The Account That Was Never Real: How Synthetic Identities Defeat Modern KYC
- Elizabeth Travis

- 1 day ago
- 6 min read

When a bank approves a new customer, it assumes one thing above all else: that a real person sits behind the application. For most of the history of customer due diligence, that assumption held. The fraudster of the past stole an identity that belonged to someone, and somewhere a victim would eventually notice. Yet synthetic identity fraud breaks that logic entirely. There is no victim to raise the alarm, because the person being onboarded does not exist. The identity is assembled, not stolen, and it is engineered to pass exactly the checks designed to stop it.
The numbers make this impossible to treat as a fringe concern. According to Mitek Systems and Datos Insights, 84 per cent of fraud executives identify synthetic identity fraud as a high or moderate risk to application processes, with US unsecured credit losses reaching around 2.94 billion dollars in 2025, up from 1.8 billion in 2020. The same research puts annual growth at roughly 16 per cent. Equifax has gone further, describing synthetic identity fraud as the fastest-growing financial crime and warning that losses could reach 23 billion dollars a year by 2030. This is not a typology on the rise. It is a typology that has industrialised.
The fraud lives in the assembly, not the components
The defining feature of a synthetic identity is that every fragment can be real while the whole is fictional. The pattern is most developed in the United States, where a criminal combines a genuine social security number, often harvested from a child or an elderly person who does not use credit, with another person's name, a third party's address, and a fresh email account under the fraudster's control. The mechanics differ by jurisdiction, since countries without a single national identifier present a harder assembly problem, but the principle travels: each element survives scrutiny in isolation, no single data point is false, and the deception sits in the combination. An identity with no legitimate owner has no one to dispute it.
This is why legacy verification struggles. Traditional know your customer (KYC) controls were built to confirm that data points are valid and internally consistent. They were never designed to ask whether a plausible set of records actually belongs to a single living human being. As the firm Zyphe observes from its own network data, the fraud lives in the assembly rather than the components, and reused-but-real personal data patched into fresh accounts passes static onboarding checks precisely because nothing in it is technically wrong.
Patience is the weapon
What makes synthetic identity fraud so corrosive is not speed but patience. A synthetic identity is rarely cashed out on day one. The criminal opens a modest account, makes small transactions, repays a first line of credit on time, and waits. Over months or years the identity accrues a transaction history, a credit file and the quiet credibility of an ordinary customer. Then comes the bust-out: every available facility is drawn down at once and the identity vanishes. There is no one to pursue, because there was never anyone there.
The crime that hides in the write-off
Here lies the most uncomfortable feature of the threat. Institutions often fail to recognise they have been attacked at all, because the losses surface as ordinary credit write-offs, indistinguishable from customers who simply could not pay. And a write-off is a tidier number than a fraud loss. It demands no incident report, no regulatory notification, no awkward conversation about control failure. The incentive to look closely is weak, and the incentive to file the loss quietly is strong.
The pattern is visible even where firms do detect the problem. The Financial Conduct Authority (FCA) found that of 194,084 money mule accounts offboarded by 25 firms between January 2022 and September 2023, only 37 per cent were reported to the National Fraud Database. Detection and disclosure are not the same act, and the gap between them is where synthetic identities thrive. A threat that disguises itself as ordinary bad debt does not need to defeat a firm's defences if the firm never counts it as an attack.
Generative AI has changed the economics
The threat is not new, but its economics have shifted decisively. Generative AI has collapsed the cost of producing convincing synthetic personas at scale. Mitek reports that 40 per cent of financial institutions are already seeing increased attack rates linked to AI. The Payments Association puts it more starkly still, describing today's criminals as operating less like opportunists and more like agile technology firms offering fraud as a service. Synthetic identity creation is no longer a craft practised by skilled individuals; it is a productised service, sold and scaled like any other software.
The same forces have undermined the biometric defences many firms adopted as their answer. Document-and-selfie verification, the dominant onboarding pattern of the last decade, was tested against printed photographs and crude video replays, not against real-time face swaps and camera-injection tools available at commodity prices. The identity verification firm iProov reported a 741 per cent annual increase in injection attacks across 2025, and Gartner predicted that by 2026, 30 per cent of enterprises would no longer consider face-based identity verification reliable in isolation because of AI-generated deepfakes. The control meant to close the gap has itself become porous.
Regulators have named the threat
The supervisory position is no longer ambiguous. The Financial Action Task Force (FATF) published its Horizon Scan on AI and Deepfakes on 22 December 2025, explicitly identifying synthetic and hybrid identities as a means of opening accounts and evading detection, and warning that many AML systems remain ill-equipped to detect synthetic content. Supervisors will now scrutinise AI-specific controls as part of standard reviews, and the consequences of failure extend beyond fraud loss into regulatory exposure. The question a supervisor asks is not whether a firm suffered a synthetic onboarding, but whether its controls were proportionate to a risk that has been publicly catalogued.
The UK direction of travel sharpens the point. Cifas recorded a record 444,000 fraud cases in 2025, naming identity fraud as the most reported offence alongside more than 22,000 cases of money muling, and synthetic identities feed this trade directly, since an account in a fabricated name is the ideal vehicle for moving criminal proceeds without exposing a real person. The test firms must satisfy is also changing. HM Treasury intends to repeal the existing Strong Customer Authentication standards so the FCA can set more agile, outcomes-focused rules, which means the question is no longer whether a bank applied a prescribed control but whether its controls adapted as the threat changed. A firm that can show only that it followed yesterday's rulebook will find that a thin defence.
Why no single control is enough
The uncomfortable truth is that no single test exposes a well-built synthetic identity. Document checks confirm authenticity but not ownership. Biometric liveness confirms a live human but not that the human matches a real record. Database validation confirms that records exist but not that they belong together. Each control answers a different question, and a synthetic identity is engineered to give the right answer to each one in turn.
Effective defence therefore depends on layering, and on shifting the burden onto the points where synthetic assemblies break down. Cross-database validation, testing whether a name, address, date of birth and identifier have ever coexisted, catches identities that pass each component check individually, though it carries its own cost in false positives and data-protection obligations. NFC chip reading works because the issuing authority never signed the assembled identity, only the genuine one, where the document and the hardware support it. Most powerful of all is continuous monitoring after onboarding, because a synthetic identity has no real history and cannot sustain a consistent long-running behavioural pattern. None of these closes the gap on its own. The signal is not in the application. It is in the gap between the declared profile and the actual conduct of the account over time.
There is a further lesson in the data. No single institution sees the whole picture, because a synthetic identity is distributed across many firms by design, each holding one harmless-looking fragment. Network-level intelligence and consortium data sharing are becoming the difference between detection and blindness, and the smaller institution that cannot see across the network is the weak link the attacker selects.
Control effectiveness, not control existence
The lesson of synthetic identity fraud is the one OpusDatum has long pressed in other contexts: control existence is not control effectiveness. A firm can hold every certificate, run every scan and pass every audit while remaining wide open to a threat engineered around the very tests it relies upon. The presence of a KYC process proves nothing if that process was designed for a world in which identities were stolen rather than manufactured.
The firms that weather this shift will be those that treat onboarding not as a gate but as the first moment in a continuous assessment, and that measure their controls against the adversary as it now operates rather than as it once did. Synthetic identity fraud rewards complacency and punishes paper compliance. The account that was never real will keep passing the checks until the checks are built to ask a different question: not whether the data is valid, but whether the person is.
Is your onboarding built to detect a customer who was never real?
OpusDatum helps financial institutions stress test their customer due diligence and onboarding controls against the threats that now define the fraud landscape, including synthetic identities, AI-generated documents and deepfake-enabled circumvention. We focus on operational realism rather than audit comfort, assessing whether controls work in practice against an adversary that has industrialised. Contact us to discuss how we can help you test it.
%20-%20C.png)


