CaraComp
CaraComp
Forensic-Grade AI Face Recognition for:
Get Started7-day refund guarantee**
biometrics

Synthetic Identity Fraud: How Banks Catch Fake Applicants

Someone Is Building a Fake You — And Your Bank Has 30 Seconds to Stop It
A stylized illustration of a digital identity check, representing how banks detect synthetic identity fraud during account signup.

Somewhere right now, a fake person is applying for a credit card. They have a name, a Social Security number, a date of birth, all real details, pulled from a data breach. The photo ID they're uploading? Generated by AI. The face blinking at the camera to prove it's "live"? A deepfake that cost someone twenty bucks to rent online. And if the bank's front door isn't locked tight enough, that fake person walks right in, and starts building a financial life in someone else's name. The name for this crime is synthetic identity fraud.

TL;DR

Financial apps are adding stricter identity checks at account opening because synthetic identity fraud lets fraudsters manufacture fake-but-convincing identities that pass basic screening, and the scam only becomes visible months later, after real damage is done.

This is the scam before the scam. And most people have no idea synthetic identity fraud exists until their credit score drops, a collections notice arrives, or a lender calls about an account they never opened. Financial platforms like Plaid are now tightening what happens in that first thirty seconds when someone tries to open a new account, because that thirty-second window is, increasingly, the only chance to stop the whole operation before it starts.


Synthetic Identity Fraud: Building a Fake Financial Identity

Here's what makes synthetic identity fraud so maddening: the criminals are patient. They're not smashing and grabbing. They're playing a long game.

CaraComp DailyEP.80
3 stories · 3:14
Starts at 01:13 — this story
3:14

Watch this story, in under a minute

Plays right here · jumps to 01:13
In this episode

A new briefing every weekday — three stories, three minutes.

Subscribe on YouTube

A synthetic identitythink of it as a Frankenstein profile, stitched together from real stolen data and AI-generated details, gets submitted to open a new account. Maybe it passes the basic check. The account sits quietly, building a small history. A credit file gets created. The "person" makes a few small purchases and pays them off. Credit bureaus, seeing consistent data over time, start treating the file as legitimate. Lenders see a real-looking applicant with a real-looking track record.

Then the criminal maxes everything out. Disappears. Leaves behind unpayable balances tied to a person who never existed, and sometimes, to a real person's name or number that got woven into the fake profile without their knowledge. According to research from Feedzai, losses from synthetic identity fraud are on track to hit $23 billion by 2030. That's not a rounding error. That's the GDP of a small country, quietly evaporating. This article is part of a series, start with Retail Facial Recognition Washington Privacy Gap.

1.8B
credentials, usernames, passwords, ID details, were stolen from data breaches and sold in 2025 alone
Source: Proof, The Fraud Files, June 2026

That 1.8 billion number matters because it's the raw material supply chain. Fraudsters aren't guessing your information. They're shopping for it, cheaply, at scale, from massive credential dumps on the dark web (private, hard-to-reach corners of the internet where stolen data gets bought and sold like commodities). The information gets combined with AI-generated faces and documents, and suddenly there's a synthetic identity that looks real because parts of it are.

How Synthetic Identity Fraud Builds a Credit File

Synthetic identity fraud works on a calendar, not a clock. The first application from a synthetic identity is usually rejected, but the inquiry alone can be enough for a bureau to start a file. A second application months later succeeds, and the synthetic identity now has a payment history. Repeat that for a year and the credit reports and credit scores attached to a person who does not exist look entirely ordinary. That slow build is why synthetic identity fraud is called a long con rather than a theft: the fraud is assembled one legitimate-looking record at a time.

Two things make synthetic identity fraud harder to unwind than ordinary identity fraud. First, there is often nobody calling to complain, because the identity is partly invented, no one pulls a credit report for a person who was never born. Second, the unpaid balance lands on the lender, so the loss can be written off as an ordinary credit default and never labelled synthetic identity fraud at all. Organizations that mislabel the loss never learn how much synthetic identity fraud they are actually carrying, which is one reason fraud mitigation budgets are set too low.

  • Fabricated identityevery element is invented, including the name and the supporting information. These fully synthetic identities are the easiest to detect, because nothing in the file matches any real record.
  • Manipulated identitya real, stolen identity with small alterations to the name, address, or date of birth. Much harder to detect, because the underlying data checks out.
  • Compiled identityreal fragments from several different people, glued together with synthetic IDs and AI-generated documents. This is the shape most synthetic identity fraud takes today, and the reason document checks alone fail.

Identity Verification at the Front Door Stops Account Takeover

Most of us think fraud happens when someone breaks into an existing account, your email, your bank login. That's account takeover, and yes, it's a real problem. But new account fraud is different and, in some ways, harder to fight. Once a synthetic identity is inside the system, it starts accruing legitimacy just by existing. Banks and credit bureaus are built to trust accounts with history.

This is why Plaid's research on synthetic identity fraud frames account opening as infrastructure, not just a formality, but the moment when the whole criminal operation either gets stopped or gets a green light to run. Once the fake account is open, the fraud has already succeeded in its first phase.

The front door is also where synthetic identity fraud is cheapest to stop. Every extra week a synthetic identity spends inside the system, it gathers records that make the next check easier to pass: a payment history, a device fingerprint, an address with mail attached to it. Organizations that detect synthetic identity fraud at application are dealing with one bad record; organizations that catch it eighteen months later are unwinding a credit file, several accounts, and a balance nobody will ever repay.

"Detecting synthetic identity fraud is challenging because the fabricated identities can pass standard onboarding checks. Many credit bureaus, if they see consistent data over time, will generate credit files for synthetic identities, which then appear legitimate to lenders and banks." Plaid, Synthetic Identity Fraud Resource

The arms race around synthetic identity fraud has shifted. When banks started requiring photo ID uploads, fraudsters started making better fake IDs. When banks added a live selfie check, asking you to blink or turn your head to prove you're a real human and not a still photo, fraudsters started using deepfakes. According to Proof's June 2026 analysis, deepfake tools capable of fooling a live video check are available online for $10 to $50 per use. The barrier to entry is almost nothing.

So the question becomes: if a bad actor can fake a face AND a document AND manufacture a convincing synthetic identity history, what's actually left to check? Previously in this series: Your Face Their Loophole Court Just Killed The Its Healthcar.


Trusted by Investigators Worldwide
Run Forensic-Grade Comparisons in Seconds
Detailed facial comparison reports. Results in seconds.
Get Started
7-day refund guarantee**

Detecting Deepfakes: How Pattern Recognition Stops Fraud

Here's where it gets interesting. The new approach isn't just checking your face more strictly or your ID more carefully. It's checking patterns across many applications at once, looking for the fingerprints of a synthetic identity fraud operation rather than a single suspicious document.

Think of it this way. One application with an unusual address? Could be anyone. Fifty applications in a week with slightly different names but the same device, the same IP address (your internet location), or the same small cluster of linked phone numbers? That's a manufacturing operation, not a person. ACI Worldwide calls this shared identity risk, the idea that fraud signals need to be read across the whole customer journey, not just at sign-up.

Plaid's updated approach leans heavily on real-time network signals, essentially, what patterns are showing up across multiple institutions simultaneously. If something looks off at one bank, that signal becomes useful context for another bank seeing a similar application minutes later. It's coordinated detection, which makes sense because the fraud itself is coordinated.

What Organizations Should Watch For

Pattern work is how synthetic identity fraud gets caught at scale. No single signal below proves fraud on its own. The point is that synthetic identity fraud produces clusters, and real customers rarely do, so organizations increasingly read these signals together rather than one application at a time.

  • Shared devices and IP addressesdozens of unrelated names applying from one machine is the clearest fingerprint of synthetic identity fraud.
  • Recycled fragmentsthe same phone number, email pattern, or Social Security number showing up across several applications suggests one operator running many synthetic identities.
  • Thin but tidy historiesperfect small payments and none of the messy behaviour of a real financial life is a common signature of a synthetic identity being groomed for a bust-out.
  • Velocitya burst of applications over days rather than months. Fraud rings work in batches; people do not.
  • Mismatch between identity and behaviouran identity claiming a decade of history with no digital footprint older than the application itself.

Why This Matters for You, Specifically

  • Your name is in the supply chainIf your data was in any of the major breaches of the last five years (and statistically, it probably was), your real details may already be for sale as raw material for synthetic identity fraud. You may not know until an account surfaces.
  • 📊 The damage is slow and delayedBust-out fraud (where criminals build fake credit over months before maxing out and vanishing) can take 12-18 months to fully surface. By then, the trail is cold and the losses are real.
  • 🏦 Faster payments = faster fraud windowsAccording to ACAMS, instant payment channels are a top target in 2026 because money moves before anyone can flag a problem.
  • 🔮 The annoying check IS the protectionThat extra step asking you to verify again? It's not random. It's the system trying to detect something slightly off and asking you to resolve it before an account gets created.

The good news, and there actually is some, is that PwC's 2026 fraud trend analysis confirms that risk-based models are getting better at targeting friction. Most legitimate users, people just trying to open a savings account without drama, complete the whole verification process in under 30 seconds. The extra steps are supposed to land on the applications that are actually suspicious, not on you trying to move your direct deposit on a Tuesday morning. (Whether that calibration always works perfectly is a fair question. It doesn't. False positives, getting flagged when you're entirely legitimate, are a real and frustrating cost of this system. Smaller banks with less data to draw on are especially prone to them.)


What You Can Actually Do Right Now

You cannot audit a bank's onboarding stack, but you can make your own identity poor raw material for synthetic identity fraud. The steps below cost nothing and take about twenty minutes.

If you've ever wondered whether a profile, an application, or an identity-based request is really who it claims to be, that instinct is exactly right, and increasingly it's what entire financial systems are being rebuilt around. Up next: Your Face Is Being Scanned At The Grocery Store And Washingt.

Warning Signs on Your Credit Report

Because a synthetic identity often borrows a real Social Security number, the first visible trace of synthetic identity fraud can appear on somebody else's credit report. Read yours line by line at least once a year, and read the ones you can request for dependants too.

  • Accounts, addresses, or employers you do not recognise, the usual residue of a stolen identity fragment being blended into a fake profile.
  • Credit inquiries from lenders you never approached.
  • A child's Social Security number with any credit history attached at all. Minors are prime material for synthetic identity fraud, because nobody checks their credit reports for years.
  • Mail, calls, or notices addressed to a name that is close to yours but not quite right.

One practical step that costs nothing: freeze your credit. A credit freeze (also called a security freeze) tells the three major credit bureaus, Experian, Equifax, and TransUnion, not to let anyone open new credit in your name without your explicit permission. It doesn't hurt your existing credit. It doesn't cost anything. And it makes the first step of synthetic identity fraud, the part where someone tries to establish credit using your real details, dramatically harder. You can lift it temporarily if you need to apply for something yourself, then refreeze it.

That won't stop every variation of this scam, but it closes the door on one of the most common entry points. It's the equivalent of the stronger front door lock that the banks are now building, except this one you control.

Key Takeaway

The identity check you find annoying isn't protecting the bank from you, it's protecting your name from someone who wants to borrow it, spend against it, and leave you holding the mess. The more advanced synthetic identity fraud gets, the more that front-door moment matters. One extra step at account opening beats six months of damage control after the fact.

Financial fraud losses from synthetic identities are growing at roughly 16% per year, per Proof's analysis. The total loss figure is already in the billions. And the tools to manufacture a fake-but-convincing person cost less than a pizza delivery. The banks upgrading their front-door checks right now are not doing it because it's trendy. They're doing it because the alternative, waiting to catch the fraud after the fake account is already open, credit-building, and operational, has proven expensive, slow, and largely ineffective.

The real question isn't whether extra verification is annoying. It's this: the person who just opened a credit account in your name is already twelve months into their patience game. How long before you find out?

Detect Synthetic Identity Fraud Before Accounts Open

The most effective defense against synthetic identity fraud happens before a fake identity ever gets a chance to build history. Banks and fintech companies now deploy machine learning models that detect synthetic identity patterns in real time, flagging applications that show hallmarks of fraud even when the individual documents look real. These systems examine opening accounts across thousands of applications per day, looking for clusters of behavior that suggest a coordinated fraud operation rather than legitimate customers. By catching synthetic identity fraud at the moment of application, financial institutions prevent the long con from ever taking root. The economics are simple: synthetic identity fraud stopped at the front door costs a fraction of synthetic identity fraud discovered after a bust-out.

Prevent Synthetic Identity Theft by Monitoring Mule Accounts

A mule account is a financial account opened and controlled by a fraudster using synthetic identity credentials, often one of many accounts in a larger bust-out scheme. Mule accounts are where synthetic identity fraud converts into cash, which makes them the natural place to look. By monitoring for mule accounts, banks can prevent synthetic identity theft chains before they expand. Fraud detection systems now flag accounts that receive transfers consistent with money laundering patterns, show no legitimate spending behavior, or exist only to move funds quickly. This approach to prevent synthetic accounts represents a shift from looking at individual identity signals to watching how money actually moves through the financial system. Organizations that can prevent synthetic account networks from forming cut losses dramatically.

Identity Fraud Detection Across Multiple Institutions

Entity verification technology enables real-time sharing of fraud signals across banks and lenders. When one institution detects a suspicious identity fraud application, that signal can immediately alert other institutions reviewing applications from the same device, phone number, or email. This collaborative approach to identity fraud detection means that even if a synthetic identity passes one bank's checks, coordinated fraud intelligence across the system can catch it before it opens multiple accounts. The result: synthetic identities have far fewer opportunities to establish legitimacy across the financial network. With better fraud intelligence flowing between organizations, identity fraud that would once take months to surface now gets caught in days or hours, and synthetic identity fraud loses the one advantage it depends on, time.

Questions People Ask About Fake Applicants

How is synthetic identity fraud different from ordinary identity theft? Classic identity theft impersonates you with your whole identity. Synthetic identity fraud takes one fragment, usually a Social Security number, and builds a new person around it, so the account never carries your name and may never reach your credit report at all. Fraud detection teams treat the two categories differently because the evidence trail differs: ordinary identity theft has a real victim filing a police report, while synthetic identity fraud often has no victim to complain until a lender calls about an unfamiliar account.

Why is synthetic identity fraud so hard to detect? Because most of the underlying data is genuine. As Plaid notes, fabricated identities can pass standard onboarding checks, and bureaus will generate files for synthetic identities that then look legitimate to lenders. There is no single false field to catch, only patterns across many applications, which is why fraud intelligence sharing between institutions has become the strongest available defense against synthetic identity fraud.

Who actually pays for synthetic identity fraud? Mostly lenders, in written-off balances; Feedzai puts the trajectory at $23 billion by 2030. Consumers pay in a different currency, disputed accounts, damaged credit scores, and months of proving a negative when a stolen identity fragment was used to build the profile. Credit card issuers absorb much of this synthetic identity fraud loss directly, which is part of why credit approval checks have grown stricter for everyone, not just applicants who look suspicious.

Can a credit freeze stop synthetic identity fraud? It blocks the common version that needs a real Social Security number to open a new line of credit. It cannot stop a fully fabricated file built on numbers never issued to anyone, which is why entity verification and shared fraud intelligence between organizations still matter. A credit freeze is one layer, not a complete answer to synthetic identity fraud on its own.

Detect Synthetic Patterns Before They Become Credit Files

Detect synthetic activity early and the entire economics of the crime change. When a financial institution can detect synthetic identity signals at the application stage, the fraudster loses the months of patient history-building that make the scheme work in the first place. This is why so much fraud detection investment has moved toward the first sixty seconds of an application rather than the months that follow it.

Prevent Synthetic Identity Fraud With Layered Verification

No single check can prevent synthetic identity fraud on its own, which is why banks stack several imperfect checks together. Document verification catches crude fakes, biometric liveness checks catch simple deepfakes, and network-level pattern analysis catches the coordinated operations that slip past both. Together, these layers prevent synthetic identity fraud from having any single point of failure a fraud ring can reliably exploit.

How Stolen Identity Fragments Become Synthetic IDs

A stolen identity fragment, a Social Security number, a name, a date of birth, is raw material, not a finished product. Fraudsters combine several stolen identity fragments with invented details to produce synthetic IDs that pass a first glance but do not correspond to any real, whole person. Understanding this assembly process is what allows fraud teams to build detection rules that look for the seams between real and invented data.

Fraud Intelligence Sharing Closes the Detection Gap

Fraud intelligence sharing means banks, lenders, and credit bureaus pool anonymized signals about suspicious applications instead of each institution fighting synthetic identity fraud alone. Because a single synthetic identity often applies to several institutions in a short window, shared fraud intelligence turns a pattern invisible to any one bank into a pattern obvious across the network. This is one of the few defenses that scales as fast as the fraud itself does.

Data Quality Determines Fraud Detection Accuracy

Fraud detection models are only as good as the data feeding them. Organizations with rich, well-labeled data on past synthetic identity fraud cases catch new attempts faster than organizations relying on thin or outdated records. This is why larger banks with more historical data generally outperform smaller institutions at flagging synthetic identity fraud, even when both use similar detection technology.

Payments Speed Cuts Both Ways

Faster payments make life easier for real customers and easier for fraudsters running synthetic identity fraud schemes, because money moves before a suspicious pattern can be confirmed. Organizations that speed up payments without also speeding up fraud detection are widening the exact window that synthetic identity fraud depends on to convert a fake account into cash.

Why Synthetic Identity Fraud Targets Credit, Not Cash

Synthetic identity fraud almost always aims at credit products rather than cash accounts, because credit is what a fake person can build without ever showing up in person. A synthetic identity applies for a card, a small loan, or a retail credit line, and each approval adds another data point that makes the next application look more credible. Credit reports are the scoreboard this fraud is built to win, which is why every layer of synthetic identity fraud defense eventually runs through the same three bureaus.

This also explains why synthetic identity fraud losses concentrate so heavily among credit issuers rather than being spread evenly across the financial system. A bank holding a checking account has less exposure than a lender extending revolving credit to an identity with a thin but tidy file. Financial institutions that issue credit are, in effect, underwriting the risk of an identity that was never real to begin with.

The Role of Stolen Data in Manufacturing Synthetic Identities

Every synthetic identity starts with stolen data, a name, a birth date, or most often a Social Security number pulled from a breach and sold in bulk. Fraudsters treat this stolen data as raw inventory, mixing genuine fragments from several breaches with invented details to keep any single data point from looking obviously fake. The more stolen data circulating from large breaches, the cheaper and more convincing synthetic identities become, which is why breach volume and synthetic identity fraud volume tend to rise together.

Financial institutions cannot stop breaches at other companies, but they can treat certain data patterns as a warning sign rather than proof of identity. A Social Security number that has never been tied to a credit file before, paired with a brand-new address and a brand-new phone number, is exactly the kind of thin, freshly assembled data profile that stolen-data-driven synthetic identity fraud produces.

Financial Institutions Carry Uneven Synthetic Identity Fraud Risk

Not every financial institution faces the same exposure to synthetic identity fraud. Lenders that approve credit quickly, with less manual review, tend to attract more synthetic identity applications simply because the fraud succeeds more often there. Financial institutions that rely heavily on automated approval without network-level pattern checks are, often unknowingly, the path of least resistance for a fraud ring testing where its synthetic identities will pass.

This uneven risk is part of why fraud intelligence sharing matters so much: a financial institution with strong detection can still get hit if a partner institution with weaker checks approves the same synthetic identity first, handing it a credit history that makes it look legitimate everywhere else. Risk, in this sense, is only as strong as the weakest financial institution in the shared credit reporting system.

Frequently asked questions

What is synthetic identity fraud?

Synthetic identity fraud is a scam where criminals build a fake person using real stolen details, like a name, Social Security number, and date of birth pulled from a data breach, combined with an AI-generated photo ID and even a deepfake video to pass liveness checks. This fabricated identity then applies for accounts like credit cards.

Why is synthetic identity fraud hard to detect?

Fraudsters behind synthetic identity fraud are patient and play a long game rather than smashing and grabbing quickly. Most people have no idea it exists until their credit score drops, a collections notice arrives, or a lender calls about an account they never opened, meaning damage is usually visible only months later.

How are banks trying to stop synthetic identity fraud?

Financial platforms like Plaid are tightening identity checks during the first thirty seconds when someone tries to open a new account, since that window is increasingly the only chance to stop the operation before it starts. This front-door verification aims to catch fake applicants before they can build a financial life in someone else's name.

Ready for forensic-grade facial comparison?

Full forensic reports with detailed similarity scoring. Results in seconds.

Run My First Search