Synthetic Identity: How Fraudsters Are Becoming People Who Never Existed
Synthetic identity fraud combines real and fabricated data to create untraceable personas. It is the fastest-growing financial crime category globally.
Synthetic identity fraud occupies a category of its own in the fraud taxonomy because it is, in a technical sense, undetectable using traditional identity verification methods. A synthetic identity is not a stolen identity. It is a constructed one. It combines genuine elements, typically a real national identification number obtained from a data breach, with fabricated biographical data: a name, date of birth, and address combination that has never existed as a real person.
The constructed identity is then cultivated over months or years before it is used. Fraudsters establish credit histories for synthetic identities through a series of legitimate-appearing financial activities, building a profile that passes automated underwriting and background check systems. When the identity is finally exploited, it often carries a clean credit history and passes every verification check the targeted institution runs.
The scale of synthetic identity fraud has grown in direct proportion to the availability of data breach material on dark web markets. Tens of millions of national identification numbers are available for purchase at minimal cost, providing the foundation for synthetic persona construction on an industrial scale. Financial institutions, healthcare providers, and government benefit systems are the primary targets, but the vulnerability extends to any organisation that relies on document-based identity verification.
The corporate exposure beyond direct financial fraud includes: vendor fraud using synthetic identities in supplier onboarding; employment fraud where synthetic identities are used to pass background checks; and access fraud where constructed identities are used to obtain credentials or access to regulated systems.
Effective defence against synthetic identity requires moving beyond document verification to behavioural analysis: assessing the consistency and plausibility of the full identity profile rather than verifying individual data points in isolation. Custodia One's identity fraud advisory covers the full spectrum of synthetic identity risk across financial, employment, and access contexts.
"The distinguishing feature of synthetic identity fraud is that no victim reports it. The person whose identity has been constructed does not exist. The fraud can run for years before it surfaces."
Custodia One Advisory Perspective
What Your Organisation Should Do
Review your identity verification processes for reliance on document checks that synthetic identities can satisfy
Implement behavioural analysis across your onboarding and verification flows to detect implausible identity profiles
Assess your vendor and supplier onboarding for synthetic identity vulnerability, particularly in remote or volume onboarding contexts
Engage with your financial crime team on the specific synthetic identity typologies relevant to your sector
Advisory Enquiries
Facing this issue in your organisation?
Custodia One advises on all of the issues covered in our Intelligence Library. Contact us to discuss your specific situation in confidence.
