Not your identity, a new one
You picture identity fraud as someone pretending to be you. They use your name, your accounts, and your post goes astray. Synthetic identity fraud is different and harder to see. It does not impersonate a living adult. It builds a new person.
The fraudster takes one real identifier and attaches it to details that belong to nobody. They use an invented name, a made-up date of birth, and an address they control. The result is a composite that has a genuine key to the financial system. There is no real human behind it who might notice.
This is mostly a problem of credit systems that hang a person's whole financial history on a single number. The clearest case is the United States, where the Social Security number does that job. The pattern applies wherever one identifier is enough to open a credit file.
The real identifiers come from the same breaches that supply ordinary identity theft. They are traded in bulk, and what stolen identity data sells for shows how cheaply. Synthetic fraud simply uses them more patiently.
The lifecycle of a person who does not exist
Synthetic identities are grown, not used immediately. The process is patient and, until the last step, looks like a responsible new customer.
Creation. The fraudster applies for credit using the composite identity. A rejection is expected and useful. The application itself can cause a credit bureau to open a file for the new "person". The synthetic identity now exists on record.
Building. Next the identity collects history. It might be added as an authorised user on someone else's established card, borrowing that account's good standing. It opens small secured cards or store accounts and pays them on time, month after month. The score climbs from nothing to good.
Bust-out. Once several lenders have extended meaningful limits, everything is drawn at once. They take cash advances and purchase goods that resell easily. Then the payments stop. The person who never existed disappears, leaving debts that cannot be collected from anyone.
The long building phase is what defeats detection. For a long time the identity is a model customer, and models trained to reward good behaviour reward it.
Why children's identifiers are favoured
The identifier is chosen for one property: nobody is watching its credit file. Adults check their reports, receive statements and notice accounts they did not open. A child has no reason to have a credit file at all, and parents rarely think to look for one. The same is true, for a while, of the identifiers of people who have recently died.
A child's number can therefore anchor a synthetic identity for years. The real owner discovers it at the worst moment. They apply for a first loan, a student account or a flat, and find a credit history they never built, often in collections.
There is a wider lesson in this about systems that treat one number as proof of a whole person. This theme runs through age verification and the identity trap. The personal defence is the credit freeze, covered in whether you should freeze your credit; this piece is about how the fraud itself works.
How generative AI lowers the cost
The old bottleneck was evidence. Higher-value accounts ask for documents and, increasingly, a selfie or a short video to prove a live person is present. Producing convincing utility bills, payslips and faces for a person who does not exist used to take skill.
Generative tools have made that cheaper. Consistent sets of plausible documents can be produced on demand. Face-swap and synthetic-video tools aimed at identity checks are sold as services, as described in deepfake tools sold to fraudsters. They do not beat every check, but they make supporting a synthetic identity's paperwork far less work. This means more identities can be grown at once.
The money that comes out at the end needs moving. This is where money mule recruitment enters: the bust-out proceeds are passed through accounts belonging to people who were told they had found a job.
How a bust-out looks from inside a lender
Picture a new customer application. It is thin but meets the basic criteria, so you approve a small credit limit. The account is opened under the name "Alex Vance", linked to a real identifier. For two years, the behaviour is perfect. Payments are made on time, utilisation is low.
Your systems automatically grant a limit increase, then another. The customer's score is good, and they have opened a few other accounts elsewhere, which is normal. You see nothing alarming.
Then, over a single weekend, the pattern breaks. The utilisation on your card spikes to the limit, mostly from cash advances. Simultaneously, you see alerts that the same customer has maxed out several new accounts opened recently with other lenders. You attempt contact, but the phone number is disconnected and the address yields no response.
From your perspective, each step looked reasonable. The initial thin file was a young adult building credit. The perfect payments earned trust. The new accounts elsewhere suggested a life event, like a move or a new job. The sudden coordinated bust-out across multiple lenders is the first unambiguous signal, but by then the money is gone.
What lenders should look for
For organisations, detection relies on spotting the seams in a fabricated identity. Look for mismatches between the claimed person and the identifier's history. An identifier whose credit file is too new or too old for the claimed age is a strong signal. Watch for clusters of thin files appearing at the same address or linked to the same phone number, a sign of a fraud farm.
Be sceptical of authorised-user relationships that show no plausible family link. In the United States, the randomised issuance of Social Security numbers has weakened the old age checks that looked for patterns in the identifier itself, such as grouping by year. This makes behavioural and clustering signals more important.
A synthetic identity can build a good score, but it cannot create a plausible, dense history of life events from birth. The lack of depth is a tell.
Questions people ask
How is synthetic identity fraud different from ordinary identity theft?
Ordinary identity theft uses your whole identity, so you see the damage. You get bills for accounts you did not open. Synthetic fraud uses only a piece of your identity under a different name, so you may see nothing until much later. You only discover it when debts or a strange credit file surface against your number.
Why does this fraud often go undetected for years?
The synthetic identity is built to mimic a good customer. It makes small, regular payments and builds a positive history over time. Automated credit and fraud systems are designed to flag suspicious or bad behaviour, not patient, perfect behaviour. The fraud only triggers alerts at the final, coordinated bust-out.
What role does generative AI play now?
It drastically lowers the cost of creating supporting documentation for the fake person. Fraudsters can generate consistent fake bills, payslips, and even synthetic video for identity verification checks. This makes it easier to support more synthetic identities at once, scaling the fraud.
Can lenders stop this completely?
No check is perfect, but lenders can improve detection. They must move beyond just rewarding a good score. They need to analyse the context of an identity, looking for mismatches, unnatural clusters of similar thin files, and relationships that lack a real-world logic.
Close
Synthetic identity fraud succeeds because the person it uses does not exist and the person whose number it borrows is not watching. It exploits the gap between a financial identifier and a human life. The defence for lenders is to stop treating a well-behaved file as absolute proof of a real person. They must look for the clusters, the missing history, and the seams a patient fraudster cannot entirely hide.