Why KYC Struggles Against Synthetic Identities

Miscellaneous

8

min read

September 1, 2026

Author

Karan Patel

Know your customer processes were built to answer a specific question: is this person who they claim to be. Synthetic identity fraud breaks that question in a way traditional KYC was never designed to handle, because the identity being verified often isn't stolen from a real person at all. It's fabricated, assembled from a mix of real and invented data, then reinforced with synthetic media convincing enough to pass the very checks meant to catch it.

This post explains why synthetic identities are proving so difficult for conventional KYC frameworks, how these identities are actually constructed, and what institutions are doing to close the gap. This is a core part of the identity verification hardening work Deepdive Forensics Lab does with banks, fintechs, and other institutions rethinking onboarding in light of this threat.

What Makes an Identity "Synthetic"

A synthetic identity combines real and fabricated information into a new identity that doesn't correspond to any actual person. A common pattern involves pairing a real, often stolen, government identifier, a Social Security number or national ID number, with a fabricated name, date of birth, and address, sometimes assembled from data harvested across multiple breaches.

This differs meaningfully from traditional identity theft, where a fraudster impersonates a specific real person and has to work around that person eventually noticing the fraud. A synthetic identity has no real owner to notice anything. It exists purely as a construct, often nurtured over months with legitimate-seeming activity, small purchases, on-time payments, before being used for a larger fraud event.

Why Traditional KYC Wasn't Built for This

Document Verification Assumes the Document Is Tied to a Real Person

Standard KYC document checks verify that an ID document appears authentic and that the person presenting it matches the photo. This process assumes the underlying identity is real, just potentially misrepresented. It has no reliable mechanism for detecting an identity that was fabricated from partially legitimate components in the first place.

Credit Bureau and Database Checks Can Be Gamed Over Time

Cross-referencing an identity against credit bureau data is a standard KYC step, but synthetic identities are frequently built specifically to pass this check. Fraud rings often establish a thin credit file for a synthetic identity months or years in advance, using it for small, legitimate-looking transactions specifically to build the kind of credit history that makes the identity appear established and low-risk by the time it's used for larger fraud.

Biometric Checks Face Deepfake-Enabled Circumvention

Video-based identity verification, increasingly standard in digital onboarding, is meant to confirm a live human matches their submitted documents. Deepfake and face-swap technology directly targets this checkpoint, allowing a fabricated visual identity to be presented convincingly during the verification process itself.

KYC Is Largely a Point-in-Time Check

Most KYC processes are heavily weighted toward the onboarding moment, with less continuous verification afterward. Synthetic identities, particularly those cultivated over time before a fraud event, are specifically designed to exploit this front-loaded verification model, appearing clean at onboarding and only revealing fraudulent intent much later.

How Synthetic Identity Fraud Rings Typically Operate

Identity Construction

Fraud rings acquire real identifiers, often Social Security numbers belonging to children, deceased individuals, or people unlikely to actively monitor their credit, and combine them with fabricated personal details to create a new synthetic identity.

Credit Building

The synthetic identity is used to open accounts, often starting with secured credit products or accounts specifically designed for thin-file applicants, and builds a legitimate-looking payment history over an extended period, sometimes a year or more.

Bust-Out Fraud

Once the synthetic identity has established sufficient credit history and trust, it's used to max out available credit lines or execute a larger fraudulent transaction, with no intention of repayment, before the identity is abandoned.

Reuse Across Institutions

The same synthetic identity is frequently used across multiple financial institutions simultaneously, since siloed KYC processes rarely share enough information across institutions to detect an identity being cultivated in parallel at several places at once.

How Institutions Are Adapting KYC to Address This Gap

Continuous Verification Rather Than Point-in-Time Checks

Institutions are increasingly building ongoing monitoring into the customer relationship rather than treating onboarding verification as a one-time event, watching for behavioral patterns consistent with synthetic identity cultivation over time.

Cross-Institutional Data Sharing and Consortium Approaches

Because synthetic identities are often cultivated across multiple institutions simultaneously, some fraud prevention efforts now rely on consortium data sharing, allowing institutions to identify identities being built in parallel across the industry rather than relying solely on their own internal data.

Layered Biometric and Liveness Verification

Pairing document verification with active liveness detection, requiring specific real-time movements that are harder for synthetic video to replicate convincingly, closes part of the gap left by static document and photo checks.

Device and Behavioral Fingerprinting

Examining device characteristics, application behavior, and session patterns used during account opening can reveal inconsistencies, the same device used to open multiple seemingly unrelated identities, for example, that document and biometric checks alone would miss.

Machine Learning Models Trained Specifically on Synthetic Identity Patterns

Rather than relying solely on traditional fraud models built around stolen identity patterns, institutions are increasingly training detection systems specifically on the behavioral and data patterns characteristic of synthetic identity cultivation, which looks meaningfully different from both legitimate customer behavior and traditional identity theft.

Helping institutions design this kind of layered, continuous verification approach is central to the identity verification hardening services Deepdive Forensics Lab provides to financial institutions confronting synthetic identity fraud at scale.

A Misconception Worth Correcting

There's a common assumption that synthetic identity fraud is primarily a document forgery problem, solvable with better ID verification technology alone. In practice, the more sophisticated synthetic identities are specifically designed to pass document and biometric checks convincingly, and the more reliable detection signals often come from behavioral patterns and cross-institutional data that have nothing to do with the document itself.

The Bottom Line

Synthetic identity fraud exposes a structural gap in traditional KYC processes, which were built to verify whether a claimed identity matches a real person, not to detect an identity that was fabricated from partially legitimate components in the first place. Point-in-time document and biometric checks, however well executed, aren't sufficient on their own against an attack specifically designed to pass them.

Institutions managing this risk effectively are moving toward continuous verification, cross-institutional data sharing, and behavioral analysis layered alongside traditional document and biometric checks, treating KYC as an ongoing process rather than a single onboarding gate.

Building this kind of modernized, layered verification architecture is the work Deepdive Forensics Lab does with financial institutions working to close the gap synthetic identities have opened up in traditional KYC.

get started

Ready to verify and protect digital truth?

Submit a file, a link, or an enquiry. Our team will assess your case and respond within one business day.