fake information, with no real person's data behind it.
  • Identity manipulation uses slightly altered real PII, for example a lightly changed SSN or date of birth. These manipulated synthetics often collide with the real identity and fail validity checks, so they are the easier type to catch.
  • Identity compilation combines a real, valid SSN with a fabricated name, date of birth, and contact data. These manufactured synthetics are the dangerous type, because the SSN is genuine and validates cleanly.
Common misconception
A valid SSN does not mean a real applicant
If the Social Security number checks out, the applicant is a real person.
A genuine SSN attached to a fabricated name and date of birth is the textbook manufactured synthetic. The number validates, but the person it is stapled to does not exist.

Why an unused SSN is the raw material

Before 2011 the Social Security Administration encoded geography and issue order into SSN digits, so a number could be sanity-checked against a person's age and birthplace. On 25 June 2011 the SSA randomised all newly issued SSNs to protect privacy. The unintended effect: an SSN can no longer be validated against age or region, so a criminal can take a child's dormant but valid SSN, attach an adult name and date of birth, and nothing about the number itself looks wrong.

This is why the classic victims are children, the elderly, the deceased, and people who do not actively use credit. Their SSNs can sit unused and unmonitored for years, and nobody checks a credit file that nobody expects to exist.

How synthetic identity fraud works: the lifecycle

A synthetic is not created and cashed out in a day. It is grown patiently over months, which is what makes it look legitimate right up until the end.

  1. 1Create. Combine a real, unused SSN with a fabricated name, date of birth, address, phone, and email.
  2. 2Apply and get declined. The synthetic applies for credit. The first application is usually rejected because there is no credit file, but the rejection itself causes the credit bureaus to open a file for the identity. The synthetic now exists in the system.
  3. 3Incubate. The fraudster gets the identity onto subordinate products such as secured cards, buy-now-pay-later, and small store credit. Payments are made on time, so the identity behaves like a legitimate thin-file customer rebuilding credit and fraud models do not flag it.
  4. 4Piggyback. The synthetic is added as an authorised user on a real, well-aged, high-limit account, sometimes a knowing accomplice, sometimes a tradeline-for-sale service. It inherits that account's history and its score jumps quickly.
  5. 5Bust out. Once limits are high, the fraudster draws everything down across every account at once with no intent to repay. Losses land as charge-offs, and there is no real person to complain.
Common misconception
A fast-rising score is not always reassuring
A good, quickly rising credit score means the applicant is low risk.
Here it is often the opposite. A high score built almost entirely from authorised-user tradelines, with almost no independent history behind it, is the single clearest red flag for a synthetic.
How a synthetic identity is built and cashed out
Real data plus fabricated data, grown patiently, then a bust-out with no victim to complain.
REAL
A genuine, unused SSN
Often a child’s. It validates cleanly.
+
FABRICATED
A made-up name and date of birth
Increasingly with an AI face and document.
1Create
Combine real SSN with fabricated identity.
2Get declined
First application rejected, but a credit file opens.
3Incubate
Small products, on-time payments, looks legitimate.
4Piggyback
Added to an aged account; score jumps fast.
5Bust out
Draw everything down at once, then vanish.

Who gets hurt: the not-victimless reality

Because no real person is impersonated, synthetic identity fraud is often dismissed as a victimless paperwork crime. It is not. The Federal Reserve Bank of Boston has framed it as a crime that harms real people and funds further crime, and the human cost is concentrated among those least able to notice.

The SSNs used most often belong to children, the elderly, the deceased, and people outside the credit system. A child can reach adulthood to find their SSN already carries a fraudulent credit history built over a decade. The accounts a synthetic holds are also durable infrastructure for other crime: they front money laundering, act as mule accounts, and move the proceeds of trafficking.

Common misconception
It is not a victimless crime
Nobody is really harmed because the identity is not a real person.
Children, the elderly, and the deceased have their genuine SSNs used, often for years before anyone notices. The accounts also fund money laundering, mule networks, and trafficking.

How big is it? The 2025 to 2026 numbers

Headline total-loss figures for synthetic identity fraud vary widely, roughly USD 20 billion to USD 40 billion, precisely because so much of it is miscoded as ordinary credit loss rather than fraud. Synthetic identity fraud has been estimated at roughly 10 to 15 percent of charge-offs in a typical unsecured lending portfolio, which is the core reason the problem is under-measured. Treat every figure below as an attributed estimate, not a single agreed number.

FigureValueSource
US lender exposure to suspected syntheticsUSD 3.3 billion (as of end-2024)TransUnion H1 2025 report
Forecast US synthetic-identity losses by 2030At least USD 23 billionDeloitte Center for Financial Services
Wider US generative-AI fraud by 2027USD 40 billion, from USD 12.3 billion in 2023Deloitte (32 percent CAGR)
Synthetic share of 2025 deepfake fraud attemptsAbout 42 percent (vendor estimate)Shufti Pro deepfake index
Detection market sizeUSD 3.12 billion (2025), forecast USD 13.24 billion (2034)Intel Market Research (vendor)
Note
Why the totals disagree

When a synthetic busts out, the loss usually books as a credit charge-off, not a fraud loss, because there is no victim filing a report. That miscoding is why regulator-grade figures stay conservative while vendor estimates run higher. Present ranges, not a single hero number.

The regulatory response, 2020 to 2026

The official response has moved from defining the problem to building verification tools and, in the EU, to attacking the root cause with cryptographic identity.

  1. 12020, SSA eCBSV. Under the Economic Growth, Regulatory Relief and Consumer Protection Act of 2018, the SSA launched Electronic Consent Based Social Security Number Verification. For a fee, and with the consumer's electronic consent, permitted entities can confirm whether an SSN, name, and date of birth combination matches SSA records. A no-match is a strong synthetic signal. A 2024 GAO review flagged cost and adoption issues.
  2. 22021, Federal Reserve common definition. The first agreed industry definition, so institutions could finally classify and size these cases consistently.
  3. 3November 2024, FinCEN deepfake alert (FIN-2024-Alert004). FinCEN warned that criminals use generative AI as a low-cost tool to create falsified documents, photos, and video to defeat identity verification, and to build synthetic identities from stolen or fabricated PII. It asked institutions filing suspicious activity reports to reference the key term FIN-2024-DEEPFAKEFRAUD.
  4. 42024 to 2027, EU eIDAS 2.0. Under Regulation (EU) 2024/1183, all 27 EU member states must make an EU Digital Identity Wallet available to citizens by December 2026, built on selective disclosure and government-verified credentials. Financial-institution acceptance of wallet credentials is expected to follow by around December 2027. Wallet-based, cryptographically verified identity is the structural counter to fabricated identities.
  5. 52024 to 2025, UK. APP fraud reimbursement rules (from October 2024, up to GBP 85,000) raise the cost to banks of onboarding fraudulent and mule accounts, many of which are synthetic-fronted, and the Online Safety Act's phase-2 illegal-harms duties put fraudulent content and mule recruitment on platforms in scope.

How AI is arming the attackers

Building a convincing synthetic used to need skill and hours of PII assembly. Generative AI has reduced it to one image or a text prompt, so volume, not sophistication, is now the story. FinCEN's November 2024 alert exists specifically because the volume of suspicious activity reports describing this rose sharply.

Turnkey fraud-as-a-service kits are sold openly. OnlyFake produced forged IDs covering the US and roughly 56 other countries; its operator was extradited from Romania in September 2025, pleaded guilty in the Southern District of New York, and agreed to forfeit USD 1.2 million after the service sold more than 10,000 fake documents. ProKYC, identified by Cato Networks in October 2024 and reportedly priced around USD 629 a year, bundles a virtual camera, emulator, facial animation, and verification-photo generation to defeat exchange and payment-provider KYC. A synthetic face able to pass many checks now reportedly costs under USD 20 and about 30 minutes.

Attackers have also moved from holding a fake up to the camera to injecting a live deepfake stream through a virtual camera driver, which defeats the premise of a camera check. iProov reported native virtual-camera attacks up 2,665 percent across 2024, and separately a 1,151 percent surge in iOS injection attacks in the second half of 2025. These are iProov's own figures, useful for trend direction.

AI as the threat
Synthetic files now ship with synthetic faces

The classic synthetic, a real SSN plus fake bio, increasingly arrives with a matching AI-generated face and document so it can also clear selfie and liveness onboarding. That merges the synthetic-identity and deepfake threats into one workflow, which is why bureau checks alone no longer suffice.

How AI defends against it

AI is the main reason detection is viable at all, because a synthetic is invisible to rules that assume a real victim will complain. The defensive centre of gravity is moving to cross-institution analysis, because a synthetic looks clean at any single institution and only reveals itself when signals are pooled.

  • Graph and link analysis. Machine learning clusters applicants across accounts and institutions to reveal that many identities share an address, phone, device, email, or SSN, the tell of a synthetic farm. Consortium data multiplies this, because the pattern only appears when institutions pool signals.
  • Behavioural biometrics and device intelligence. Models read thousands of signals, from typing rhythm to hesitation on fields a genuine owner would know, to separate a real thin-file customer from an operator running many synthetics.
  • Lifecycle anomaly detection. Models flag the specific synthetic signature: a thin file whose score rises fast almost entirely from authorised-user tradelines, or clusters of accounts that incubate quietly then draw down together before a bust-out.
  • Deepfake and injection defence at onboarding. Because the synthetic now often arrives with an AI face, liveness and injection-detection models, such as one-time challenge illumination that is hard to pre-render, matter at the KYC step.
AI on the defender’s side
The counter is coordination, not a single model

No one detector catches a well-built synthetic. The winning defence layers several independent signals, bureau and eCBSV checks, device and behavioural intelligence, injection detection, and consortium graph data, so that a pattern invisible to any one of them becomes obvious across all of them.

How banks and lenders detect and prevent it

There is no single test for a synthetic. Detection comes from combining several red flags, none decisive alone, into a picture. The checklist below reflects what the mechanism above tells you to look for.

  • A thin file whose credit score rises fast, driven almost entirely by authorised-user tradelines with little independent history.
  • An eCBSV no-match, where the SSN, name, and date of birth combination does not match SSA records.
  • A shared address, phone, device, or SSN across applicants who appear otherwise unrelated.
  • The declined-then-file-created pattern, where a first application is rejected but a credit file appears immediately after.
  • AI-face or injection signals at onboarding, such as a virtual-camera stream or liveness anomalies.
  • Continuous monitoring for the incubate-then-drawdown pattern over time, not just a one-off check at onboarding.

What the future looks like

Three shifts define where this is heading. First, verified-credential identity is the structural fix: EU Digital Identity Wallets and similar verifiable-credential schemes attack the root cause, because if identity is cryptographically issued and selectively disclosed, a fabricated persona has nothing to present. Expect wallet acceptance to become a compliance expectation in the EU, with the US following through eCBSV expansion and state mobile-driver-licence programmes.

Second, the onboarding arms race continues. As liveness improves, attackers move to injection; as injection detection improves, they move again. Layered, continuously updated defences become table stakes rather than differentiators. Third, defence shifts from point-in-time checks to continuous monitoring, because synthetics incubate quietly for months before bust-out, and the incubate-then-drawdown pattern only shows up over time. That is the same logic behind perpetual KYC.

Where orchestration fits: your vendors plus Zenoo

Zenoo is a KYC, KYB, and AML orchestration platform, not a synthetic-identity detector. It does not decide whether an applicant is a synthetic. The providers that score that are specialists: bureau and SSN verification (and eCBSV in the US), device and behavioural-biometrics vendors, deepfake and injection-detection vendors, and consortium and graph-data providers. Zenoo's job is to make that stack of vendors work as one system.

Because a synthetic only reveals itself when several independent signals are combined, orchestration is a natural fit. Zenoo can route one applicant through several checks in parallel through its Marketplace of 240+ check types, combine the results instead of relying on any single provider, and re-route to a better anti-injection vendor without a rebuild as the arms race moves. Every check and decision is recorded across 32 immutable audit event types in 8 categories, which matters for the suspicious activity report narrative FinCEN's alert asks for. On the investigation side, Zenoo's 10 specialised AI agents can pre-classify up to 80 percent of screening alerts with high confidence, cut per-alert investigation from an industry benchmark of 22 hours to 12 minutes, and help teams reach a 95 percent reduction in false positives within 90 days.

Honest scope
Where Zenoo does not solve the problem

Zenoo does not generate the synthetic-identity risk score, verify an SSN against SSA records, or detect a deepfake by itself. Those come from the specialist vendors it orchestrates. Orchestration cannot compensate for weak underlying detectors: if none of the connected vendors catches injection attacks, routing to them will not catch it either. Zenoo's value is coverage, parallelism, failover, one audit trail, and investigation speed, not a detection breakthrough. No Zenoo metric measures synthetic-identity catch rates, because none exists.

Key takeaways
  • It manufactures a new person rather than impersonating a real one, so for a long time there is no victim to raise the alarm.
  • The dangerous type pairs a real, unused SSN (often a child's) with a fabricated name and date of birth, so the number validates cleanly.
  • The lifecycle runs create, get declined, incubate, piggyback on aged tradelines, then bust out.
  • TransUnion measured USD 3.3 billion of US lender exposure to suspected synthetics as of end-2024.
  • Deloitte estimates synthetic identity fraud could drive at least USD 23 billion in US losses by 2030.
  • Generative AI now pairs the classic synthetic file with an AI face and document, merging synthetic identity and deepfake threats.

Frequently asked questions

What is synthetic identity fraud?

It is the use of a combination of real and fabricated personal data to build a person or entity that does not exist, most often a genuine Social Security number paired with a made-up name and date of birth. Criminals nurture that fictional identity until it holds real credit, then draw it down and disappear.

How is synthetic identity fraud different from identity theft?

Traditional identity theft impersonates a real victim who eventually notices and disputes the activity. Synthetic identity fraud manufactures a new person, so for a long time there is no human victim to raise the alarm. That is why it evades conventional fraud models and often hides for months or years.

How do criminals create a synthetic identity?

They combine a real, unused SSN, often a child's, with a fabricated name, date of birth, and contact details. A first credit application is usually declined but causes a credit file to be opened. The identity then builds credit on small products, gets added as an authorised user on an aged account to boost its score, and eventually busts out.

What is a bust-out in synthetic identity fraud?

A bust-out is the cash-out stage. Once the synthetic has high credit limits, the fraudster draws everything down across every account at once with no intent to repay, then vanishes. Because no real person complains, the losses usually book as ordinary credit charge-offs rather than fraud.

Why is synthetic identity fraud so hard to detect?

Because there is no real victim, it behaves like a legitimate thin-file customer building credit rather than like a stolen identity, so fraud models do not flag it. A genuine SSN validates cleanly, and 2011 SSN randomisation removed the ability to sanity-check a number against age or region. Losses are also miscoded as credit charge-offs, so the scale is under-measured.

How much does synthetic identity fraud cost?

Estimates vary widely, roughly USD 20 billion to USD 40 billion, because so much is miscoded as credit loss. TransUnion measured USD 3.3 billion of US lender exposure to suspected synthetics as of end-2024, and Deloitte estimates synthetic identity fraud alone could drive at least USD 23 billion in US losses by 2030.

How do banks detect synthetic identities?

By combining several red flags: a thin file whose score rises fast from authorised-user tradelines, an eCBSV no-match on the SSN, name, and date of birth combination, shared addresses, phones, or devices across applicants, the declined-then-file-created pattern, and AI-face or injection signals at onboarding. Graph and consortium data and continuous monitoring are central, because a synthetic looks clean at any single institution.
ZenooWhere this fits, honestly

Zenoo does not score synthetics. It orchestrates the specialist vendors that do, running SSN, device, behavioural, and injection checks in parallel, with one immutable audit trail and a faster investigation surface for your analysts.

Sources

Last reviewed 3 June 2026. Every statistic is traceable to a named source.
  1. 01Federal Reserve (FedPayments Improvement), Synthetic Identity Fraud Defined
  2. 02Thomson Reuters Institute, US Fed-led group agrees on common definition
  3. 03Federal Reserve Bank of Boston, synthetic identity fraud is not a victimless crime
  4. 04SSA, Social Security Number Randomization
  5. 05TransUnion, H1 2025 State of Omnichannel Fraud (USD 3.3bn synthetic exposure)
  6. 06Deloitte, generative AI and deepfake banking fraud (USD 40bn by 2027)
  7. 07SSA, new Electronic Consent Based SSN Verification service (eCBSV)
  8. 08US GAO-24-106770, actions needed on eCBSV
  9. 09FinCEN, alert on deepfake media fraud schemes (FIN-2024-Alert004)
  10. 10US DOJ (SDNY), OnlyFake creator charged and pleads guilty
  11. 11iProov, native virtual-camera injection attacks
  12. 12LexisNexis Risk Solutions, Synthetic Identity Fraud
Was this helpful?
Share