Synthetic identity fraud combines a real identification number with fabricated personal details to create an identity that doesn't belong to anyone. Unlike stolen identity fraud, there's no victim monitoring the account for suspicious activity, which is why it can take months or years to catch. The fabricated identity often looks like a normal, creditworthy customer.
Globally, synthetic identity fraud costs businesses an estimated US$20 billion to US$40 billion annually, and fraud incidents are expected to keep growing.
Below, we'll cover how the fraud lifecycle works, how to prevent synthetic identity fraud, and why standard fraud detection tools can miss it.
Key takeaways
Synthetic identity fraud pairs a real identification number with a fabricated name and address, so there's no actual victim to flag suspicious activity.
The fraud typically unfolds over months or years through a credit-building phase before ending in a bust-out that exhausts available credit.
Businesses that offer fast onboarding, sign-up incentives, or credit to thin-file customers face the highest exposure to this type of fraud.
What is synthetic identity fraud?
Synthetic identity fraud happens when someone pairs a real piece of personal information, usually an identification number such as a Social Security number (SSN), with fabricated details such as an invented name, birthdate, or address. This creates a customer identity that doesn't correspond to a real person.
How does synthetic identity fraud work?
The synthetic identity fraud lifecycle plays out in stages.
Here's how it typically unfolds:
Identity creation
The fraudulent actor pairs a real identification number with a fabricated name, date of birth, and mailing address, then applies for a low-value credit product, such as a secured card or store card with lenient underwriting. Even a denied application helps because it links the identification number and fake name together in a credit bureau file, creating what the industry calls a credit profile number.
Credit building
Once that thin file exists, the identity behaves like a real borrower. This can last months or, more often, years. The fraudulent user might use the file to become an authorised user on someone else's account to inherit their payment history, make small purchases and pay them off on time, then gradually apply for more credit as the file thickens. These are common tactics in synthetic identity fraud.
Ring coordination
Some operations run dozens of synthetic identities at once, then cross-reference them as authorised users on each other's accounts to accelerate the build-up. This turns a slow, individual process into something closer to an assembly line.
The bust-out
Once an identity has built up enough credit, its handler maxes out every available line, including credit cards, personal loans, and buy now, pay later (BNPL) balances in a short window, sometimes just days, then disappears.
Incentive exploitation
On platforms with sign-up bonuses or referral rewards, the bust-out looks different. The identity might cash out rewards or exploit a promotional credit before going dormant rather than max out a credit line.
AI tools have changed the economics of synthetic identity fraud. In just minutes, generative models can produce a convincing fabricated ID document with a photo. Large language models (LLMs) can generate the consistent transaction histories and correspondence that previously required manual effort across dozens of fake profiles.
Why is synthetic identity fraud so hard to detect?
Most fraud detection systems are built to catch someone impersonating a real, identifiable person, but with synthetic identity fraud there's no real person to compare against. A synthetic identity's credit file looks legitimate because it was built the same way a real one would be: through on-time payments and gradually increasing limits. That's why it won't show up as fraudulent on a standard credit pull.
Identity verification rules based on document matching have similar blind spots. Someone can submit a driver's licence with a fabricated name that matches the address on file, and the identification number check will come back valid because the number itself is real, just misattributed. That application will clear every check in a rules-based system. The fraud only becomes evident at the bust-out, and by then the loss has already occurred.
Fraud teams often look at a small number of suspicious accounts scattered across a much larger customer base at any given moment. Because building a single synthetic identity takes months, teams should review accounts over time to spot a pattern rather than focus on a single transaction or account.
Which businesses are most at risk of synthetic identity fraud?
Synthetic identity fraud tends to concentrate wherever new-account incentives, credit extension, and thin-file customers intersect.
A few categories carry high exposure:
BNPL providers: These businesses often extend credit to first-time borrowers with limited credit history, which makes it harder to distinguish a legitimate new customer from a synthetic one.
Subscription platforms with free-trial or referral bonuses: There is financial incentive to create new accounts, but the identity verification during subscription signup is often lighter than what a bank would require.
Marketplaces with onboarding bonuses: A single ring can create dozens of accounts to claim signup credits or referral rewards before any one account draws attention.
Card issuers and consumer lenders: Those competing for new account volume with fast approval times are especially exposed since faster underwriting usually means less time to verify identity.
Businesses serving younger or credit-invisible populations: Student-focused financial products fall into this group because these customers naturally have thin credit files that make it harder to distinguish between a real first-time borrower and a synthetic one.
How do businesses prevent synthetic identity fraud?
To prevent synthetic identity fraud, start with where your exposure actually sits. If most of your new accounts come from customers with established credit histories, you have a different risk profile than you would with first-time borrowers or running sign-up incentives that draw higher fraud attempts. Map your fraud losses back to account age since synthetic identity losses cluster in accounts that are months or years old. When your chargeback and default data isn't segmented that way, it's hard to know how much of your loss is actually synthetic versus something else entirely.
From there, check whether your current verification is point-in-time or continuous. A one-time identity check at sign-up misses the behavioural drift that shows up during the credit-building phase, such as a sudden change in transaction patterns right before a bust-out. Stripe Radar addresses this by evaluating risk signals across the full customer lifecycle rather than only at account creation. It draws on patterns observed across Stripe's network of businesses to flag behaviour that looks inconsistent with how a legitimate account typically matures.
Whatever tools you use, plan for a testing cadence. Fraud rings change tactics, which means a detection setup, such as a specific device fingerprint pattern or a particular sequence of account behaviours, that works well this quarter can lose effectiveness next quarter if nobody reassesses it against new data.
What are the constraints and limitations of synthetic identity fraud prevention?
Machine learning models need historical examples of confirmed synthetic fraud to train on. Because this fraud type often isn't discovered until the bust-out, months or years after the account opened, the labelled data available for training is inherently delayed and incomplete.
There's also a trade-off between detection strength and sign-up experience. Requiring extra steps, such as a selfie match against a government ID or live video verification, catches more synthetic identities but adds complications that might make legitimate customers abandon the process partway through. Track your false-positive rate alongside your catch rate. It can be costly if legitimate customers are declined or pushed into unnecessary verification steps. Businesses have to decide how much of that trade-off they're willing to accept.
Cross-institution data sharing helps, too. A synthetic identity that looks clean at one business might show suspicious patterns across many others. But sharing is limited by privacy regulations and the fact that competitors don't always want to exchange fraud signals. Consortium data models address this; however, coverage varies by sector, and a business in a less-covered industry doesn't get the same benefit as one in banking or card issuing.
How Stripe Radar can help
Stripe Radar helps detect fraud and unlock growth, using AI trained on data from Stripe's global network. Radar helps protect your business from fraud throughout the customer lifecycle before it affects your bottom line, while helping you approve more legitimate customers and payments.
Radar can help your business:
Prevent fraud losses: Radar's AI learns from more than US$1.9 trillion in annual transactions across Stripe's global network, helping it identify and block fraud patterns that individual businesses may not catch on their own.
Unify protection across evolving fraud attacks: Radar brings protection against transaction fraud, account fraud, and customer abuse all into one solution, so you gain unified protection across major fraud types.
Adapt as fraud evolves: Radar continuously adapts to changing fraud patterns, from first-party abuse to agentic transactions, helping protect your business against emerging threats.
Work with your existing tech stack: Use Radar with Stripe payments with no integration required, or access Radar's intelligence through programmable APIs, whether you process payments on Stripe or not.
Learn more about Stripe Radar or get started today.
FAQs about synthetic identity fraud
The content in this article is for general information and education purposes only and should not be construed as legal or tax advice. Stripe does not warrant or guarantee the accuracy, completeness, adequacy, or currency of the information in the article. You should seek the advice of a competent lawyer or accountant licensed to practise in your jurisdiction for advice on your particular situation.