TL;DR: Synthetic identity fraud now evades many traditional checks because fraudsters combine real identifiers with fabricated personal data, let profiles age into creditworthiness, and then execute bust-out fraud, according to Yoti. The control gap is not a single weak check but a verification model that treats static identity data as sufficient proof of a real person.
NHIMG editorial — based on content published by Yoti: What is synthetic identity fraud?
By the numbers:
- Traditional fraud tools fail to detect 85% of synthetic identity fraud cases.
- 99% of synthetic identities remain unchanged over 2 years.
Questions worth separating out
Q: How should organisations detect synthetic identities after onboarding?
A: They should treat onboarding as the start of verification, not the end.
Q: Why do synthetic identities make traditional fraud controls less effective?
A: Synthetic identities reduce the value of controls that rely on spotting obviously fake profiles at signup.
Q: What signals indicate a synthetic identity is being built over time?
A: Watch for repeated small applications, static personal details, reused contact information, and a thin or absent real-world footprint such as no school, employment, utility, or address-change history.
Practitioner guidance
- Add multi-signal assurance to onboarding Combine document authenticity, liveness detection, biometric matching, and authoritative database checks before allowing high-risk accounts to progress.
- Flag slow-burn identity growth patterns Monitor for repeated small applications, unchanged personal data over long periods, reused contact details, and sparse real-world footprint.
- Use external and shared intelligence sources Cross-check applicants against death indicators, sanctions or financial crime lists, and trusted identity databases, then feed suspicious patterns into broader industry data-sharing mechanisms where permitted.
What's in the full article
Yoti's full article covers the operational detail this post intentionally leaves for the source:
- Step-by-step guidance on using advanced document verification and AI-led authenticity checks in onboarding flows
- Practical examples of biometric authentication, liveness detection, and expert human review for harder cases
- Checks against death indicators, sanctions lists, government-held records, and eCBSV in the US
- Consumer-facing protection steps for credit monitoring, suspicious activity reporting, and child identity protection
👉 Read Yoti's guide on detecting and preventing synthetic identity fraud →
Synthetic identity fraud: what identity teams need to change now?
Explore further
Synthetic identity fraud exposes a verification trust gap. The control failure is not simply weak identity data, but overconfidence in data that can be assembled from real and fake components. Once a system accepts a valid identifier as evidence of a real person, fraudsters can build credibility over time and exploit the gap later. For identity programmes, the lesson is that assurance must be based on provenance and convergence, not on static attribute completeness.
A question worth separating out:
Q: Who is accountable when synthetic identity fraud inflates onboarding growth?
A: Accountability should sit across identity verification, fraud operations, and product growth leadership because the harm is both security-related and financial. If synthetic users consume biometric spend, manual review time, or incentives, the issue is not only fraud prevention. It is also governance of the onboarding workflow and the metrics used to judge success.
👉 Read our full editorial: Synthetic identity fraud exposes the gaps in identity verification