Synthetic identity fraud is on the rise with generative AI, forcing companies to strengthen the onboarding process.
Synthetic identity fraud involves creating a person who does not exist by combining real and fabricated data, with the aim of opening accounts, obtaining credit, and moving money. It is a type of fraud that is difficult to quantify. Unlike identity theft, there is usually no individual who detects the deception and reports it, and when the identity stops making payments, the institution tends to record the loss as just another default, without identifying it as fraud.
Generative AI has added a new layer of complexity, as it makes it possible to create convincing faces and documents that these identities can use to attempt to bypass the document and biometric checks carried out during digital onboarding.
Understanding how a fabricated identity is constructed, the stages through which it evolves, and the points at which it can be detected—from account opening through the life of the account—allows fraud and risk teams to determine where to strengthen their controls.
What Is Synthetic Identity Fraud?
Synthetic identity fraud involves combining real personal data, such as a genuine identification number, with fabricated data, such as a name, address, or photograph. The result is a new identity with a legitimate appearance, which is used to obtain credit or channel funds.
By design, a synthetic identity is created to bypass the KYC verification process. Some of its data exists in official records, the fabricated information is consistent with the rest of the identity, and, over time, the profile builds up a track record of behavior similar to that of a legitimate customer. It is often confused with a false identity, which is built entirely from fabricated data or documents created from scratch. The distinction matters because the presence of real data is precisely what allows a synthetic identity to pass checks that cross-reference information against external sources.
Synthetic Identity vs. Identity Impersonation
While identity theft uses a real person’s data to impersonate them, synthetic identity fraud creates someone who has never existed. This difference determines who detects the fraud and how long it takes to uncover it.
| Criterion | Identity theft | Synthetic identity |
|---|---|---|
| Victim | A real person whose identity is used, who usually notices the misuse | The owner of the real data rarely notices. The institution absorbs the loss |
| Data used | A real person’s complete data | A mix of real and fabricated data |
| Who detects it | Usually the victim, on spotting transactions or debts they don’t recognize | The institution, when the customer disappears after maxing out their credit |
| Time to detection | Usually short, because the victim reports it | Can stretch over months, and is sometimes never identified as fraud |
| Impact | Losses for the victim and claims against the institution | Losses booked as credit defaults, which make the true scale of fraud hard to measure |
The absence of someone coming forward to report the fraud in time helps explain why synthetic identity fraud is so difficult to quantify. When these losses are written off as bad debt, the accounts are treated as though they belonged to legitimate customers who stopped making payments, and they are often never reclassified as fraud.
The difference can be seen in a recent case in Mexico. A lawyer discovered that an auto loan of more than one million pesos had been taken out in his name when his bank notified him of an outstanding payment he did not recognize. In cases of identity impersonation, the real person ultimately receives the debt and raises the alarm. With a synthetic identity, notifications are sent to contact details controlled by the fraudster, and no one raises a complaint until the institution identifies the default. This selection of real-world identity fraud cases includes this and other documented examples of identity impersonation.
The Life Cycle of a Synthetic Identity
A synthetic identity is rarely used on the day it is created. Its value to the person controlling it increases over time, which is why its life cycle is typically described in four stages.
1. Identity Construction
The starting point is a piece of data that is valid in official records, typically an identification number. This is combined with a name, date of birth, address, phone number, and email address created for the occasion and, increasingly, an AI-generated photograph. Because it is assembled from pieces of different origins, this practice is also known as Frankenstein fraud.
2. Credit History Maturation
Once the identity has been created, low-risk products such as a bank account, a card with a low credit limit, or a small loan are opened and used responsibly. In markets with credit bureaus, even a rejected application can leave a record and establish the credit file. For months, the identity makes payments on time, increases its credit limits, and builds a profile that scoring models interpret as that of a reliable customer.
3. Bust-Out Fraud
Bust-out fraud, or the abrupt exit, occurs when the identity, after reaching high credit limits, maxes out all of its credit lines at once and stops making payments. Since there are no prior indications of fraud, the institution records the loss as another default and manages it as a credit risk.
4. Money Laundering and Fund Extraction
The funds obtained must leave the financial system without leaving a trace leading back to those who control them. To achieve this, accounts opened under other identities—synthetic or stolen—are used as mule accounts to move and fragment the funds before they are withdrawn. The synthetic identities behind mule accounts link this type of fraud to broader money laundering networks, turning what initially appears to be a credit loss issue into an AML compliance risk.
How Generative AI Multiplies Synthetic Identities
For years, document and biometric verification during onboarding placed a limit on synthetic fraud, because creating a convincing document and presenting oneself in front of a camera required time and skill. Generative AI has reduced that cost, making it possible to create credible synthetic identities more quickly and automate fraudulent applications at scale.
Institutions are beginning to recognize the issue, although official statistics still do not adequately capture the phenomenon. In the United Kingdom, the Home Office launched a public consultation on unauthorised fraud in July 2026, warning that criminals are turning to stolen or synthetic identities to bypass institutional defenses, and identifying them, alongside forged official documents, as tactics being enhanced by AI. The document itself acknowledges that the available evidence is still insufficient to reliably determine the scale of the problem.
The change affects three components of digital onboarding. AI-generated faces provide a consistent document photo and selfie for a person who does not exist. Fabricated documents reproduce official formats with a level of quality that makes manual review more difficult. Deepfakes in identity verification can also animate that face during a video identification. FinCEN, the United States financial intelligence unit, issued an alert in November 2024 on schemes using this type of content to open accounts with financial institutions.
These three elements are compounded by injection attacks, in which synthetic content is introduced directly into the capture flow without passing through the device’s camera. A control that only analyzes the image it receives cannot determine whether it originated from a real sensor, which is why protection against injection attacks has become a necessary capability for digital onboarding.
Note: the term “synthetic identities” is also used to describe artificially generated faces used to train facial recognition systems. That use is covered in the article on synthetic data in facial recognition.
How to Detect Synthetic Identity Fraud: Warning Signs
A single warning sign rarely confirms a synthetic identity. Detection depends on combining the indicators observed during onboarding with what happens afterward throughout the life of the account.
During Onboarding: Identity Signals
- A credit file with no prior history, or one whose age doesn’t match the applicant’s stated age.
- A phone number, email or address that was created recently or is shared with other applications.
- An ID document that doesn’t biometrically match the selfie, or that shows signs of digital tampering.
- A selfie or video that fails the liveness check or shows signs of having been generated or altered with AI.
- A capture coming from an emulator, a virtual camera or a rooted or jailbroken device.
- A single device linked to several applications under different identities.
After Onboarding: Behavioral Signals
- App interaction that doesn’t fit human patterns, such as uniform typing cadence or automated navigation.
- Rapid credit limit increases and requests for new products without usage that justifies them.
- Accounts linked by device, address or beneficiary that form a network.
- Funds received and immediately forwarded.
Behavioral biometrics analyzes how a person interacts with an application and helps distinguish a legitimate user from an automated bot or an attacker.
How to Prevent Synthetic Identity Fraud with Connected Capabilities
Stopping a synthetic identity requires action at multiple points throughout the customer relationship, because the signals that reveal it emerge at different stages. The World Economic Forum, in its 2026 report on deepfakes and digital identity verification, concludes that maintaining trust in identity verification requires adaptive defenses that continuously improve and are capable of combining different identity signals.
Regulation is also beginning to move in this direction. In Colombia, Law 2573 of 2026, which will come into force in November, requires financial and credit institutions, telecommunications operators, and businesses that extend credit to adopt sufficient and reasonable digital security measures to verify individuals’ identities. Although the regulation focuses on identity impersonation, its requirements apply to the same point at which a synthetic identity can be stopped: onboarding, as detailed in this analysis of Colombia’s Law 2573 on identity impersonation. When verification capabilities work together in a coordinated manner, detection can take place at the application stage, before the identity has had time to mature.
1. Verify Document and Face During Onboarding
Identity verification confirms that the document is authentic and belongs to the person presenting it by comparing the document photo with a selfie using facial biometrics. A synthetic identity may have consistent data, but it still needs a face. At this point, digital onboarding with biometrics provides a check that does not rely on external data sources.
2. Confirm Liveness and Block Injection Attacks
Facial comparison is only meaningful if the image comes from a real person who is physically present. Liveness detection analyzes the capture to rule out photographs, videos, masks, or generated faces. Injection detection, in turn, verifies that the signal originates from the device’s physical camera. A benchmark when evaluating these technologies is compliance with ISO/IEC 30107-3, as demonstrated by iBeta Level 1 and Level 2 evaluations.
3. Maintain Continuous Verification Throughout the Life of the Account
A synthetic identity that passes onboarding still needs to operate for months before the bust-out, and this maturation phase provides a window for detection. Reverification at risk events, such as a credit limit increase, a device change, or an unusual transfer, combined with behavioral intelligence in every session, makes it possible to identify inconsistencies that were not visible during onboarding.
4. Detect Mule Accounts Before the Bust-Out
Synthetic identities rarely operate in isolation. Mule account detection involves analyzing relationships between accounts, such as patterns of receiving and forwarding funds or newly created accounts that interact with others already flagged, to identify networks before the money leaves the system.
5. Connect Signals on a Single Platform
Each capability generates useful signals on its own, but the pattern of a synthetic identity often emerges when those signals are cross-referenced: a valid document, a device previously used in another application, and an unusual increase in credit limits. When these signals reside in separate tools, it is difficult to see the full picture. Identity fraud prevention solutions that connect identity, behavior, and transactions on a single platform enable context-based decision-making, both at the application stage and throughout the customer relationship.
Sectors Most Exposed
Synthetic identity fraud is concentrated in sectors where a new identity can obtain credit or move money quickly. Retail banking is a natural target, given the volume of digital onboarding and the range of products a single identity can accumulate. In this sector, identity verification for banks is the first line of defense.
Consumer credit and credit cards offer limits that increase with good behavior, which is precisely the pattern exploited by bust-out fraud. Fintechs and neobanks, with fully digital onboarding processes, and buy now, pay later (BNPL) services, with near-instant credit decisions, leave less room to review each application. Telecommunications operators complete the picture, because a mobile line registered to a synthetic identity provides a verifiable contact detail.
It involves creating a person who does not exist by combining real and fabricated data to open accounts and obtain credit. It is difficult to detect because the individual whose real data is used rarely discovers the fraud, and the institution typically records the loss as a default.
Identity impersonation uses the identity of a real person, while synthetic identity fraud creates a new one. Because there is no victim to raise the alarm in time, the accounts can mature for months before the bust-out.
Because some of the data is real and passes checks against external sources, while the identity’s history is built over time. Generative AI adds convincing faces and documents that make onboarding reviews more difficult.
Tools that confirm that a real person who is physically present matches the document through document verification, facial biometrics, liveness detection, and protection against injection attacks, combined with device and behavioral signals.
By using connected capabilities that verify identity during onboarding, reverify it at risk events, analyze behavior, detect mule accounts, and bring all signals together on a single platform.