Synthetic identity

An identity built from data that doesn't belong to any real person. What defines it, how it differs from identity theft, and why that difference decides when it gets uncovered.

In short

A synthetic identity is an identity built to look like a real person's, without that person existing. It is assembled by combining real data from different sources with invented data, or by generating the whole set, and the result is a coherent profile on paper that belongs to no one.

The key is coherence: this is not one false data point inside an otherwise correct file, but an entire file built to withstand the usual checks — because it was built for exactly that.

It is not identity theft, and that's why it takes longer to surface

It is the core distinction in this category, and the one that decides which controls go looking for each thing.

  • Identity theft — the attacker uses a real person's data. There is a victim, and at some point that victim reviews a statement, gets a notification, or files a complaint. The complaint is what triggers the investigation.
  • Synthetic identity — the data does not belong to anyone. There is no one to review it, no one to complain, and no notification that reaches the wrong person. The file behaves like any other customer.

That is where the operational consequence comes from: identity theft is detected from the outside, when the real account holder speaks up. A synthetic identity is only detected from the inside, when the organization looks for patterns with no one having flagged that there is something to look for. That is why it tends to sit inside a portfolio for much longer, and why it often gets classified as a write-off before it gets classified as fraud.

Where it shows up in an identity journey

  • Account opening — this fraud's own moment. Every synthetic identity comes in through onboarding, because that is where it gets built.
  • Document and watchlist checks — the file passes, because the data is consistent and there is no prior record to compare it against.
  • Later behavior — the identity operates normally and builds a history, which is exactly what makes it credible to the controls that follow.

A well-run KYC check confirms that the file is consistent. A synthetic identity is designed to be exactly that.

Which control exposes it

Biometric deduplication is the control that answers this fraud, because it changes the question. Instead of asking whether the file is coherent, it compares the face of whoever is signing up against the faces already on record and looks for the same face under different identities.

It works because the usual pattern in this fraud is repetition: synthetic identities are rarely a one-off, and whoever builds them reuses what works. A generated face is also a common ingredient, which connects this term to the deepfake.

The full sequence, from how the file gets built to how it gets monetized, is on the fraud-type page: synthetic identity.

Frequently asked questions

It is an identity built from a combination of real data from different sources and invented data, and it does not correspond to any existing person. The resulting file is internally coherent, which is why it passes checks that look for inconsistencies. There is no real account holder behind it — not even a victim.

In whether the person exists. Identity theft uses a real person's data, and sooner or later that person notices the activity and complains. A synthetic identity does not correspond to anyone, so no complaint is possible, and the organization only finds it if it actively looks for it. That is why the gap between onboarding and detection is much longer.

By comparing instead of checking. Document verification confirms that a file is consistent, and a synthetic identity is built to be exactly that. Biometric deduplication compares the applicant's face against faces already on record and exposes the pattern this fraud repeats: the same face tied to different identities.

One identity, one SDK

VU ONE brings identity verification, authentication and fraud protection together on a single identity graph.

The verification you run at signup stays available to authentication and to your fraud rules, with no repeated processes and no duplicated data.

Verify, Authenticate and Protect, consolidated in one place.

Request a demo