Subscribe to the Non-Human & AI Identity Journal

Why do synthetic identities and deepfakes make ecommerce fraud harder to stop?

They make weak verification signals less reliable. Synthetic profiles and AI-generated behaviour can look legitimate enough to pass basic proofing, especially when teams rely on email age, form completion, or single-factor checks. The answer is stronger identity assurance and behavioural monitoring throughout the account lifecycle.

Why This Matters for Security Teams

Synthetic identities and deepfakes reduce the value of signals that ecommerce teams have relied on for years, such as email history, basic device consistency, and simple document checks. Once attackers can blend fabricated identity attributes with AI-generated images, audio, or chat behaviour, fraud reviewers lose the ability to trust surface-level indicators. That matters not only at signup, but also during checkout, account recovery, chargeback disputes, and loyalty abuse.

The practical risk is that fraud controls can be tuned to reject obvious bad actors while still missing high-quality deception. A synthetic identity may age over time, build transaction history, and appear operationally normal until it is used for abuse at scale. Deepfakes add another layer by helping attackers bypass liveness checks, impersonate account holders, or social-engineer support teams into resetting credentials. Guidance from NIST SP 800-53 Rev 5 Security and Privacy Controls remains relevant because the problem is not only fraud detection, but also identity proofing, access governance, and auditability across the full customer journey.

In practice, many security teams encounter synthetic identity fraud only after losses appear in chargebacks, refund abuse, or account takeover investigations, rather than through intentional identity assurance design.

How It Works in Practice

These fraud patterns succeed because they exploit the gaps between individual controls. A single check may look strong in isolation, but attackers combine low-risk signals into a profile that appears plausible enough to pass automated workflows. Synthetic identities often use real and fabricated data together, which makes them harder to blacklist than fully fake records. Deepfakes extend the attack by making remote verification look authentic when teams depend on static images, voice prompts, or scripted support interactions.

Effective defence depends on layered verification and continuous risk scoring, not one-time gatekeeping. Current guidance suggests combining identity proofing, device intelligence, behavioural analytics, transaction monitoring, and step-up authentication when risk changes. Teams should also align operational controls with fraud review procedures so that exceptions are investigated consistently rather than handled ad hoc.

  • Strengthen onboarding with document, liveness, and consistency checks that compare claims across data sources.
  • Track account age, payment behaviour, device reuse, and velocity patterns to identify slow-burn synthetic identities.
  • Use step-up verification for sensitive actions such as password resets, payout changes, and support-led recovery.
  • Log verification events and review outcomes so fraud patterns can be tuned and audited over time.

For organisations building digital identity assurance, NIST SP 800-63 Digital Identity Guidelines remain a useful reference for proofing and authenticator assurance, while CISA guidance on deepfakes helps security teams understand how synthetic media changes trust decisions. These controls tend to break down when fraud operations are fragmented across ecommerce, support, and payments teams because no single function owns the full identity risk path.

Common Variations and Edge Cases

Tighter verification often increases customer friction and manual review cost, requiring organisations to balance fraud reduction against conversion and support overhead. That tradeoff is real, especially in marketplaces, subscription businesses, and cross-border commerce where legitimate customer diversity makes rigid rules unreliable.

Best practice is evolving for AI-generated identity risk, and there is no universal standard for this yet. Some environments can rely on stronger device reputation and payment intelligence, while others need more formal identity assurance because the abuse pattern targets onboarding or recovery. Deepfakes are also not equally effective across all channels: voice cloning may matter more in call-centre workflows, while image synthesis is more relevant in remote proofing and KYC-like review flows. Identity teams should treat high-risk recovery paths as part of fraud control design, not just customer service.

When ecommerce platforms connect loyalty programs, stored payment methods, marketplace payouts, or BNPL products, the fraud blast radius becomes larger and identity signals become more valuable. That is where alignment with stronger control baselines matters, including OWASP application security verification guidance for abuse-resistant workflows and MITRE ATLAS for understanding AI-enabled attack patterns. The most difficult cases are those where genuine customers look unusual and synthetic identities look normal, because static rules tend to fail when attacker behaviour adapts faster than review thresholds.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATLAS and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 IAL/AAL/FAL Identity proofing and authenticator assurance limit synthetic identity acceptance.
NIST CSF 2.0 PR.AA-1 Access and identity assurance support fraud-resistant account lifecycle controls.
NIST AI RMF AI risk governance is needed when deepfakes and synthetic behaviour affect decisions.
MITRE ATLAS AML.TA0002 ATLAS helps model adversarial manipulation of AI-driven fraud detection and deepfakes.
OWASP Agentic AI Top 10 Agentic and AI-driven workflows can amplify identity abuse and recovery fraud.

Set proofing and authenticator levels that match fraud risk before allowing high-value actions.