Fraud & identity·May 3, 2026·10 min read

Synthetic Identities: The Fraud That Doesn't Look Like Fraud

Synthetics behave well for years, then bust out. What Federal Reserve, GAO and FinCEN evidence says about synthetic identity fraud detection.

Alfred BEditorial Reviews
Oil painting of a market green where a sealed crate is held ready while a clerk works down three separate tally boards

The files that cost the most rarely look wrong. A payment history with no missed months, a card used lightly and paid off, an address stable for two years. Underwriting is built to catch the applicant who overstates income. Almost none of it is built to catch the applicant who was never born, which is why synthetic identity fraud detection fails on document quality and succeeds on data consistency.

Synthetic identity fraud is the use of a combination of personally identifiable information to fabricate a person or entity, in the definition the Federal Reserve published with an industry focus group in 2021. The identity is assembled, used carefully for years, then cashed out. What gives it away is data consistency, not paperwork.

That gap between how the fraud behaves and how lenders look for fraud is the whole subject.

What makes a synthetic identity hard to see?

A synthetic identity is hard to see because it does nothing suspicious for most of its life. The Federal Reserve's October 2019 paper on detecting synthetic identity fraud reported that traditional fraud models did not flag 85% to 95% of applicants later identified as potential synthetics, citing research from ID Analytics, a vendor. The models were tuned for people in a hurry.

Speed is the difference. A stolen-identity fraudster has a short window before the real person notices, so the activity clusters and looks anomalous. A fabricated identity has no real person to notice, so there is no clock. The US Government Accountability Office, reporting in July 2017 on its forum on combating synthetic identity fraud, described it as a much slower process in which an institution may not realise an account is fraudulent until after the bust-out has already happened.

Everything a fraud rule normally keys on, such as a mismatch, a rush, an inconsistency between stated and observed behaviour, is absent by construction. The applicant answers the questions correctly because the answers were chosen in advance and then made true by repetition.

How does a fabricated identity end up with a real credit file?

A fabricated identity acquires a credit file because the credit system creates one on request. The Federal Reserve's July 2019 white paper on synthetic identity fraud in the US payment system states that when an application arrives with an identifier the bureau has not seen, a new credit profile is created even if the application is declined, because the applicant is treated as new. The paper also notes the bureaus presume the first applicant using a given number is legitimate.

That single design choice is the engine. A decline is not a dead end for a fabricated identity, it is a first entry.

The second mechanism is borrowed history. The Federal Reserve's October 2019 paper describes piggybacking, the adding of a fabricated identity as an authorized user on an account belonging to someone with good credit, as one route into a credit standing, and attaches no published share to it. The same paper gives the corresponding red flag: individuals without a common city or surname who appear as authorized users on multiple accounts. Authorized-user tradelines are ordinary, so the pattern matters rather than the tradeline. Work by Robert Avery, Kenneth Brevoort and Glenn Canner at the Federal Reserve Board, published in March 2010, found 35% of scoreable US consumers had one on file.

A third factor is the loss of an old check. The US Social Security Administration changed how Social Security numbers are issued on 25 June 2011, eliminating the geographic meaning of the first three digits and freezing the high-group list, which removed the sequence information that made a number's issue period readable. The GAO's 2017 forum recorded participants saying institutions can no longer verify from published lists whether a number was ever issued.

None of this requires sophistication. It requires patience and a system that treats first contact as evidence of existence.

Why does a bust-out get booked as a credit loss?

A bust-out gets booked as a credit loss because it looks like one. The account is real, the balance is real, the borrower simply stops paying, and there is nobody to file a dispute or claim identity theft. The Federal Reserve's October 2019 paper notes that when the loss is categorised as credit rather than fraud, the delinquency eventually ages off the credit file and the same fabricated identity can be used again.

The scale figures in circulation all trace back to vendor work, and deserve that label. The Federal Reserve's July 2019 white paper cited Auriemma Group research putting synthetic identity fraud at $6 billion in costs to US lenders in 2016, with an average charge-off balance of more than $15,000 per attack, accounting for up to 20% of all credit losses that year. The Federal Reserve's July 2020 mitigation paper cited a Coalesce study finding synthetics represented under 1% of loans while accounting for more than 20% of portfolio losses, with average losses about 4.6 times a typical credit loss.

Court records give the clearest single picture of the economics. The US Attorney's Office for the District of New Jersey announced on 5 February 2013 that eighteen people had been charged in a scheme built on more than 7,000 false identities, supported by over 1,800 drop addresses and dozens of shell companies, with confirmed losses exceeding $200 million. Fabricated credit profiles were cultivated with false reports of creditworthiness before the accounts were drawn down and abandoned.

Here is the part that matters more than any loss estimate. A portfolio that books these as credit losses will conclude its credit model is drifting and tighten policy on real applicants, which is a worse outcome than the fraud loss itself. The measurement error funds the wrong fix.

What signals actually drive synthetic identity fraud detection?

Linkage drives synthetic identity fraud detection. The Federal Reserve's October 2019 detection paper lists the characteristics institutions look for: multiple applications from one device or IP address, several applicants sharing an address or phone number, clusters of authorized users on one account without a common surname or city, and credit file depth that does not match the applicant's stated age, the example given being a 40-year-old with a six-month file.

Account behaviour on its own is close to useless here. The Federal Reserve's October 2019 paper reported, citing TransUnion, that about 70% of suspected synthetic identity accounts are temporarily exhibiting typical consumer payment patterns. Good behaviour is the product being manufactured, so measuring it measures the fraudster's diligence.

The other family of signals is absence. TransUnion research published on 17 September 2025, which is vendor research, reported that no known relatives and no motor vehicle registrations appear in 30% to 50% of synthetic identities, and that those two conditions raised the likelihood of an identity being synthetic by up to seven times. TransUnion put US lender exposure at $3.3 billion for the year ending 2024.

A real person accumulates unrelated corroboration without trying. Relatives, addresses that overlap with other people's addresses, a vehicle, an employer, a phone number with tenure. A fabricated identity has whatever was built for it and nothing else, and building breadth across unconnected systems is expensive.

What each check can and cannot answer about a fabricated applicant:

CheckWhat it establishesWhat it cannot settle
Document authenticityWhether the document is genuine and unalteredA genuine document can describe a person who does not exist
Liveness and face matchWhether a live person matches the photo presentedA real face can be attached to an identity that belongs to nobody
Credit scoreHow the file has performed to dateThe file was cultivated to perform; about 70% of suspected synthetics are temporarily exhibiting typical consumer payment patterns (TransUnion, via Federal Reserve, Oct 2019)
Identifier format checkWhether the number is well formedUS randomization since June 2011 removed the geographic and sequence meaning formats used to carry (SSA)
SSA eCBSV matchWhether name, date of birth and number agree with SSA recordsApplies at account opening, and only where the underlying number is genuine
Cross-application linkageWhether the applicant shares device, address, phone or tradelines with othersThis is where synthetics surface (Federal Reserve, Jul 2020)
Public-record corroborationWhether a life has left traces in unrelated systems30% to 50% of synthetics had no known relatives and no vehicle registration (TransUnion vendor research, Sep 2025)

Why do credit bureaus struggle with this?

Credit bureaus struggle because their view is wide but their incentives around flagging are narrow. The GAO's July 2017 forum recorded that bureaus and data brokers hold data across a cross-section of institutions and can often trace an identity back to an original source, which is precisely the vantage point needed. Forum participants also said they were reluctant to share those findings, citing reputational risk from wrongly flagging a real customer, and asked for clearer guidance before collaborating more openly.

There is also a population problem. The US Consumer Financial Protection Bureau's May 2015 Data Point on credit invisibles found that as of 2010, 26 million American adults, about 11%, had no credit record at all, and a further 19.4 million held records that could not be scored. A thin new file is the ordinary condition of millions of real people.

The reporting data shows the same blind spot from the other end. FinCEN's financial trend analysis of identity-related suspicious activity, covering Bank Secrecy Act reports filed in 2021 and published in January 2024, found roughly 3,000 reports referencing synthetic identity fraud, amounting to about $182 million in suspicious activity. Those reports were under 0.2% of the roughly 1.6 million discrete identity-related reports examined, ranking synthetic identity 13th of the 14 exploitation typologies FinCEN assessed.

Set that beside the loss estimates and the shape of the problem is clear. Either synthetic identity fraud is a minor typology and the billion-dollar estimates are wrong, or it is substantially under-reported because institutions do not recognise it when it happens. The Federal Reserve's own description of bust-outs being categorised as credit losses points to the second reading.

What does a layered defence look like?

A layered defence means no single check carries the decision. The Federal Reserve's July 2020 mitigation paper states plainly that there is no single solution to completely mitigate synthetic identity payments fraud, and concludes that a multi-layered approach using both manual and technological data analysis gives organisations the best chance of identifying synthetics.

Three components recur in that paper. Link analysis across an institution's own book, connecting accounts by shared device, address, phone and authorized-user relationships. Consortium data, which the paper describes as better than organisation-level data for detecting trends, since a fabricated identity applying at one lender has usually applied at others. And identifier verification at the point of account opening.

The US Social Security Administration's electronic Consent Based Social Security Number Verification service, launched to pilot participants in June 2020, is the identifier layer in the United States. The GAO reported in September 2024 that in fiscal 2023 the service had 25 direct users, served roughly 946 financial institutions indirectly, and processed 76.8 million transactions, against $62 million in development and operating costs from fiscal 2018 through 2023 of which $37.3 million remained unrecovered. In November 2020 the SSA had projected 123 direct users making 1.1 billion transactions in fiscal 2021.

The Federal Reserve's 2020 paper is also candid about what tightening onboarding does. Experts consulted expected stronger account-opening controls to push fraudsters toward conventional identity theft rather than to end the activity. Displacement is the expected outcome of a working control, and it arrives whether or not anyone planned for it.

Is there Canadian data on any of this?

There is no Canadian synthetic identity data. Canada's federal reporting on fraud does not break out synthetic identities as a category, so lenders here are working from US structural evidence and their own books.

The Canadian Anti-Fraud Centre's 2024 annual statistical report shows identity fraud as the most frequently reported fraud type in Canada by report volume, and does not use the term synthetic identity anywhere in the document. The centre reported on 6 March 2026 that Canadians lost more than $704 million to fraud in 2025, with identity fraud among the three most reported types, and repeated its estimate that only 5% to 10% of frauds are ever reported.

Statistics Canada's police-reported crime release of 22 July 2025 put the 2024 rate of identity fraud at 50 incidents per 100,000 population, up 2%, with identity theft stable at 14 per 100,000, and it remains the most recent Canadian breakout available, because the 22 July 2026 release reports only a combined total fraud rate. Those counts exclude the Montréal Police Service for 2024 because of a data transmission problem, which Statistics Canada flags in the release. Neither figure separates fabricated identities from stolen ones.

What we couldn't verify

Four things, stated plainly, because this topic attracts confident numbers.

The most quoted figure in the field, $20 billion in US synthetic identity losses in 2020, circulates widely and appears in Federal Reserve payments-improvement material from 2022. We could not find a published methodology behind it.

The Auriemma figures of $6 billion, up to 20% of credit losses and a charge-off of more than $15,000 per attack survive as citations inside the Federal Reserve's July 2019 white paper. We could not reach the underlying study, so the Federal Reserve's citation is the furthest back the claim goes.

There is no published distribution for how long a synthetic identity is cultivated before bust-out. Sources agree on months to years, and the Federal Reserve's October 2019 paper describes accounts nurtured for months and sometimes years, but no dataset behind that range is public.

And there is no Canadian incidence or loss estimate for synthetic identities at all. Not from the Canadian Anti-Fraud Centre, not from Statistics Canada, not from any federal source we could find.

Common questions

What is synthetic identity fraud?
The Federal Reserve's industry-recommended definition, published in 2021, is the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain.

Why don't fraud models catch synthetic identities?
The Federal Reserve's October 2019 paper reported that traditional models missed 85% to 95% of potential synthetics, citing ID Analytics vendor research, because those models look for speed and inconsistency while a fabricated identity behaves normally for years.

What are the strongest synthetic identity fraud detection signals?
Linkage and absence. Shared devices, addresses, phones and authorized-user clusters across applicants, per the Federal Reserve, plus missing public-record corroboration such as no known relatives or vehicle registration, per TransUnion vendor research from September 2025.

Does document verification stop synthetic identity fraud?
Not on its own. Document checks establish whether a document is genuine, not whether the person described exists, and the Federal Reserve's mitigation work concludes there is no single control that resolves synthetic identity fraud.

How much synthetic identity fraud is there in Canada?
No published Canadian figure exists. The Canadian Anti-Fraud Centre's 2024 statistical report does not use the term, and Statistics Canada's identity fraud rate of 50 incidents per 100,000 in 2024 does not separate fabricated identities from stolen ones.


Carousel's intake layer collects applicant data from sources that corroborate each other rather than from documents alone. See how verification fits your flow

Fraud & identitysynthetic-identityfraud-detectioncredit-bureauidentity-verification