What synthetic identity fraud is, how it differs from ordinary identity theft, how criminals pull it off, how big it is now, and how banks detect and stop it.
Synthetic identity fraud combines real and fabricated personal data, often a genuine Social Security number paired with a made-up name and date of birth, to build a person who does not exist. Criminals nurture that fictional identity until it holds real credit, then draw it all down and vanish. Because no real victim complains, it hides for months.
Synthetic identity fraud is the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain. That wording is the first common industry definition, published in 2021 by a Federal Reserve led group of fraud experts, because until then institutions classified these cases inconsistently and could not size the problem.
The Federal Reserve framework splits the data into two tiers. Primary elements are identifiers usually unique to one person: name, date of birth, Social Security number, and government-issued ID numbers. Supplemental elements are supporting data that adds plausibility but cannot establish identity on its own: address, phone, email, and digital footprint. A synthetic is built by mixing a few real primary elements with fabricated ones, then wrapping them in supplemental data.
The two crimes look similar on paper and behave nothing alike in practice. The distinction below is the single most important thing to understand, because it explains why detection is hard and why losses are so badly measured.
The Federal Reserve describes three construction methods. The difference between them decides how easy the identity is to catch.
Before 2011 the Social Security Administration encoded geography and issue order into SSN digits, so a number could be sanity-checked against a person's age and birthplace. On 25 June 2011 the SSA randomised all newly issued SSNs to protect privacy. The unintended effect: an SSN can no longer be validated against age or region, so a criminal can take a child's dormant but valid SSN, attach an adult name and date of birth, and nothing about the number itself looks wrong.
This is why the classic victims are children, the elderly, the deceased, and people who do not actively use credit. Their SSNs can sit unused and unmonitored for years, and nobody checks a credit file that nobody expects to exist.
A synthetic is not created and cashed out in a day. It is grown patiently over months, which is what makes it look legitimate right up until the end.
Because no real person is impersonated, synthetic identity fraud is often dismissed as a victimless paperwork crime. It is not. The Federal Reserve Bank of Boston has framed it as a crime that harms real people and funds further crime, and the human cost is concentrated among those least able to notice.
The SSNs used most often belong to children, the elderly, the deceased, and people outside the credit system. A child can reach adulthood to find their SSN already carries a fraudulent credit history built over a decade. The accounts a synthetic holds are also durable infrastructure for other crime: they front money laundering, act as mule accounts, and move the proceeds of trafficking.
Headline total-loss figures for synthetic identity fraud vary widely, roughly USD 20 billion to USD 40 billion, precisely because so much of it is miscoded as ordinary credit loss rather than fraud. Synthetic identity fraud has been estimated at roughly 10 to 15 percent of charge-offs in a typical unsecured lending portfolio, which is the core reason the problem is under-measured. Treat every figure below as an attributed estimate, not a single agreed number.
When a synthetic busts out, the loss usually books as a credit charge-off, not a fraud loss, because there is no victim filing a report. That miscoding is why regulator-grade figures stay conservative while vendor estimates run higher. Present ranges, not a single hero number.
The official response has moved from defining the problem to building verification tools and, in the EU, to attacking the root cause with cryptographic identity.
Building a convincing synthetic used to need skill and hours of PII assembly. Generative AI has reduced it to one image or a text prompt, so volume, not sophistication, is now the story. FinCEN's November 2024 alert exists specifically because the volume of suspicious activity reports describing this rose sharply.
Turnkey fraud-as-a-service kits are sold openly. OnlyFake produced forged IDs covering the US and roughly 56 other countries; its operator was extradited from Romania in September 2025, pleaded guilty in the Southern District of New York, and agreed to forfeit USD 1.2 million after the service sold more than 10,000 fake documents. ProKYC, identified by Cato Networks in October 2024 and reportedly priced around USD 629 a year, bundles a virtual camera, emulator, facial animation, and verification-photo generation to defeat exchange and payment-provider KYC. A synthetic face able to pass many checks now reportedly costs under USD 20 and about 30 minutes.
Attackers have also moved from holding a fake up to the camera to injecting a live deepfake stream through a virtual camera driver, which defeats the premise of a camera check. iProov reported native virtual-camera attacks up 2,665 percent across 2024, and separately a 1,151 percent surge in iOS injection attacks in the second half of 2025. These are iProov's own figures, useful for trend direction.
The classic synthetic, a real SSN plus fake bio, increasingly arrives with a matching AI-generated face and document so it can also clear selfie and liveness onboarding. That merges the synthetic-identity and deepfake threats into one workflow, which is why bureau checks alone no longer suffice.
AI is the main reason detection is viable at all, because a synthetic is invisible to rules that assume a real victim will complain. The defensive centre of gravity is moving to cross-institution analysis, because a synthetic looks clean at any single institution and only reveals itself when signals are pooled.
No one detector catches a well-built synthetic. The winning defence layers several independent signals, bureau and eCBSV checks, device and behavioural intelligence, injection detection, and consortium graph data, so that a pattern invisible to any one of them becomes obvious across all of them.
There is no single test for a synthetic. Detection comes from combining several red flags, none decisive alone, into a picture. The checklist below reflects what the mechanism above tells you to look for.
Three shifts define where this is heading. First, verified-credential identity is the structural fix: EU Digital Identity Wallets and similar verifiable-credential schemes attack the root cause, because if identity is cryptographically issued and selectively disclosed, a fabricated persona has nothing to present. Expect wallet acceptance to become a compliance expectation in the EU, with the US following through eCBSV expansion and state mobile-driver-licence programmes.
Second, the onboarding arms race continues. As liveness improves, attackers move to injection; as injection detection improves, they move again. Layered, continuously updated defences become table stakes rather than differentiators. Third, defence shifts from point-in-time checks to continuous monitoring, because synthetics incubate quietly for months before bust-out, and the incubate-then-drawdown pattern only shows up over time. That is the same logic behind perpetual KYC.
Zenoo is a KYC, KYB, and AML orchestration platform, not a synthetic-identity detector. It does not decide whether an applicant is a synthetic. The providers that score that are specialists: bureau and SSN verification (and eCBSV in the US), device and behavioural-biometrics vendors, deepfake and injection-detection vendors, and consortium and graph-data providers. Zenoo's job is to make that stack of vendors work as one system.
Because a synthetic only reveals itself when several independent signals are combined, orchestration is a natural fit. Zenoo can route one applicant through several checks in parallel through its Marketplace of 240+ check types, combine the results instead of relying on any single provider, and re-route to a better anti-injection vendor without a rebuild as the arms race moves. Every check and decision is recorded across 32 immutable audit event types in 8 categories, which matters for the suspicious activity report narrative FinCEN's alert asks for. On the investigation side, Zenoo's 10 specialised AI agents can pre-classify up to 80 percent of screening alerts with high confidence, cut per-alert investigation from an industry benchmark of 22 hours to 12 minutes, and help teams reach a 95 percent reduction in false positives within 90 days.
Zenoo does not generate the synthetic-identity risk score, verify an SSN against SSA records, or detect a deepfake by itself. Those come from the specialist vendors it orchestrates. Orchestration cannot compensate for weak underlying detectors: if none of the connected vendors catches injection attacks, routing to them will not catch it either. Zenoo's value is coverage, parallelism, failover, one audit trail, and investigation speed, not a detection breakthrough. No Zenoo metric measures synthetic-identity catch rates, because none exists.
Zenoo does not score synthetics. It orchestrates the specialist vendors that do, running SSN, device, behavioural, and injection checks in parallel, with one immutable audit trail and a faster investigation surface for your analysts.