Table of Contents
- 1 Key Takeaways:
- 2 What Is Synthetic Identity Fraud?
- 3 What Are the Types of Synthetic Identity Fraud?
- 4 Factors Contributing to the Complexity of Fighting Synthetic Identity Fraud
- 5 The Process of Carrying Out Synthetic Identity Fraud
- 6 Traditional vs. Synthetic Identity Fraud
- 7 Why Is Synthetic Identity Fraud Rising?
- 8 How Financial Institutions Can Protect Themselves from Synthetic Identity Fraud
- 9 How to Protect Yourself from Synthetic Identity Theft
- 10 Conclusion
- 11 Identity.com
Key Takeaways:
In 2022, 46% of organizations faced synthetic identity fraud, and by 2023, auto loan exposure to synthetic identities reached $1.8 billion. Combined with other U.S. lenders, the total impact soared to $3 billion. Research suggests these numbers could escalate to $5 billion by the end of 2024, indicating a concerning trend for the future.
As alarming as these statistics are, there is an even greater issue at hand. Financial institutions and enterprises affected by this type of fraud are often at a loss for effective countermeasures. Many are unsure if their current strategies are sufficient. The sophistication, complexity, and danger of synthetic identity fraud can be overwhelming. So let’s dive into, what exactly is synthetic identity fraud, and what measures are currently proving effective for some financial institutions.
What Is Synthetic Identity Fraud?
Synthetic identity fraud is a financial crime where criminals create fake identities by combining real and fabricated personal information. Unlike traditional identity theft, which involves stealing an existing identity, synthetic identities are entirely new and fictitious. This often includes using stolen Social Security Numbers (often from minors or deceased individuals) combined with fake names, addresses, and birth dates.
For example, a synthetic identity might have a real mailing address and a valid-looking Social Security Number. However, when cross-checked, the combination of these details doesn’t match any real person.
What Are the Types of Synthetic Identity Fraud?
1. Manipulated Synthetics
Manipulated synthetics use minor changes to real data to exploit vulnerabilities in verification systems for credit or loans. These fraudulent identities are based on real people’s information with slight modifications, such as altered addresses or dates of birth. Some users with poor credit history may create manipulated identities to access new credit, with the intent to repay it. However, this practice is still fraudulent.
2. Manufactured Synthetics
Manufactured synthetic identity fraud, also known as Frankenstein fraud, combines real and fake information to create a completely new identity. This type of fraud is the most challenging to detect and trace. Fraudsters create these identities by mixing real elements, such as Social Security Numbers (SSNs) or dates of birth, with fabricated information like phone numbers or email addresses. For instance, a fraudster might create a new name, address, and email address while using a genuine SSN. Recently, fraudsters have taken this a step further by using entirely fabricated information, including generating random SSNs from the same range used by the Social Security Administration. This method uses entirely fabricated information to create a new, fictitious identity.
Factors Contributing to the Complexity of Fighting Synthetic Identity Fraud
Financial institutions face a growing challenge in combating synthetic identity fraud. This type of fraud thrives due to several factors:
Complex Financial Systems
The interconnectedness of modern financial systems creates vulnerabilities for synthetic identities. Criminals can exploit discrepancies in verification standards across different institutions, making it difficult to detect fraud as the identity moves through the system. For example, two men in Miami used synthetic identities and shell companies to steal over $3 million from multiple banks.
SSN Randomization
While intended to improve security, the Social Security Administration’s (SSA) decision to randomize SSNs in 2011 has unintentionally aided synthetic identity fraud. Fraudsters can now create fake identities with less risk of detection by fraud systems programmed to identify non-randomized SSNs.
Exploiting Unassigned SSNs
Fraudsters often target SSNs belonging to children or deceased individuals. These numbers are valid but not actively monitored, making them ideal for creating synthetic identities that lack credit history and evade initial detection.
Fragmented and Inconsistent Data
Synthetic identities are a blend of real and fake information. This makes them difficult to detect with traditional fraud systems, which rely on identifying inconsistencies. For instance, an identity might use a real address but have a fabricated name and birthdate.
Lack of a Single Victim
Unlike traditional identity theft, synthetic identity fraud doesn’t target a specific person. There’s no single individual to report the crime, making detection more challenging. For example, in 2019, a ring used hundreds of fake identities to obtain credit cards and loans, causing millions in losses for financial institutions.
Regulatory Gaps
Existing regulations may not be comprehensive enough to address the nuances of synthetic identity fraud. Stringent financial reporting regulations, for example, might not cover the sophisticated methods used by fraudsters. This creates loopholes that allow synthetic identity fraud to flourish, making it one of the fastest-growing financial crimes in the US.
Data Breaches and Information Availability
Frequent data breaches provide fraudsters with the information needed to create synthetic identities. For instance, the Equifax data breach in 2017 exposed the personal information of 147 million people, including SSNs, which fraudsters could use to create synthetic identities.
Delayed Detection
Synthetic identity fraud can remain undetected for long periods, often until the fraudster defaults on significant loans. For instance, a group of 11 individuals in New York defrauded multiple financial institutions of $1 million before being caught.
Inadequate Identity Verification Processes
Many institutions rely on basic verification processes that can be bypassed with fabricated data. For example, a synthetic identity with a valid but stolen SSN and a fabricated name might pass through automated verification systems without raising any red flags.
The Process of Carrying Out Synthetic Identity Fraud
The process involved in carrying out synthetic identity fraud can be understood through its definition and components, as listed above. The following steps summarize these processes for easy understanding:
- Acquiring Foundational Data: This involves obtaining a core element of a real person’s identity, such as a Social Security number, personal identification number (PIN), or other government-issued ID.
- Fabricating Additional Information: Creating fictitious names, dates of birth, and other personal details to complement the valid SSN.
- Establishing a Credit Profile: The fraudster uses the synthetic identity to apply for various financial products like credit cards, loans, or utilities to build a credit history.
- Building a Trustworthy Credit Profile: Gradually increasing the credit limit by demonstrating responsible usage and timely payments, in turn building a high credit score over time.
- Cashing out and Defaulting: Maximizing the available credit by taking out loans and making large purchases. Eventually, the identity defaults on the debt, leaving lenders with significant losses.
- Evading Detection: Utilizing various addresses, phone numbers, and other details to complicate detection and hinder fraud prevention measures.
Traditional vs. Synthetic Identity Fraud
Traditional identity fraud involves stealing and using an individual’s complete personal information to commit fraud directly without modification, while synthetic identity fraud involves creating a new, fictitious identity by combining real and fabricated information.
While both types of fraud have a significant impact on individuals, there are key differences between them. Below is a detailed breakdown of both types:
S/N | Feature/Aspect | Traditional Identity Fraud | Synthetic Identity Fraud |
1 | Nature | Involves stealing and using the individual’s complete personal information to commit fraud directly without modification. | Involves creating a new, fictitious identity by combining real and fabricated information. |
2 | Process |
|
|
3 | Detection | Easier to detect as it involves real individuals who report unauthorized activities. | The combination of real and fake data in synthetic identity fraud makes it hard to detect. Without victims reporting the fraud, discovery is delayed, leading to greater financial losses for organizations. |
4 | Impact | Directly impacts real individuals whose identities are stolen, causing financial and emotional distress. | It primarily impacts financial institutions and lenders. Secondarily, it can lead to the misuse of real individuals’ SSNs. |
Why Is Synthetic Identity Fraud Rising?
Synthetic identity fraud is increasing due to several factors, including:
Data Breaches and Security Vulnerabilities
Many organizations, particularly those using centralized systems, lack proactive measures to effectively protect customer data. This vulnerability often leads to data breaches where vast amounts of personal information are exposed. High-profile breaches, such as the 1.5 billion records leaked in Real Estate Wealth Network data breach, demonstrate the ease with which fraudsters can acquire the foundational data needed for synthetic identity fraud when organizations fail to implement robust security protocols, encrypt sensitive data, or regularly update their defenses against cyberattacks.
Weaknesses in Lenders’ Verification Processes:
Lenders often have verification processes that can be exploited by fraudsters. These processes might rely heavily on basic data points, such as Social Security Numbers and dates of birth, which can be fabricated or manipulated. Additionally, the pressure to approve loans quickly can lead to less rigorous checks, allowing synthetic identities to slip through the cracks. The loosening of credit requirements, aimed at making credit more accessible, can also unintentionally facilitate fraud.
Challenges in the Credit Reporting System:
The credit reporting system struggles to keep up with the evolving nature of synthetic identity fraud. Since synthetic identities are created using a mix of real and fake information, they can establish a credible credit history over time, making detection difficult. Credit bureaus may not have the means to cross-verify the authenticity of all the information they receive, leading to synthetic identities maintaining good credit scores for extended periods. This lag in detection allows fraudsters to exploit the system for significant financial gains before being caught.
Impact of Generative Artificial Intelligence (AI)
AI is a powerful tool used by fraudsters for analyzing large amounts of data. AI algorithms can piece together bits of real and fabricated data to create identities that appear legitimate. Furthermore, the rise of deepfake technology, a by-product of AI advancements, poses additional concerns. In the hands of bad actors, deepfake tools can create realistic fake images and videos, making synthetic identities more believable, even to sophisticated verification systems. This capability significantly complicates the detection and prevention of synthetic identity fraud. AI can automate tasks like data analysis and identity generation, streamlining the creation of synthetic identities for fraudsters.
How Financial Institutions Can Protect Themselves from Synthetic Identity Fraud
An industry where scammers steal an average of $81,000 to $97,000 per incident before detection must act quickly to avoid significant financial losses. Below are steps financial institutions can take to reduce the impact of synthetic identity fraud:
Enhance Identity Verification Processes
Financial institutions already utilize multi-factor authentication (MFA) to add security layers, but biometric verification offers an even stronger defense. This technology requires a customer’s physical attribute, such as a fingerprint or facial ID, making it difficult for fraudsters to bypass security measures. JPMorgan Chase is a prime example of a financial institution using MFA to prevent unauthorized access and ensure multiple security layers.
Implement Decentralized Identity Verification with Verifiable Credentials (VCs)
Verifiable Credentials (VCs) offer a secure and tamper-proof way to verify an individual’s identity. These digital credentials go beyond traditional methods by not only holding government-issued ID information, but also incorporating biometric data like fingerprints or facial scans. This combined approach provides a strong layer of security. Biometric data is unique to each person, making it highly effective in verifying an individual’s uniqueness. Additionally, VCs can confirm genuine presence through real-time interactions such as live video verification or real-time biometric scans. This ensures the person using the credential is truly present at the time of verification.
Artificial Intelligence (AI) and Machine Learning (ML) Detection
Implementing AI/ML allows institutions to detect unusual patterns and behaviors that might indicate synthetic identities. For example, HSBC has successfully used AI to improve the detection of financial fraud, resulting in increased positive alerts and a reduction in false positives. Google’s Anti-Money Laundering AI (AML AI), tested with HSBC, demonstrated these capabilities by providing risk scores based on transaction data and other relevant information, significantly enhancing fraud detection efficiency.
Real-Time Monitoring and Data Analysis
Real-time monitoring systems can quickly detect and respond to fraudulent activities. By utilizing data analytics tools, institutions can assess risk and continuously flag suspicious activities.
Education and Compliance
Regularly train employees to recognize and respond to potential fraud attempts. Educate customers about the importance of safeguarding their personal information and how to recognize phishing attempts. Regularly train employees to recognize and respond to potential fraud attempts.
Strict Compliance with Regulations
Follow regulatory guidelines and industry standards for identity verification and fraud prevention. Implement Know Your Customer (KYC) and Anti-Money Laundering (AML) protocols rigorously.
How to Protect Yourself from Synthetic Identity Theft
While financial institutions are the biggest victims of synthetic identity fraud, real people’s SSNs are often involved. Below are some ways to protect yourself from from identity theft leading to synthetic identity fraud:
- Monitor Your Credit Regularly: Consider credit monitoring services that alert you of any changes or suspicious activities on your credit report. By regularly reviewing your credit reports, you can spot unfamiliar accounts or inquiries indicating synthetic identity fraud.
- Freeze Your Credit: Freezing your credit with the major credit bureaus can prevent fraudsters from opening new accounts in your name. A freeze restricts access to your credit report, making it harder for synthetic identities to be approved for credit.
- Watch for Unusual Activities: Be alert and do not ignore mail or bills addressed to you from unfamiliar sources. This could indicate that someone is using your information to create synthetic identities.
- Protect Personal Information: Be cautious with your personal information, both online and offline. Avoid sharing sensitive details like SSNs, birthdates, and addresses unless absolutely necessary.
- Protect Your Login Details: Avoid sharing login credentials with third parties. Implement strong and unique passwords for your accounts. Adding an extra layer of security through multi-factor authentication (MFA) is necessary for all your online accounts.
- Be Cautious with Social Media: Be mindful of the information you share on social media platforms. Fraudsters can gather details from your profiles to create synthetic identities. Ensure your privacy settings also limit the number of people who can see some private information.
Conclusion
The rise of synthetic identity theft poses a significant threat, demanding a comprehensive strategy for mitigation. Advancements in decentralized identity with verifiable credentials can verify the genuineness of an an individual, offering a promising path toward more secure and efficient verification. Stricter data protection regulations can further limit the information fraudsters exploit. However, collaboration among institutions to standardize verification processes is equally crucial. Ultimately, success hinges on a collective effort – institutions working together and individuals taking proactive steps to safeguard their information.
Identity.com
Identity.com, as a future-oriented organization, is helping many businesses by giving their customers a hassle-free identity verification process. Our organization envisions a user-centric internet where individuals maintain control over their data. This commitment drives Identity.com to actively contribute to this future through innovative identity management systems and protocols.
As members of the World Wide Web Consortium (W3C), we uphold the standards for the World Wide Web and work towards a more secure and user-friendly online experience. Identity.com is an open-source ecosystem providing access to on-chain and secure identity verification. Our solutions improve the user experience and reduce onboarding friction through reusable and interoperable Gateway Passes. Please get in touch for more information about how we can help you with identity verification and general KYC processes.