Synthetic Identity Fraud Risk

1-800-953-2877

Contact Us

The Synthetic Identity Problem Is Getting Harder to Ignore

synthetic identity fraud
Synthetic identity theft is taking up a larger share of global fraud. The LexisNexis® Risk Solutions Cybercrime Report, which is based on analysis of 116 billion transactions in 2025 via the Digital Identity Network, shows the global human-initiated attack rate increased by 8% year over year.¹ Against that backdrop, synthetic identity theft rose to 11% of all reported fraud, up from 1.4% in the previous year.¹ It is one of the clearest shifts in this year’s fraud classifications, signaling a change in criminal behavior. 

Synthetic identity theft is no longer a region-specific issue. It now appears across regions and industries, with the report showing it is widely reported in ecommerce, communications, mobile and media, and gaming and gambling.¹ Synthetic identity theft has also overtaken true identity theft, which declined to 6.4% of reported fraud, down from 9.9% in the previous year.¹

What makes synthetic identity fraud difficult to detect?

Synthetic identity fraud can involve a combination of real, stolen, manipulated and fabricated identity attributes that do not collectively represent one genuine person. Individual elements may appear valid when checked separately, but the identity as a whole has been constructed. Because the identity may not map neatly to one real person or known customer, there is often no immediate victim complaint to trigger an investigation, making detection slower and more complex.

When losses materialize, the pattern often becomes clear only after the scheme has reached its endpoint. A carefully nurtured customer with a spotless history may disappear overnight after exhausting available credit or value through transactions they have no intention of paying for. Investigators find that the customer never existed in the way the account history suggested. The account was built around a synthetic identity rather than a genuine customer.

That delayed visibility is part of the challenge. Synthetic identity theft is a shift from short-term opportunism toward longer-term fraud. Synthetic identities can take months to establish, so the eventual return needs to justify the time and effort invested. Simply put, the longer a criminal nurtures the profile, the greater the payoff often needs to be.

To be successful, fraudsters must stitch together attributes, open accounts, behave like low-risk customers and build positive histories before executing their attack. This patience is part of what makes synthetic identity theft difficult to spot. The identity profile may appear credible for months, even as it is being prepared for eventual monetization.

Static identity checks, identity verification and credit bureau data still play an important role, but they can struggle to detect synthetic identities deliberately designed to appear stable and credible. These profiles may not trigger obvious red flags at onboarding because the issue is not always inconsistency, but artificial consistency. This creates a challenge for institutions that rely too heavily on single-point controls.

This long development period is what makes the risk harder to see. The account looks and acts normally, often building a credible history before any losses appear. That is why the risk can remain hidden until the profile is monetized.

What fraud and identity teams should reassess

Synthetic identity theft puts pressure on one of the basic assumptions behind identity checks: that a credible-looking identity belongs to a genuine customer. That assumption is becoming harder to rely on when a profile can pass initial checks, build a normal account history and only become risky months later.

The question for organizations is whether their controls can see that risk as it develops. Are they only assessing the identity at onboarding, or are they also looking at how the account behaves over time? Can they connect identity, behavior and transaction context when a profile begins to deviate from its expected pattern?

The answer is not to add friction everywhere. It is to understand where synthetic identity risk can enter, how long it can remain hidden and what signals may show that a credible-looking profile is no longer behaving like a genuine customer. 


1. LexisNexis® Risk Solutions, 2026 Cybercrime Report.

Have Sales Contact Me

Related Resources

Loading...


Products You May Be Interested In