Skip to content

Synthetic Identity Fraud

Synthetic identity fraud is the use of a combination of real and fabricated personal information to build a person who does not exist, and then to obtain credit or services in that invented name. Because there is usually no real consumer whose file visibly breaks, it is found late.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The identity is assembled rather than stolen. Real elements, most often a Social Security number, are combined with a fabricated name and date of birth.
  • There is no single legal definition. The one in general use was recommended by a Federal Reserve-convened focus group and its adoption is expressly voluntary.
  • A synthetic is cultivated over months or years, because the fabricated person has to build a credit history before it is worth anything.
  • It is found late because the usual alarm, a real person noticing accounts they did not open, often never sounds.
  • The identifiers most useful to build one belong to people who do not use their own credit, which is why children's and the deceased's numbers are attractive.

Definition

Synthetic identity fraud is the creation of a person or business that does not exist, assembled from a combination of personal information, and then used to obtain credit, goods or services. The definition in general use across the payments industry reads: "Synthetic identity fraud (SIF) is the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain."

That definition is worth attributing carefully, because its status is unusual. It was developed by a focus group of twelve fraud experts convened by the Federal Reserve, working from fall 2020 to early 2021, specifically to fix a problem the industry had created for itself: multiple competing definitions meant the same losses were being classified in different ways by different institutions, so nobody could measure the scale of the problem. The published definition carries an explicit disclaimer that it is "not intended to result in any regulatory or reporting requirements, imply any liabilities for fraud loss, or confer any legal status, legal definitions, or legal rights or responsibilities", and that adoption is voluntary. It is a shared vocabulary, not a rule.

The distinction from ordinary identity theft is the one that governs everything else. In identity theft, a real person's identifying information is used as that person, so the fraud lands in that person's credit file and they eventually see it. In synthetic identity fraud the identifying elements are recombined into somebody new, and the new person is the customer of record. There is often no individual whose file visibly breaks, which removes the fastest detection mechanism the credit system has: a complaining consumer.

Advanced Explanation

The building blocks are classified, and the classification explains the targeting. The focus group's published material splits the raw material in two. Primary elements are those that "in combination, typically unique to an individual or profile", and it names name, date of birth, Social Security number and other government-issued identifiers. Supplemental elements are those that "can help substantiate or enhance the validity of an identity but cannot establish an identity by themselves", and it names mailing or billing address, phone number, email address and digital footprint.

Read that as a shopping list and the pattern of harm follows. What is needed is a primary identifier that will not collide with a real, active person, since a living adult using their own credit generates conflicting records. That makes the identifying numbers of children, of people who have never used credit and of the recently deceased the useful raw material. A child's Social Security number may sit unused for eighteen years, and nobody is checking a file that is not supposed to exist yet.

Cultivation is the part that separates this from a smash-and-grab. A fabricated identity with no history is worth very little: it will be declined for anything meaningful. So the identity is grown. It applies for credit and is refused, which itself creates a record. It is added as an authorized user on an existing account. It obtains a small secured or subprime line and pays it, which produces exactly the file a lender wants to see. Each successful step raises the next lender's willingness, and the whole point of the exercise is to reach a credit profile large enough to be worth abandoning.

The four common uses, and they are not all the same crime. The Federal Reserve focus group set out four. Credit repair is a synthetic used "to hide from previous negative credit history or bad debt in order to appear creditworthy". Fraud for living is a synthetic used "to apply for employment or services (e.g., utilities, housing, bank accounts) because an individual is unwilling or unable to do so with existing primary PII elements, with no intent to default on payment". Payment default scheme is a synthetic used "to obtain goods, cash or services with no intent to repay over a period of time". And other criminal activity is a synthetic used to facilitate other illegal acts, with the group's own note naming money laundering, trafficking and terrorist financing among them. Only the third is the classic run-up-and-vanish version, and the first two are the reason a page on this subject should not describe every synthetic as a theft in progress.

Why the loss falls where it does. When a payment default scheme ends, the balances belong to a customer who cannot be found because that customer was never a person. The lender writes the balances off. The individual whose Social Security number was used has not usually had accounts opened in their own name, so the usual remedies keyed to a consumer's own file do not obviously engage, and they may not learn of it at all until something forces the number's other uses into view: a tax return that fails to process, a benefits application that returns unexpected records, an employment check that surfaces income they never earned. That is a real harm with a slow fuse, and it is different in shape from the harm ordinary identity theft causes.

Used in a Sentence

“The account had been paid perfectly for two years before it defaulted, and the bank's review concluded it was synthetic identity fraud, because the applicant's Social Security number belonged to a nine-year-old.”

How It Works

The lifecycle is long by design.

  1. Assembly. A real primary identifier, typically a Social Security number belonging to someone who does not use it, is combined with a fabricated name and date of birth, and dressed with supplemental elements such as an address, a phone number and an email history.
  2. Seeding. Applications are submitted that are expected to fail. The applications themselves create records, and a file that exists is a file that can be built on.
  3. Cultivation. Small credit is obtained and repaid on time, sometimes for years. Authorized-user positions on other accounts accelerate the process.
  4. Expansion. As the profile strengthens, limits rise and more lenders will approve it. Nothing at this stage looks like fraud, because at this stage nothing is being taken.
  5. The exit, in whichever of the four forms applies. In a payment default scheme the available credit is drawn at once and the identity is abandoned. In fraud-for-living the identity simply continues, paying its bills.

A hypothetical example, with the arithmetic that makes cultivation worth the wait. A fabricated identity opens a secured card with a $300 deposit and pays it monthly. Eighteen months later the profile supports four unsecured accounts with limits of $8,000, $12,000, $15,000 and $5,000, which is $40,000 of available credit ($8,000 + $12,000 + $15,000 + $5,000). All four are drawn to their limits within a few days and nothing is repaid, so the four lenders are left holding $40,000 against a customer who cannot be traced because the customer was never real.

Set the $300 deposit and eighteen months of small on-time payments against $40,000, and the economics of the patience are obvious. It is also why the behavior looks like an excellent customer for most of its life: every payment made during cultivation is a real payment.

Pros and Cons

Synthetic identity fraud has no upside, so what follows is what limits exposure and where the ordinary defenses do not reach.

What genuinely reduces exposure

  • Freezing a child's credit file. Federal law provides a separate freeze for a protected consumer, and it addresses the specific reason a child's Social Security number is valuable: that nobody is watching a file that should not exist. Our page on the credit freeze sets out who qualifies and what it blocks.
  • Guarding the Social Security number itself, since it is a primary element and the one that is hardest to change after the fact.
  • Treating a data breach that exposed Social Security numbers as a long-horizon event rather than a short one, because a number's usefulness for this purpose does not expire.

What the protections do not reach

  • The alarm that ordinary identity theft eventually sets off. If no accounts are opened in your own name, your own credit report may show nothing wrong.
  • Monitoring aimed at your file. A fabricated person is a different customer of record, so a service watching for changes to your report is looking in the wrong place.
  • The definition itself, which carries no legal force. It standardizes how institutions classify losses; it creates no rights for the individual whose identifier was used.
  • Measurement. Because classification was inconsistent for years, published figures for the size of the problem are not comparable across sources, and federal complaint statistics do not report it as a category at all.

People Also Asked

Answers to the most frequently asked questions.

How is synthetic identity fraud different from ordinary identity theft?
In identity theft, a real person's information is used as that person, so the fraudulent accounts land in that person's credit file and are eventually visible to them. In synthetic identity fraud the information is recombined into someone who does not exist, and that invented person becomes the customer of record. The practical consequence is detection: identity theft usually surfaces because a real consumer notices, and a synthetic has no such consumer to notice.
Does the industry definition of synthetic identity fraud have legal force?
No, and the document containing it says so directly. The definition was produced by a Federal Reserve-convened focus group of twelve fraud experts to give the payments industry a common vocabulary, and it states that it is "not intended to result in any regulatory or reporting requirements, imply any liabilities for fraud loss, or confer any legal status, legal definitions, or legal rights or responsibilities", with adoption voluntary. Treat it as the industry's shared description, not as a rule.
Why are children's Social Security numbers used?
Because the number needs to be real but inactive. A living adult who uses their own credit generates records that would conflict with a fabricated profile, while a child's number may go unused for years and no one is reviewing a credit file that is not supposed to exist. That is also why a credit freeze placed on a minor's file addresses this particular risk directly.
If someone uses my Social Security number this way, will it show on my credit report?
Not necessarily, and that is the difficulty. The accounts are opened in a fabricated name, so they belong to a different consumer record and may never appear in the file kept under your name. The signs tend to arrive by other routes instead, such as a tax return that will not process, a benefits application that returns records you do not recognize, or an employment or income check that surfaces work you never did.
Is every synthetic identity used to run up credit and disappear?
No. The Federal Reserve focus group set out four common uses, and only one is the run-up-and-abandon pattern. The others are hiding a poor credit history, obtaining employment or services with the intention of paying for them, and facilitating other criminal activity, which is why institutions classify these losses differently even though the mechanism of assembly is the same.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Reserve Banks, FedPayments Improvement. "Synthetic Identity Fraud Defined."
  2. U.S. Government Accountability Office. "Highlights of a Forum: Combating Synthetic Identity Fraud." GAO-17-708SP.

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor