Synthetic identity fraud occurs when criminals construct an identity that does not accurately represent a real person. The identity may combine stolen information with fabricated attributes, or it may be entirely fictional.
Unlike straightforward impersonation, synthetic identities are often designed to appear credible over time. Fraudsters may use them to open accounts, establish transaction histories, access credit, exploit promotions, or move illicit funds.
The Federal Reserve describes a common synthetic identity as a combination of real information—such as a legitimate identification number—and fictional information such as a false name, address, or date of birth. Federal Reserve: Synthetic Identity Payments Fraud
1. Synthetic Identity Fraud vs Traditional Identity Theft
Traditional identity theft normally involves impersonating an existing person using their stolen identity information.
Synthetic identity fraud creates a new identity profile from several components:
- Genuine information belonging to one or more people
- Fabricated names, dates, addresses, or contact details
- Altered, counterfeit, or fraudulently obtained documents
- Newly created email addresses and phone numbers
- Faces that may be stolen, generated, manipulated, or repeatedly reused
Because no single victim necessarily corresponds to the entire profile, discrepancies may be harder to resolve through conventional identity-theft alerts.
2. How Synthetic Identities Are Constructed
Fraudsters typically assemble identity elements from different sources rather than relying on one complete stolen identity.
At a high level, the resulting profile may combine:
- A real identification number with a fabricated name
- Genuine personal data with a substituted portrait
- A real address associated with invented contact information
- Altered document images containing internally consistent fields
- One face reused across several nominally different identities
- Multiple identities sharing the same device or payment infrastructure
The objective is to create enough consistency for individual controls to pass. A document may be readable, a phone number may work, and a face may be present—while the overall identity remains artificial.
FATF has also identified synthetic identities as combinations of real and fake information used to create accounts fraudulently. FATF: Illicit Financial Flows from Cyber-Enabled Fraud
3. Why Synthetic Identities Can Appear Legitimate
Synthetic identities may not be used for immediate fraud. Some are maintained until they develop a credible account, payment, or credit history.
During this period, activity may appear ordinary:
- Small purchases or repayments
- Regular account access
- Consistent contact details
- Gradual increases in transaction value
- Low-value use of several related accounts
This behavior can create the impression of a stable customer. The risk becomes visible only when the platform connects identity, biometric, device, and behavioral evidence across applications and over time.

4. How Synthetic Identities Are Used
The exact purpose varies by market and business model. Common abuse scenarios include:
- Credit abuse: Building apparent creditworthiness before defaulting across several facilities
- Account farming: Creating accounts for resale, promotion abuse, or later fraudulent activity
- Money movement: Using controlled accounts to receive, layer, or transfer funds
- Marketplace abuse: Operating coordinated buyer and seller profiles
- Telecommunications fraud: Obtaining services, devices, or subsidized contracts
- Platform re-entry: Returning after a previous account was restricted
These identities may form part of a larger fraud network. Different accounts can appear unrelated at the profile level while sharing faces, devices, addresses, beneficiaries, or transaction patterns.
5. Warning Signs of Synthetic Identity Fraud
No single inconsistency proves that an identity is synthetic. Stronger detection comes from combined evidence.
Potential indicators include:
- Identity attributes that cannot be validated together
- Document fields that conflict with encoded or submitted data
- A face associated with multiple names or document numbers
- Several identities sharing devices or payment instruments
- Recently established contact information with limited history
- Repeated applications containing small variations
- Coordinated account activity or common beneficiaries
- A customer profile that changes substantially after approval
A common name, shared household device, or recycled phone number can also produce legitimate overlap. Risk controls should therefore distinguish suspicious relationships from confirmed fraud.
6. The Role of Face Verification and Face Search
Face++ 1:1 face comparison can determine whether the applicant’s current face resembles the portrait associated with the submitted identity evidence. It returns a confidence score and thresholds that can support a match decision. Face++ Face Comparing
However, a successful 1:1 match does not prove that the underlying identity is real. The same person could consistently present a document created around fabricated attributes.
Where permitted and appropriately governed, Face++ 1:N face search can compare an applicant against an enrolled face collection. This can help identify one face connected to multiple customer profiles or previously restricted accounts. Face++ Face Search
Candidate similarities require contextual review. Biometric search results should not independently determine that fraud occurred.
7. Why Liveness Detection Is Still Necessary
Fraudsters may submit stolen portraits, screen replays, masks, or other presentation attacks instead of appearing personally.
Face++ liveness detection helps assess whether the facial sample represents a genuinely present person rather than a photo, video, or mask. This strengthens biometric capture but answers only one question: whether the presented face appears live.
A live person can still participate in synthetic identity fraud. Liveness should therefore be combined with document checks, identity-data validation, face comparison, duplicate detection, and contextual risk signals.
8. Detecting Synthetic Identities Across Accounts
A layered workflow can include:
- Extracting and normalizing document and application data
- Validating attributes through suitable authoritative sources
- Evaluating document authenticity and internal consistency
- Performing Face++ face comparison and liveness detection
- Searching for permitted biometric duplication signals
- Linking shared devices, contact details, payments, and beneficiaries
- Analyzing coordinated behavior and transaction patterns
- Applying risk-based approval, step-up, review, or restriction
This approach evaluates the identity as a connected entity rather than a collection of isolated fields.

9. Frequently Asked Questions
Q1. Is synthetic identity fraud the same as identity theft?
No. Traditional identity theft impersonates a real person. Synthetic identity fraud constructs a new profile using fabricated information, stolen information, or both.
Q2. Can a synthetic identity pass KYC?
Yes. Individual checks may pass when the document is readable, the data appears plausible, and the presenter matches the supplied portrait. Cross-source and cross-account analysis is needed to expose broader inconsistencies.
Q3. Can Face++ detect synthetic identity fraud by itself?
No single capability can determine that an identity is synthetic. Face++ face comparison, face search, and liveness detection can provide biometric evidence that should be combined with document, device, data, and behavioral signals.
Q4. Does one face linked to several accounts always indicate fraud?
No. Duplicate enrollment, account recovery, shared records, or operational errors may create legitimate matches. The relationship must be reviewed in context.
10. Detect the Identity Behind the Application
Synthetic identity fraud exploits gaps between otherwise valid controls. A readable document, responsive phone number, live face, and normal-looking account may each appear trustworthy in isolation.
By combining Face++ biometric capabilities with document validation, authoritative data, device intelligence, entity linking, and behavioral monitoring, digital platforms can detect inconsistencies across the full identity rather than relying on a single successful check.



