Synthetic identity and video-based impersonation attacks target the trust step itself, not just account credentials. They can bypass weak onboarding, exploit remote verification channels, and create accounts that look legitimate from the start. This makes fraud harder to detect later, because the identity foundation is already compromised before normal monitoring begins.
Why Synthetic and Video-Based Impersonation Change the Fraud Baseline
Synthetic identity and video-based impersonation attacks are different from traditional account fraud because they compromise the trust decision before an account is even considered “real.” Traditional fraud often abuses an existing account, stolen credential, or weak reset path. These attacks can instead manufacture credibility at onboarding, exploit remote proofing, and seed an identity that appears consistent across later checks. That shifts the problem from account protection to trust assurance.
For security, fraud, and identity teams, the consequence is that ordinary monitoring may be too late. If the onboarding signal is accepted, later device checks, login analytics, and step-up authentication may only confirm an identity that was already fraudulently established. That is why the strongest controls live upstream in identity proofing, liveness assurance, and verification governance. CISA’s cyber guidance on identity and access risk is useful here because the failure is not simply a bad login, but a compromised trust path that becomes difficult to unwind once downstream systems accept it.
In practice, many security teams encounter these cases only after a “valid” account has already created damage, rather than through intentional onboarding review.
How the Attack Works Across Onboarding, Proofing, and Account Creation
Synthetic identity fraud usually combines real and fabricated attributes into a profile that can survive basic screening. A video-based impersonation attack adds a stronger deception layer by presenting a convincing human face, voice, or real-time interaction during remote verification. Together, they target the point where an organisation decides whether to trust the person, not just whether to trust a password or device.
The operational difference matters. Traditional account fraud often depends on stolen credentials, phishing, session theft, credential stuffing, or account recovery abuse. By contrast, synthetic and video-based impersonation attacks can produce a clean-looking record from the start: a new identity, a verified session, and a legitimate-looking customer or user profile. That makes post-event investigation harder because logs may show normal onboarding steps, not obvious compromise.
- They exploit weak document checks when identity proofing is overly automated or poorly calibrated.
- They benefit from remote channels where liveness, presentation attack detection, and human review are inconsistent.
- They create downstream ambiguity because the account owner, profile attributes, and verification artifacts may all appear internally consistent.
The key control question is whether the organisation can distinguish “successful onboarding” from “credible identity.” Those are not the same thing. NIST SP 800-63 is relevant because it separates identity proofing assurance from authentication strength, which is exactly where these attacks create confusion. When teams treat onboarding as a one-time checkbox, the control breaks down at the trust boundary, not at the login page.
This guidance breaks down when the organisation cannot perform meaningful identity proofing at all, or when every verification step has been reduced to low-confidence automation.
Where Synthetic Identities and Deepfakes Create Operational Edge Cases
Tighter verification often increases friction and review cost, so organisations have to balance conversion, user experience, and fraud resistance. That trade-off becomes especially sharp where remote onboarding is the only viable path, or where a legitimate population lacks strong documentary history.
There is still no full consensus on how much video verification should rely on automation versus human judgment. The practical issue is not whether video is “good” or “bad,” but whether the organisation can prove that the channel resists presentation attacks, replay, and coached impersonation. In many environments, the best answer is layered assurance: use stronger proofing where account value is high, and treat remote video evidence as one signal rather than the entire trust decision.
Edge cases also matter. Synthetic identities may look harmless individually but become dangerous at scale, especially in lending, payments, onboarding for privileged internal systems, or partner access. Deepfake-based impersonation can also target exception handling, where staff are pressured to override normal checks. MITRE ATT&CK is useful for thinking about the abuse path once a deceptive identity is established, because the same trust failure can support credential access, persistence, and lateral abuse later in the lifecycle.
In practice, the failure mode is most severe when organisations assume the verification channel is trustworthy simply because it is interactive and live.
Risk and Threat Considerations
These attacks create identity integrity risk, not just account compromise risk. The exposure is that an organisation may grant trust, access, or financial relationship to an identity that never had a reliable proofing basis, which weakens fraud controls, audit confidence, and recovery options.
Failure mechanism: The attacker uses synthetic attributes, manipulated media, or real-time impersonation to pass onboarding controls that were designed to validate presence rather than authenticity. Once the identity is accepted, later authentication and monitoring are operating on a false foundation.
Impact: Organisations can end up issuing legitimate-looking accounts, enabling payment fraud, credential escalation, abuse of customer privileges, or prolonged persistence that is difficult to distinguish from normal activity.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST SP 800-63, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | IAL — Identity Proofing Assurance Level | Synthetic identity and impersonation attacks target identity proofing trust. |
| Recommendation — Raise proofing assurance where identity trust drives onboarding decisions. | ||
| CIS Controls v8 | 5 — Account Management | Fraud turns into durable access when bad identities are onboarded as valid accounts. |
| Recommendation — Tighten account lifecycle controls and challenge anomalous new-account creation. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | The question concerns trust establishment and access decisions across the identity lifecycle. |
| Recommendation — Align onboarding and access controls to the assurance level of the identity source. | ||
| MITRE ATT&CK | T1589 — Gather Victim Identity Information | Synthetic identity abuse depends on assembling believable identity attributes. |
| T1110 — Brute Force | Traditional account fraud commonly reuses or attacks existing account credentials. | |
| Recommendation — Map identity-attribute abuse to T1589 and watch for staged profile-building activity. Correlate account-access anomalies with T1110-style credential abuse. | ||
Practitioner Guidance
What to prioritise: Treat identity proofing assurance as a separate control objective from login security. If the onboarding channel cannot support a defensible trust decision, the account should carry lower initial privilege, tighter review, or additional verification before it can access high-value functions.
What to verify: Check whether the organisation can evidence the full proofing chain, not just the final approval. That includes the quality of document verification, liveness checks, exception handling, and how often manual overrides are used. If investigators cannot reconstruct why the identity was trusted, the control is too opaque to rely on.
Practitioner takeaway: The real risk is not that impersonation gets an account, but that it gets a believable identity record that downstream controls are unlikely to question.
Related resources from NHI Mgmt Group
- Why do non-human identities create more risk than many human accounts?
- Why do non-human identities create more remediation risk than many human accounts?
- Why do vishing attacks bypass traditional phishing training and create a different risk profile for identity security teams?
- Why do synthetic identities and identity theft create such high risk in new account origination?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org