Synthetic fraud is identity fraud that uses AI-generated or manipulated content to impersonate a person or create a believable false identity. It can include deepfake media, doctored documents, and fabricated supporting evidence. The main risk is that automated systems may accept convincing but fake inputs as genuine.
Expanded Definition
Synthetic fraud is not limited to obvious deepfakes. In NHI and IAM contexts, it includes any AI-assisted fabrication that makes a person, device, or supporting artefact appear credible enough for a system or reviewer to trust. That can mean generated face video, voice cloning, doctored onboarding documents, altered invoices, or fabricated evidence that supports an account takeover or false enrolment. The key distinction is that the fraud is synthetic in its construction, but operational in its goal: bypass identity proofing, access approval, or exception handling.
Usage in the industry is still evolving. Some teams use the term narrowly for media manipulation, while others include document fraud, synthetic personas, and AI-generated corroboration. In practice, defenders should treat it as a fraud pattern that targets identity workflows rather than a single file type. Alignment to controls in NIST SP 800-53 Rev 5 Security and Privacy Controls is usually strongest when organisations map it to evidence validation, access approval, and incident response. The most common misapplication is treating synthetic fraud as only a media problem, which occurs when teams ignore document, workflow, and approval-layer deception.
Examples and Use Cases
Implementing synthetic-fraud detection rigorously often introduces verification friction, requiring organisations to weigh faster onboarding and customer conversion against stronger proofing and review cost.
- A fraud team receives a deepfake video used to pass remote identity verification during account creation, prompting layered checks against liveness, document provenance, and step-up review.
- An attacker submits AI-generated utility bills and employment letters to open privileged access or financial accounts, showing how fabricated supporting evidence can be as damaging as fake biometrics.
- A help desk receives a cloned voice call requesting a password reset or MFA rebind, a pattern that mirrors the credential abuse risks discussed in the Ultimate Guide to NHIs when trust is placed in weak approval paths.
- A third-party vendor onboarding flow accepts manipulated incorporation records, leading to downstream exposure when the false entity is granted API access or shared secrets.
- An internal exception process accepts synthetic evidence that an administrator has approved an urgent change, which can be paired with governance gaps noted in Ultimate Guide to NHIs and reinforced by identity assurance controls in NIST SP 800-53 Rev 5 Security and Privacy Controls.
Why It Matters in NHI Security
Synthetic fraud is especially dangerous in NHI security because machine-driven workflows often evaluate evidence faster than humans can verify it. If an organisation allows fabricated artefacts to justify creation, delegation, or recovery of identities, the attacker may gain durable access through service accounts, API keys, or delegated automation. This is why fraud controls and NHI governance should be treated as connected disciplines rather than separate programmes. NHI Mgmt Group reports that only 5.7% of organisations have full visibility into their service accounts, which means synthetic fraud can exploit blind spots after a false identity has already been accepted.
Defenders should pair strong proofing, approval logging, and evidence review with baseline controls that resist manipulation, including lifecycle governance from the Ultimate Guide to NHIs and control discipline from NIST SP 800-53 Rev 5 Security and Privacy Controls. Organisations typically encounter the impact only after a fraudulent identity has been used to request access, at which point synthetic fraud becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | Agentic systems can amplify synthetic content into fraudulent actions or approvals. | |
| NIST AI RMF | Addresses AI-generated deception as a risk to trustworthy system outcomes. | |
| NIST CSF 2.0 | PR.AC | Identity and access controls are directly undermined by fabricated proof and impersonation. |
| NIST SP 800-63 | IAL/AAL | Identity assurance levels define how much evidence is needed before trusting a claimant. |
| OWASP Non-Human Identity Top 10 | NHI-01 | False identities often lead to compromised or improperly governed NHIs. |
Constrain tool use and verify external evidence before any autonomous action based on identity claims.
Related resources from NHI Mgmt Group
- Why do synthetic identities make traditional fraud controls less effective?
- What fails when synthetic identity fraud gets past onboarding?
- What is the difference between identity theft and synthetic identity fraud?
- How should security teams reduce fraud when attackers use deepfakes and synthetic identities?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org