Synthetic identity fraud, the practice of combining one real piece of personal data, often a Social Security number belonging to a child, a deceased person or someone who has never used credit, with fabricated name, address and date-of-birth details to build an entirely new borrower, is now responsible for tens of billions of dollars in annual US lending losses. The Federal Reserve’s own synthetic identity fraud programme attributes the “fastest-growing financial crime in the United States” label to the FBI and fraud analytics firms including Experian and GIACT, and the newest lender data shows the cost concentrated squarely in auto loans and credit cards.
Federal Reserve Bank of Boston payments fraud expert Mike Timoney put a number on the growth in a March 2025 interview for the bank’s Six Hundred Atlantic podcast: synthetic identity losses ran at roughly $8 billion a year in 2020, climbed to about $14 billion within a couple of years, and now sit above $30 billion. “It’s a big problem. It’s growing fast, and it’s costing us a lot of money,” Timoney said.
How synthetic identity fraud is built and aged
A synthetic identity is not stolen from one victim the way ordinary identity theft is. It is assembled from pieces, most often a real Social Security number paired with an invented name, date of birth and address. Fraudsters then “season” the fabricated profile for months or years: opening a small credit line, paying it on time, and letting the credit bureau file grow, before maxing out the available credit and disappearing in what the industry calls a bust-out. Timoney said the original route into the system was a credit card application, because approval gave the fake identity what he called “proof of life”: a credit bureau file that made the fabricated borrower look real to the next lender that checked it.
Certain Social Security numbers are more attractive to build on than others. Numbers belonging to children are rarely used before adulthood, giving fraudsters a decade or more before the gap is noticed. Numbers belonging to older or incarcerated people carry years of established credit history with little ongoing activity to disturb, which is precisely what makes a synthetic profile built on top of them look creditworthy.
Why auto lending and credit cards carry the losses
TransUnion’s most recent fraud analysis, published in October 2025 and based on loans originated between March and September 2023, found that average dollar losses from fraud in auto lending were 21 times higher than in credit cards and six times higher than in unsecured personal loans originated over the same period. Average auto loan losses reached $19,611, against $3,427 for personal loans and $940 for credit cards, and the gap held even among borrowers with strong credit scores.
- Super prime auto borrowers flagged by TransUnion as likely synthetic averaged more than $50,000 in losses per account.
- Fraud incidence rates in auto lending lag behind credit cards and personal loans, but dollars lost per case are far higher because loan amounts are larger.
- TransUnion flagged a related tactic, credit washing, in which consumers fraudulently dispute accurate but unfavourable credit history to inflate their apparent risk tier.
“The risk of fraud is no longer isolated to fringe cases. It’s becoming a systemic challenge that requires proactive, data-driven and innovative solutions,” said Satyan Merchant, TransUnion’s senior vice president for auto and mortgage, in the October release.
What FinCEN’s identity data shows
The clearest regulatory picture of the scale of identity-based fraud comes from the Financial Crimes Enforcement Network. In a report published in January 2024, FinCEN found that 1.6 million identity-related suspicious activity reports, 42% of all Bank Secrecy Act filings that year, were tied to $212 billion in suspicious activity during calendar year 2021. FinCEN identified more than a dozen distinct identity-exploitation typologies in that data; fraud, false records, identity theft, third-party money laundering and circumvention of verification standards accounted for 88% of the reports between them, and the analysis separately found that compromised credentials carry a disproportionately large financial impact compared with other exploitation types. FinCEN’s figures cover identity exploitation broadly rather than synthetic identity fraud alone, but they establish the size of the underlying problem that synthetic schemes sit inside.
Generative AI is closing the gap between fake and real identities
Synthetic identity fraud is a different threat from account takeover fraud, where a criminal hijacks a real person’s existing account rather than inventing a new borrower, and lenders now have to screen for both at once. Timoney said generative AI tools let fraudsters parse stolen data at a scale no human team could match, building more varied and convincing fake profiles and learning from the applications that get rejected. The raw material keeps growing: more than 3,200 data breaches were reported in the United States in 2024, sending between 1.6 billion and 1.7 billion breach notices to consumers, Timoney said.
That volume of exposed personal data is what feeds synthetic identity construction at scale, and it is pushing banks to rebuild digital identity verification around signals a fabricated profile struggles to fake: how long a phone number or email address has been active, whether an applicant has any identifiable family or social connections, and whether a sudden jump in applications from new accounts matches genuine demand or a fraud ring testing a weakness. A bank that sees weekly account applications jump from 300 to 3,000 overnight, Timoney said, is not looking at new customers.
Where auto lenders and regulators are focusing next
Synthetic fraud carries compliance exposure of its own. Attorneys Daniel Wittenberg and Tanya Lewis of Snell & Wilmer wrote in May 2026 that gaps in customer identification programmes required under the Bank Secrecy Act and anti-money-laundering rules, particularly in indirect auto lending channels where dealers collect and pass on applicant information, have drawn closer regulatory attention when they contribute to fraud losses. The warning signs they list for lenders include thin credit files carrying unusually high scores, multiple applications sharing one phone number or address, income that cannot be independently verified, and borrowers with no social media presence despite an established credit history.
Card networks are investing in comparable tooling outside the US. Abu Dhabi Islamic Bank’s deployment of Visa’s threat intelligence platform reflects the same shift toward real-time, data-driven fraud screening that US auto lenders and card issuers are now being pushed toward. A fuller list of active fraud-prevention and identity-verification vendors is on Fintechly’s regtech sector directory.