Glossary

What is a synthetic identity?

A synthetic identity is a fictitious person created by combining real data, typically a genuine government ID number, with an invented name, date of birth and contact details. Fraudsters use it to open accounts, build a credit history over months and then borrow as much as possible and disappear. Kavra links synthetic identities created from the same devices.

What a synthetic identity is

In classic identity theft, a criminal pretends to be a real person, and that person eventually notices. A synthetic identity belongs to no one. It borrows one real anchor, most often a Social Security number in the US or a national ID number elsewhere, frequently one that belongs to a child, an elderly person or someone who rarely uses credit, and wraps it in a made-up name, birthday, address, email and phone. Nobody receives the bills or checks the credit report, so nobody complains.

Synthetic identities are mainly a problem for banks, lenders, card issuers, buy now pay later providers and fintech apps, anywhere that extends credit or moves money after an identity check. They also show up as fake accounts on marketplaces and crypto platforms that need a verified user to trade.

How synthetic identity fraud works

  1. 01

    Assemble

    A real ID number is combined with invented personal details. Stolen data from breaches and the dark web supplies the anchor.

  2. 02

    Create a credit file

    The first applications are usually declined, but they make credit bureaus create a file for the new identity.

  3. 03

    Build trust

    The identity gets a small card or loan, pays on time, and may be added as an authorized user on other cards to borrow their history.

  4. 04

    Scale

    Over months, limits grow and more accounts are opened. Rings run many identities in parallel, often from the same few devices.

  5. 05

    Bust out

    Every line of credit is maxed out at once and the identity goes silent. The losses are often written off as bad debt, not recognized as fraud.

Why synthetic identities are hard to catch

Each piece checks out on its own. The ID number is valid, the address receives mail, the phone answers, the credit file exists and the payment history is clean. Document checks can be passed with forged or AI-generated documents that match the invented details. Because there is no victim to raise the alarm, many lenders only see the fraud after the bust-out, and some never label it as fraud at all.

What synthetic identities share is the operation behind them. A ring that runs dozens of identities tends to apply from the same devices, the same networks and the same scripts, with the same typing patterns and navigation, in bursts. That is where device and behavior evidence adds what identity data alone cannot see.

  • Several applicants with different names applying from one device.
  • Application data typed or pasted at identical speed across identities.
  • Emulators, virtual machines or spoofed devices used at onboarding.
  • New contact details that are recent and unlinked to any history.

Synthetic identity vs fake account

Synthetic identity

  • A made-up person anchored on a real ID number
  • Built to pass KYC and credit checks
  • Grown for months, then busted out
  • Hits lenders, banks and fintech hardest

Fake account

  • Any account not tied to a genuine customer
  • Often disposable, created in bulk
  • Used quickly for rewards, spam or scams
  • Hits any platform with signup value

How to detect synthetic identities

Identity data checks remain the base layer. In the US, for example, the Social Security Administration's eCBSV service lets permitted financial institutions confirm that a name, date of birth and SSN belong together. Kavra adds the layer those checks lack: it recognizes returning devices across applications, links applicants who share a device, network or behavior, and exposes emulators and spoofed environments at onboarding, so a ring shows up as one actor rather than many strangers. See fake account detection and the onboarding view for fintech and banking.

FAQ

Frequently asked questions

Something else? Talk to our team.

What is a bust-out in synthetic identity fraud?

A bust-out is the final stage of the scheme. After months of building a clean payment record and higher credit limits, the fraudster draws every available line of credit at once, through cash advances, purchases or transfers, then stops paying and abandons the identity. Because no real person is behind it, there is no one to collect from.

Why are children's Social Security numbers used in synthetic identity fraud?

Because a child's number has no credit history and nobody checks it for years. The fraud can run until the child applies for their first loan or job and finds a credit file they never opened. Numbers belonging to elderly people, deceased people and recent immigrants are attractive for similar reasons.

Can KYC stop synthetic identity fraud?

Document and data checks stop weak attempts, but well-built synthetic identities are designed to pass them, sometimes with forged or AI-generated documents. KYC works best combined with checks on the device and behavior at onboarding, which can reveal that many different applicants are really one operator.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.