The Complete Guide to Synthetic ID Fraud Stacks
Synthetic identities are built to pass the checks most fraud stacks run. Catching them takes layers that ask a different question – not whether an identity exists, but whether it holds together like a real person over time.

A synthetic identity fraud detection stack is a set of layers that each test a different part of an identity: the session, the submitted details, the records behind them, the risk they carry and the outcome they lead to. No single check catches synthetic identities, because they are built to pass checks one at a time. The layer most stacks lack is the one that tests coherence – whether an identity has the depth, consistency and history of a real person, not just records that match.
Key takeaways
- Synthetic identities are designed to pass structural checks. A matching name, Social Security number and address proves that the details exist, not that a real person is behind them.
- Generative AI is making fabricated identities faster to build and more convincing.
- Detection depends on how eight layers work together, and on which signals actually change the final decision.
- The most common gap is coherence over time: consistent, persistent, cross-validated evidence of a real person.
- Evaluate vendors by the layer they serve and the decision value they add on your own data, not by feature lists.
What is synthetic identity fraud?
The Federal Reserve defines synthetic identity fraud as “the use of a combination of personally identifiable information to fabricate a person or entity in order to commit a dishonest act for personal or financial gain.”
In practice, a fraudster combines real and invented details. A genuine Social Security number, often one whose owner is unlikely to notice, is paired with a fabricated name, date of birth and address. The result can appear in bureau records without belonging to anyone.
That is what makes synthetic identities hard to stop. They are not stolen from a victim who complains. They are assembled to look ordinary.
Why is synthetic identity fraud growing?
The Boston Fed describes generative AI as an accelerant. It lets fraudsters automate the creation of synthetic identities and make them look legitimate – for instance, by creating records of synthetic parents, producing authentic-looking documents and generating deepfake audio and video.
The playbook is patient. A synthetic identity opens accounts, transacts normally and builds a relationship. Then it draws down credit it never intends to repay. By the time the loss appears, the identity has passed every control it met along the way, and the loss can look like ordinary bad debt.
Why do traditional fraud checks miss synthetic identities?
Most fraud controls rely on structural validation. Does the name match the Social Security number? Is the address real? Is the phone number active? Synthetic identities pass these checks because they are built to.
The weakness is not in what these tools check. It is in what they cannot see. A real person accumulates a messy, uneven trail: years of online presence, contact details that persist, addresses that connect into a history. A synthetic identity has the right attributes but little of that depth.
What are the eight layers of a synthetic identity fraud detection stack?
An effective stack works as one decisioning system with eight functional layers. Each contributes a distinct kind of signal.
| Layer | What it does | Synthetic blind spot |
|---|---|---|
| 1. Signal collection | Captures device, IP, behavioural and submitted identity data at the point of interaction | A clean device and a normal session say little about whether the identity is real |
| 2. Identity verification | Checks attributes against bureau headers, government records and sanctions lists | Synthetic identities are assembled to match these records |
| 3. Data enrichment | Adds email, phone, address and consortium context | Most enrichment confirms that attributes exist, not that they hold together over time |
| 4. Risk scoring | Turns signals into probabilistic risk for specific fraud types | Models are only as strong as the variety of evidence they receive |
| 5. Rules engine | Enforces policy, velocity limits and known fraud patterns | New patterns fall outside predefined conditions |
| 6. Orchestration and decisioning | Combines signals, scores and rules into approve, review or decline | Thin or conflicting evidence is resolved under tight time budgets |
| 7. Step-up and case management | Escalates intermediate cases for extra verification or analyst review | Analysts need evidence they can read, not just a score |
| 8. Feedback and model governance | Feeds confirmed outcomes back into models and rules | Synthetic losses surface late, so the feedback arrives late |
For a closer look at how these layers produce decisions in practice, read The Modern Fraud Stack.
How do the layers work together?
Each layer answers a different question. Signal collection and verification ask whether the session and the submitted details are valid. Enrichment and identity intelligence ask whether the identity behind them is coherent. Scoring and rules weigh the evidence. Orchestration turns it into a decision, step-up resolves the uncertain middle, and feedback makes the next decision better.
The layers complement each other only when their evidence is different. Three vendors that all confirm an address exists add cost, not coverage. In transaction environments the whole loop typically has a budget of around 300 milliseconds, so every signal has to earn its place.
Where do fraud stacks fail against synthetic identities?
Failures rarely happen because a layer is missing. They happen when a layer returns an answer that looks sufficient but has little underneath it.
A synthetic identity can pass bureau validation, show no device risk and return acceptable enrichment results. Yet there may be no consistent digital footprint, no reinforcing signals and no evidence that the identity has existed as a real person for any length of time.

Three structural pressures widen this gap. Latency limits how much data a decision can draw on in real time. Cost limits the number of enrichment calls. Conversion targets discourage extra steps at onboarding. The result is a heavy reliance on existence checks and on reactive signals such as prior fraud exposure.
Where do identity and web intelligence fit?
Web intelligence examines whether an identity’s digital footprint is consistent, persistent and organic. Real people leave accumulated, uneven traces across the open web. Synthetic identities, however polished, tend to be too uniform, too recent and too disconnected from everything around them.
Heka adds net-new, cross-validated identity intelligence to the stack you already run. It assesses digital, social, breach and contact sources to answer three questions: do identity details align across independent sources, does the identity have a credible, persistent online footprint, and do its contact details or credentials appear in breach data? The output is a 0–100 score with explainable signals, delivered through a simple API into existing decisioning.
Heka does not replace orchestration platforms, credit bureaus, KYC vendors, document checks or device tools. It sits alongside them, mainly at the enrichment layer, and strengthens the scoring, orchestration and step-up decisions that follow.
In an evaluation with a digital consumer lender, Heka detected 48% additional fraud cases among applicants who had passed the lender’s existing identity, credit, device and rules checks. Generative AI can fabricate a document or a convincing video. Manufacturing years of consistent, independently corroborated presence is much harder. The same cross-validation helps with account takeover, where an established identity suddenly arrives with contact details it has never used before.
What signals indicate a synthetic identity?
Patterns worth flagging in live applications include:
- A digital presence that is sparse for the claimed identity age
- Phone numbers and email addresses that overlap with other applicant identities
- An address linked to multiple unrelated identities
- Identity details that do not align across independent sources
- Rapid credit-building on an identity with no earlier history
- A recently established record that is flawless in a way real histories rarely are
- Behaviour that is unusually uniform across sessions and applications
No single indicator is conclusive. Together, and cross-validated, they separate fabricated identities from legitimate thin-file applicants who simply have less history.
How should you evaluate synthetic identity fraud vendors?
Feature lists rarely tell you whether a vendor will change your outcomes. These criteria do.
Map capabilities to stack layers
Identify which of the eight layers each vendor actually serves. A “full-stack” platform may work mainly at verification and enrichment. If your gap is coherence, that vendor may not close it.
Measure incremental decision value
Ask whether the vendor’s output changes your final decision. A signal that repeats what you already know is redundant. A signal that reveals what your stack cannot see is what closes the gap.
Require explainability
Every flag should trace back to a source and a reason an analyst can read. Opaque scores slow investigations and are harder to defend in model governance and external review.
Test against your own synthetic cases
Generic detection rates say little about identities designed to look legitimate. Run a blind backtest: the vendor scores your historical applications before seeing any outcomes, and you compare the results with confirmed fraud.
Questions to ask vendors
- Which stack layer does your output serve, and which layers do you assume other tools cover?
- Scored blind on our historical applications, how much confirmed fraud do you surface that our stack missed?
- What happens to false positives at the same detection rate?
- Can every flag be traced to a source an analyst can review?
- How does your output reach our orchestration platform, and within what latency?
- Is your data net-new, or does it repackage sources we already buy?
How do orchestration, traditional data and net-new intelligence work together?
The orchestration platform is where decisions are made. Traditional data – bureau records, KYC and document checks, device intelligence – confirms that an identity exists and that someone is present. Net-new intelligence tests whether the identity is coherent over time. Each needs the others.
- Audit signal coverageFor each layer, list the vendors and internal systems that contribute, and mark where their evidence overlaps.
- Find the decision-critical gapsFocus on the gaps that let synthetic identities through. If the stack confirms existence and presence but not coherence, start there.
- Add evidence without adding frictionChoose signal sources that return structured, explainable output through an API, within your existing latency budget.
- Close the feedback loopFeed every confirmed fraud case, false positive and escalation result back into models and rules so the stack adapts as tactics change.
Why does explainability matter for synthetic identity risk?
A shared definition of synthetic identity fraud makes losses easier to classify, report and compare. It also raises a fair question for every institution: can its controls tell a verified identity from a fabricated one?
Answering that question means every layer should produce outputs that can be traced back to data and logic. That protects decisions in internal model governance and external review, and it gives analysts the confidence to act.
The stacks that stop synthetic fraud earliest ask a better question. Not “does this identity exist?” but “does it behave like a real person across time and context?” To see how Heka’s identity intelligence fits alongside your existing controls, explore more resources or book a demo.
Sources · Federal Reserve Bank of Boston, “Gen AI is ramping up the threat of synthetic identity fraud” (April 2025), citing FiVerity; FedPayments Improvement, “Synthetic Identity Fraud Defined”; Heka customer evaluation with a digital consumer lender (performance varies by portfolio and use case).
Frequently asked questions
- What is a synthetic identity fraud detection stack?
- It is a layered decisioning system that combines signal collection, identity verification, data enrichment, risk scoring, rules, orchestration, step-up verification and feedback. Each layer contributes a different kind of evidence, and detection quality depends on how well the layers work together rather than on any single check.
- How do you detect synthetic identities?
- Look beyond whether identity details match records. Synthetic identities tend to have a thin or recent digital footprint for their claimed age, details that do not align across independent sources, contact points shared with other applicants and unusually uniform behaviour. Detecting them reliably means testing coherence over time, not just existence.
- Why do traditional fraud tools miss synthetic identities?
- Traditional tools validate attributes against bureau, government and sanctions records. Synthetic identities are assembled to pass those checks, so a match confirms that the details exist, not that a real person stands behind them.
- What is web intelligence in fraud detection?
- Web intelligence analyses an identity’s footprint across open web, social, breach and contact sources to test whether it is consistent, persistent and corroborated by independent sources. It adds evidence that structural checks do not provide.
- How should you evaluate synthetic identity fraud vendors?
- Map each vendor to the stack layer it serves, then test it blind on your own historical cases. Measure the confirmed fraud it adds beyond your current stack, the effect on false positives and whether every flag can be explained to an analyst and an auditor.
- How much does synthetic identity fraud cost?
- Losses from synthetic identity fraud crossed $35 billion in 2023, according to the anti-fraud platform FiVerity, as reported by the Federal Reserve Bank of Boston in April 2025.
- Does Heka replace KYC, bureau or device checks?
- No. Heka adds net-new, cross-validated identity intelligence alongside orchestration platforms, credit bureaus, KYC and document checks and device tools, so existing decisioning has evidence those layers do not surface.


