What a synthetic identity is
In classic identity theft, a criminal pretends to be a real person, and that person eventually notices. A synthetic identity belongs to no one. It borrows one real anchor, most often a Social Security number in the US or a national ID number elsewhere, frequently one that belongs to a child, an elderly person or someone who rarely uses credit, and wraps it in a made-up name, birthday, address, email and phone. Nobody receives the bills or checks the credit report, so nobody complains.
Synthetic identities are mainly a problem for banks, lenders, card issuers, buy now pay later providers and fintech apps, anywhere that extends credit or moves money after an identity check. They also show up as fake accounts on marketplaces and crypto platforms that need a verified user to trade.
How synthetic identity fraud works
- 01
Assemble
A real ID number is combined with invented personal details. Stolen data from breaches and the dark web supplies the anchor.
- 02
Create a credit file
The first applications are usually declined, but they make credit bureaus create a file for the new identity.
- 03
Build trust
The identity gets a small card or loan, pays on time, and may be added as an authorized user on other cards to borrow their history.
- 04
Scale
Over months, limits grow and more accounts are opened. Rings run many identities in parallel, often from the same few devices.
- 05
Bust out
Every line of credit is maxed out at once and the identity goes silent. The losses are often written off as bad debt, not recognized as fraud.
Why synthetic identities are hard to catch
Each piece checks out on its own. The ID number is valid, the address receives mail, the phone answers, the credit file exists and the payment history is clean. Document checks can be passed with forged or AI-generated documents that match the invented details. Because there is no victim to raise the alarm, many lenders only see the fraud after the bust-out, and some never label it as fraud at all.
What synthetic identities share is the operation behind them. A ring that runs dozens of identities tends to apply from the same devices, the same networks and the same scripts, with the same typing patterns and navigation, in bursts. That is where device and behavior evidence adds what identity data alone cannot see.
- Several applicants with different names applying from one device.
- Application data typed or pasted at identical speed across identities.
- Emulators, virtual machines or spoofed devices used at onboarding.
- New contact details that are recent and unlinked to any history.
Synthetic identity vs fake account
Synthetic identity
- A made-up person anchored on a real ID number
- Built to pass KYC and credit checks
- Grown for months, then busted out
- Hits lenders, banks and fintech hardest
Fake account
- Any account not tied to a genuine customer
- Often disposable, created in bulk
- Used quickly for rewards, spam or scams
- Hits any platform with signup value
How to detect synthetic identities
Identity data checks remain the base layer. In the US, for example, the Social Security Administration's eCBSV service lets permitted financial institutions confirm that a name, date of birth and SSN belong together. Kavra adds the layer those checks lack: it recognizes returning devices across applications, links applicants who share a device, network or behavior, and exposes emulators and spoofed environments at onboarding, so a ring shows up as one actor rather than many strangers. See fake account detection and the onboarding view for fintech and banking.