SardineCon SF/2026

Learn More
Fraud types4 min read

What is Identity fraud?

SUBSCRIBE

Identity fraud is using stolen, synthetic, or altered identity data to commit fraud. It is the use of the data, not the act of stealing it, and it powers account opening, account takeover, and application fraud alike.

What is identity fraud, in plain English?

Identity fraud is the use of identity data to commit fraud. The data can be stolen from a real person, invented as a synthetic persona, or altered from genuine documents. Whatever its source, the fraud is in what happens next: opening an account, taking over an existing one, or pushing through an application under an identity that is not legitimately the user's to use.

It is important to keep it distinct from identity theft, which is the earlier act of acquiring the data in the first place, through a breach, phishing, or skimming. Theft is the setup; fraud is the payoff. One stolen dataset can fuel many separate acts of identity fraud across many institutions.

Identity fraud is the engine behind a large share of fraud types: account opening fraud, account takeover, and application fraud all run on it. A crucial nuance is that it includes synthetic identities that belong to no single real victim, which means waiting for a victim to report the crime will never catch them. Those cases need behavioral and network signals to surface.

Identity fraud versus identity theft

What changes

Identity theft

Identity fraud

What it is

Stealing the identity data

Using the data to commit fraud

Where in the chain

The setup step

The payoff step

Data source

Breaches, phishing, skimming

Stolen, synthetic, or altered data

Victim

A real person is compromised

May have no single real victim

How identity fraud is committed

Once identity data is in hand, fraudsters turn it into money along a familiar path:

  1. Acquire — Obtain the data. Buy stolen records, assemble a synthetic identity, or alter genuine documents to build a usable profile.
  2. Choose — Pick the attack. Open a new account, take over an existing one, or submit an application, depending on the target and data on hand.
  3. Pass — Clear the checks. Present the identity to verification, matching PII, documents, or biometrics well enough to be accepted.
  4. Extract — Cash out. Draw credit, move funds, or buy goods, then abandon the identity before it is flagged.

What it looks like in practice

In practice

A batch of personal records surfaces from a breach. Within weeks, a lender sees a cluster of loan applications using those identities, each with correct names and Social Security numbers but new phone numbers and devices that do not match the applicants' history. Some are real people being impersonated; a few are synthetic personas assembled from mixed data.

The real-victim cases eventually generate complaints, but the synthetic ones never will, because no single person owns them. What ties the whole batch together is shared device fingerprints, reused addresses, and behavior that does not fit the claimed identities. The team catches them through links and behavior, not by waiting for victims to call.

Why it matters to operators

Identity fraud is upstream of a huge portion of losses, so getting verification right shapes everything downstream. But the category has a built-in blind spot: synthetic identities have no victim, which means the standard signal of "someone reports their identity was misused" never fires for them. A program that leans only on victim reports and document checks will keep letting them through.

That is why effective detection combines identity verification, document and biometric checks, and linking PII across applications and devices. The verification confirms a coherent identity; the linking and behavioral signals catch the fabricated ones and the reused stolen data. Treating identity fraud as purely a document problem misses the half of it that has no victim at all.

What to watch in the data

  • PII reuse across applications. The same SSN, address, or phone appearing on multiple otherwise-distinct identities.
  • Identity-behavior mismatch. Correct personal data paired with a device, location, or behavior that does not fit the claimed person.
  • Post-breach surges. Spikes in applications using data that matches a known breach or dark-web dump.
  • No-victim identities. Personas that never generate a complaint, a hallmark of synthetic rather than stolen identities.
  • Document and biometric anomalies. Altered documents, template reuse, or liveness failures at onboarding.

Quick questions

What is the difference between identity fraud and identity theft?

Identity theft is stealing the data; identity fraud is using it to commit fraud. Theft is the setup, fraud is the payoff, and one theft can power many separate acts of fraud.

Does identity fraud always have a victim?

No. When it uses a synthetic identity assembled from mixed or fake data, there is no single real victim to report it, which is why behavioral and network signals matter more than victim complaints.

Which fraud types rely on identity fraud?

Account opening fraud, account takeover, and application fraud all run on it. Whenever a fraudster needs to appear as a legitimate identity, identity fraud is the underlying mechanism.

How is it detected?

Through identity verification, document and biometric checks, and linking PII across applications and devices. The linking and behavioral layer is what catches synthetic and reused-data cases that pass individual checks.

Why are synthetic identities so hard to catch?

Because they belong to no real person, nobody reports them, and their individual data fields can each be valid. They only surface through inconsistency checks, shared PII links, and unusual behavior.

Go deeper

  • FTC Consumer Advice: Scams ↗ — US consumer guidance on current scams and fraud, and how to report them.
  • FBI IC3 ↗ — The FBI Internet Crime Complaint Center. Fraud reporting and annual trend reports.

What to know alongside Identity fraud