Get the hottest Fintech Hong Kong News once a month in your Inbox
Synthetic identity fraud is one of the fastest-growing fraud types globally, where fraudsters fabricate a person who never existed.
They typically stitch together a blend of real, stolen, manipulated and invented attributes until the composite is convincing enough to enter through the front door.
This shift moves away from years of defensive fraud management thinking. Fraud prevention has almost always focused on stolen credentials.
Now, attackers no longer need to steal an identity, as they can manufacture one.
Research from LexisNexis Risk Solutions backs this, indicating that more than one in ten frauds (11%) now involve a synthetic identity, representing an eightfold global YoY increase.
The most unsettling challenge for fraud prevention teams here is that there’s no longer a victim to raise an alarm immediately.
Generative AI and deepfakes are making these profiles all the more convincing, and manufactured identities are becoming remarkably difficult to detect.
What’s worse is that synthetic identity fraud is no longer isolated to a single market. It is happening more across regions and industries, and quickly becoming a global issue.
Which leaves an uncomfortable question for any fraud strategy still optimised for downstream threats: the exposure now sits upstream, at the point of onboarding.
What can you do about it?
Why Are Traditional Fraud Strategies Failing?
Traditional fraud strategies are starting to falter as synthetic identities are largely invisible at onboarding, which is the exact place point-in-time verification collapses.
When fraudsters can walk in the front door, downstream detection becomes either too late or costly. Static checks and siloed tooling struggle to detect AI-assisted personas that can appear consistent and “clean” at a single point in time.
Verification confirms that a set of attributes is valid and internally coherent. It does not establish that the person those attributes describe has ever existed. A composite built from real fragments clears the first bar comfortably, and the second bar is rarely raised.
And in a manufactured-identity world, the seams between tools create blind spots, and blind spots create risk exposure.
“Deepfakes vastly complicate digital identity verification. Protecting against this surge of attacks requires a solid line of defence incorporating end-to-end capture, fraud analysis and liveness checks. Even the smallest gap in your defences is like an open window that a fraudster can climb through.”
Left unattended, bad actors can use deepfakes to pass identity checks and create new accounts to make withdrawals and online purchases, launder crime proceeds, or abuse new customer bonus incentives.
The challenge, therefore, lies in determining whether the identity has a genuine, corroborated data footprint or whether it has been artificially constructed to appear legitimate.
How Do You Determine if You Can Trust an Identity?
While authenticity is necessary, it may not be sufficient on its own. An identity can be real and still represent elevated risk, too. Trust then comes into the picture, and it requires a mix of coherence and corroboration across attributes, behaviour and design signals.
This includes assessing if identity elements fit together, whether their patterns are consistent with genuine customer histories, and if the identity shows characteristics linked to synthetic formation or manipulation.
Real identities tend to have imperfect, inconsistent and long-running data footprints, like address changes and other forms of ‘data noise’.
Synthetic identities, meanwhile, can appear unusually clean or too perfect, with limited variation or an unrealistic density of corroborating data.
Now, what risk does this identity present now and over time? Risk is contextual and time-bound, and is not simply about whether an identity is legitimate. It can also involve whether it should be approved, challenged, limited or blocked at any given moment.
This requires ongoing trust monitoring and adaptive step-up, which allows your organisation to intervene only when evidence justifies the friction.
More Scrutiny Should Not Mean More Hurdles For You
Businesses cannot solve this by making every application harder. It’s tricky because genuine customers also bear the consequences of fraud controls through additional checks, delays, and manual human reviews.
LexisNexis Risk Solutions shares that assessing document, device, behavioural and network information has to be done together, so that businesses have a stronger basis for deciding which identity requires closer attention.
A suspicious connection or change in behaviour may justify another check, but evidence that continues to support trust should allow a customer to proceed without unnecessary interruption.
Many organisations already have elements of this capability. The difficulty is ensuring that findings from separate systems inform the same decision, rather than leaving each tool to assess its own small part of the customer.
Fraud also persists in the seams: between document checks, device intelligence, behavioural analytics and network insights. Orchestration is what removes those seams by ensuring that friction is applied only when risk warrants it.
Done well, it means asking three questions in sequence: is the identity real, can it be trusted, and what risk does the identity present now and over time?