Synthetic identity fraud is the creation of a fictitious identity by combining real and fabricated information, such as a genuine government ID number paired with a made-up name, birthdate, and address. Unlike stolen identity fraud, there is no single victim to notice and report the crime, which makes synthetic identities durable tools for opening accounts, obtaining credit, and defrauding commerce brands.
How Synthetic Identity Fraud Works
Bad actors assemble the identity from pieces: leaked personal data purchased on the dark web, generated names and histories, and increasingly AI-generated documents and profile photos. The identity is then aged. It opens small accounts, builds transaction history, and behaves normally until it has enough standing to be useful. In ecommerce, synthetic identities power promo abuse at scale, reseller alias accounts, BNPL and credit abuse, and refund schemes that need a clean identity with no claims history.
Visa’s Fall 2025 threats report lists synthetic identities among the reusable infrastructure bad actors now build once and deploy across attack types, and its Spring 2026 report notes that AI has fundamentally lowered the barrier to producing convincing fakes.
Why Synthetic Identities Beat Traditional Checks
Identity verification asks whether the presented details are internally consistent and match a record somewhere. A well-aged synthetic identity passes both tests: the details are consistent because they were designed together, and the record exists because the identity created it. What a synthetic identity cannot fake is coherent behavior over time. Device reuse across supposedly unrelated identities, network overlap, impossible activity patterns, and accounts that only exist to redeem value are the seams where synthetics show.
How to Detect Synthetic Identity Fraud
Layered signals work where document checks fail: device intelligence and network telemetry that link identities sharing infrastructure, behavioral analysis that distinguishes organic account history from manufactured aging, velocity checks on account creation, and consortium-style intelligence that spots the same synthetic identity moving between merchants. Guidance from NIST on digital identity emphasizes exactly this kind of layered assurance over single-point verification.
How Wyllo Helps
A synthetic identity is built to pass identity checks, so Wyllo evaluates what it can’t manufacture: intent expressed through behavior. Wyllo Bot and Reseller Detection connects device, network, telemetry, and behavioral signals to expose masked and manufactured identities, and Wyllo Payment Fraud Protection screens the transactions they attempt.
Frequently Asked Questions
How is synthetic identity fraud different from identity theft?
Identity theft hijacks a real person’s complete identity, and that person eventually notices. Synthetic identity fraud manufactures a new identity from mixed parts, so no individual victim exists to raise the alarm, and schemes can run for years.
Why does synthetic identity fraud matter to ecommerce brands?
Because it feeds the abuse economics upstream of payments: fake accounts for promotions and referrals, alias accounts for resellers, and clean identities for claim and refund schemes. The payment often approves; the loss arrives later.
Can synthetic identities be detected at signup?
Often, yes. Device and network fingerprints shared with existing accounts, disposable contact details, and telemetry inconsistent with a human signup are visible on day one, before the identity has transacted at all.