Traditional identity theft uses another person’s identity. Synthetic identity fraud combines real and fictitious information to construct an identity that may not correspond to any single real person.

01

The identity is assembled

A fraudster may combine a real identifier with a fabricated name, address, date of birth or contact information. Some elements may pass individual checks even though the complete identity is false.

The real information can belong to a child, an older adult or another person who may not notice activity quickly, while the invented details remain under the fraudster’s control.

02

A thin credit profile can become established

Early applications may be declined or result in small accounts. Over time, reporting from lenders and payment activity can create a credit record associated with the synthetic identity.

The fraudster may make payments and behave like a legitimate customer to build history, increase limits and strengthen the identity’s apparent credibility.

03

The eventual loss may be deliberately delayed

Once the identity has access to larger credit lines, the fraudster may draw on several accounts and stop paying. This is sometimes called a bust-out because the apparent customer relationship was cultivated before the loss occurred.

The long preparation period can make the behavior harder to distinguish from an ordinary customer who later experiences financial difficulty.

04

Detection connects evidence across time and systems

Banks may compare identity data with authoritative records, look for inconsistent combinations, analyze shared devices or contact details and monitor patterns across applications and accounts. No single signal proves that an identity is synthetic.

Information sharing and consistent definitions can help institutions recognize related activity that would appear harmless when each account is viewed alone.

05

Controls must balance fraud prevention and access

Stronger identity checks can reduce fraud but may also create friction or false positives for legitimate applicants with limited records. Banks need proportionate review, escalation and correction processes rather than relying entirely on automated rejection.

The objective is to combine identity proofing, account monitoring and human judgment while protecting personal information and giving legitimate customers a way to resolve errors.

Sources

Read the primary material

Banking Explained prioritizes regulators, official publications and first-party announcements.