Synthetic identity fraud uses a person who does not exist. Real and fabricated details are combined, and increasingly reinforced with AI-generated faces, voices and documents, to pass identity checks and gain a position of trust: an account, a loan, or a job.
This library records 11 cases, which makes it one of the fastest-growing patterns documented here.
How the attack runs
- Assembly. Genuine fragments are combined with invented ones so the identity partly matches real records.
- Reinforcement. A face, a voice, and supporting documents are generated to satisfy verification.
- Passing the check. The identity clears onboarding, including automated liveness tests in several documented cases.
- Establishing trust over weeks or months of ordinary behaviour.
- Extraction, whether financial or access to internal systems.
Documented cases
How it differs from related techniques
Voice cloning imitates a specific real person; synthetic identity invents one. Recruitment fraud is the most common delivery route. Account takeover seizes an existing account, whereas this creates a new one that was never legitimate.
The control that would have stopped it
- Liveness detection that resists replay, since the Aadhaar case shows simple blink checks can be satisfied by generated video.
- Verify references independently. CoHost’s references were fabricated and were never checked through a separate channel.
- At least one unscripted live interaction in hiring. Vidoc caught both candidates this way.
- Corroborate identity against sources the applicant does not control, rather than the documents they supply.
- Treat remote onboarding as a security boundary, with the same rigour applied to system access as to payments.