Key takeaways
- Synthetic identity fraud definition: Synthetic identity fraud combines stolen real personal data with fabricated information to create "Frankenstein" identities used to execute financial crimes.
- Role of AI in accelerating fraud: Generative AI allows criminals to produce convincing counterfeit documents, automate fraud operations at scale, and target victims with high precision.
- Synthetic identity fraud vs. deepfakes: Synthetic identity fraud builds fabricated personal profiles, making it distinct from deepfakes, which are AI-generated audiovisual files designed to impersonate specific real individuals.
- UK economic impact of synthetic fraud: Synthetic identity fraud is one of the fastest-growing financial crimes in the UK, accounting for over £4 million in direct losses to the economy.
We all have a digital footprint which, among other things, indicates how, where, when and why we spend money. All of which amounts to our personal identity information - but also the central component of crimes committed by identity thieves and fraudsters.
Recent advances in technology have given criminals the ability to combine real personal data with artificially created ‘records’, stitching the two together to forge what is being called ‘synthetic identities’. They are also known, perhaps aptly, as ‘Frankenstein identities’.
The fact that these identities contain some legitimate details makes it relatively easy for them to pass through checkpoints undetected, details which are often the spoils of other crimes such as cyber attacks on corporations such as banks, utilities and retailers and even government departments.
By carrying out legitimate online transactions and applying for credit, the criminals quietly build online profiles for these hybrids of factual datapoints and non-existent identifiers. That lends fake identities credibility and a digital backstory for when they finally ‘bust out’ and are used at some future date in thefts, loan defaults or acquiring credit. Sometimes this happens years after personal information was initially acquired, before the fake identities vanish into cyberspace.
“Some criminals have highly-organised setups with hundreds, if not thousands, of synthetic accounts,” says Kathryn Westmore, Director, Financial Crime and interim Director, Fraud at UK Finance, the membership association for the banking and financial services industry. “Companies might well be good at spotting irregularities during customer onboarding. It’s also possible that accounts are being used for what appear to be normal small purchases, but which are done over multiple accounts.”
Risk analysis agency Lexis-Nexis Risk Solutions discovered a group of cottages found to be housing 439 “highly suspect” identities, some of which were registered there for seven years before detection. According to the agency, the identities made “hundreds of applications for credit, such as short-term and payday loans,” and were linked to a similar farm hundreds of miles away in Scotland. The agency estimated that synthetic identity fraud could cost the UK economy around £4.2bn by 2027, if target firms did not introduce robust screening measures.
Credit reference agency TransUnion, estimates that up to 5m UK consumers “may be synthetic fraud creations,” in contrast to Lexis-Nexis’ 2.8m valuation.
The challenge of spotting synthetic fraud in action
“Criminals using synthetic identities can be really difficult to identify,” says Westmore, pointing out that the nature of banking in particular has changed in recent years, adding complexity and challenges when it comes to rooting out fraudulent accounts and activity.
“It’s so common for one person to have multiple bank accounts now - one for bills, one for wages and so on. That means spending patterns of even one person are now different and look different, which the fraudsters are very aware of. Many make small purchases from a retailer, for example - with amounts often small enough to slip under the payment threshold at which suspicion is raised.”
Fake people, fake businesses
Synthetic identities are of course not restricted to impersonating individuals. A similar methodology is used to forge fake companies that go on to be used to commit a variety of crimes such as corporate fraud and even money laundering.
The criminals tend to exploit the gaps between the disparate verification systems of HMRC and Companies House. The ease with which one can register a company online in the UK can also be a drawback when it comes to checks rigorous enough to pick up on synthetic or other fraudulent entities. The Economic Crime and Corporate Transparency Act 2023 is attempting to address some of these gaps.
Synthetic identities are not deepfakes
It is worth noting that these synthetic identities are distinct from ‘deepfakes’. Banks and other organisations regularly report the onslaught of AI-generated voice files that can create an authentic-sounding clone of a real customer’s voice, from just a few recorded words. AI has also developed ways of bypassing selfie verification by generating ‘live’ fake facial images.
However, AI is making synthetic identity fraud easier. “AI is both a blessing and a curse,” Westmore says. “Yes, there are tools being developed by tech providers and in-house, but the technology can struggle with particularly sophisticated attacks. Criminals will sometimes sit on these identities for years, quietly building up their records before unleashing them in attacks.”
Fighting the fraudsters
Identity threat protection or detection must now go beyond the cursory checks made when a user logs into a system. It must be multi-layered to be effective against an evolving, tech-driven threat. Firms must be perpetually vigilant, monitoring all system activity throughout a session’s duration. In that time, any number of factors related to the session could change mid-flow – the access device, its IP address and location – all of which could trigger a defensive response.
UK Finance has five recommendations for its member companies on how to protect themselves.
1. Use identity verification at onboarding
Use Biometric checks and real-time data, and not just document validation, to confirm credit that applicants are real people
2. Use your device and behavioural analytics
Metrics such as uniform typing speeds, lack of cursor movement and repeated device use across identities, can indicate non-human or scripted behaviour. Using these to build behavioural and device profiles could improve the chances of spotting suspicious activity.
3. Continuous monitoring
Monitoring transaction patterns, personal data changes and digital activity can catch fraud well after onboarding, especially if the synthetic identities remain dormant for a period before launching.
4. Machine learning risk scoring
AI and machine learning tools can now identify combinations of online traits and behaviours that indicate synthetic identity long after an account is created.
5. Industry collaboration
Intelligence sharing across sectors is crucial. Organisations can then train their systems using shared insights to shore up their fraud defences, without exposing sensitive data.
Because these crimes can be committed through multiple ‘attack surfaces’ at any time of the criminals’ choosing, target companies must accept that there is no suspension of hostilities to be had in this war. Perpetual vigilance is the only conceivable solution in their fight against synthetic identity fraud.