Synthetic Identity Fraud
Synthetic identity fraud is the creation of a fictitious person by combining real personally identifiable information, most often a legitimate Social Security number, with a fabricated name, date of birth, or address. The resulting identity belongs to no actual person, yet it can pass standard verification checks and build a credit history over years.
How a synthetic identity gets built
The scheme starts with an SSN that has little or no credit history attached, frequently a child’s or a recent immigrant’s. The fraudster pairs it with an invented name and applies for credit repeatedly until a lender’s system creates a credit file. From there the identity is cultivated like a real customer: small tradelines, on-time payments, growing limits. The payoff is the "bust-out," maxing every line and disappearing, sometimes years after the identity was seeded.
The Federal Reserve estimates synthetic identity fraud has cost US lenders $6 billion, and calls it the fastest-growing financial crime in the country.
Why community banks are particularly exposed
Synthetic identities have no victim to complain, so the fraud surfaces as an ordinary charge-off rather than a fraud report. Detection requires cross-referencing identity elements against authoritative sources: does this SSN’s issuance history match this date of birth, does this person exist anywhere except a credit header? Document-based onboarding, which is what most community bank processes rely on, checks none of that.
The Social Security Administration’s eCBSV service (electronic SSN verification) and multi-source identity checks exist precisely for this gap: they validate that the name, SSN, and date of birth belong together according to the issuing authority, not according to the application.
Common questions
How is synthetic identity fraud different from identity theft?
Identity theft impersonates a real person, who eventually notices and disputes. A synthetic identity is a fabricated person, so there is no victim to raise the alarm; losses usually get booked as credit losses instead of fraud.
How do lenders detect synthetic identities?
By validating identity elements against authoritative sources (SSA eCBSV, document + biometric checks, multi-bureau consistency) and by treating thin, fast-growing credit files with inconsistent histories as review triggers.
Why is it called a bust-out?
The endgame of a synthetic identity: after building credit limits over months or years, the fraudster draws every available line at once and abandons the identity.