Key Takeaways
  • A synthetic identity combines a genuine identifier with fabricated personal details to create a fictitious identity. Synthetic identity fraud differs from traditional identity theft, where a fraudster impersonates an existing person. 
  • The fraud unfolds in three phases: identity manufacturing, credit building, and bust-out. Security teams get the best chance to intervene during credit building, before losses peak. 
  • Group-IB’s Fraud Protection platform and Cyber Fraud Intelligence Platform help enterprises detect synthetic identities and disrupt coordinated rings without exposing raw customer data. 

What Is Synthetic Identity Fraud?

Synthetic identity fraud is a financial crime in which an attacker combines real and fabricated data to create a new, fictitious identity. The attacker then uses this identity to open fraudulent accounts and make unauthorized purchases.

Synthetic identity fraud differs from traditional identity theft because it involves creating a blended identity rather than impersonating an existing individual. While threat actors harvest authentic identifiers, such as a Social Security Number (SSN), from vulnerable populations like minors or the deceased, they combine these legitimate markers with fabricated names and addresses. 

This results in a fake identity with a valid credit-building record, even though it doesn’t belong to an actual person. No real victim notices a strange charge or a denied application, which is why this fraud can go undetected for so long. 

Why Synthetic Identity Fraud Is Growing

Synthetic identity fraud is growing because Generative AI enables the mass production of hyper-realistic personas that exploit the static nature of traditional Know Your Customer (KYC) verification processes.

The proliferation of Personally Identifiable Information (PII) on the dark web, combined with AI-driven automation (specifically bots, Generative AI, and app-cloning tools), enables threat actors to assemble and manage thousands of blended identities simultaneously.

Meanwhile, traditional KYC processes fail because they verify data points in isolation rather than checking whether they belong together. Synthetic identities often pass verification checks because they use genuine identifiers with clean histories.

TransUnion named synthetic identities its top fraud trend for 2026, citing continued growth in scale, sophistication, and impact. 98% of U.K. fraud leaders TransUnion surveyed said they worry synthetic identities are affecting their portfolios, and the firm’s research suggests as many as 5 million U.K. consumers may already be synthetic identities.

A Group-IB investigation into deepfake fraud identified a criminal group in Indonesia that bypassed multilayered biometric security. The attackers used app cloning and face-swapping technologies to execute AI-powered synthetic identity fraud during digital onboarding, revealing the limitations of traditional KYC processes. 

How Synthetic Identity Fraud Unfolds Over Time

Synthetic identity fraud unfolds in three main phases. First is the identity manufacturing stage, where criminals create fake identities. Next comes credit building, as criminals build up credit limits over time. Finally, in the bust-out phase, they spend all available funds and then abandon the identity.

The table below provides a quick breakdown of the synthetic identity fraud lifecycle.

Phase Key Actions & Goals
Identity manufacturing  – Construct a synthetic identity by combining real and fake data.

– Establish a credible blended persona before introducing it to financial systems.

Credit building – Introduce a synthetic identity into financial systems through low-risk applications or piggybacking.

– Build trust by maintaining on-time payments and controlled account activity.

– Expand access to higher credit limits across multiple institutions.

Bust-out  – Exploit accumulated credit through cash-outs, high-value transactions, or refund abuse.

– Abandon the identity after extraction.

Phase 1: Identity manufacturing

In the identity manufacturing phase, the attacker constructs a synthetic identity by blending legitimate identifiers with fabricated personal data.

Threat actors commonly use “clean” SSNs gathered from data breaches, the dark web, or social engineering. Their goal is to establish a believable digital persona before it ever interacts with financial systems.

The fake profile looks legitimate because its core identifiers are real and either unused or barely used, so it can easily pass onboarding checks when entering credit and banking systems for the first time.

Phase 2: Credit building

In the credit-building phase, the attacker introduces the synthetic identity into financial systems and builds trust over time. Their goal is to expand the identity’s access to higher credit limits across multiple institutions.

Threat actors introduce synthetic profiles into financial systems through low-value accounts, such as retail cards, or by piggybacking as authorized users on legitimate accounts. These early interactions create a record of existence within credit bureaus and financial databases.

Over time, the attacker builds credibility by maintaining clean repayment behavior and controlled account activity.

During this phase, attackers can reuse the same synthetic identity or its components across banks, lenders, and payment platforms to maximize yield while preserving the appearance of legitimacy.

Group-IB’s investigations show this pattern in Authorized Push Payment (APP) fraud, where attackers use synthetic identities to open mule Demand Deposit Accounts (DDAs). Attackers receive and rapidly redistribute scam proceeds across institutions, evading detection.

Phase 3: Bust-out

In the bust-out phase, the attacker spends or withdraws all available funds, loans, and credit lines before abandoning the account.

Once credit limits and transactional access reach their peak, attackers exploit the synthetic identity by rapidly withdrawing funds through cash-outs, high-value purchases, or payment fraud. These actions often occur simultaneously across multiple institutions where the identity has been seeded.

After extraction, the fraudster abandons the profile entirely, leaving financial institutions with no real individual to pursue for recovery. The identity may resurface elsewhere, repurposed for additional fraud paths or reintroduced through related synthetic profiles.

Signals That Suggest a Synthetic Identity

Synthetic identities are most reliably identified through behavioral and technical inconsistencies, not static personal data. The strongest signals are shared devices across unrelated accounts, robotic interaction patterns, and shared infrastructure. 

1. Device and session patterns that don’t add up

Multiple, unrelated accounts linked to the same device or technical environment signal synthetic activity.

Although the PII in each application seems unique, underlying patterns (device attributes,  network settings, IP behavior, and browser configurations) reveal a shared infrastructure. Shared infrastructures often point to organized criminal groups.

2. Behavior and velocity anomalies across apps

During onboarding, fraudsters often use automated scripts or “copy-paste” functions for sensitive fields like SSNs, bypassing the natural hesitation and keystroke rhythm of a real human. 

As synthetic accounts mature, they exhibit sudden spikes in activity, such as multiple credit limit increase requests or simultaneous actions across multiple banking apps.  

3. Link analysis clues 

Link analysis clues reveal when attackers reuse components of synthetic identities to scale attacks.

Shared devices and repeated attributes offer strong clues. Repeated email naming conventions, reused addresses, shared VoIP phone numbers, and common device fingerprints connect seemingly distinct profiles. 

Detecting these repeated attributes allows security teams to disrupt entire fraud rings at once, rather than chasing individual accounts.

Where To Place Controls Across the Customer Journey

The best touchpoints to place controls across the customer journey are at onboarding and credit application, account servicing, and payments and dispute activity. This multi-layered approach lets security teams spot subtle inconsistencies in a blended identity during its incubation period, rather than waiting for a reactive alert during a bust-out.

Below, we examine the distinct behavioral and technical indicators that surface at each stage of the customer journey.

1. Onboarding and credit application

Synthetic identities often pass initial data verification but reveal anomalies during application. Entry-point controls should evaluate device reputation, environmental signals, and document authenticity. Monitoring for “robotic” interaction patterns during credit applications, such as rapid submissions, can catch accounts that look legitimate on paper but behave suspiciously in practice.

2. Account servicing, limit increases, and profile updates

Changes to account details are high-signal indicators of synthetic identity fraud. Sudden updates to addresses, phone numbers, or email addresses, especially when followed by a credit limit increase request, can indicate an impending bust-out. Monitoring these actions allows controls to intervene before the fraud escalates.

3. Payments, refunds, and dispute activity

Transactional anomalies can expose synthetic identities post-onboarding. Patterns such as sudden bursts of activity after dormancy, high refund-to-purchase ratios, frequent high-value refunds, and rapid-fire disputes often signal extraction attempts or account abuse. Spotting them gives you a final chance to mitigate losses.

Detection Tactics That Work in Production

Effective synthetic identity fraud detection in production relies on tools and processes that separate legitimate thin-file users from synthetic constructs without blocking real customers. These tactics are deployed in live systems, ensuring real-time protection across the customer journey.

1. Device intelligence and risk scoring

Device intelligence collects and analyzes data from user devices to detect suspicious behavior.

Techniques such as device fingerprinting and interaction analytics provide security teams with a persistent view of how applicants interact with digital services. 

Risk scoring uses collected device and behavioral data to quantify fraud risk. This process guides security teams on whether to approve, flag, or require more verification for the application.

2. Document and face checks with liveness and replay protection

Static documents and photo checks are no longer enough because Generative AI enables deepfake attacks.

Liveness detection requires users to perform random actions, helping security teams ensure the person interacting with the system is real and that the input is not pre-recorded or a deepfake. 

3. Consortium and shared-risk signals without exposing identifiers

Synthetic identities are often used simultaneously across multiple organizations. Consortium and shared-risk signals allow security teams to identify coordinated patterns across environments without sharing raw customer data. 

This strengthens ecosystem-level defense, preventing synthetic identity fraud from spreading while maintaining regulatory compliance.

How To Exchange Fraud Signals While Protecting Customer Privacy

Security teams can exchange fraud signals while protecting customer privacy by tokenizing identifiers before sharing them across institutions. This requires privacy-preserving workflows that connect the right intelligence to the right controls.

1. Tokenize and minimize identifiers

Security teams should implement one-way hashing to convert sensitive identifiers into unique, irreversible tokens before they leave the organization’s perimeter. 

Tokens protect raw data while still allowing match-on-token analysis across platforms.

  • Identify sensitive identifiers (e.g., SSN, phone number) linked to blended identities.
  • Apply a cryptographic hash with a shared salt to generate anonymized tokens. 
  • Share only the tokens to a shared fraud intelligence hub or consortium.

2. Match patterns across participants to spot coordinated activity

Once identifiers are tokenized, security teams should compare patterns across multiple participants. Shared devices, repeated behavioral traits, and synchronized activity timelines reveal synthetic identity rings that would otherwise remain invisible.

In practice, this plays out in three steps.

  • Aggregate tokenized signals from participating organizations.
  • Analyze for repeated behaviors or device reuse across accounts. 
  • Flag clusters for further investigation or automated controls.

3. Governance for consent, retention, and audit

Maintaining privacy while exchanging signals requires governance embedded in every workflow. Security teams should enforce a privacy-by-design framework built on three pillars. 

  • Dynamic consent management to ensure users authorize data use.
  • Automated retention policies that purge tokens once their investigative purpose is fulfilled. 
  • Immutable audit logs that track every data transaction for compliance and accountability.

Combining these workflows within a Fraud Protection platform can help organizations detect synthetic identity fraud at scale and keep customer data secure and compliant.

Catching Sophisticated Synthetic Fraud

Detecting sophisticated synthetic identities requires a layered defense strategy that goes beyond basic KYC checks. Organizations must combine behavioral analytics, device intelligence, and AI-driven pattern recognition to identify accounts that appear legitimate on the surface but exhibit inconsistent behavior. 

Below are the key areas where your security team can apply these defenses to catch synthetic identity fraud early.

When an identity passes KYC but fails the behavior

Behavioral anomalies signal synthetic fraud. Even with valid stolen documents, fraudsters cannot easily mimic natural “digital body language,” such as mouse movements, typing rhythms, or app navigation patterns.

Security teams should respond to suspicious behavior on verified accounts through five steps. 

  • Collect and analyze behavioral telemetry. Track session activity, keystrokes, navigation patterns, and device signals.
  • Flag high-risk accounts. Identify accounts that deviate from typical human behavior or exhibit rapid, suspicious activity.
  • Cross-check with device and session risk scores. Combine behavioral anomalies with device fingerprints, IPs, and network patterns to prioritize investigations.
  • Classify risk type. Determine if anomalies suggest first-party manipulation or third-party synthetic fraud.
  • Take targeted action. Monitor low-risk but anomalous accounts. Suspend high-risk synthetic accounts.
  • Maintain ongoing monitoring. Watch accounts that pass initial review for any new suspicious activity.

Separating first-party abuse from synthetic fraud patterns

Distinguishing first-party abuse from third-party synthetic fraud ensures Security Operations Center (SOC) teams apply the right controls while preserving a legitimate user experience. 

  • First-party abuse involves a real user manipulating their own account, while third-party synthetic fraud comes from organized actors using fabricated identities. 
  • First-party abuse signals include unusual edits or inconsistencies on a single account, activity from a consistent device, or minor manipulations in self-reported information. 
  • Third-party synthetic fraud signals include coordinated activity across multiple accounts, reused devices or IPs, and repeated behavioral patterns across unrelated accounts.

Using behavioral, technical, and cross-channel signals, security teams can accurately classify the fraud type and respond appropriately. Here’s how teams can tell the difference:

  • Collect behavioral and technical signals. Device fingerprints, IP addresses, account edits, cross-channel connections.
  • Compare patterns across accounts. Single-account anomalies are likely first-party abuse. Multi-account coordination is likely third-party synthetic fraud.
  • Apply a targeted response based on classification. Manual review, limit adjustments, or direct user outreach for first-party abuse. For third-party fraud, use account suspension, network-wide alerts, and partner notifications.

Reducing manual review while protecting acceptance rates

Continuous risk scoring is essential, particularly as Group-IB’s report Weaponized AI highlights how threat actors can bypass initial onboarding checks by mimicking human behavior. 

Automated risk scoring allows security teams to stop synthetic identity fraud without blocking real customers. AI and machine learning models can instantly approve low-risk users and escalate accounts with synthetic identity signals. 

  • Integrate automated risk scoring across touchpoints. Apply scoring during onboarding, account changes, and transaction activity.
  • Define clear action thresholds. Set rules for automatic approval, step-up verification, manual review, or real-time intervention.
  • Continuously update detection models. Retrain models using newly observed synthetic fraud behaviors and cross-channel intelligence.

How To Prevent Synthetic Identity Fraud

Enterprises can prevent synthetic identity fraud by layering verification, device intelligence, and behavioral monitoring across the entire customer lifecycle, rather than relying on a single onboarding check. The four areas below cover the full customer journey, from first application to ongoing account monitoring.

Strengthen identity verification and KYC controls

KYC controls should check whether identity elements belong together, not just whether each one is individually valid. 

  • Cross-reference the SSN against the applicant’s stated age, since a genuine but stolen number passes a standalone lookup every time.
  • Check address history and credit file depth alongside the SSN, not as separate, isolated checks.
  • Flag mismatches, such as a 45-year-old applicant with a two-month credit history, for manual review.

Apply device, behavioral, and network intelligence to assess risk

Applying device, behavioral, and network intelligence at the prevention stage means combining individual application signals with patterns across many applications.

  • Combine device fingerprinting and behavioral analytics into a single risk score at onboarding through Group-IB Fraud Protection Platform, before a fraudulent account gets approved. 
  • Flag clusters of accounts sharing a device fingerprint or phone number rather than reviewing them one at a time. 
  • Extend detection across institutions with Group-IB Cyber Fraud Intelligence Platform, letting members compare tokenized signals without exposing raw customer data.

Monitor accounts for suspicious activity after onboarding

Monitoring accounts after onboarding means running continuous behavioral checks against each account’s baseline, not stopping analysis once an account is approved. 

  • Track account behavior against its own established baseline rather than a generic, one-time risk score.
  • Trigger automated alerts when behavior deviates from that baseline, especially during the credit-building phase when risk peaks.
  • Treat onboarding-only screening as incomplete, since it misses months of buildup before a bust-out.

How AI and Machine Learning Improve Synthetic Identity Fraud Detection

AI and machine learning improve synthetic identity fraud detection by processing behavioral, device, and transactional signals at a scale and speed manual review cannot match. 

A human analyst can review a handful of flagged accounts a day. In comparison, a machine learning model can track millions of applications in real time. That scale changes what’s possible:

  • Learn a baseline from millions of applications instead of a fixed set of rules.
  • Flag deviations the moment they happen, not during a periodic review cycle.
  • Adapt to new fraud patterns as they emerge, rather than waiting on a rule update.

Group-IB’s Weaponized AI research shows threat actors are already using generative tools to automate the creation and management of large volumes of blended identities. Static, rule-based systems lose effectiveness once fraudsters learn to route around them.  Machine learning models that continuously retrain on newly observed fraud behavior are one of the few defenses that can keep pace with this rate of change.

Measuring the Effectiveness of Synthetic Identity Fraud Detection

Enterprises measure the effectiveness of synthetic identity fraud detection through more than one number. A single pass-or-fail metric can be misleading, since a program that lowers false positives by approving more applications will also let more fraud through unless detection accuracy improves at the same time.

Research from the Federal Reserve points to three of the clearest signals to track.

Metric What It Means for Your Program
Detection timing Detection is often too slow to matter. In the Federal Reserve’s 2026 Risk Officer Report, 51% of financial institutions reported identifying mule accounts, many involving synthetic identities, only after losses have already occurred.

Catching a synthetic identity during credit building, rather than at bust-out, preserves far more of the potential loss.

False positive rate Red flags like a short address history or an SSN that doesn’t match an applicant’s age also describe legitimate individuals, like recent immigrants.

The Federal Reserve’s 2020 Payment Fraud Insights recommends pairing red flags with manual validation before treating them as automatic denials.

Manual review reliance Detection still leans heavily on people, not automation. The  2026 Risk Officer Report found 71% of institutions rely on manual review at account opening, and fewer than half use any automated review at all.

Programs that stay fully manual will struggle to keep pace as synthetic identity volume grows.

Enterprises with mature synthetic fraud detection programs review these metrics on a rolling basis rather than a one-time deployment, since fraud patterns shift as attackers adapt.

How Group-IB Fights Synthetic Identity Fraud

Synthetic identities succeed by passing static KYC checks during manufacturing, then building a clean credit history for months before the bust-out drains the account. Stopping that pattern requires device intelligence, behavioral signals, and cross-institution collaboration, as this guide covers. 

Group-IB Fraud Protection brings those signals together, helping enterprises disrupt fake personas before they scale into coordinated bust-out attacks. The platform stops synthetic identity fraud by analyzing device fingerprints, behavioral biometrics, and session risk instead of relying on static identifiers alone. Your team can apply synthetic fraud detection in three ways. 

  • Detect synthetic patterns in real-time during onboarding by cross-referencing device intelligence, behavioral biometrics, and session risk. This surfaces anomalies like automated data entry or non-human navigation that traditional KYC checks miss.
  • Prioritize investigation with high-fidelity signals, such as repeat device fingerprints and velocity anomalies. This eases the manual review workload and reduces dependence on inconclusive PII verification.
  • Collaborate via privacy-safe signal exchange. The Cyber Fraud Intelligence Platform enables industry-wide collaboration through patented tokenization. Members can identify coordinated fraud across institutions without exposing raw PII, thereby maintaining compliance with GDPR and global privacy regulations.

Contact Group-IB experts to start identifying behavioral signals that expose blended identities.  We can show you how our Fraud Protection platform helps you reduce risk and strengthen your onboarding against coordinated fraud.

 

How do fraudsters create synthetic identities?

arrow_drop_down

Fraudsters create synthetic identities by combining a real, often stolen identifier, such as a Social Security number, with fabricated personal details like a new name, date of birth, or address. The identifiers most commonly targeted for synthetic identity theft belong to children, deceased individuals, or others unlikely to check their credit files, which delays discovery.

 

What are the warning signs of synthetic identity fraud?

arrow_drop_down

The warning signs of synthetic identity fraud include a credit file with no history before a certain date, an applicant age inconsistent with the length of their credit file, shared devices or contact details across unrelated accounts, and robotic input patterns during onboarding, such as copy-pasted data fields.

 

How can banks detect synthetic identity fraud?

arrow_drop_down

Banks detect synthetic identity fraud by combining device intelligence, behavioral analytics, and cross-institution signal sharing rather than relying on document checks alone. Layering these controls across onboarding, account servicing, and transaction monitoring helps banks catch identities that pass initial verification but behave abnormally afterward.

 

What is the difference between synthetic identity fraud and identity theft?

arrow_drop_down

Synthetic identity fraud differs from traditional identity theft in one key way. Traditional identity theft impersonates a real, existing person who can eventually notice and report the fraud. Synthetic identity fraud, sometimes called synthetic identity theft, fabricates a new identity using a real identifier and invented details, so no real person notices the activity or reports it. That missing victim is why synthetic identity fraud often goes undetected for months or years longer than traditional identity theft.

 

What technologies are used to detect synthetic identity fraud?

arrow_drop_down

Enterprises use technologies such as device fingerprinting, behavioral biometrics, link analysis, and machine learning risk scoring to detect synthetic identity fraud. Consortium data sharing adds a further layer, letting institutions compare tokenized signals to catch identities and fraud rings operating across multiple organizations at once.

Group-IB: Fight
against cybercrime