// blog / synthetic-identity-fraud-guide.md

If you think identity fraud means someone pretending to be you, it's not quite like that. Synthetic identity theft, also called synthetic identity fraud, is about creating a fake person – and it’s already one of the fastest-growing scams today.

It's true that identity theft isn't a new thing in our world. People have been warned about credit card scams, phishing emails, and other frauds for years, but there is one type of fraud that's more confusing than others because it's harder to identify and catch. Moreover, it's growing faster than almost any other type of scam.

In our guide, we'll break it all down in simple terms, so you will understand what synthetic identity fraud is, how it works, why it is so dangerous, and most importantly: what you can do to protect yourself and your business from it.

Key takeaways

  • Synthetic identity fraud means building a fake person from a real Social Security number plus invented details – not stealing an existing identity.
  • It accounts for roughly 20–24% of identity fraud worldwide, with an average charge-off around $15,000 per case and losses projected to reach $23 billion by 2030.
  • It’s hard to catch because there’s no real victim to notice the bills – a synthetic identity can build credit quietly for years.
  • Children are prime targets: roughly 1 in 19 US kids has been affected, because their clean SSNs can sit dormant for a decade.
  • The best personal defenses: check your credit reports regularly and freeze your child’s credit.

What Is Synthetic Identity Fraud and Why Is It So Dangerous?

At its core, synthetic identity fraud happens when a fraudster (a person who initiates a scam) creates a fake identity using a mix of real and falsified information. For example, fraudsters might use the real Social Security number of a person, mostly those who don't have much credit history, like newcomers to the country or children. They attach a fake name, date of birth, or address to this identifier and a new person starts to exist. But there is an important difference: this person doesn't exist. It's not someone pretending to be you but someone pretending to be someone who isn't even real.

This type of crime is often referred to as synthetic identity theft because it relies on stealing real data and combining it with fake details. The TransUnion Global Fraud Report (2025) shows that it makes up about 20–24% of identity fraud cases worldwide and costs businesses tens of billions of dollars each year.

The reason synthetic identity fraud is such a big problem is because it's very hard to detect. For example, if someone steals your real identity and opens a credit limit in your name, you'll probably notice it quickly because you will start receiving bills. But if someone creates a totally new fake person, there is no one to report the fraud. The banks don't know it's fake, the credit bureaus don't know it's fake, and government records may show nothing unusual. This makes it a very risky and dangerous long-term scam case and in many situations, it can go on for years before anyone notices. To reduce the risk of fraud, it’s important to handle personal and business information carefully in every interaction.

These fakes come in two flavors: manipulated identities, where a real person alters one or two details of their own identity (often to hide a bad credit history), and manufactured identities, built entirely from a mix of stolen and invented data. The manufactured kind is harder to catch – there's no real person underneath at all.

How Does It Work?

Let's walk through how the synthetic identity concept works and what usually happens:

Step 1: Getting a real identifier

Most of the time, this means a Social Security number in the U.S., especially one with no activity. That might be a child's Social Security number or one that was never activated properly. These numbers can be bought on the dark web, stolen in data breaches, or generated illegally.

Step 2: Adding fake details

The fraudster creates a name, date of birth, address, and all other information they need to make this identity look legit. An important part: these details are made up to avoid linking to any real person.

Step 3: Building credit

This is where things get more risky. The fraudster might do concrete actions to build credit for this new synthetic identity. For example, they might apply for a credit card with it and even if at first they get denied, this application itself may start a credit file for this unreal person. Then they try again, maybe with a secured card or by becoming an authorized user on someone else's account. So slowly, step by step, the fake person starts to build a credit history in the real world.

Step 4: Borrowing big and disappearing

Once the synthetic identity has a strong credit score, the fraudster opens credit cards, takes loans, and disappears. The banks get unpaid bills, and there is no real person to find.

get-startedFREESECURE

Stop leaking the data fraudsters need

PDFized removes SSNs and personal details from documents before you share them – free.

Start Redacting – Free

How Widespread Is Synthetic Identity Fraud? Why Does It Happen?

According to the U.S. Federal Reserve, synthetic identity fraud is one of the most widespread and fastest-growing financial crimes in the United States. This form of fraud is especially difficult to track because it combines real and fake information that looks completely legitimate to most systems. Industry estimates suggest it accounts for a large share of identity-fraud activity and causes tens of billions of dollars in losses every year.

The fact is that it's not just individuals who are at risk. Businesses, especially, in industries like financial technologies, healthcare, leasing, and e-commerce are involved as well.

It's theoretically possible to spot a fake person. But most financial systems weren't designed to track someone who doesn't even exist. They're designed to verify identities, not to ask whether those identities are real.

Credit bureaus, banks, and lenders often rely on automated checks so if a name matches a Social Security number and shows some credit history, it's assumed to be valid. There's no big red flag saying that this identity is synthetic, and because the fraud often starts small and builds slowly, it can remain undetected for a long time.

To put numbers on it: the average charge-off runs around $15,000 per synthetic identity case, and Deloitte projects losses will reach at least $23 billion by 2030.

Until 2011, a Social Security number told you something about its owner. The first three digits showed the state where it was issued, and the rest followed a set order – so a bank could check whether a number matched the age and birthplace someone claimed.

In 2011 the Social Security Administration started handing out numbers at random. That was good for privacy, but it took away the easiest fraud check banks had. Now a made-up number looks the same as a real one.

What Changed in 2026: AI-Assisted Synthetic Identities

Building a convincing fake person used to take patience. Generative AI removed most of that friction:

  • Documents on demand. Fraudsters generate passable ID scans, utility bills, and pay stubs instead of sourcing forgeries.
  • Deepfaked liveness checks. Selfie and video verification (long treated as the fallback when document checks fail) can now be defeated with a generated face.
  • Backstories at scale. Social profiles, post histories, and photos give a synthetic identity the digital footprint that used to be its weakest point. The "lack of real digital footprints" red flag gets less reliable every year.
  • Volume. What was a specialist crime is now scriptable, so organizations that were never worth targeting now are.

The defense hasn't changed shape, but the weighting has: document and footprint checks matter less, behavioral signals and device intelligence matter more.

What These Fake Identities Can Do

1. Hurt businesses

Banks lose billions of dollars annually to unpaid loans made to fake people. Every time a fraudster fails to pay, that's a financial loss, and the cost is often passed on to consumers who get higher fees, prices, and stricter credit checks.

2. Exploit children

Children are prime targets because their Social Security numbers are usually clean, and they don't have any credit history, so fraudsters can use them without a problem. Many parents don't realize their child's identity was stolen until years later, often when the child turns 18 and applies for student loans or credit cards.

Roughly one in nineteen US children has been affected by identity fraud in recent years, and a synthetic identity built on a child's number can sit dormant for a decade – quietly accumulating a credit history that's waiting when the fraudster decides to cash out.

3. Weaken trust

The more fraud happens, the less we trust the systems that are supposed to protect us. It makes everyone more cautious, more suspicious, and unfortunately, more burdened with bureaucracy.

4. Distort data and risk models

When fake data is treated as real users, it creates a lot of risks. Synthetic identities weaken system processes as fake customer profiles of banks and other institutions are treated as real customers and algorithms are trained incorrectly. As a result for both businesses and legitimate users.

How Can You Spot Synthetic Identity Fraud?

Here are several red flags to pay attention to:

  • Mismatched personal details like names not matching credit histories, or inconsistent data across applications
  • Multiple identities linked to the same phone number or address
  • Credit files that grow too fast
  • Applicants with SSNs issued in recent years but claiming to be older
  • Lack of real digital footprints
  • A valid SSN with no public records attached – no voter registration, tax filings, or employment history

Where the Real Data Comes From

Every synthetic identity needs at least one real identifier, and it comes from somewhere it was never meant to leave: a breached database, a misconfigured server, or a shared file that still had the original data underneath. That last one is easy to miss. An SSN doesn't need a big breach to get out – it leaks from an onboarding PDF sent to a vendor, a scanned form attached to a support ticket, or a document where the identifiers were covered with a black box that copy-paste reveals in seconds. Redaction that only looks like redaction leaves the data fully intact. The fewer real identifiers in the files you send and store, the less raw material there is for fraudsters.

What Can You Do to Protect Yourself?

If you're an individual, here's what you can do:

Check your credit reports regularly. Make sure there are no strange accounts or unfamiliar names linked to your Social Security number.

Freeze your child's credit. Most parents don't know this, but you can request a credit freeze for your child to prevent synthetic identity fraud.

Be cautious with your data. Never share your Social Security number, date of birth, or full name with untrusted sources. Taking small daily steps to protect sensitive data can greatly reduce the risk of identity fraud.

If you're handling or sharing documents that contain sensitive data, one more smart move is to anonymize them before sending them. A financial redaction tool offers a quick and reliable way to remove personal information – names, addresses, and account numbers – from your PDFs directly online, without needing to download anything. It's a small step that can make a big difference in keeping personal or client data safe from misuse and fraud.

For businesses, using tools that detect behavioral patterns, device intelligence, and other advanced risk signals can help spot suspicious accounts early. If you have a business:

Use multi-layered identity verification. Go beyond basic name and SSN matches. Look at behavior, devices, and patterns, and analyze them.

Watch for unusual application patterns. Even certain points in applications from similar sources could be a red flag.

Educate your team. Fraud detection isn't only about technology, it's also about humans knowing what to look for.

And if you do uncover a suspicious account, act fast: freeze it to stop ongoing activity, review how it passed your checks, and report the case – every confirmed synthetic identity teaches your verification process something.

Synthetic vs Traditional Identity Fraud: A Quick Comparison

FeatureTraditional ID FraudSynthetic ID Fraud
Identity typeStolen from a real personCreated from real and fake info
TargetThe real person whose data was stolenNo one specific
DetectionCan be caught by the victimOften undetected for years
Credit damageReal person suffersCredit system takes the hit
GoalImmediate gainLong-term buildup and larger fraud

Conclusion

Synthetic identity fraud might sound like something out of a science fiction plot, but it's very real and already here. It's not just about hackers or dark web criminals - it's about how fragile our identity system has become.

But knowledge is power. Now you know what it is, how it works, and what to do to secure yourself from such frauds. Keep your information secure, protect your children's data, and if you run a business, especially one that handles credit, lending, or accounts now it's time to rethink how you're verifying customer identity. Good luck!

// faq

FAQ

// questions · 5
  • Analyze accounts that look real but don’t fully match across systems or show unusual credit activity, or behave differently from typical users. These small signals often point to bigger issues.

  • In fact, it affects both, but small businesses are often more vulnerable. Fraudsters tend to target easier entry points, not necessarily bigger companies.

  • One method alone isn’t enough anymore, especially when identities can be partially fabricated but still look normal. The most effective way is using layered verification – combining documents, behavioral data, and consistency checks.

  • Traditional systems check whether identity details match records – and synthetic identities are built to match. Because they mix real and fake data, they're hard to detect without behavioral monitoring and pattern analysis.

  • Be open about your security practices. It will ensure that clients understand how carefully you protect their data to prevent potential fraud. Such an approach creates confidence and strengthens long-term relationships.

subscribe.formFREE

// stay in the loop

Stay in the Loop

Get the latest articles on document security, PDF redaction, and data privacy delivered to your inbox.