A criminal pieces together a synthetic identity using fragments of personal information stolen from different individuals—a Social Security number from one person, a date of birth from another, and an address and phone number from a third. With the help of AI, these disparate data points can be combined into a convincing identity that can be used for a range of fraudulent activities.
The cybercriminal may then build a convincing profile around that identity, complete with social media accounts, fake employment history, and phony community ties. After establishing credit and taking out loans, the criminal “busts out,” disappearing with the borrowed funds.
As Lucas Olson, Fraud Management Analyst at Javelin Strategy & Research, detailed in the Synthetic 2.0: Evolving Identities Challenge Fraud Prevention report, many banks are unaware that a synthetic identity was involved in these cases. After the bust out, the institution may simply write off the loss rather than report it as fraud.
And that’s just one way synthetic identity fraud is impacting the financial services industry. Sometimes described as a victimless crime because no single individual is directly harmed, synthetic identity fraud is anything but.
Targeting Vulnerable Demographics
One challenge in mitigating synthetic identity fraud is the ease with which criminals can obtain consumer data. Information not already circulated on the dark web as the result of data breaches and leaks is often shared by consumers themselves on social media.
Once these data points is assembled, bad actors can use artificial intelligence to build increasingly sophisticated synthetic identities. While every demographic is at risk, some individuals’ personal information is especially valuable to fraudsters.
“A lot of times synthetics are based around Social Security numbers that are stolen from vulnerable populations,” Olson said. “If you can get the Social Security number of a kid from a data breach from a hospital, that kid’s not going to have anything to do with their credit report until they turn 18.”
“You get that decade plus where you can use the Social Security number, create a fake identity, and go build up credit,” he said. “You get a bunch of loans that you’re not going to pay off and then you disappear with all that money. Then, that kid turns 18, goes to open up a bank account, and they can’t because their credit is trashed.”
Children are especially vulnerable, but they are far from the only targets. Older adults, homeless individuals, immigrants, and prison inmates may also be targeted, particularly when their credit activity is less likely to be closely monitored.
All of these factors have made synthetic identity fraud a growing threat to financial services, with little indication that it will slow. As AI advances, synthetic identities are likely to become more sophisticated and increasingly difficult to detect.
Undefinable and Immeasurable
Despite the escalating threat, the industry still lacks a consensus definition of synthetic identity fraud.
For example, the U.S. Federal Reserve consulted industry players and defined a synthetic identity as a profile that combines primary elements such as name, date of birth, Social Security number, with supplemental information, including addresses, emails, and phone numbers.
“Banks typically don’t use this, and even the vendors that helped come up with this aren’t necessarily using this,” Olson said. “What they use is bit more operational, they may talk about first-party and third-party synthetic identity fraud. First-party is where I want to get a car and I’m planning on paying back the loan, but my credit isn’t good enough to get that loan.”
“So, I go into the car dealership and I give them all my information, but instead of giving them my Social Security number, I go online and get a credit privacy number, which will use someone else’s credit that is better than mine to get the approval,” he said. “I’m intending to pay it back, but that’s still first-party synthetic identity fraud.”
That approach differs from definitions of third-party synthetic identity fraud, in which a criminal combines disparate data points to create identity with no intention of repaying the loans back.
These grey areas have created a significant blind spot for banks, which makes it difficult to measure the scope of the problem and assess the effectiveness of fraud prevention efforts.
“A lot of this gets written off as bad debt, where banks are saying, ‘This person didn’t pay us back; it’s not fraud, it’s just they went bankrupt,’” Olson said.
“They don’t understand that it was someone intentionally defrauding them, so they don’t even see it on their balance sheet,” he said. “They can’t define it, they can’t measure it, and it disappears into the background. There are banks who are like, ‘We don’t have a problem with it.’ And those are the banks that have a huge problem with it.”
Digging into History
As financial institutions look for solutions, onboarding is one area ripe for improvement. Most institutions currently conduct identity, behavioral, and document checks, as well as ID verification and liveliness assessments, before making a final onboarding decision.
Yet synthetic identities can pass many of these checks, forcing institutions to look beyond the information presented at the point of application. Historical data can provide a more reliable basis for verification, particularly when it comes to core identity details.
“They will have a mismatch with the age of the person—it says they’re 40 years old, but they have two years of credit history—and that’s a red flag,” Olson said. “Or they’ve recently issued new contact information and there are multiple accounts that have the same information.”
“If you run their Social Security number and it is a valid number but there are three different names attached, it’s a red flag,” he said. “A lot of recent credit inquiries, a lot of unsecured debt linked to a lot of other suspicious accounts, these are common red flags.”
The earlier institutions can identify inconsistencies in these details, the better their chances of catching a synthetic identity before it takes hold. Once an identity has been established in a bank or credit union’s system, detecting the fraud can become considerably more difficult and expensive.
Onboarding is therefore a critical line of defense, but effective fraud detection can’t stop there. Modern, risk-based systems can also use ongoing Know Your Customer checks to detect warning signs of a potential bust out before it occurs.
Drilling Down on Definitions
Technology and infrastructure are essential to combating synthetic identity fraud, but banks have to first establish a clear understanding of the problem. By defining first- and third-party synthetic identity fraud and distinguishing between the two, institutions can begin analyzing their portfolios to assess the extent of their exposure.
That work is becoming increasingly urgent, not only because synthetic identity fraud continues to evolve, but also because customers increasingly expect their financial institutions to help protect them from these threats.
“Consumers don’t typically know what a synthetic identity is, but we ask them about fake identities, and they are super concerned about them,” Olson said. “They know their data is out there; they know it’s being used for all these nefarious purposes, and they’re concerned about it. It’s not a victimless crime. People know there’s a risk, and these synthetics are getting increasingly advanced.”
