Synthetic identity fraud is hard to detect because every piece of a synthetic identity can check out on its own. The Social Security number is valid, the credit file exists, the address receives mail and the phone number answers. To find one, stop checking the pieces one at a time and ask whether a life surrounds them. Does the identity have the age, the incidental history and the connections to other people that anyone accumulates without meaning to? A synthetic identity is built to pass inspection. It is rarely built to have a past.
What a synthetic identity is
The Federal Reserve's industry-recommended definition is the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain. In the US the usual recipe is a real Social Security number combined with a name and date of birth that belong to nobody. The number is typically taken from someone without an active credit profile, and the Fed notes that children's numbers are the favourite, because they usually go unused until the child's late teens and almost nobody is watching them.
Because the person does not exist, nobody checks the identity's credit report or disputes a charge on its accounts. The crime still has a victim. As the Boston Fed points out, the real owner of the number, often a child, can find their credit ruined and not learn about it until they are old enough to apply for credit or a job. What the fraudster relies on is the silence in between, and it can last for years.
How a synthetic identity gets a credit file
The credit bureaus create the file themselves. As the Boston Fed describes it, the first application in the new identity's name is usually rejected, because there is no credit history. But the lender's inquiry leaves the bureau holding a file for the identity. The fraudster keeps applying until a lender approves something small, and from then on the identity builds a record like anyone else.
The record can be accelerated. The Fed describes fraudsters adding a synthetic identity as an authorised user on well-established accounts with high credit limits, a practice it calls piggybacking, so the new identity inherits years of someone else's repayment history. The real account holder is sometimes paid to allow it.
Then, usually after months or years of on-time payments, the identity borrows as much as it can across every account it holds and stops paying. The Fed's term for this is busting out: maxing out a line of credit with no intention to repay. The Federal Reserve's own toolkit makes the point that matters most for detection: until that moment, a synthetic identity in a portfolio often behaves like a model customer, and once the loss happens there is often nothing to show it was fraud. It looks like a real customer who could not pay.
Credit bureau data put US lenders' exposure to suspected synthetic identities, across auto loans, bank and retail credit cards and unsecured personal loans, at a record $3.3 billion at the end of 2024 and $2.7 billion at the middle of 2025.
Why the usual checks pass it
A typical KYC check asks whether the name, date of birth, address and Social Security number on an application appear together in credit and data sources. After a few months of applications, they do. The bureaus and data brokers hold the identity because the fraudster's own activity put it there, so a check that compares data against data is checking the synthetic identity against itself. The Fed's detection guidance says as much: synthetic identities often pass KYC verification.
Document checks stop crude attempts. Where a document is needed at all, a good forgery or a generated one can get through, and many digital onboarding flows never ask for one.
Behavioural and credit models see perfect repayment right up to the bust-out, because the repayment is real. There is nothing wrong to see until there is a lot wrong all at once.
One older check stopped working in 2011. Until that June the first three digits of a Social Security number tied it to the state that issued it, and numbers were assigned in a known sequence, so a number could be tested for plausibility against an applicant's age and where they said they grew up. The Social Security Administration's randomisation ended both, and that plausibility test went with them for every number issued since.
The strongest single control in the US goes to the source. The Social Security Administration's eCBSV service, rolled out from late 2020, lets banks and other financial institutions check, with the customer's written consent, whether a name, date of birth and Social Security number match SSA's records, and tells them which element does not. It catches the most common recipe, a real number under an invented name, and any lender that can use it should. It also has limits. SSA says plainly that it does not verify a person's identity: it confirms that three pieces of data belong together. It depends on a Social Security number and the customer's consent, and it does nothing for the many platforms that onboard people without collecting a Social Security number at all: marketplaces, gig platforms, many payments and crypto products, and anyone outside the US.
What a real identity has that a synthetic one does not
Set the data aside and look at the life around it. Three things are hard to manufacture.
Age that agrees with itself. A real adult's email address, phone number, address history, credit file and online presence all start at different times, most of them long before today's application. A synthetic identity's traces tend to begin together, at roughly the moment it started applying for credit.
Incidental presence. Real people leave traces they never curated: a review of a local garage, a name on a race results page, a post in a hobby forum, an old account on a service nobody uses any more. None of it was created to prove anything, which is exactly why it is expensive to fake. We made the same argument about fake job candidates, and it holds for the same reason.
Other people. A real person is connected to other real people: relatives at the same address over many years, colleagues who list the same employer, a partner on a lease. A synthetic identity's connections are thin, or they loop back into the other identities in the same ring.
The signals worth checking
| Signal | What it looks like | The innocent explanation to rule out |
|---|---|---|
| Age mismatch | An eight-year credit file, and an email address with no trace older than 18 months | A genuinely new email address, which people do change |
| Shared attributes | The same address unit, phone, device or email pattern across applicants with different surnames | Families, flatmates and shared devices |
| Borrowed history | A file whose age comes mainly from authorised-user accounts belonging to strangers | A parent adding a child as an authorised user, which is common and legitimate |
| Throwaway infrastructure | Mail forwarding addresses, virtual offices, prepaid or internet phone numbers | Many real people use internet phone numbers |
| An empty life | No public records beyond credit, no professional or social presence, nobody else ever mentions them | Privacy-conscious people, recent arrivals, the young |
Every one of these signals has a common innocent cause, which is why the right-hand column is there. The useful question is whether several of them line up on one applicant.
Shared attributes deserve particular attention, because they are the signal a synthetic ring cannot easily avoid. A ring running dozens of identities has a limited supply of addresses, phones and devices, and it reuses them. That reuse is invisible to anyone looking at one application at a time and obvious to anyone looking across all of them.
A worked example
The run below is a composite assembled from the pattern, not one real case.
An application for an unsecured personal loan. The credit file is six years old, the score is respectable, and the history consists of two authorised-user accounts opened long ago on other people's cards and one card of the applicant's own, opened three years ago and paid on time every month. Every data-match check lines up.
The research starts from what the application contains: the name, the email address, the phone number and the address.
The email address appears in no public source older than fourteen months, and in no breach records at all. The phone number is an internet phone number. The address is a unit in an apartment building, and three other applications to the same lender in the last two quarters gave the same unit, under three different surnames. There is no professional profile and no social account older than a year.
One thing does not fit. A university alumni list carries the same name with a graduation year that matches the stated date of birth. The name is fairly common, so it may be someone else entirely, or it may be the one genuine anchor in the file. The research cannot say which, and pretending otherwise would be guessing.
So the output is an identity whose data checks out and whose life appears to begin about eighteen months ago, sharing an address with three other applicants, plus one open question. That is more than enough to route the application to step-up verification, and not enough to call it fraud.
When to run the check
At onboarding, because that is the cheapest point to stop a synthetic identity. But also at the moments a patient fraudster is waiting for: a large credit line increase, a new high-limit product, a sudden request for more after a long quiet period. A real customer's footprint keeps growing between those points. A synthetic identity's often does not, which gives a second look at month eighteen something to find that the first look at month zero could not.
What defeats this
An identity that was aged on purpose. Operations that open email accounts, social profiles and phone numbers years before they use them, and let those accounts sit, will produce a footprint that looks earned, because in a sense it was. Aged accounts are also bought and sold for exactly this reason.
An identity that borrows a real person's life. The closer a synthetic identity sits to a real person's details, the more of that person's genuine footprint it can lean on.
This approach raises the cost of a convincing synthetic identity. It does not make one impossible, and the identities that get through are the ones somebody spent real time and money on.
Reading a thin file fairly
Plenty of real people have thin files and thin footprints. Young adults. People who arrived in the country recently. People who have simply stayed out of credit. People who keep off the internet on purpose, including people who have left an abusive partner and removed every trace they could. The CFPB's most recent estimate, published in 2025 from December 2020 data, is that 2.7 percent of US adults, about 7 million people, have no credit record at all. That count leaves out everyone whose record is merely thin.
A system that reads thinness as fraud declines exactly the people who most need a first credit product, for a reason none of them could do anything about.
So treat thinness as a reason to verify further, not a reason to decline. The signals that point to fraud rather than to a quiet life are contradictions and sharing: traces that disagree about the identity's age, and attributes that turn up under other names. Absence on its own should only ever buy a closer look.
How Sixtyfour runs it
Sixtyfour's agent starts from what the application already contains, usually an email address, a phone number, a name and an address, and researches outward across breach records, public records, social and professional profiles, archived pages and other public sources. It weights each hit by how hard it would have been to manufacture, so a forum post from 2016 in a thread with other people replying counts for far more than a profile created last month. Every finding comes back with its source, and anything it could not establish is reported as open.
It informs the step-up decision, and the credit decision stays with your team. There is more on how it fits a fintech or lender's review process on our financial institutions page.