Compliance
Oct 8, 2026

Synthetic Identity Fraud: How It Works and How to Stop It

What synthetic identity fraud is, how fake identities are built, how big it is, why crypto exchanges are targets, and the signals and checks that stop it.

Synthetic Identity Fraud: How It Works and How to Stop It

Synthetic identity fraud is the creation of a fake person from a mix of real and invented personal data, such as a genuine Social Security number paired with a made-up name and date of birth, which is then used to open accounts, build credit and steal. Unlike ordinary identity theft, there is no single victim whose whole identity is taken, which is why it often goes undetected until the money is gone.

This guide explains how synthetic identities are built, how big the problem is, why crypto exchanges are exposed, which signals give synthetics away, and which defences work. It is written for compliance teams and for anyone wondering why an exchange asks for a live selfie on top of an ID.

What synthetic identity fraud is

In 2021 a Federal Reserve focus group of 12 fraud experts agreed an industry definition: synthetic identity fraud is "the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain" (Federal Reserve, definition overview). FinCEN uses a similar description: a combination of real and fake personal information used "to fabricate a person or entity to pass validation processes" (FinCEN alert FIN-2024-Alert004).

The difference from traditional identity theft matters:

  • True-name identity theft uses a real person's complete identity. The victim usually notices quickly, through unfamiliar accounts, bills or credit checks, and reports it.
  • Synthetic identity fraud invents a new person. Part of the data may belong to someone real, but nobody owns the whole identity, so there is often no one to raise the alarm.

A Boston Fed podcast summed it up as "the Frankenstein of identity fraud": pieces taken from several people and stitched into one fake person (Boston Fed, 31 March 2025).

How a synthetic identity is built

The Federal Reserve splits the ingredients into two groups. Primary elements are those that, in combination, are usually unique to a person: name, date of birth, Social Security number or another government identifier such as a passport or tax number. Secondary elements make an identity look more real but cannot establish it alone: a mailing address, email address, phone number and digital footprint such as device ID or IP address.

A typical US scheme follows the pattern the Fed described when it published its 2019 white paper, with detail from the Boston Fed interview:

  1. Combine. A real Social Security number, often stolen in a data breach, is paired with a fictional name, address or date of birth.
  2. Get a file. Applying for credit creates a credit bureau file for the new identity, and the first approved card gives it what the Fed specialist calls "proof of life".
  3. Grow. The fraudster opens small accounts, pays on time, and lets the limits rise.
  4. Bust out. The identity maxes out every line of credit and disappears. Because the person never existed, there is little recourse.

Social Security number randomisation made one old check less useful. Since 25 June 2011 the first three digits no longer reflect the state where the number was issued (Social Security Administration), and the old "high group" list used to validate numbers lost its significance.

Generative AI adds the finishing touches. FinCEN reported in November 2024 that criminals have combined AI-generated images with stolen or entirely fake personal data to create synthetic identities, and have used AI to alter or generate the images on driver's licences and passports.

How big the problem is

Synthetic fraud is hard to measure because much of it is written off as ordinary bad debt. The available figures are estimates, so treat them as orders of magnitude:

  • Lender exposure. TransUnion put US lender exposure to synthetic identities across auto loans, bank credit cards, retail cards and unsecured personal loans at $3.2 billion at the end of H1 2024, up from $3.0 billion a year earlier and an all-time high. Auto loans made up $2.0 billion of that, and 0.20% of newly opened accounts in those four products were linked to synthetic identities (TransUnion release, via FF News).
  • Growth. The same TransUnion analysis found synthetic identity fraud was the fastest-growing digital fraud type globally between H2 2023 and H1 2024, up 153%.
  • Total cost. In a March 2025 Boston Fed interview, a Federal Reserve payments fraud specialist estimated that the cost had grown from roughly $8 billion around 2020 to more than $30 billion.
  • Deepfakes. FinCEN observed an increase in suspicious activity reports describing suspected deepfake media in fraud schemes from 2023 into 2024, often involving altered or AI-created identity documents.

Who gets hurt

Synthetic fraud is sometimes described as victimless. It is not. The person whose Social Security number was used can find the fraud tied to their number when they apply for credit, and the Fed's 2019 paper notes knock-on effects such as denied disability benefits, rejected tax returns and errors in health records.

Some groups are targeted because their numbers sit unused for years. The Boston Fed interview names three: children, whose numbers may go unused for 14 or 15 years; older people, who rarely apply for new credit; and people in prison, who cannot see that their number is being used. Lenders and card issuers carry the direct losses.

Why crypto exchanges are exposed

Crypto platforms onboard customers remotely, often within minutes, and crypto transfers are hard to reverse. That combination makes an exchange account useful to a fraud ring in several ways:

  • Laundering and cash-out. FinCEN found accounts opened with suspected AI-generated identities being used to receive and launder the proceeds of other fraud, and lists high payments to digital asset exchanges, and withdrawals to offshore exchanges straight after deposit, among the warning signs.
  • Replacing money mules. Mules have to be recruited and paid. The Boston Fed interview describes fraudsters shifting to opening accounts in synthetic names instead, because they then control the account themselves.
  • Bonus and promotion abuse. Sign-up and referral rewards pay per new account, so a batch of fake identities can farm them. TransUnion found promotion abuse was the most common digital fraud type reported to it globally in H1 2024.
  • Deepfake onboarding. AI-generated documents and faces are aimed squarely at the remote ID and selfie checks exchanges rely on.

Outside the US there is no Social Security number to borrow, so the same idea usually shows up as a fabricated or AI-generated document attached to a mix of real and invented data. The EU's Anti-Money Laundering Regulation, Regulation (EU) 2024/1624, which applies from 10 July 2027, requires identity to be verified through an identity document plus, where relevant, information from reliable and independent sources, or through an eIDAS electronic identification at assurance level substantial or high (Article 22(6)).

Signals that point to a synthetic identity

No single signal proves fraud, and FinCEN stresses that the full circumstances matter. These are the patterns most often cited, drawn from FinCEN's red flags and the Fed's guidance:

  • A thin or shallow identity. Real people leave long trails: an email address used for years, a long-held phone number, family links. A brand-new email, a week-old phone and no history are a warning sign.
  • Inconsistent data. A photo that looks much older or younger than the date of birth, several documents that disagree, or device and location data that do not match the documents.
  • Altered or generated images. Visual signs of editing, a selfie flagged by deepfake detection, or a reverse image search that finds the face in a gallery of AI-generated faces.
  • Avoiding live checks. Repeated "technical glitches", requests to switch channel during a video check, or a third-party webcam plugin that can feed in pre-recorded video.
  • Coordinated accounts. Several similar accounts sharing devices, IP ranges or behaviour.
  • Early account behaviour. Rapid transactions on a new account, or funds withdrawn immediately after deposit in ways that are hard to reverse.

FinCEN asks US financial institutions to include the key term "FIN-2024-DEEPFAKEFRAUD" in suspicious activity reports linked to these schemes. For transaction-level patterns, see our guide to AML red flags in crypto.

Defences that work

Synthetics are built to pass one check at a time, so the answer is layering checks that test different things:

  1. Document authenticity. Inspect security features, templates and fonts, and read the chip where the document has one.
  2. Liveness and face matching. Confirm a live person is present and matches the document photo. This is a key barrier to AI-generated faces and replayed video. See liveness detection and face verification.
  3. Authoritative data checks. In the US, the Social Security Administration's eCBSV service lets permitted financial institutions confirm, with the person's signed consent, whether a name, date of birth and Social Security number match SSA records, returning a yes or no answer. In the EU, eIDAS electronic identification serves a similar purpose.
  4. Depth and device signals. Email and phone age, device reputation and links to other applications expose identities that only exist on paper.
  5. Supporting documents. A proof of address check adds another independent source to compare against.
  6. Ongoing monitoring. Synthetics are designed to look clean at onboarding, so transaction monitoring and periodic reviews catch the bust-out or laundering phase.

Most exchanges buy these layers from specialist vendors rather than building them. iDenfy, for example, combines document verification, liveness detection and face matching with human review. Our comparison of crypto KYC software providers covers the wider market.

For individuals, the defences are simple: share your Social Security number and ID scans only where you must, check your credit reports for accounts you do not recognise, and never sell or "rent" your verified exchange account to someone else. That is how real identities end up fronting fraud.

Frequently asked questions

What is synthetic identity fraud?

It is fraud using a fake identity built from a mix of real and invented personal data, such as a real Social Security number with a made-up name and date of birth. The identity is used to open accounts, build credit and then steal or launder money.

How is synthetic identity fraud different from identity theft?

Traditional identity theft uses one real person's complete identity, and that person usually notices. Synthetic fraud creates a new person from fragments of several people's data and invented details, so nobody owns the whole identity and there is often no one to report it.

How big is synthetic identity fraud?

Estimates vary. TransUnion put US lender exposure to synthetic identities at $3.2 billion at the end of H1 2024, and a Federal Reserve fraud specialist estimated in March 2025 that the cost had grown from around $8 billion in 2020 to more than $30 billion.

Why are children's Social Security numbers targeted?

Because they often go unused for 14 or 15 years. A fraudster can build a credit history on a child's number for years before anyone checks it.

How do crypto exchanges detect synthetic identities?

By layering checks: document authenticity, liveness detection and face matching, data checks against authoritative sources, device and email age signals, and monitoring after onboarding for rapid deposits and withdrawals or coordinated accounts.

Can deepfakes pass KYC checks?

Sometimes. FinCEN has reported accounts opened with suspected AI-generated identity documents. Liveness detection, deepfake detection and checks against independent data sources make it much harder, which is why exchanges increasingly combine them.

Keep reading

This article is educational and is not legal or financial advice. Figures are estimates from the sources linked inline, as published: TransUnion data covers H1 2024, the Boston Fed interview is dated 31 March 2025 and FinCEN alert FIN-2024-Alert004 is dated 13 November 2024. Sources checked on 8 October 2026.

About the author.

Co-Founder at JewelSwap & Chief Strategy Officer at iDenfy. Viktor brings his successful track record of superb development & project management.