Editorial · Identity fraud

Synthetic identity fraud: why it passes your KYC

In short. Synthetic identity fraud is the fabrication of a person who does not exist, built from a real identifier plus invented details, then used to pass KYC and draw credit. It beats onboarding because document and liveness checks verify one applicant at a time, while synthetic identities operate as coordinated networks. The network behaviour is the layer that is hard to fake.

Synthetic identity fraud is the fabrication of a person who does not exist, built by combining real data (a stolen or issued identifier) with invented details, then aged and used to pass identity checks, open accounts, and draw credit. It is widely described, including by the Federal Reserve Bank of Boston, as the fastest-growing financial crime in the United States, and it is winning for a simple structural reason: know-your-customer checks verify one applicant at a time, while synthetic identities are manufactured and operated as coordinated networks. The document and the face can be fabricated. The behaviour of the network behind them is much harder to fake.

Why KYC misses it

Traditional KYC was built to answer one question: is this document real and is this the person it belongs to. Generative AI has made both halves cheap to defeat. Digital document forgeries have risen sharply through 2024 and 2025, and liveness checks (the selfie and the head-turn that are meant to prove a real human is present) are being bypassed at scale. Group-IB documented more than 8,000 attempts to defeat a single financial institution’s liveness checks in the first eight months of 2025 alone, using AI-generated faces injected through virtual-camera drivers, software that presents a pre-recorded or live deepfake to the app as if it were an ordinary webcam. The World Economic Forum’s 2026 study of face-swapping and camera-injection tooling found most of the tools it tested defeated standard biometric onboarding checks, liveness included. Regulators have caught up to the pattern: FinCEN flagged third-party webcam plugins in verification flows as a deepfake red flag in a November 2024 alert, and the FATF’s December 2025 horizon scan names deepfakes as a tool that bypasses customer due diligence and digital ID at onboarding.

The cost is not marginal. Industry estimates compiled by Datos Insights put United States unsecured-credit losses tied to synthetic identities at roughly 2.94 billion US dollars in 2025, and the Federal Reserve Bank of Boston attributes the acceleration directly to generative AI lowering the cost of manufacturing convincing fakes. In Regula’s 2024 industry survey, almost half of businesses (49 per cent) reported experiencing both audio and video deepfake fraud, with the average financial-services loss above 600,000 US dollars per company and one in ten organisations losing more than a million.

Fraud is a network, not a face

The mistake is to treat each application as an isolated identity to approve or reject. Synthetic identities are rarely one-offs. They are produced in batches by organised fraud operations and used across many institutions, sharing infrastructure the applicant screen never sees: the same devices and emulators, the same narrow timing windows, recycled fragments of synthetic data, and coordinated application patterns that only become visible when accounts are viewed together rather than one at a time. A single synthetic identity that clears your onboarding looks clean. The ring it belongs to does not. It leaves a coordination signal, the fingerprint of many fabricated identities acting in concert, and that signal survives even when an individual deepfake fools the liveness gate.

“A fake alone is inert. It moves only when a coordinated network amplifies it.”

The same principle applies to identity fraud as to narrative attacks: detecting the fake is only half the job. The other half is detecting the coordinated network operating it. Related: deepfake detection meets behavioural intelligence.

How AI Uniti detects coordinated synthetic identity fraud

This is the problem behavioural detection is built for. Signal by AI Uniti scores accounts and identities on how they behave and how they coordinate, not on whether a single document or selfie looks authentic. The same coordination scoring that exposes bot networks and coordinated inauthentic behaviour in narrative attacks applies directly to synthetic identity rings: shared timing, shared infrastructure, and correlated behaviour across supposedly independent identities are surfaced as one connected cluster with an explainable, deterministic verdict rather than a black-box score. PulseCheck brings the same behavioural lens to individual accounts, placing them on a bot-to-human spectrum. And through AI Uniti’s content-authenticity partnership, collected media is scanned for manipulation, so a deepfaked liveness capture is flagged as synthetic content at the same time the network behind it is flagged as coordinated. The document layer and the behavioural layer reinforce each other.

What changes when you add behavioural detection

You catch the ring, not just the application. Behavioural and coordination scoring surfaces the connected cluster of synthetic identities that per-applicant KYC clears one by one, so you intercept the operation instead of chasing individual charge-offs.

Deepfakes stop being a blind spot. Content-authenticity scanning of the liveness capture, combined with behavioural signals, means an injected deepfake is caught as synthetic media even when it defeats the liveness prompt. The same applies to cloned voices in the phone channel.

Verdicts you can defend. Detection is deterministic and explainable, built for the audit trail a fraud, risk, or compliance team needs to action a decision and evidence it to a regulator, not an opaque risk number.

A signal that compounds. Behavioural patterns learned across accounts and platforms strengthen over time, so the same fabricated infrastructure gets harder to reuse against you with every network it touches.

Synthetic identity fraud will keep beating checks that inspect one face and one document at a time, because that is precisely the layer generative AI has made cheap to fake. The defensible position is to add the layer it cannot cheaply fake: the behaviour of the network. See how behavioural detection applies to your onboarding at identity verification fraud, or book a 15-minute PulseCheck demo.

Frequently Asked Questions

What is synthetic identity fraud?

Synthetic identity fraud is the creation of a fictitious person by combining real data, such as a stolen or issued identifier, with fabricated details, then using that identity to pass verification, open accounts, and obtain credit. Unlike stolen-identity fraud, there is no single real victim to raise the alarm, which is part of why it has become the fastest-growing financial crime in the United States.

Why do KYC and liveness checks miss synthetic identities?

Document and liveness checks verify one applicant at a time and are increasingly defeated by AI-generated documents and deepfakes injected through virtual-camera software. They inspect whether a face and a document look real, not whether the identity is part of a coordinated fraud network, so a well-made synthetic identity clears onboarding while the ring behind it stays invisible.

How does behavioural detection stop synthetic identity fraud?

Behavioural detection scores identities on how they act and coordinate rather than on document authenticity alone. Coordination scoring surfaces shared devices, timing, and correlated activity across supposedly independent identities as one connected cluster, and content-authenticity scanning flags deepfaked liveness captures, so the network is caught even when an individual deepfake defeats the liveness gate.

See how AI Uniti detects coordinated narratives 6 to 12 hours before traditional monitoring.