Back to Blog

[.green-span]What is synthetic identity fraud? A guide for lenders[.green-span]

BY
Lendflow Research Team
September 22, 2026
Synthetic identity fraud combines real and fabricated PII to invent a person who does not exist, then builds credit before a bust-out. Learn how it works, who is at risk, and how lenders detect and prevent it with layered, automated verification.
Strategy
Technology
Marketing

What is synthetic identity fraud? A guide for lenders

Introduction

Synthetic identity fraud is the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain, according to the Federal Reserve's industry-recommended definition. The NIST glossary offers essentially the same definition. Unlike traditional identity theft, there is no single clear victim, so the fraud is harder to catch and often booked as bad debt. Loss exposure for US lenders recently hit an all-time high of $3.3 billion, according to TransUnion. This guide explains how synthetic identities are built, how the fraud unfolds, who is vulnerable, the warning signs, and how lenders detect and prevent it.

How synthetic identity fraud works

Synthetic identity fraud stitches together real and fake data to create a person who does not exist. Fraudsters typically combine a real Social Security number with invented names, dates of birth, and contact details.

The PII that fuels a synthetic identity

Fraudsters assemble two layers of personal data to make a synthetic identity look legitimate.

  • Primary elements: name, date of birth, Social Security number, and government IDs.
  • Supplemental elements: address, phone number, email, and digital footprint.

Three ways synthetic identities are created

According to Equifax and Plaid, fraudsters build synthetic identities through three main methods.

  • Identity compilation: pairing a real SSN with invented personal information.
  • Identity manipulation: altering a real document or real data points slightly.
  • Identity fabrication: assembling entirely false data with no real anchor.

Why the problem is growing

Three forces are accelerating synthetic identity fraud, Plaid reports. More stolen PII is available on the dark web. The Social Security Administration's move to SSN randomization made fabricated SSNs harder for legacy algorithms to spot. Generative AI now lets fraudsters create and document synthetic identities at scale.

Synthetic fraud versus traditional identity theft

Traditional identity theft hijacks a real person's full identity, which produces a victim who notices and reports the crime. Synthetic identity fraud fabricates a new identity with no single clear victim. TransUnion and Plaid note that this makes it harder to detect and prosecute, and it is frequently miscategorized as bad debt or charge-offs.

That miscategorization matters for lenders. When a synthetic identity busts out, the loss often lands in a charge-off bucket rather than a fraud report. As a result, true fraud rates look lower than they are, and the identities behind them keep opening accounts elsewhere.

How Lendflow helps catch synthetic identities at onboarding

Synthetic identities pass single-point checks because no real victim exists to contradict them. Lendflow addresses this with multilayered, automated, explainable verification built into the lending workflow.

  • Lendflow Connect provides embedded lending orchestration that links to a network of data and verification partners through one integration. Lenders can run identity, KYB, and credit checks and build decline and second-look waterfalls without stitching together dozens of vendors.
  • Lendflow Automate adds an AI-agent layer. Its Doc Analyzer and Data Extraction Agent pulls and validates structured data from PDFs, IDs, tax returns, and bank files, which helps catch fabricated or altered documents. It supports 80% faster document review and 65% faster time-to-decision.
  • Lendflow Intelligence turns complete data into decisions and surfaces fraud indicators. Its SMB Intelligence sees patterns across the financing ecosystem rather than one portfolio, so it can flag synthetic patterns like stacking and high velocity, with 85% faster time-to-decision.

The five-stage synthetic identity fraud lifecycle

TransUnion maps synthetic identity fraud to a five-stage lifecycle. Understanding each stage helps lenders decide where to intervene. The earlier a lender acts, the cheaper the outcome, because a synthetic identity gets harder to distinguish from a real borrower as its credit history matures.

  1. Data acquisition. Fraudsters collect real and fabricated PII, often sourcing stolen SSNs from the dark web.
  2. Identity creation. They combine the data into a coherent synthetic profile with matching supplemental details.
  3. Credit file establishment. They apply for low-value cards or become an authorized user to seed a credit file.
  4. Credit building. They spend small amounts and pay on time to build a trustworthy history and rising limits.
  5. Bust-out fraud. They max out every available credit line at once and disappear, leaving lenders with the loss.

A common tactic is "piggybacking," where a synthetic identity is added to an established credit profile, Plaid explains. This borrows legitimacy and speeds the identity through the credit-building stage.

Who is most vulnerable

Some people make ideal targets because their SSNs rarely trigger alerts, according to Equifax and Plaid.

  • Children, whose SSNs are unused for years.
  • Elderly and deceased individuals, whose files go unmonitored.
  • People with thin or unmonitored credit files, because dormant SSNs stay quiet.

The scale and cost

The numbers show why this belongs on every risk roadmap. TransUnion found synthetic identity fraud loss exposure for US lenders grew 3% to $3.3 billion at the end of 2024, across open credit cards, retail cards, auto and personal loans. That is an all-time high since tracking began in 2009. TransUnion also reported that 6.5% of all new account transactions in 2024 were suspected digital fraud, and roughly 0.32% of attempted account openings involve synthetic identities. Broader Javelin research put total identity fraud losses at nearly $27.2 billion in 2024, up 19% year over year. The most exposed industries are financial services, telecom, healthcare, government, real estate, and ecommerce.

Best practices to detect and prevent synthetic identity fraud

Traditional single-point checks fail here because synthetic identities do not match a real victim's records. A synthetic profile can clear a name, SSN, and address match while still being fabricated. A multilayered, automated approach works better, Plaid and TransUnion advise, because it looks at behavior and relationships rather than one data point.

Watch for these warning signs

Train models and reviewers to flag the red flags that cluster around synthetic identities.

  • Recently created thin credit files, or limited history despite a claimed older age.
  • One SSN tied to multiple identities.
  • Addresses linked to multiple unrelated identities.
  • Phone numbers registered to different names.
  • High-velocity account openings across institutions.
  • Mismatched or inconsistent application data.

Build layered verification

No single check catches a well-built synthetic identity. Combine several layers instead.

  • Verify identity against authoritative data sources using data, documentary, and liveness checks.
  • Apply machine learning and neural networks to spot anomalies like recent file creation, thin history, suspicious velocity, and shared device IDs, IPs, or email domains.
  • Run document verification with OCR and facial matching to catch altered or fabricated files.
  • Use network and consortium fraud intelligence to see patterns beyond your own portfolio.

Common pitfalls to avoid

  • Relying on a single data source, which synthetic identities are built to pass.
  • Treating losses as ordinary charge-offs, which hides the true fraud rate.
  • Reviewing documents manually, which is slow and misses subtle alterations.
  • Ignoring cross-institution velocity, which is often the clearest bust-out signal.

Conclusion

Synthetic identity fraud fabricates a person from a mix of real and fake PII, then builds credit patiently before a bust-out. With no clear victim, it evades single-point checks and hides inside bad-debt figures, which is why US lender loss exposure reached a record $3.3 billion. The defense is layered and automated: authoritative data verification, document analysis, anomaly detection, and network-level intelligence applied at account opening and underwriting. Lendflow brings these layers together through Connect, Automate, and Intelligence, so lending teams can flag synthetic patterns early with explainable, automated checks instead of manual single-point review.

Frequently asked questions

What is synthetic identity fraud in simple terms?

It is when a fraudster combines real and fake personal information to invent a person who does not exist, then uses that identity for financial gain.

How is synthetic identity fraud different from identity theft?

Traditional identity theft steals a real person's full identity, so there is a victim who reports it. Synthetic fraud fabricates a new identity with no single clear victim, which makes it harder to detect and prosecute.

Who is most at risk of having their information used?

Children, the elderly, deceased individuals, and people with thin or unmonitored credit files are common targets, because their dormant SSNs rarely trigger alerts.

How much does synthetic identity fraud cost lenders?

TransUnion found US lender loss exposure grew 3% to $3.3 billion at the end of 2024, an all-time high since tracking began in 2009.

How can lenders detect synthetic identities?

Use layered verification: authoritative data checks, document verification, machine learning anomaly detection, and network-level fraud intelligence applied at onboarding rather than a single point-in-time check.

Learn More