Synthetic Identity Fraud and the No-Victim Problem

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Split human and digital wireframe face representing synthetic identity fraud and fabricated online identities.

    Synthetic identity fraud accounts for 80% of new account fraud in the US. Losses reached $2.94 billion in 2025. The reason it grows unchecked is that the person being impersonated often doesn’t exist.

    In 2023, a federal investigation in Suffolk County, New York, unraveled a fraud ring that had created more than 20 identities and used them to obtain credit from 19 different financial institutions. The identities had Social Security numbers. They had credit histories. They had addresses and phone numbers and email accounts. They had, in some cases, years of on-time payment records that made them look like model customers. None of them were real people.

    The ring’s operator was sentenced to four years in federal prison and ordered to pay $1.3 million in restitution. But the case was unusual only in that it was caught. The technique it relied on, known as synthetic identity fraud, has become so pervasive that the Mitek Systems and Datos Insights report published in June 2026 called it “the defining fraud threat” facing financial institutions. US unsecured credit losses reached $2.94 billion in 2025. The technique accounts for up to 80 percent of new account fraud in the United States. And the reason it keeps growing is built into its design: there is no victim to file a complaint, because the person at the center of the fraud was never real.

    How a synthetic identity comes to life

    It starts with a Social Security number. The number is real, typically belonging to a child, an elderly person in long-term care, a recently deceased individual, or an immigrant who does not actively monitor their credit. Everything attached to it is fabricated: a plausible name, a generated date of birth, a rented address.

    The assembled identity applies for credit. The first applications are rejected, but the rejections serve a purpose. They create a credit file with the major bureaus. That file is the foothold. Once it exists, the synthetic identity begins the slow, deliberate work of becoming a trustworthy borrower. Secured cards. Small credit lines paid on time. Authorized user tradelines purchased on dark web marketplaces that add someone else’s good credit history to the synthetic file. After 12 to 18 months of clean behavior, the identity carries a credit score north of 700. To an automated underwriting system, it is indistinguishable from any other responsible consumer.

    Then comes what fraud investigators call the bust-out. The synthetic identity maxes out every available credit line, takes cash advances, and disappears. The lender writes off the balance. There is no real person to pursue and no assets to recover. The institution absorbs the loss, and the SSN’s actual owner, often a child who will not apply for credit for years, has no idea their number was used.

    Why it looks like normal banking until it doesn't

    What makes synthetic identity fraud so difficult to detect is that the fraud, for most of its lifecycle, genuinely is not fraud. The synthetic identity is making real payments with real money. It is maintaining the kind of credit behavior that banks reward with higher limits and better terms. Every signal the fraud detection system monitors reads exactly the way a good customer’s signals should read.

    The abnormality is existential rather than behavioral. The person does not exist. But identity verification systems are designed to match an applicant against known attributes, and when the identity itself was built to satisfy those attributes, the verification confirms the fiction. The SSN is real. The credit file was constructed deliberately. The identity documents, increasingly, were generated by the same AI tools now producing deepfakes that defeat liveness checks in biometric verification.

    Sumsub’s 2025 Identity Fraud Report documented a 300 percent increase in synthetic document fraud and an 1,100 percent surge in deepfake-enabled fraud in North America in Q1 2025 alone. What once required weeks of patient construction, the careful assembly of a believable person from stolen and fabricated parts, now compresses into hours. The economics that kept synthetic identity fraud relatively contained have changed. The technique scales.

    The Mitek survey found that 84 percent of fraud executives consider synthetic identity fraud a moderate or high risk, yet the detection gap persists. The signals that distinguish a synthetic identity from a real one are invisible within any single institution’s view. A synthetic identity holding clean accounts at three different banks presents no anomaly to any of them. The pattern emerges only when data is correlated across institutions, a capability most fraud programs lack

    The brand exposure nobody measures

    The financial losses are well documented. The brand damage is not.

    A synthetic identity that opens accounts at a financial institution and transacts for 18 months has spent that entire period operating under the institution’s name. The credit cards carry the bank’s logo. The app logins display the bank’s brand. The customer service interactions are logged under the bank’s systems. When the bust-out hits, the institution absorbs the write-off. When the real SSN owner discovers the damage years later, often when applying for their first apartment or student loan, they associate the harm with the institutions that issued credit in a name they never authorized.

    The exposure extends beyond traditional lending. Ecommerce platforms that onboard synthetic seller accounts expose customers to fraudulent transactions conducted under the platform’s trust framework. Payment providers bear chargeback costs. Insurers discover the fraud only at the point of a claim that was engineered from the beginning.

    What connects synthetic identity fraud to the broader impersonation landscape is the infrastructure behind it. The dark web marketplaces where SSNs and tradelines are sold, the document generation services producing fake IDs, the mule networks providing addresses and cash-out paths, this is the same ecosystem that powers phishing and credential theft campaigns. For organizations monitoring their external brand exposure, synthetic identity fraud represents a category of impersonation that most brand protection programs do not yet address. The impersonation is not of the brand itself but of a legitimate relationship, conducted through the brand’s own systems and bearing the brand’s own name.

    Regulators have noticed

    In November 2024, FinCEN issued guidance specifically addressing synthetic identity fraud in the financial sector, expanding reporting expectations for suspicious activity tied to fabricated identities. The Federal Reserve has published multiple advisories on detection, and the OCC has incorporated synthetic identity risk into its supervisory examination framework.

    The EU AI Act’s transparency provisions under Article 50, effective August 2026, require disclosures for AI-generated content including synthetic identity documents. While enforcement is developing, the regulatory signal is clear: institutions that fail to address synthetic identity fraud face increasing exposure not only to financial losses but to supervisory action.

    Cyber insurance markets have adjusted in parallel. Swiss Re’s 2025 Sonar report warned that deepfakes and synthetic identities may increasingly contribute to cyber insurance losses, and underwriters are beginning to require documented controls for synthetic identity detection as a condition of coverage.

    The Bottom Line

    Synthetic identity fraud has grown from a niche concern to the defining fraud threat of 2026. The Suffolk County case that opened this post involved 20 identities and 19 institutions. The technique now operates at a scale orders of magnitude larger, with losses in the billions and AI compressing the creation timeline from weeks to hours. The structural challenge is that the fraud is invisible until the bust-out because the identity behaves like a real customer. For organizations whose platforms and trust frameworks are exploited by synthetic identities, the exposure extends beyond the write-off to the reputational damage that follows when customers, regulators, and insurers hold the institution accountable for fraud conducted under its name.

    Key Takeaways

    What is synthetic identity fraud?

    Synthetic identity fraud involves creating a new identity by combining real personal data, typically a stolen Social Security number, with fabricated information such as a fake name, date of birth, and address. The composite identity is used to open accounts, build credit history over months or years, and eventually default on all credit lines in a coordinated bust-out. It accounts for up to 80 percent of new account fraud in the United States.

    How much does synthetic identity fraud cost?

    US unsecured credit losses from synthetic identity fraud reached approximately $2.94 billion in 2025 and are projected to exceed $3.1 billion in 2026, according to research from Mitek Systems and Datos Insights. Global losses are estimated at $20 to $40 billion annually. These figures capture only direct credit losses and do not include downstream fraud across deposits, checks, and mule networks.

    Why is synthetic identity fraud so difficult to detect?

    Synthetic identities behave like legitimate consumers during the credit-building phase. They make payments on time, maintain normal utilization, and respond to communications. The fraud does not look like fraud until the bust-out. Detection is further complicated by the fact that patterns are often visible only when data is correlated across multiple institutions, a capability most fraud programs lack.

    How has AI changed synthetic identity fraud?

    Generative AI has accelerated every stage of the process. AI tools now generate synthetic identity documents that bypass automated KYC verification. Sumsub documented a 300 percent increase in synthetic document fraud and an 1,100 percent surge in deepfake-enabled fraud in North America in Q1 2025. The creation of a convincing synthetic identity can now be automated in hours rather than weeks.

    How is synthetic identity fraud a brand protection issue?

     Synthetic identities operate through real platforms under real brand names. The financial institution that issues credit, the ecommerce platform that onboards a synthetic seller, and the payment provider that processes the transactions all bear the brand exposure. When the fraud surfaces, the institution absorbs the financial loss and the reputational damage. The infrastructure that supports synthetic identity campaigns overlaps with the dark web marketplaces and document services that power phishing and credential theft.

    Categories:

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.