Synthetic Identity Fraud: How Fake People Get Loans
Synthetic identity fraud is the creation of a fake person from a mix of real and invented data, usually a genuine ID number paired with a different name and an AI-generated face. Fraudsters use these identities to open accounts, build credit and then borrow with no intent to repay. Because no real victim exists, the losses often look like ordinary bad debt.
What Synthetic Identity Fraud Is and How It Differs From Identity Theft

The Federal Reserve defines synthetic identity fraud as the use of a combination of personally identifiable information to fabricate a person or entity for dishonest gain. The key word is fabricate. Unlike the impersonation cases that identity verification usually targets, the fraudster is not pretending to be someone who exists. They are inventing someone new, often from pieces of several real people.
That difference changes how the fraud surfaces. In identity theft, a victim eventually notices a loan they never took and complains. With a synthetic identity, nobody complains, because the “customer” does not exist. So the account looks normal for months, and when it defaults, the lender usually books it as a credit loss rather than fraud.
| Identity theft | Synthetic identity fraud | |
|---|---|---|
| Who is the customer? | A real person, impersonated | A person who does not exist |
| Data used | One victim’s full identity | Real fragments from several sources plus invented details |
| Face on file | The victim’s, or a spoof of it | A stranger’s face, an AI-generated face or a morph |
| Who notices it | The victim, who reports it | Often nobody, or only the collections team after default |
| Where the loss lands | Fraud losses | Often bad debt |
Manipulated vs Manufactured Synthetic Identities
Fraud teams usually split synthetic identities into two kinds. The difference matters, because each one leaves different evidence behind.
- Manipulated identities start from one real person and alter a few details, such as a changed digit in the ID number or a new date of birth. They often pass loose data checks because most fields still look valid.
- Manufactured identities combine fragments from several people, or invent most of the record outright. They tend to arrive with a generated face, a new phone number and a fresh email address.
In practice, manipulated identities show up as data inconsistencies, while manufactured ones show up as a thin, very recent footprint. A good onboarding flow looks for both.
How Fraudsters Build Synthetic Identities: Real ID Number Plus Fake Face
Fraudsters assemble a synthetic identity, grow it, then cash it out. Each stage leaves different traces, which is why detection works best when it watches more than one stage.
Stage 1: Assemble the Identity
The base is usually one real identifier, such as a national ID number taken from a data breach. Often it belongs to someone unlikely to check their records, such as a child, an elderly person or someone recently deceased. The fraudster then adds a new name, a date of birth, a phone number, an email address and a face. Today, fraudsters increasingly generate that face with AI, so it matches no real person.
Stage 2: Pass Onboarding and Build History
Next, the identity applies for something easy: a prepaid card, an e-wallet, a small BNPL limit. Some applications fail, and the fraudster simply tweaks details and tries again. Each approval creates a record, and each record makes the next application look more credible. Fraud teams call this “cultivating” the identity.
Stage 3: Bust Out
Finally, once limits have grown, the identity borrows as much as it can across every lender at once, then disappears. Collections teams chase a person who never existed. Because one fraud ring often runs dozens of identities in parallel, a single bust-out can hit several lenders in the same week.
How Generative AI Changed the Synthetic Identity Playbook
Synthetic identities are not new, but they used to be slow to make. A convincing ID, a face that matched it and supporting documents took time and skill. Generative AI removed most of that effort.
A Federal Reserve toolkit on the subject, published in November 2024, describes how. According to the toolkit, generative AI lets fraudsters automate identity creation and produce authentic-looking documents such as payslips, bank statements and utility bills. It also notes that AI tools can produce deepfake images and videos that respond to questions during account opening. The same toolkit gives an example of the system learning from failure: if a lender rejects an older synthetic applicant with a new credit history, the tool simply makes the identity younger.
The scale has grown with it. According to the same Federal Reserve toolkit, synthetic identity fraud cost an estimated $35 billion in 2023, a figure for the US market. No public body has released a comparable total for Southeast Asia, but fraudsters use the same tools everywhere.
The face is now the weakest link. A generated face passes face matching against a forged ID, because both images came from the same source. Our guide to detecting deepfakes explains why matching alone cannot see this.
Why Synthetic Identities Target Lending and BNPL First

Synthetic identities need credit to grow, so they gravitate to products that extend it fast. Digital lending, BNPL and credit cards fit that profile. Three features make them especially exposed.
- Thin-file approval. In many Southeast Asian markets, a large share of applicants have little or no credit history. So a new identity with no history does not stand out, because many genuine customers look the same.
- Speed as a selling point. Instant approval leaves little room for manual checks, especially at small first limits.
- Limits that grow automatically. Good repayment on a small limit unlocks a larger one, which is exactly the path a cultivated identity follows.
E-wallets and digital banks face a related risk. Here, fraud rings often use synthetic accounts as mule accounts to receive and move scam proceeds, rather than to borrow. The account may never default, yet it still moves stolen money for a fraud ring.
Warning Signs of a Synthetic Identity at Onboarding
No single signal proves an identity is synthetic. Several together, however, should push an application into review:
- An ID number whose issue details clash with the stated date of birth or name.
- A phone number, email or address shared with other recent applicants.
- An email address or phone number created only days before the application.
- Many applications for the same identity across products within a short window.
- A selfie or ID portrait flagged as generated, or a face that matches another account.
- Device signals linking the application to other identities, such as one phone behind many names.
After approval, watch for the classic bust-out pattern: steady small repayments, a quick series of limit increases, then maximum use of every available line at once.
Detecting Synthetic Identities: Deduplication, Liveness, Deepfake and Device Signals
No single control catches synthetic identities, because fraudsters build each one to pass the obvious checks. Instead, effective programmes stack controls that look at different evidence. The table maps the main ones.
| Control | What it catches | What it misses on its own |
|---|---|---|
| Authoritative database check | ID numbers that do not match the registered name, birth date or photo | Markets or products without access to a government database |
| Face deduplication (1:N search) | The same face reused behind several names | A fresh AI face used only once |
| Liveness detection | Photo prints, replays on a screen and masks | Injected or real-time deepfakes |
| Deepfake detection | AI-generated and face-swapped selfies, and generated ID portraits | Fraud that uses a real accomplice’s face |
| Device signals | Emulators, cloned apps and one device behind many applications | Rings that buy a fresh phone per identity |
| Behaviour and velocity monitoring | Bust-out patterns, sudden limit use across lenders | The identity before it cashes out |
Start With an Authoritative Source Wherever You Can
The strongest single check is matching the applicant against a government record that includes a photo. A synthetic identity can borrow a real ID number, but it cannot change the photo the state holds for that number. Several markets now require exactly this. For example, Vietnam’s Decision 2345 and its follow-up rules require banks to match customers against chip-based citizen ID data.
Then Check That the Face Is Real
Where no database check is available, the selfie carries more weight. In that case, liveness and deepfake detection need to run together, because AI usually generates a synthetic identity’s face. The VeriSecure SDK runs both on one capture and checks the device for emulators and injection. Separately, Verihubs deepfake detection can screen ID portraits and selfies your current flow already collects.
Watch the Device and the Account Afterwards
Finally, fraud rings usually run synthetic identities in batches. So one phone, one IP range or one cloned app often sits behind many applications. Device signals and post-onboarding monitoring catch the ring even when each identity looks clean. For the wider set of tools, see our overview of how a fraud detection system works.
Frequently Asked Questions About Synthetic Identity Fraud
What is synthetic identity fraud?
Synthetic identity fraud is the creation of a fake person from a mix of real and invented information, then using that identity to open accounts or borrow money. The Federal Reserve defines it as combining personally identifiable information to fabricate a person or entity for dishonest gain.
How is synthetic identity fraud different from identity theft?
Identity theft impersonates a real person, who usually notices and reports it. Synthetic identity fraud invents a new person, so there is no victim to raise the alarm, and losses often look like bad debt.
How do fraudsters create a synthetic identity?
They usually start with a real ID number from a data breach, then add a new name, contact details and a face. Today they often generate the face with AI, and they can generate supporting documents such as payslips too.
Why is synthetic identity fraud hard to detect?
Fraudsters design each identity to pass standard checks, and it behaves like a good customer for months before cashing out. Face matching does not help when the same AI model produced both the ID photo and the selfie.
How can lenders detect synthetic identities?
Lenders combine checks: matching against government records, face deduplication across applications, liveness and deepfake detection on the selfie, device signals, and monitoring for bust-out behaviour after onboarding.
Does liveness detection stop synthetic identity fraud?
Only partly. Liveness stops printed photos, replays and masks, but a generated face delivered through an injected stream can pass. Deepfake detection and device checks need to run alongside it.
What are the warning signs of synthetic identity fraud?
Common signs include contact details shared with other applicants, very new email addresses and phone numbers, ID details that clash with the stated birth date, AI-flagged selfies, and one device behind several identities.
Synthetic Identity Fraud Is a Lending Problem Disguised as a Credit Problem
The most expensive thing about synthetic identities is not the fake face. It is the accounting. When a synthetic borrower defaults, the loss usually lands in credit risk, so fraud teams never see it and models learn the wrong lesson. Some lenders that believe they have a credit quality problem may actually have a fraud problem.
Generative AI makes the fix more urgent, because it removed the cost that used to limit how many identities a ring could run. The response is not one better check but a sequence: an authoritative source where possible, then a face that is real and captured live, then a device and account that behave like one person. Each layer is imperfect. Together, they turn a cheap, scalable attack back into an expensive one.
Building a synthetic identity defence for lending or BNPL? Talk to Verihubs about combining liveness, deepfake and device checks in your onboarding.