Fraud & Risk

Synthetic Identity Fraud

What Is Synthetic Identity Fraud? Definition and How It Works

Definition

Synthetic identity fraud is a fraud technique in which a criminal creates a fictitious identity by combining real and fabricated personal information, typically a genuine Social Security Number paired with a fabricated name, address, and date of birth, to open accounts, obtain credit, and ultimately commit financial theft through a coordinated bust-out.

How it works

Synthetic identity fraud exploits gaps in identity verification systems designed to detect entirely fabricated or stolen real identities, not blended ones. Because the Social Security Number is real (passing SSN validation), while the associated name and address are fabricated, the composite identity can pass basic KYC checks.

Fraudsters follow a structured playbook. First, they create the synthetic identity and apply for secured cards or small credit lines. They make payments on time for months or years, credit farming, building a credit file under the synthetic identity. During this period the synthetic identity behaves identically to a legitimate consumer.

Once sufficient credit is established, the fraudster executes a bust-out: maxing out all available credit lines across multiple institutions simultaneously, withdrawing proceeds, and abandoning the identity. Because multiple institutions are hit simultaneously, fraud alerts at one lender trigger too late.

Why it matters

Synthetic identity fraud is widely described as one of the fastest-growing financial crimes in the US and a leading driver of unrecoverable credit losses, costing financial institutions billions annually. The slow-burn nature, fraudsters build legitimate-seeming histories over 12–24 months, means losses are often undetected until bust-out, by which point recovery is minimal.

For payment facilitators and platforms onboarding sub-merchants, synthetic identity fraud presents a specific risk: a fraudster passing onboarding KYC with a synthetic identity can process fraudulent transactions, generate chargebacks, and exit before monitoring detects the pattern. Financial liability typically falls on the platform.

With PXP

PXP supports merchants and partners across the payments value chain. To talk through identity fraud prevention as part of your payment strategy, get in touch with our team.

Talk to a payments specialist

Frequently asked questions

How is synthetic identity fraud different from identity theft?

Identity theft steals a real person's complete identity and uses it fraudulently, the real victim discovers the fraud through unexpected bills or denied credit. Synthetic identity fraud constructs a new fictitious identity using mixed real and fabricated data. There is no single real-world victim who experiences direct harm in the same way.

Why are children's SSNs particularly vulnerable?

Children's SSNs are assigned at birth but have no credit file. This makes them attractive: the SSN passes validation checks but there is no existing credit record to conflict with the fabricated identity. Parents typically don't check their child's credit until the child applies for credit themselves, often years later.

How can payment platforms detect synthetic identity fraud during onboarding?

Effective detection combines multiple signals: email address age, phone number tenure and type (VoIP numbers are a risk signal), SSN issuance state versus stated birth location, device fingerprint against fraud databases, and ML models trained on bust-out patterns. No single check is sufficient; layered signals are required.