Skip to main content
Category: Fraud Typologies

Synthetic Identity Fraud

Also known as: SIF, Synthetic Identity Theft, Synthetic ID Fraud
Simply put

Synthetic identity fraud is a type of financial fraud in which a criminal creates a fake identity by combining real personal information, such as a Social Security number or date of birth, with fabricated or fictitious details. Because the resulting identity does not fully correspond to any single real person, it can be harder to detect than fraud involving a wholly stolen identity. Reports indicate the threat has been growing, with generative AI cited as a factor that may make fabricated identities easier to produce.

Formal definition

Synthetic identity fraud (SIF) is the use of a combination of personally identifiable information (PII) — which may include genuine data elements such as a Social Security number or date of birth blended with fabricated or synthetic credentials — to construct a person or entity that does not exist as a single real individual, for the purpose of committing fraud. It is distinct from traditional identity theft, in which an existing real person's identity is misappropriated, because a synthetic identity is partially or wholly fabricated and may not map to any single genuine consumer, complicating attribution and detection. Sources note that generative AI is an emerging factor influencing how such identities are created; exact prevalence and loss figures depend on source, period, and methodology and are not specified here.

Why it matters

Synthetic identity fraud poses a distinct challenge because the fabricated identity does not map cleanly to any single real consumer. Traditional identity theft leaves an identifiable victim who can report unauthorized activity, but a synthetic identity may generate no such complaint, allowing the fraudulent account to persist and mature before losses surface. This complicates attribution, detection, and remediation, and it can mean fraudulent activity is misclassified as ordinary credit loss rather than fraud.

Reporting indicates that synthetic identity fraud is a growing and costly form of financial fraud, and that generative AI is an emerging factor that may make fabricated identities easier to produce. Because the threat blends genuine PII elements — such as a Social Security number or date of birth — with fabricated details, controls designed to match against a known real individual may not flag the identity as suspicious. Exact prevalence and loss figures depend on the source, period, and methodology, and are not established here.

For institutions that onboard customers and extend credit or payment capabilities, synthetic identity fraud is significant because it can defeat identity verification steps that assume every application corresponds to a real person. Detection controls trade off false positives against false negatives, and no single control should be assumed to eliminate this risk; layered verification and ongoing monitoring are typically needed to help reduce exposure.

Who it's relevant to

Merchant Risk and Onboarding Teams
Teams responsible for evaluating new accounts and applications are directly exposed to synthetic identity fraud because these identities are designed to pass as legitimate consumers. Verification steps that assume every applicant is a single real person may not detect an identity that blends genuine PII with fabricated details, so these teams should treat identity verification as one layer among several rather than a definitive control.
Fraud Analysts
Fraud analysts must distinguish synthetic identity fraud from traditional identity theft, in which an existing real person's identity is misappropriated. Because a synthetic identity may not map to any single genuine consumer, it can generate no victim complaint and may be misclassified as credit loss. Analysts should account for the trade-off between false positives and false negatives when tuning detection for identities that partially match real data.
Acquirers and Payment Processors
Organizations that provision payment capabilities to merchants or account holders have an interest in identifying fabricated identities before they are used to commit fraud. Because attribution is complicated when an identity does not correspond to a real individual, ongoing monitoring may be needed alongside initial verification to help surface synthetic accounts.
Compliance and Financial Institution Teams
Teams handling customer due diligence and identity verification requirements are relevant because synthetic identities are engineered to satisfy verification processes. As generative AI is cited as a factor that may make such identities easier to produce, these teams should periodically reassess whether existing verification controls remain effective, recognizing that no single control should be assumed to eliminate the risk.

Inside SIF

Fabricated Identity Construction
Synthetic identity fraud typically involves combining real and fictitious personal information, such as a valid or stolen identifier paired with an invented name, date of birth, or address, to create an identity that does not correspond to a single real person.
Credit Profile Cultivation
Perpetrators often establish and build up a credit history for the synthetic identity over time, sometimes through initially small accounts, so the profile appears legitimate to lenders and scoring systems before larger fraud is attempted.
Bust-Out Behavior
A common end stage in which the synthetic identity, having accumulated available credit, maxes out accounts with no intent to repay, after which the fictitious identity is abandoned rather than a real victim being pursued for repayment.
Distinction From Traditional Identity Theft
Unlike account takeover or classic identity theft that targets an existing real person's accounts, synthetic identity fraud centers on identities that are partly or wholly invented, which complicates victim notification and detection because there is often no single individual reporting the misuse.
Relationship to Payment Fraud Categories
Synthetic identities can be used to obtain payment cards or credit that later manifest as card-not-present or card-present fraud, and outcomes intersect with chargeback and liability rules that are governed by card brand and network rules and vary by region.

Common questions

Answers to the questions practitioners most commonly ask about SIF.

Is synthetic identity fraud just a form of account takeover?
No. Account takeover involves a fraudster gaining control of a legitimate victim's existing account, so there is a real, identifiable victim whose credentials or access were compromised. Synthetic identity fraud instead involves the fabrication of an identity, often by combining real and fictitious data elements, so there may be no single victim who recognizes the account as theirs. Because the identity does not map cleanly to one defrauded consumer, synthetic identity cases can be harder to detect and attribute than account takeover, and controls tuned for one may not perform well against the other.
Does synthetic identity fraud always require a stolen Social Security number or government identifier?
Not necessarily. Synthetic identities may be assembled from a mix of real and fabricated elements, and the specific data components used can vary by scheme and region. Some synthetic identities incorporate a real identifier belonging to another person, while others rely more heavily on fabricated or manipulated attributes. Because the composition varies, treating any single data element as a required ingredient can create detection blind spots. The exact prevalence of different construction methods depends on source, period, and methodology and is not a fixed fact.
How does synthetic identity fraud relate to PCI DSS scope and cardholder data protection?
Synthetic identity fraud is primarily an identity and application-fraud problem rather than a cardholder data storage problem, so it is largely out of scope for the specific storage and protection controls that PCI DSS governs. PCI DSS focuses on protecting cardholder data and sensitive authentication data within the cardholder data environment, and its requirements differ by version, so confirm any control against the current published standard. Defenses against synthetic identity fraud typically sit in onboarding, underwriting, and account-lifecycle monitoring rather than in the PCI DSS control set, though good data governance can support both objectives.
What signals can help detect synthetic identities at account onboarding?
Teams often look at consistency and correlation across identity attributes, the history and depth of an identifier's associated records, velocity of applications sharing overlapping data elements, and mismatches between claimed and observed behavior. These signals are intended to help surface fabricated or manipulated identities, but each carries false-positive and false-negative trade-offs: thin or newly established legitimate profiles can resemble synthetic ones, and well-aged synthetic identities can evade attribute-consistency checks. No single signal is authoritative, so most programs combine multiple indicators and periodically retune thresholds.
How should detection controls be tuned to balance synthetic-identity risk against customer friction?
Tuning generally involves setting thresholds and step-up rules that reflect an organization's risk appetite, since tighter controls may reduce fraudulent approvals but can increase declined or delayed legitimate applicants, and looser controls do the reverse. It helps to segment by product and channel, apply proportionate verification only when risk indicators warrant it, and monitor both false-positive and false-negative rates over time. Because performance drifts as fraud tactics change, thresholds should be reviewed on an ongoing basis rather than set once.
How can suspected synthetic identities be handled across the account lifecycle rather than only at onboarding?
Because synthetic identities may be built up gradually before any fraudulent loss occurs, monitoring is often extended beyond onboarding to include ongoing behavioral review, re-verification triggers on high-risk events, and analysis of linked accounts sharing common data elements. Actions can range from additional verification to restricting activity pending review. Any adverse action should follow applicable legal, regulatory, and network requirements, which vary by region and change over time, so operational playbooks should be validated against current obligations rather than assumed.

Common misconceptions

Synthetic identity fraud is just another name for identity theft.
They are distinct. Identity theft and account takeover misuse the accounts or credentials of a real, identifiable person, whereas synthetic identity fraud constructs an identity that is partly or entirely fabricated, so there is frequently no single real victim to report the activity, which changes both detection and response.
Standard identity verification or a single authentication control will stop synthetic identities.
No single control eliminates this risk. Verification, multi-factor authentication, and payment-time controls such as 3-D Secure or EMV chip authentication address different risks at different points and may help reduce exposure, but a cultivated synthetic profile can pass many checks; detection controls carry false-positive and false-negative trade-offs.
PCI DSS compliance addresses synthetic identity fraud.
PCI DSS focuses on protecting cardholder data and the security of the cardholder data environment, not on validating whether an applicant's identity is genuine. Synthetic identity risk is largely an onboarding, underwriting, and fraud-monitoring concern that falls outside the scope of PCI DSS controls.

Best practices

Correlate identity attributes across multiple independent sources during onboarding rather than relying on any single identifier, since synthetic identities combine real and fabricated elements that may individually appear valid.
Monitor for patterns consistent with credit profile cultivation and bust-out behavior, such as accounts that build history in small steps and then rapidly draw down available credit, while accepting that such heuristics produce false positives and false negatives.
Treat synthetic identity detection as an ongoing lifecycle activity spanning application, account cultivation, and transaction stages, rather than a one-time check at onboarding.
Layer complementary controls, recognizing that verification, multi-factor authentication, and payment authentication such as 3-D Secure or EMV chip authentication address different risks and none eliminates fraud on its own.
Coordinate with acquirers, processors, and card brands on chargeback and liability handling, confirming current requirements against the applicable brand and network rules, which change and vary by region.
Document detection thresholds and review outcomes so false-positive and false-negative trade-offs can be measured and tuned over time.