What synthetic identity fraud is, how fake identities are built, how big it is, why crypto exchanges are targets, and the signals and checks that stop it.

Synthetic identity fraud is the creation of a fake person from a mix of real and invented personal data, such as a genuine Social Security number paired with a made-up name and date of birth, which is then used to open accounts, build credit and steal. Unlike ordinary identity theft, there is no single victim whose whole identity is taken, which is why it often goes undetected until the money is gone.
This guide explains how synthetic identities are built, how big the problem is, why crypto exchanges are exposed, which signals give synthetics away, and which defences work. It is written for compliance teams and for anyone wondering why an exchange asks for a live selfie on top of an ID.
In 2021 a Federal Reserve focus group of 12 fraud experts agreed an industry definition: synthetic identity fraud is "the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain" (Federal Reserve, definition overview). FinCEN uses a similar description: a combination of real and fake personal information used "to fabricate a person or entity to pass validation processes" (FinCEN alert FIN-2024-Alert004).
The difference from traditional identity theft matters:
A Boston Fed podcast summed it up as "the Frankenstein of identity fraud": pieces taken from several people and stitched into one fake person (Boston Fed, 31 March 2025).
The Federal Reserve splits the ingredients into two groups. Primary elements are those that, in combination, are usually unique to a person: name, date of birth, Social Security number or another government identifier such as a passport or tax number. Secondary elements make an identity look more real but cannot establish it alone: a mailing address, email address, phone number and digital footprint such as device ID or IP address.
A typical US scheme follows the pattern the Fed described when it published its 2019 white paper, with detail from the Boston Fed interview:
Social Security number randomisation made one old check less useful. Since 25 June 2011 the first three digits no longer reflect the state where the number was issued (Social Security Administration), and the old "high group" list used to validate numbers lost its significance.
Generative AI adds the finishing touches. FinCEN reported in November 2024 that criminals have combined AI-generated images with stolen or entirely fake personal data to create synthetic identities, and have used AI to alter or generate the images on driver's licences and passports.
Synthetic fraud is hard to measure because much of it is written off as ordinary bad debt. The available figures are estimates, so treat them as orders of magnitude:
Synthetic fraud is sometimes described as victimless. It is not. The person whose Social Security number was used can find the fraud tied to their number when they apply for credit, and the Fed's 2019 paper notes knock-on effects such as denied disability benefits, rejected tax returns and errors in health records.
Some groups are targeted because their numbers sit unused for years. The Boston Fed interview names three: children, whose numbers may go unused for 14 or 15 years; older people, who rarely apply for new credit; and people in prison, who cannot see that their number is being used. Lenders and card issuers carry the direct losses.
Crypto platforms onboard customers remotely, often within minutes, and crypto transfers are hard to reverse. That combination makes an exchange account useful to a fraud ring in several ways:
Outside the US there is no Social Security number to borrow, so the same idea usually shows up as a fabricated or AI-generated document attached to a mix of real and invented data. The EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, which applies from 10 July 2027, requires identity to be verified through an identity document plus, where relevant, information from reliable and independent sources, or through an eIDAS electronic identification at assurance level substantial or high (Article 22(6)).
No single signal proves fraud, and FinCEN stresses that the full circumstances matter. These are the patterns most often cited, drawn from FinCEN's red flags and the Fed's guidance:
FinCEN asks US financial institutions to include the key term "FIN-2024-DEEPFAKEFRAUD" in suspicious activity reports linked to these schemes. For transaction-level patterns, see our guide to AML red flags in crypto.
Synthetics are built to pass one check at a time, so the answer is layering checks that test different things:
Most exchanges buy these layers from specialist vendors rather than building them. iDenfy, for example, combines document verification, liveness detection and face matching with human review. Our comparison of crypto KYC software providers covers the wider market.
For individuals, the defences are simple: share your Social Security number and ID scans only where you must, check your credit reports for accounts you do not recognise, and never sell or "rent" your verified exchange account to someone else. That is how real identities end up fronting fraud.
It is fraud using a fake identity built from a mix of real and invented personal data, such as a real Social Security number with a made-up name and date of birth. The identity is used to open accounts, build credit and then steal or launder money.
Traditional identity theft uses one real person's complete identity, and that person usually notices. Synthetic fraud creates a new person from fragments of several people's data and invented details, so nobody owns the whole identity and there is often no one to report it.
Estimates vary. TransUnion put US lender exposure to synthetic identities at $3.2 billion at the end of H1 2024, and a Federal Reserve fraud specialist estimated in March 2025 that the cost had grown from around $8 billion in 2020 to more than $30 billion.
Because they often go unused for 14 or 15 years. A fraudster can build a credit history on a child's number for years before anyone checks it.
By layering checks: document authenticity, liveness detection and face matching, data checks against authoritative sources, device and email age signals, and monitoring after onboarding for rapid deposits and withdrawals or coordinated accounts.
Sometimes. FinCEN has reported accounts opened with suspected AI-generated identity documents. Liveness detection, deepfake detection and checks against independent data sources make it much harder, which is why exchanges increasingly combine them.
This article is educational and is not legal or financial advice. Figures are estimates from the sources linked inline, as published: TransUnion data covers H1 2024, the Boston Fed interview is dated 31 March 2025 and FinCEN alert FIN-2024-Alert004 is dated 13 November 2024. Sources checked on 8 October 2026.