Thursday, September 17, 2026
25.9 C
Los Angeles

Former Georgian Defense Minister Juansher Burchuladze Receives Reduced Sentence in Plea Deal

A high-profile criminal case involving former Georgian...

Singapore Moves to Strengthen Stablecoin Regulation Under Proposed Payment Services Act Amendments

Singapore is moving to formalise and strengthen...

Former Ecuador President Lenín Moreno Sentenced to Five Years in Prison in Sinohydro Bribery Case

Former Ecuadorian President Lenín Moreno has been...

Synthetic Identities: When the Fraudster Stops Stealing People and Starts Inventing Them

AI/MLSynthetic Identities: When the Fraudster Stops Stealing People and Starts Inventing Them

The defining challenge for banks is shifting from “Is this information genuine?” to “Does this customer actually exist?”

Synthetic identity fraud combines real and fabricated personal information to create identities capable of passing conventional onboarding, credit and authentication checks. Unlike traditional identity theft, there may be no single victim whose identity has been stolen. Instead, criminals assemble a convincing profile from fragments of legitimate data and invented attributes.

The model is particularly effective because it rewards patience. A synthetic customer may initially open a low-limit account, make regular payments and gradually establish a credible financial history. Once sufficient trust and credit capacity have been accumulated, the fraudster can execute a so-called “bust-out” — maxing out credit facilities, taking loans or purchasing goods before abandoning the identity.

The consequences can be difficult to trace because investigators may ultimately discover that the customer they are pursuing never existed as represented.

The scale of the problem is becoming clearer

The U.S. lending market provides a significant indication of the financial exposure. TransUnion estimated that lender exposure to synthetic identities across auto loans, bank cards, retail cards and unsecured personal loans reached $3.3 billion at the end of 2024, the highest level recorded in its dataset.

That figure represents exposure rather than a universal estimate of realised losses. Measuring synthetic identity fraud remains difficult because cases can be recorded as ordinary credit defaults or first-party fraud.

That classification problem creates a second risk: institutions may underestimate the effectiveness of their own controls because a synthetic customer who defaults can look like a conventional credit-loss case rather than a fraud case.

The threat is also extending beyond individual consumers. The Federal Reserve has warned about synthetic business fraud, in which criminals construct apparently legitimate companies using fabricated or manipulated addresses, telephone numbers, officers and other corporate information.

The potential payoff is significantly greater. A synthetic company may gain access to larger credit facilities, payment accounts and commercial transactions, turning identity fabrication into a vehicle for much larger financial flows.

Generative AI changes the economics

Synthetic identities are not new. What is changing is the cost and speed at which they can be created.

Historically, fraudsters needed considerable effort to assemble supporting information, maintain email and telephone accounts, produce documents and establish credible financial histories. Generative AI can now automate or accelerate many of these activities.

Text-generation tools can produce convincing communications and application narratives. Image-generation and manipulation technologies can create or alter documents. Voice and video synthesis can make remote interactions more difficult to authenticate. Automated systems can maintain activity across large numbers of accounts.

The result is an economic shift: activities that once required specialised skills and substantial manual effort can increasingly be performed at scale.

Experian has reported that a large majority of surveyed U.S. business leaders expect AI-generated fraud and deepfakes to become a significant challenge. TransUnion has similarly warned that generative AI is making static identity verification less effective.

The problem for financial institutions is straightforward: a document, photograph or voice sample can appear authentic without proving that the underlying identity is authentic.

Fraud is becoming an industrial supply chain

Synthetic identity fraud increasingly resembles an ecosystem rather than an isolated criminal act.

Stolen personal information can provide the raw material. Data obtained through breaches, social engineering or illicit markets can be combined with fabricated information. AI tools can produce synthetic media. Mule networks can move funds. Other participants may specialise in opening accounts, building credit histories or monetising the resulting accounts.

The broader financial-crime environment reflects the same trend.

The Financial Action Task Force reported in February 2026 that 156 jurisdictions, or 90% of those assessed, identified fraud as a major money-laundering risk. INTERPOL’s 2026 assessment similarly described the industrialisation of fraud as criminal networks increasingly combine AI, inexpensive digital tools and international collaboration.

Synthetic identities fit naturally into this environment because the identity itself can become reusable infrastructure.

A convincing identity can potentially open a bank account, obtain credit, establish a merchant relationship, receive payments, create a company or act as a financial intermediary.

The criminal asset is no longer merely stolen personal information. It is a manufactured identity with an operational financial history.

Why conventional KYC can create false confidence

Traditional KYC controls remain fundamental, but synthetic identities expose a weakness in relying too heavily on individual data points.

A bank may establish that:

  • the identification number is valid;
  • the document is genuine;
  • the address exists;
  • the telephone number works;
  • the applicant’s name is not on a sanctions list; and
  • the biometric check passes.

Every individual answer can be correct while the overall identity is fabricated.

The challenge is therefore moving from data validation to identity coherence.

Financial institutions increasingly need to ask whether the pieces make sense together.

Does the applicant’s address correspond with independent records? Does the telephone number have an appropriate history? Has the same device been associated with apparently unrelated customers? Does the customer’s behaviour match the profile declared at onboarding? Are several accounts sharing infrastructure that should logically be independent?

These questions require institutions to connect information that traditionally sits in separate systems.

The most dangerous synthetic customer may look perfectly normal

Synthetic identity fraud creates an unusual problem for conventional fraud models: the strongest signal may be the absence of obvious signals.

A fraudster building an identity has an incentive to behave normally.

The account may make payments on time. Credit utilisation may remain low. Contact information may remain consistent. Transactions may initially resemble those of an ordinary customer.

Normality is part of the deception.

That makes synthetic identities particularly difficult for systems designed primarily to identify anomalies at the point of application or transaction.

The meaningful evidence may only become visible when multiple identities are examined together.

A shared device, address, IP range, employer, telephone number, funding source or beneficiary may reveal relationships that are invisible when each account is assessed independently.

This is where graph analytics and network intelligence become increasingly important. The objective is not simply to determine whether one applicant appears legitimate, but whether that applicant belongs to a wider network of identities and infrastructure that does not make sense.

AI is becoming both the weapon and the defence

Artificial intelligence is accelerating synthetic identity fraud, but the same technologies can help institutions identify it.

Machine-learning systems can detect behavioural inconsistencies, identify relationships between apparently unrelated applicants, analyse documents and recognise patterns that static rules may miss.

The challenge is that defensive AI depends on the quality and breadth of the underlying data.

One financial institution may have strong document verification but limited device intelligence. Another may have sophisticated transaction monitoring but little visibility across different products. A third may not connect its fraud, KYC and credit information effectively.

Synthetic identities thrive in those gaps.

The emerging model is therefore less about finding a single “perfect” fraud-detection technology and more about orchestrating multiple sources of evidence.

Device intelligence, behavioural analytics, document verification, biometrics, public records, credit information, transaction monitoring and customer information need to contribute to a common identity-risk picture.

The objective should not be maximum friction. It should be targeted friction when the evidence becomes inconsistent.

No single institution sees the entire identity

Another structural problem is that synthetic identities often operate across institutions.

A bank may see the account.

A fintech may see the wallet.

A lender may see the credit application.

A telecommunications provider may see the phone number.

A payment company may see the transaction.

Individually, each signal may look unremarkable. Collectively, they can reveal the fraud network.

That is making information sharing increasingly important.

Recent Federal Reserve guidance concerning FinCEN’s Section 314(b) framework has highlighted circumstances in which participating financial institutions can share information concerning suspected fraud associated with money laundering or terrorist financing.

The broader principle is significant: networked financial crime requires networked intelligence.

International law-enforcement operations are moving in the same direction. INTERPOL’s Operation First Light 2026 involved 97 countries and territories and resulted in thousands of arrests and hundreds of millions of dollars in illicit assets being intercepted.

Although the operation covered a broader range of scams and financial crime, it demonstrates the scale of international cooperation increasingly required to disrupt modern fraud networks.

The compliance challenge is no longer simply KYC

For financial institutions, the implications extend beyond strengthening onboarding.

The emerging control environment needs to address the entire identity lifecycle.

An identity that looks credible on day one may become suspicious six months later. A customer may begin displaying connections to other accounts, devices or payment networks that were invisible during onboarding.

Continuous monitoring can therefore become as important as initial verification.

Institutions should also connect data across products and channels. Fragmented customer records can allow the same device, address or telephone number to appear across multiple supposedly unrelated identities without triggering meaningful alerts.

Most importantly, financial institutions need to distinguish between document authenticity and identity authenticity.

A genuine document proves that the document exists and may be valid. It does not necessarily prove that the person presenting it is the person represented by the document or that the broader identity is coherent.

Fraud detection must also avoid creating excessive friction

There is a competing risk.

Banks cannot respond to synthetic identity fraud by requiring every legitimate customer to undergo increasingly complex verification. Excessive friction can increase abandonment, damage customer experience and disproportionately affect customers with thin credit histories or limited conventional documentation.

The more sustainable approach is risk-based.

Straightforward customers should be able to complete onboarding efficiently. Customers presenting contradictory or unusual evidence should receive additional verification, investigation or human review.

This also makes false positives an important part of the equation.

A fraud system that catches suspicious identities but routinely rejects legitimate customers may create a different form of operational and reputational risk.

The objective is therefore not simply to increase the number of fraud alerts. It is to improve the quality of the institution’s understanding of identity risk.

What financial institutions need to reconsider

The rise of synthetic identities points toward several changes in financial-crime controls:

Identity should be treated as a lifecycle.
Verification should not end when an account is opened.

Data should be connected across products.
Repeated devices, addresses, telephone numbers, beneficiaries and funding sources can expose relationships between apparently unrelated customers.

Document verification should not stand alone.
A genuine document does not necessarily establish a genuine identity.

Credit losses should be examined for potential fraud.
Synthetic bust-outs can easily be recorded as ordinary defaults, masking weaknesses in onboarding and monitoring.

Investigators need contextual evidence.
A risk score is less useful than understanding why several customers appear connected through infrastructure that should be independent.

Ambiguity should trigger investigation rather than automatic rejection.
The most sophisticated synthetic identities may not look obviously fraudulent; they may simply fail to make sense when the evidence is viewed collectively.

The customer who never existed

Synthetic identity fraud represents a fundamental change in the identity problem facing financial institutions.

Traditional identity theft asks: Who has stolen this person’s identity?

Synthetic identity fraud asks a different question:

Who created this identity — and does the person it represents exist at all?

Generative AI is making that question harder because convincing documents, images, voices and digital histories can increasingly be manufactured at scale.

The response will require more than stronger document checks or better onboarding forms. Financial institutions need to develop a broader understanding of identity — one that incorporates behaviour, relationships, devices, transactions, historical information and external data.

The future of identity verification is therefore unlikely to be determined by whether an individual piece of information is genuine.

It will depend on whether the entire identity makes sense.

And in an increasingly automated financial system, that may become one of the most important questions a bank can ask before deciding to trust a customer.

By FCCT Editorial Team

Disclaimer: The views expressed in this article are independent views solely of the author(s) expressed in their private capacity.

Check out our other content

Ad


Check out other tags:

Most Popular Articles