They defeat traditional checks because the profile can look consistent across multiple data sources while still being fabricated. That makes early-stage verification critical, especially before account creation, credit approval, or transaction access. Strong programmes look for cross-channel inconsistency, device anomalies, and weak evidence of real-world identity rather than relying on a single signal.
Why This Matters for Security Teams
Synthetic identities and identity theft are especially dangerous at new account origination because the decision point is early, high impact, and often made with limited evidence. A fabricated profile can still look internally consistent across bureau data, device signals, and application fields, which means conventional checks may approve the account before deeper validation occurs. That is why controls aligned to NIST Cybersecurity Framework 2.0 need to be paired with stronger identity proofing, not treated as a substitute for it.
The risk is not just fraud loss. A successful synthetic identity can become a durable foothold for credit abuse, mule activity, account takeover, and downstream laundering across multiple products. NHIMG’s Ultimate Guide to NHIs shows how often organisations underestimate identity sprawl and control gaps in adjacent identity systems, and the same pattern appears in customer onboarding when teams overtrust a single signal. In practice, many security teams encounter the fraud only after the account has already matured enough to access value, rather than through intentional early-stage detection.
How It Works in Practice
Effective origination controls look for proof of real-world identity, not just consistency of submitted data. Synthetic identities often pass basic validation because the attacker assembles a profile from partially stolen, partially invented, or recycled attributes. That makes the workflow less about one perfect check and more about layered evidence, scored at the point of decision. Current guidance suggests treating onboarding as a risk engine, where document checks, device reputation, behavioural signals, and linkage analysis are evaluated together.
In practice, teams should combine:
- Cross-channel consistency checks to spot mismatches between application data, device characteristics, and historical interactions.
- Document and attribute validation that looks for reused images, manipulated artifacts, or thin identity history.
- Device and network anomaly analysis, especially when multiple “people” originate from the same infrastructure.
- Velocity and relationship checks that identify clusters of related applications sharing emails, phones, addresses, or payment instruments.
- Step-up verification before account creation, credit approval, or first transaction access when risk is elevated.
This is also where the broader identity and secrets picture matters. NHIMG’s 52 NHI Breaches Analysis and Top 10 NHI Issues show how identity abuse tends to exploit weak assurance and weak lifecycle control, which is directly relevant when an attacker is trying to turn a synthetic profile into a lasting account. For control design, NIST SP 800-53 Rev. 5 is useful for mapping evidence handling, access enforcement, and fraud monitoring to formal security controls.
These controls tend to break down when onboarding is optimised for conversion alone, because high-friction evidence requests are removed before risk-based exceptions can catch the fraud.
Common Variations and Edge Cases
Tighter onboarding controls often increase customer friction and review overhead, requiring organisations to balance conversion rate against fraud containment. That tradeoff becomes more difficult in low-document markets, thin-file populations, and channels where identity data is sparse or inconsistent.
There is no universal standard for this yet, but current guidance suggests using different assurance levels by product risk. A deposit account, a consumer credit line, and a high-limit business account should not share the same verification threshold. For thin-file applicants, teams may need alternative evidence such as in-person verification, trusted third-party attestations, or delayed limit expansion rather than a flat denial. For higher-risk channels, step-up controls should be automatic when device linkage, behavioural anomalies, or application clustering crosses a threshold.
One important edge case is that identity theft and synthetic identity fraud can overlap. A real person’s stolen attributes may be blended into an otherwise fabricated profile, which means a simple “real or fake” classification is too coarse. The stronger pattern is to ask whether the person behind the application can sustain the claimed identity over time, across channels, and under review. NHIMG’s Why NHI Security Matters Now supports that broader point: identity risk is rarely isolated, and weakness in one control plane often predicts failure in another.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.AM-1 | Identity proofing depends on knowing what identities and evidence sources exist. |
| NIST SP 800-63 | IAL2 | Identity assurance levels directly govern how much proof is needed at onboarding. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Weak identity lifecycle and trust assumptions enable fabricated or stolen identities. |
| NIST AI RMF | Risk governance is needed when scoring models make high-impact origination decisions. |
Set onboarding assurance targets by account risk and require stronger evidence for higher-risk products.
Related resources from NHI Mgmt Group
- Why do non-human identities create more risk than many human accounts?
- Why do non-human identities create more remediation risk than many human accounts?
- Why do Windows admin gateways create such high-risk identity exposure when AD CS is nearby?
- Why do account takeovers create such a large risk for enterprise identity programmes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org