Palm Logo
August 8, 2026·PalmAI-ProductTeam

Synthetic Identity Fraud: Why Document-Only KYC Is No Longer Enough

Synthetic identity fraud: how fabricated identities pass document KYC and why document-only verification misses them

TL;DR

Synthetic identity fraud is a type of identity crime in which an attacker combines real and fabricated personally identifiable information (PII) — often a legitimate Social Security number paired with a fake name and birthdate — to create a new identity that belongs to no real person. The fabricated identity is then used to apply for credit, build a transaction history over months, and "bust out" with maximum loans before anyone notices. Document-only KYC verification frequently misses this attack because the documents and credit files check out — the problem is that the identity itself was manufactured. No amount of document checking can confirm that a well-built synthetic identity corresponds to a real human being.


What Is Synthetic Identity Fraud?

Synthetic identity fraud is a form of identity crime in which an attacker fabricates a new identity by combining real PII (typically a stolen SSN or national ID number) with fictitious names, birthdates, and addresses, then builds a credit or transaction history under that identity before exploiting it for financial gain.

Unlike traditional identity theft — where a fraudster impersonates an existing, real person — synthetic identity fraud creates an identity that never existed. There is no victim who notices unfamiliar charges on their statement. The "person" is a composite, and the crime often goes undetected until the fraudster "busts out": maxing out all available credit lines and disappearing.

The U.S. Federal Trade Commission has flagged synthetic identity fraud as one of the fastest-growing financial crimes, and the American Bankers Association has reported that it accounts for a significant share of credit-card losses for U.S. issuers. The damage is hard to quantify precisely because the identities are designed to evade detection — industry estimates suggest billions of dollars in annual losses, but no single figure is universally accepted.


How Synthetic Identities Are Built

The fabrication process is methodical and patient. It typically unfolds over months, sometimes longer:

  1. Obtain a real SSN or national ID number. Fraudsters acquire legitimate numbers — often belonging to minors, elderly individuals, or people who rarely check their credit — through data breaches, dark-web marketplaces, or insider sources. The number is real and valid; the rest of the identity will be invented.

  2. Apply for credit using the fabricated identity. The fraudster pairs the real SSN with a fake name, birthdate, and address, then applies for a credit card or store account. The initial application is usually rejected — but the application itself creates a credit file at a reporting agency. The synthetic identity now "exists" in the financial system.

  3. Build a payment history. The fraudster secures a subprime credit card or an authorized-user slot on another account, makes small purchases, and pays them off reliably for months. Each on-time payment strengthens the synthetic identity's credit score. Some fraudsters use "piggybacking" services that sell authorized-user positions on seasoned accounts to accelerate the process.

  4. Bust out. Once the credit score is high enough, the fraudster applies for multiple credit lines in quick succession — cards, personal loans, auto loans — maxes them all out simultaneously, and disappears. Because no real person is associated with the identity, collection efforts lead nowhere.

The entire cycle exploits a structural weakness: credit reporting systems treat the existence of a credit file as evidence of a real person. A well-executed synthetic identity builds a file that looks indistinguishable from a genuine consumer's.


Why Document-Only KYC Misses It

Standard KYC verification — photographing a government ID, checking it against watchlists, and matching a selfie to the ID photo — is designed to answer the question: Is this document authentic, and does the person holding it match the photo? That question is necessary, but it is the wrong question for synthetic identity fraud.

Here's why: the fraudster's documents often do check out. In many cases, the fraudster obtains a genuine driver's license or state ID using the synthetic identity — because the issuing authority itself relied on the same credit-file existence that banks rely on. The document is real. The selfie matches the document. The name and SSN are consistent. The KYC check passes.

The problem is not that the document is fake. The problem is that the identity the document represents was fabricated from the start. No document check can tell you whether the identity behind the paper corresponds to a real human being, because the identity was built to satisfy document checks.

This is fundamentally different from the deepfake and injection-attack problem we cover in our Deepfake-Era KYC guide. That article addresses attackers who use AI-generated face swaps and camera-feed substitution to impersonate a real person during remote onboarding. Synthetic identity fraud is a different threat: the attacker isn't impersonating anyone — they're inventing someone who doesn't exist, then proving that invention with legitimate-looking documents. Both attacks defeat document-plus-selfie KYC, but they attack different layers of the identity stack.


Synthetic Identity Fraud vs. Deepfake and Presentation Attacks

The table below separates the two threat models — both of which bypass document KYC, but at different layers and for different reasons.

Synthetic identity fraud vs. deepfake/presentation attacks: different threats, different KYC failures
DimensionSynthetic Identity FraudDeepfake / Presentation Attacks
Attack vectorFabricate a new identity from real + fake PII; build credit history over monthsSubstitute a synthetic face or camera feed during a live verification session
What's fakeThe identity itself — the person doesn't existThe face on camera — the person exists but isn't present
TimelineMonths of patient credit-building before exploitationReal-time, during a single onboarding or login session
What document KYC seesA legitimate document issued to a fabricated identity — checks outA real person's document, paired with a synthetic face — may check out
What KYC layer catches itIdentity proofing upstream: SSN cross-checks, credit-bureau velocity checks, utility/property history verificationLiveness detection, injection-attack detection, camera-path integrity
What a physical biometric anchor doesTies the fabricated identity to a real physical body at enrollment — but doesn't verify the identity record is genuineProvides a verification signal the camera cannot spoof — subcutaneous vein patterns have no public dataset

The distinction matters for any team building a KYC fraud prevention stack. If you invest only in deepfake detection, you remain vulnerable to synthetic identities that walk in with legitimate documents. If you invest only in identity proofing and credit-bureau checks, you remain vulnerable to real-time deepfake injection. The two threats require different defensive layers.


What a Physical Biometric Anchor Does — and Doesn't — Solve

A physical biometric anchor — such as palm recognition that reads both surface palm print and subcutaneous vein patterns — can play a role in defending against synthetic identity fraud, but the role is specific and bounded. An honest assessment requires separating what it accomplishes from what it does not.

What it does

Palm recognition ties an enrolled identity to a physical body. When a user enrolls their palm, the system captures a biometric template that is unique to that individual and cannot be reconstructed from photographs or public data (because the vein pattern sits beneath the skin and is only revealed via near-infrared light). Once a palm template is linked to an account, subsequent transactions require the same physical hand at the sensor.

This creates a property that document KYC alone cannot provide: a one-to-one binding between the identity record and a real, present human body. A fraudster who fabricated a synthetic identity cannot transact on that identity's account without physically presenting the palm that was enrolled — and a fabricated identity has no real body attached to it. If enrollment requires a physical palm scan at a branch, kiosk, or partnered location, the fraudster must show up in person, creating a physical-trace risk that purely digital synthetic identity schemes are designed to avoid.

What it doesn't solve

Here is the honest limitation: a physical biometric anchor does not verify that the underlying identity record is genuine. If a fraudster builds a synthetic identity, obtains a legitimate driver's license under that identity, and then enrolls their palm at a branch, the palm recognition system faithfully binds the fraudster's real hand to a fake identity. The biometric lock is strong — but it's locking a fabricated identity.

This means palm recognition is not a standalone solution for synthetic identity fraud. It needs to be paired with upstream identity proofing: SSN or national-ID cross-checks against issuing authorities, credit-bureau velocity checks (does this identity's credit file appear suddenly, with no history of utility or property records?), and device or network risk scoring during the application process. The biometric anchor adds a physical-presence requirement that raises the cost and risk of the attack — but it doesn't replace the need to verify the identity itself.

To put it directly: if your identity proofing layer accepts synthetic identities, a palm scan will just biometrically lock the fake identity to the fraudster's hand. The biometric improves transaction-level security after enrollment; it does not retroactively validate the identity that was enrolled.


How AI Is Scaling Synthetic Identity Fabrication

The fabrication process described above has existed for years, but generative AI is lowering the effort and increasing the scale at which it can be executed. This is where the synthetic identity problem intersects with the broader AI identity fraud landscape.

Large language models can generate consistent backstories, employment histories, and residential narratives that hold up under manual review. Automated form-filling tools powered by AI can submit hundreds of credit applications across different lenders in parallel, each with slightly varied PII combinations, to discover which synthetic identities pass which lenders' checks. AI-generated profile photos — faces that don't belong to any real person but are photorealistic — can populate social media accounts that lend credibility to a fabricated identity when a fraud analyst searches for the applicant online.

This scaling effect matters because it shifts synthetic identity fraud from a craft practiced by individuals to an industrial process. A fraudster who previously maintained two or three synthetic identities over a year can now manage dozens, each with a plausible digital footprint, because the labor of maintaining consistency has been automated. Industry reporting from PwC's 2026 fraud analysis noted that generative AI is accelerating both deepfake-based and synthetic-identity-based fraud simultaneously — the two threats are distinct, but they share a common amplifier.

The defensive implication is straightforward: identity proofing that relies on manual review of application data is increasingly outmatched. Automated cross-checks against issuing authorities, velocity analysis across credit bureaus, and physical-presence requirements at key enrollment moments all become more important when the volume of synthetic applications rises.


Where Palm Recognition Fits

For institutions building a layered KYC fraud prevention stack, palm recognition fits at a specific point in the process — not at the document-checking stage, but at the identity-binding stage that follows it.

After document KYC, credit-bureau verification, and sanctions screening have been completed, a palm enrollment step binds the verified identity to a physical biometric that cannot be transferred or remotely spoofed. Subsequent high-risk transactions — large transfers, account changes, new credit applications — can require a palm scan as a step-up check, confirming the same physical person is present. KYCMax is built for this identity-binding and step-up verification use case.

For transaction-level authentication in payment flows, PayMax extends the same palm-based verification to point-of-sale and self-service scenarios. And for institutions deploying across branches, ATMs, and kiosks, PalmAI's industry solutions cover the hardware and integration patterns needed for multi-channel rollout.

The key framing: palm recognition doesn't replace document KYC or identity proofing. It adds a physical-presence layer that synthetic identities — which have no real body — cannot satisfy without exposing the fraudster to physical-trace risk. Combined with upstream identity proofing, it raises both the cost and the detectability of synthetic identity fraud.


Limitations and Considerations

A balanced assessment requires acknowledging where palm recognition falls short as a defense against synthetic identity fraud:

  • It does not replace identity proofing. As stated above, a palm scan binds a body to an identity record, but it doesn't validate that the identity record itself is genuine. Upstream checks — SSN verification, credit-bureau history analysis, utility and property record cross-references — remain essential and irreplaceable.
  • It requires hardware at the enrollment point. Palm vein patterns cannot be captured by a standard smartphone camera; deployment requires dedicated near-infrared sensors. This means palm-based enrollment works at branches, kiosks, and partnered locations, but not in fully remote, app-only onboarding flows.
  • It adds a step to enrollment. Any additional verification step introduces friction and potential drop-off. Institutions should reserve palm enrollment for identity-binding moments where the security gain justifies the added step — typically high-value account opening, not every consumer signup.
  • Synthetic identities detected after enrollment remain a problem. If a fraudster enrolls a palm under a synthetic identity and the fraud is later discovered, the institution must be able to revoke the template and flag the biometric for future detection. Template management and cross-institutional information sharing are operational requirements, not just technical ones.
  • Regulatory guidance on palm biometrics is still maturing. While palm data falls under the same biometric-data categories as face or fingerprint data under GDPR, PIPL, and equivalent frameworks, specific implementation guidance for palm vein is less developed than for face. Compliance teams should confirm mapping with their DPO before deployment.

Frequently Asked Questions

What is synthetic identity fraud?

Synthetic identity fraud is a type of identity crime in which an attacker combines real and fabricated PII — typically a stolen Social Security number paired with a fake name, birthdate, and address — to create a new identity that belongs to no real person. The fabricated identity is used to apply for credit, build a payment history over months, and then max out all available credit lines in a "bust-out" before disappearing. Because no real victim is being impersonated, the crime often goes undetected until the losses are realized.

How is synthetic identity fraud different from deepfake-based KYC fraud?

Synthetic identity fraud fabricates an identity that doesn't exist and builds a credit history under it over months. The documents are often legitimate because the issuing authority itself relied on the same credit-file existence. Deepfake-based KYC fraud, by contrast, is a real-time attack in which an impersonates a real person during a live verification session using AI-generated face swaps and camera-feed injection. Both defeat document-plus-selfie KYC, but they attack different layers — one corrupts the identity record, the other corrupts the verification session. See our Deepfake-Era KYC guide for the deepfake threat model.

Can palm recognition stop synthetic identity fraud?

Palm recognition cannot stop synthetic identity fraud on its own. What it does is add a physical-presence requirement: a fabricated identity has no real body, so enrolling a palm at a branch or kiosk forces the fraudster to physically appear and bind their real hand to the fake identity. This raises the cost and risk of the attack, but it does not verify that the underlying identity record is genuine. Effective synthetic identity fraud prevention requires upstream identity proofing (SSN cross-checks, credit-bureau velocity analysis) combined with physical biometric binding at enrollment.

Why does document-only KYC fail against synthetic identities?

Document-only KYC checks whether a document is authentic and whether the person presenting it matches the photo. Synthetic identities often pass both checks because the fraudster obtains a genuine driver's license issued under the fabricated identity — the issuing authority itself was fooled by the credit-file existence the fraudster built. The document is real; the identity behind it is not. No document check can determine whether the identity corresponds to a real person, because the identity was constructed to satisfy document-based verification.

What should institutions do first to defend against synthetic identity fraud?

The highest-leverage first step is strengthening upstream identity proofing: cross-check SSN or national ID numbers against issuing-authority databases, analyze credit-bureau file velocity (does the file appear suddenly with no utility, property, or employment history?), and flag applications where the applicant's age doesn't match the SSN issuance date. After identity proofing, add a physical biometric anchor — such as palm recognition via KYCMax — at enrollment to bind the verified identity to a real body. Use the contact form on this page to discuss deployment scenarios for your institution.


Related Resources


About Tencent PalmAI

Tencent PalmAI is an AI-powered palm recognition service combining palm print and palm vein identification. As synthetic identity fraud and AI-driven identity threats reshape the KYC landscape, PalmAI provides a physical-presence verification layer that complements — rather than replaces — upstream identity proofing.

Learn more at palm.tencent.com

Ready to start ?
Use PalmAI in your business now!