Synthetic Identity Fraud Is Quietly Building People Who Don't Exist
Criminals stitch real data points together with fake ones to invent 'people' banks and payroll systems will lend to, hire, and eventually be defrauded by.

Key points
- Synthetic identity fraud invents a person from a mix of real and fake data instead of stealing one real identity outright.
- No living victim ever notices the misuse, so the fraud can sit undetected inside banks, lenders and payroll systems for months or years.
- The Federal Reserve calls it the fastest-growing financial crime in the United States, with losses running into billions of dollars a year.
- Machine identities, the digital credentials software uses to talk to other software, are now being spun up the same way inside company networks.
- Consumers can freeze their credit and check their Social Security earnings record to make it harder for fraudsters to use their data.
Most people picture identity theft as a criminal grabbing your name, date of birth and card number, then pretending to be you. Synthetic identity fraud works differently, and it is far harder to spot.
The attacker does not steal a whole person. They build one.
A real Social Security number, often a child's or a pensioner's that is rarely checked, gets glued to a fake name, a made-up date of birth and an address the fraudster controls. The result is a credit file for a human being who has never existed. Because no real victim ever sees a strange charge on their statement, nobody complains. The fake person just quietly builds a credit history, gets approved for a card, borrows more, and eventually disappears with the money. Lenders call this last step a "bust-out".
The Hacker News flagged this week that the same trick is now being aimed at machine identities, which is the part that should make security teams sit up.
What is a machine identity, in plain English?
A machine identity is the digital ID card a piece of software uses to prove who it is to other software. Every time an app talks to a database, or a cloud server talks to a payments provider, it logs in using one of these credentials rather than a human username and password.
Modern companies run tens of thousands of them. They are created and destroyed automatically, often faster than any human can review. That churn is exactly what makes them attractive to fraudsters.
How does the synthetic trick apply to machines?
Attackers create a service account or an API key, which is a long string of characters an application uses as its password, that looks legitimate on paper. It borrows the naming pattern of real accounts. It sits in the right folder. It has plausible permissions. Nobody made it on purpose, but nobody flags it either, because it blends into the noise of a busy environment.
Over time, that fake machine identity gets trusted. It reads data. It moves money. It talks to production systems. By the time anyone audits it, the damage is done and the credential is gone.
Why is it so hard to catch?
Traditional fraud controls are built around a victim complaining. Synthetic fraud has no victim to complain. Human synthetics slip past credit bureaus because the file looks thin but not fake. Machine synthetics slip past identity tools because most companies still cannot list, with confidence, every non-human account inside their own network.
| Fraud type | Who the "identity" is | Who notices first |
|---|---|---|
| Classic identity theft | A real person | The real person, on their statement |
| Human synthetic fraud | A fabricated person built on real data scraps | The lender, after the bust-out |
| Machine synthetic fraud | A fake service account or API key | Usually nobody, until an audit |
What should ordinary people do?
Freeze your credit with each of the major bureaus. It is free, and it stops new accounts being opened in your name or against your Social Security number. Check your Social Security earnings record once a year for jobs you never had, a classic sign someone is using your number on payroll. Do the same for any children in your household, whose numbers are prime targets precisely because nobody thinks to look.
If you spot a credit file for a name that isn't yours attached to your number, report it to the Federal Trade Commission at IdentityTheft.gov and to the bureau that issued the file.



