Synthetic Identity Fraud: How a Customer Who Never Existed Passes Every Check
Sigilith Research
Institutional AI governance & accountability
A note on scope. This is an explainer about a fraud family, written from public government and industry sources. Every figure in it is an estimate, attributed to whoever made it, and the difficulty of measuring this crime is part of the story. Defenses are described at the level the Federal Reserve and the standards community publish them: families of controls, not any production system's mechanics, including our own.
The short version
-
The identity is manufactured, not stolen. Traditional identity theft impersonates a real person, who eventually notices and complains. A synthetic identity pairs a real Social Security number, often a child's, with an invented name and birth date. There is no owner to notice anything, which is why so much of this fraud is never even counted as fraud.
-
The credit system helps build it. The first application a synthetic identity files is designed to fail. The rejection itself causes a credit bureau file to come into existence, and from that moment the identity has the one thing every later check will ask for: a paper trail.
-
Document and data checks read the paper trail. They can confirm that records exist, that they are internally consistent, and that a name, number, and birth date match a government database. None of that establishes that one real, live human being stands behind the application. That gap is the entire business model.
1. What is synthetic identity fraud?
For years the industry could not even agree on what to call the problem, so in 2021 a Federal Reserve-convened focus group of fraud experts settled a common definition: synthetic identity fraud is "the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain." The Government Accountability Office, which had convened its own expert forum in 2017, describes the same crime: perpetrators combine real and fictitious information, such as Social Security numbers and names, to create identities used to defraud financial institutions, government agencies, or individuals.
The construction gives the crime its nickname. A typical synthetic identity takes one primary element that will survive a database lookup, most often a genuine SSN, and stitches it to fabricated everything else: name, date of birth, address, phone, email. The industry calls the result a Frankenstein identity, assembled from parts of the real and the invented, and the term is now common enough that Experian uses it in its own consumer guidance. Some variants are also described as synthetic identity theft, because a real person's number is caught up in the fabrication even though no complete person was impersonated.
The scale is genuinely difficult to state, and honest sources say so. The Federal Reserve's Payments Fraud Insights series opens with the claim, taken from McKinsey's 2019 analysis, that synthetic identity fraud is the fastest-growing type of financial crime in the United States, and immediately cautions that the figures around it are estimates, because inconsistent definitions and detection make the crime hard to measure. The estimates that exist are substantial: Auriemma Group put the direct cost to US lenders at $6 billion in 2016, with an average charge-off balance above $15,000 per instance, accounting for up to 20 percent of all credit losses that year. An industry estimate from FiVerity, cited by the Federal Reserve when it released its mitigation toolkit in 2022, put losses to US financial institutions at $20 billion in 2020. And identity exploitation in general dwarfs even that: FinCEN's January 2024 Financial Trend Analysis found that roughly 1.6 million Bank Secrecy Act reports filed in 2021, about 42 percent of everything filed that year, were identity-related, flagging $212 billion in suspicious activity.
Treat the specific numbers as ranging shots rather than measurements. The structural fact underneath them is not in dispute, and it is the subject of the rest of this piece: this fraud grows because the checks meant to stop it examine records, and the fraud manufactures records.
2. How a Frankenstein identity gets a credit file
Start with the raw material. On June 25, 2011, the Social Security Administration began assigning SSNs randomly, ending the era in which the first three digits encoded where a number was issued. Randomization protected the integrity of the numbering scheme, but it had a side effect the Federal Reserve's white paper spells out: geographic consistency checks stopped working for newly issued numbers, and it became harder to tell a legitimately issued SSN from an unissued or fabricated one. ID Analytics estimated that nearly 40 percent of synthetic identities use a randomized SSN.
The most valuable numbers belong to people who will not look. Children, the elderly, and the homeless rarely check their credit, which is why the Federal Reserve identifies them as the typical owners of the real SSNs inside synthetic identities. Javelin Strategy & Research estimated that more than one million children were victims of identity fraud in 2017; the figure is not specific to synthetic fraud, but it indicates the exposure of a population whose credit files should be empty and silent for a decade or more. A synthetic identity built on a child's number can operate, mature, and default years before its owner turns 18 and discovers, applying for a first student loan, that their number has a history.
Then comes the step that separates this crime from everything else in the fraud taxonomy. The fraudster applies for credit. The lender queries a credit bureau, the bureau reports that no history exists, and the application is declined, exactly as the system intends. But the inquiry itself causes the bureau to create a file for the identity. The Federal Reserve's detection paper is explicit about the consequence: the bureau creates a credit profile for the synthetic identity, and that profile "helps legitimize its identity even when credit is denied." The rejection was not a failure. It was the point. A person who never existed now exists in the data that every subsequent lender will consult.
The file showsA credit inquiry, and then a file. The bureau now holds a record for this identity.
The truthNo such person exists. The application was built to be declined; the Federal Reserve notes the resulting profile helps legitimize the identity even though credit was denied. The rejection was the point.
Lifecycle and statistics are drawn from the Federal Reserve’s Payments Fraud Insights white papers (2019–2020), which describe the mechanism at the level published here and attribute the estimates quoted. The reading that matters: the paper trail improves at every stage, the truth never changes, and every standard check consults the paper trail.
From there the identity is cultivated like an asset, because it is one. Repeated applications eventually find a high-risk lender willing to extend a small line. Progress can be bought outright through piggybacking: paying an existing account holder to add the synthetic identity as an authorized user, so that a stranger's years of on-time payments flow into the synthetic file overnight. The Federal Reserve's fraud analyses describe piggybacking as a way fraudsters can accelerate the process of building good credit for a synthetic identity. The identity then behaves impeccably, small purchases and punctual payments over months or years, while limits rise. The Federal Reserve's papers call these sleeper accounts, and cite a TransUnion estimate that the average charge-off rate for likely synthetic identities in a lending portfolio is under 30 percent at any given time, meaning roughly 70 percent of suspected synthetics are, at this moment, model customers.
The end state is the bust-out: every line drawn to its maximum, and then silence. The Federal Reserve notes the payout can even be doubled, by paying balances down with bad checks and drawing the lines again before the checks bounce. There is no borrower to pursue, because there never was one.
One case shows the mechanism at industrial scale. In February 2013, federal prosecutors in New Jersey charged 18 people over a scheme that, according to the charging documents, fabricated more than 7,000 identities, obtained more than 25,000 credit cards, maintained over 1,800 drop addresses, and inflated credit scores by feeding false payment histories to the bureaus through sham companies, with confirmed losses above $200 million. Those figures come from the government's complaint, which is an accusation; the Federal Reserve's account of the case notes that most defendants ultimately pleaded guilty, while a few indictments were dismissed. The detail worth keeping is not the total but the method: the ring did not defeat the credit reporting system. It operated the credit reporting system, patiently, as designed.
3. Why traditional KYC misses an identity that exists on paper
Know Your Customer programs were built against a different adversary. Their record against synthetic identities is poor for three structural reasons, and none of them is carelessness.
There is no victim to raise the alarm. Traditional identity theft announces itself: the real person disputes charges, and the fraud is detected and reported quickly. The GAO's expert forum identified the absence of that mechanism as the defining detection problem here. Nobody disputes a synthetic identity's debts. When the account defaults, the loss is routinely booked as a credit loss, an ordinary bad debt, and the Federal Reserve notes that institutions often decline to spend money investigating a delinquency that looks like a lending mistake rather than a crime. The fraud is not merely unpunished; it is uncounted, which is why every aggregate statistic in section 1 carries a hedge.
The identity is real, on paper. By the time a matured synthetic identity reaches a serious lender, it does not resemble a fake. It has an aged bureau file, tradelines, a plausible score, a deliverable address, a phone that answers. The Federal Reserve states plainly that these identities "often pass Know Your Customer (KYC) requirements," and cites an ID Analytics study finding that fraud models built to catch traditional identity fraud failed to flag 85 to 95 percent of likely synthetic identity applicants. The models are not broken. They are looking for the signature of a stolen life, an inconsistency between applicant and history, and a synthetic identity has no inconsistency because the history was grown for the application.
Each check validates a record, not a person. This is the deepest of the three, and it survives even good tooling. Consider the strongest data check available: the Social Security Administration's electronic Consent Based SSN Verification service (eCBSV), mandated by Section 215 of the Economic Growth, Regulatory Relief, and Consumer Protection Act and first rolled out in June 2020. With the consumer's consent, a permitted financial institution can ask whether a name, SSN, and date of birth combination matches SSA records, and receive a yes or no in real time. This genuinely closes the door the 2013 ring walked through, an unissued number with no owner to object. But read what the answer asserts: the combination matches. It does not assert that the person presenting the combination is its owner, or that any person is present at all. FinCEN's 2024 analysis makes the same structural point across the whole identity lifecycle, sorting exploitation into impersonation of another identity (69 percent of identity-related filings), use of compromised credentials (18 percent), and outright circumvention of weak verification (13 percent). Validation, verification, and authentication each examine artifacts: documents, database rows, credentials. An applicant who controls the artifacts passes.
- 01Confirms
Credit bureau history“Does this identity have a track record?”
A file exists, with age, tradelines, and a score consistent with the application in front of you.
- 02Confirms
SSA record match (eCBSV)“Are the name, SSN, and birth date genuine?”
With consent, the Social Security Administration answers yes or no: this exact combination matches its records.
- 03Confirms
Document verification“Is the ID document authentic?”
The document is well-formed: fonts, security features, and machine-readable data all internally consistent.
- 04Confirms
Address, phone, and email checks“Can this identity be reached?”
The address is deliverable, the phone answers, the email account has age and activity.
- 05Confirms
Watchlist and sanctions screening“Is this identity known to be bad?”
The name appears on no list, matches no alert, carries no derogatory record.
Check families and their limits are drawn from public sources: the Federal Reserve’s toolkit and white papers, the SSA’s published description of eCBSV, and FinCEN’s 2024 identity analysis. Flip the question: 5 of 5 checks answer it. Every row interrogates records about an identity; whether one live human stands behind the file is a different instrument’s job.
Stated once, cleanly: document and data checks establish that an identity's paper trail is in order. A synthetic identity is a paper trail in order. The one question the entire stack never asks is whether one real, live human being stands behind the file, and that is the only question the fraud cannot survive.
4. Credit washing: fraud aimed at the record itself
If section 2 described manufacturing a clean file, there is a companion crime for dirtying ones that already exist: credit washing. TransUnion defines it as removing legitimate, accurate, and non-obsolete credit data from credit profiles, and the mechanics run through a consumer protection built for real victims. Under section 605B of the Fair Credit Reporting Act, a credit bureau must block information a consumer identifies as resulting from identity theft within four business days of receiving an identity theft report and proof of identity. The provision exists because genuine victims should not carry a thief's debts. Credit washing abuses it: accurate, negative tradelines are disputed as identity theft, and while the claim is processed the debt vanishes from the file and the score rises.
The abuse is documented at both ends. In May 2022 the FTC moved to shut down a credit repair operation called The Credit Game, alleging among other things that it filed thousands of false identity theft reports with the FTC on behalf of clients to strip accurate negative information from their files; knowingly filing a false report is itself unlawful. On the receiving end, TransUnion reported in late 2025 that consumer-initiated suppressions of charged-off accounts had grown nearly 700 percent in two years, that roughly 5 percent of US consumers had charged-off accounts suppressed for atypical reasons in 2025, and that approximately $10 billion in debt would be erased from credit files by year's end.
Credit washing matters to this explainer for two reasons. First, it is the same attack surface: lenders trust the bureau file, so the profitable move is to edit the file, whether by growing a synthetic one or laundering a real one. Second, the two crimes meet. The Federal Reserve's white paper notes that bust-out fraudsters may simply claim identity theft on the way out, disputing the synthetic identity's own debts to reset the asset instead of abandoning it. The record, in other words, is not merely unreliable evidence of a person. It is writable, by the adversary, through channels built for the adversary's victims.
5. What actually detects synthetic identity fraud
The public playbook, published across the Federal Reserve's white papers and its Synthetic Identity Fraud Mitigation Toolkit, is layered, and the layers group into three ideas.
Correlation across applications and accounts. No single indicator identifies a synthetic identity; the toolkit is explicit that combinations tell. The signals live between records rather than inside them: the same SSN under different names, dozens of authorized users with no shared surname or city on one account, one address or device or digital footprint serving many applicants, a file whose depth is implausible for its owner's age. Link analysis of this kind is how the sleeper portfolio in section 2 stops looking like thousands of unrelated model customers and starts looking like one organism. It is also, not incidentally, an argument for institutions sharing more than they do; the Federal Reserve's summary is that no single organization can stop synthetic identity fraud on its own.
Live presence verification. The paper trail gap closes only from outside the paper. A liveness check asks the question the data stack cannot: is a real, live human present at capture time, once, for this application. We have written a full explainer on how that field works and how it is measured, and the family-level point carries over directly: a fabricated identity can accumulate any quantity of consistent records, but it cannot supply a living person on demand, and the same few people fronting for many identities is precisely the correlation signal the previous layer feeds on. Mobile money operators face the same arithmetic at their own perimeter, where enrollment fraud mints the mule accounts that every later scam drains into. Presence checks do not replace document and data validation; they answer a different question, and it is the question synthetic identities are built to avoid.
Human review of ambiguity, on the record. Every layer above emits probabilities, and somewhere between the clear pass and the clear fraud is a band of applicants who are merely unusual: thin-file immigrants, young people, the recently bankrupt, exactly the populations that automated caution excludes at the highest human cost. The defensible pattern is the one we have argued for in the context of AI decision records: ambiguity escalates to a person with authority, the evidence is assembled in front of them, and the resolution is recorded so that the institution can later account for who decided, on what basis, and when. A declined application is an adverse action against someone who may well be real; an approval is a potential decade-long loss. Both deserve a decider and a durable record of the decision.
Our own entry in this field is Sigilith Sentry, and consistent with the scope note at the top, we will say here only what we say publicly: one capture, an active light challenge, server-side analysis, escalation of ambiguous sessions to a named human officer, and a sealed, tamper-evident record of every verdict. It establishes presence, not identity, which is exactly the division of labor this article describes: the paper trail tells you an identity has a history; presence tells you somebody is actually there.
The synthetic identity is sometimes described as a victimless crime. The description fails on contact with the record: the child whose number carries a stranger's defaults, the lenders absorbing billions in losses booked as bad luck, and every honest thin-file applicant treated with suspicion because the system cannot tell them apart from an invention. The fraud thrives in the gap between records and people. Institutions close it by asking, at least once per customer, a question no file can answer.
Sources
Federal Reserve
- Federal Reserve, Synthetic Identity Fraud in the U.S. Payment System: A Review of Causes and Contributing Factors, Payments Fraud Insights, July 2019
- Federal Reserve, Detecting Synthetic Identity Fraud in the U.S. Payment System, Payments Fraud Insights, October 2019
- Federal Reserve, Mitigating Synthetic Identity Fraud in the U.S. Payment System, Payments Fraud Insights, July 2020
- FedPayments Improvement, Synthetic Identity Fraud Defined: the industry-recommended definition, 2021
- FedPayments Improvement, Federal Reserve Releases Synthetic Identity Fraud Mitigation Toolkit, 2022, and toolkit modules on detection and validation
Government
- U.S. Government Accountability Office, GAO-17-708SP: Highlights of a Forum: Combating Synthetic Identity Fraud, July 2017
- FinCEN, Financial Trend Analysis: Identity-Related Suspicious Activity: 2021 Threats and Trends, January 2024, and the accompanying news release
- Social Security Administration, electronic Consent Based SSN Verification (eCBSV)
- Social Security Administration Office of the Inspector General, Eighteen People Charged in International $200 Million Credit Card Fraud Scam, 5 February 2013
- Federal Trade Commission, FTC Acts to Shut Down 'The Credit Game', May 2022
- Fair Credit Reporting Act, 15 U.S.C. § 1681c-2 (FCRA § 605B): Block of information resulting from identity theft (Cornell LII)
Industry
- TransUnion, TransUnion Responds to Growing Challenge of Credit Washing, 13 November 2025
- Experian, Synthetic Identity Fraud: The Frankenstein of Identity Theft
- ABA Banking Journal, Report: Synthetic identity fraud results in $20 billion in losses in 2020, October 2021, reporting the FiVerity estimate
Related Sigilith analysis
Also Applicable To