Synthetic identity fraud is the fastest-growing financial crime in the US. In India, digital fraud rates are nearly double the global average. Most compliance teams don’t see it coming until after the loss. Here’s what makes it so hard to catch: there’s no victim filing a complaint. The person doesn’t exist.
Table of Contents
- Introduction: The Invisible Crime
- The Four Stages of Synthetic Identity Fraud
- Why It’s So Hard to Detect
- The Indian Context: A Perfect Storm for Synthetic Identity Fraud
- The Fraud-AML Structural Gap
- How to Defend Against Synthetic Identity Fraud
- Regulatory and Reporting Implications
- Conclusion: Closing the Gap
- Frequently Asked Questions (FAQs)
1. Introduction: The Invisible Crime
Synthetic identity fraud is the fastest-growing financial crime in the US, and India’s digital fraud rate is nearly double the global average. Most compliance teams don’t see it coming until after the loss. The reason is simple: there’s no victim filing a complaint because the person doesn’t exist .
A criminal takes a real identity number—often from a child, a recent immigrant, or a deceased person—pairs it with a fabricated name, date of birth, and address, and builds a credit profile over months until it looks completely legitimate . Then they borrow as much as possible across multiple lenders at once and disappear.
In India, the problem is amplified by the scale of digital adoption. With over 800 million digital users and UPI processing nearly ₹30 trillion in a single month, every new rail built for legitimate money is also a new lane for illicit money . The suspected digital fraud rate in India reached 7.1% in 2025, nearly double the global average of 3.8% . Fraudsters are increasingly targeting existing user accounts through identity-based attacks .
2. The Four Stages of Synthetic Identity Fraud
Stage 1: Acquire the Seed Data
The fraudster obtains a real identity number. These are typically sourced from:
- Dark web breach data
- Stolen from children (whose identity numbers are often unused for years)
- Taken from deceased individuals
- Obtained from recent immigrants
In India, AI tools like Google’s Nano Banana Pro have been shown to generate highly realistic fake Aadhaar and PAN cards without safety checks, raising serious concerns about AI misuse and identity fraud .
Stage 2: Build the Synthetic Profile
The fraudster combines the real identity number with fabricated biographical details:
- Fake name
- Fake date of birth
- Fake address
- Fake phone number
- Fake email address
In India, fraudsters are creating “synthetic financial identities” using pre-activated SIM cards, forged bank documents, and debit/credit cards linked to dummy accounts . These “synthetic bank account kits” allow cybercriminals to operate untraceable shadow banking systems .
Stage 3: Cultivate the Credit
The fraudster builds a credit profile over months to make it look legitimate:
- Open secured credit cards
- Become an authorized user on legitimate accounts
- Make on-time payments consistently
- Maintain low credit utilization
In India, fraudsters use Buy Now Pay Later (BNPL) and “Nano Loans” to build a CIBIL score of 750+ over 12 months . This is called “credit warming.”
Stage 4: The Bust-Out
Once the credit profile is established and credit limits are high, the fraudster:
- Maxes out credit across multiple lenders simultaneously
- Disappears
- Leaves lenders with no recourse (the person doesn’t exist)
The result: Lenders are left with unpaid debt, and the fraudster walks away.
3. Why It’s So Hard to Detect
No Victim Complaint
Unlike traditional identity theft, there is no victim filing a complaint because the identity is synthetic—the person doesn’t exist. This means the fraud can go undetected for months or years. In India, approximately 90% of synthetic fraud is misclassified as “Gross NPAs” because there is no one to report the identity as fake .
Static Document Checks Don’t Work
Traditional onboarding processes rely on static document checks—verifying a driver’s license or passport. These checks won’t catch synthetic identity fraud because the documents can be fabricated or the fraudster can create a thin file that appears legitimate.
In India, Video KYC (V-CIP) has become the standard for digital onboarding. However, deepfake-related fraud attempts rose roughly 3,000% between 2022 and 2025, and attackers now inject synthetic video straight into the camera feed . Liveness checks built for 2021 do not stop this . Synthetic identity fraud drives an estimated $12 billion in losses globally in 2025, and the average synthetic identity goes undetected for around 18 months .
The Signals Are Network-Level
The signals that work for detecting synthetic identity fraud are network-level:
- Shared device IDs across multiple accounts
- Overlapping address histories
- Common phone numbers
- Thin files that behave too perfectly
- Rapid credit limit increases
In India, fraudsters use “synthetic social footprints” with LinkedIn profiles showing 500+ connections but no engagement older than six months .
4. The Indian Context: A Perfect Storm for Synthetic Identity Fraud
India’s Digital Fraud Crisis
Synthetic Bank Account Kits
Delhi Police recently busted a pan-India cybercrime syndicate using “synthetic bank account kits” . These kits included:
- Pre-activated SIM cards
- Forged bank documents
- Debit/credit cards linked to dummy accounts
- Mobile devices for real-time transaction control
These items collectively formed what is termed a “synthetic financial identity,” allowing cybercriminals to operate untraceable shadow banking systems . The syndicate operated through multiple verticals, including fake loan call centres and an orchestrated sextortion racket, with a money trail of over ₹5 crore identified .
The RBI’s Response
The Reserve Bank of India has recognized the growing threat of synthetic identity fraud and has mandated several measures:
Industry Impact
- Logistics: Highest suspected fraud rate at 16.3%
- Telecommunications: 14.7% fraud rate
- Insurance: 11.5% fraud rate, with a 145% year-on-year surge in suspected fraud volumes
- Financial services: Relatively lower at 2.6%, with a 65% year-on-year decline, suggesting investments in fraud detection are delivering results
5. The Fraud-AML Structural Gap
Synthetic identity fraud sits at the boundary between fraud and AML.
| Aspect | Fraud Focus | AML Focus |
|---|---|---|
| Primary concern | Loss prevention | Money laundering / terrorist financing |
| Detection | Transaction anomalies | Suspicious patterns |
| Reporting | Internal loss reports | SAR/STR filing |
| Time horizon | Immediate | Ongoing |
The structural gap: If your fraud and AML functions are still operating in silos on this typology, that’s a structural gap worth closing. Fraud teams may see the activity as a loss event. AML teams may see it as a suspicious pattern. Neither has the full picture.
In India, the RBI’s Master Direction on Fraud Risk Management (July 2024) recognizes the need for integrated fraud risk management, requiring banks to classify frauds including “cheating by impersonation” and “fraudulent electronic banking/digital payment related transactions” .
6. How to Defend Against Synthetic Identity Fraud
Data Integration
- Cross-functional collaboration: Fraud and AML teams must share data and insights
- Network analysis: Use network-level analytics to identify shared identities
- Data enrichment: Enhance KYC data with third-party sources
Behavioral Monitoring
- Track credit behavior: Monitor for rapid credit limit increases
- Payment patterns: Look for unusual payment patterns (e.g., consistent on-time payments with little other activity)
- Velocity: Monitor for rapid application activity across multiple lenders
Regulatory Compliance in India
- eCBSV integration: Verify identities against government databases
- MNRL checks: Monitor for revoked mobile numbers
- Video KYC: Use trained officials, geotagging, IP controls, and India-resident data storage
- Early Warning Systems: Implement real-time fraud detection
7. Regulatory and Reporting Implications
SAR Filing
Suspicious Activity Reports (SARs) for synthetic identity fraud should reflect:
- The network of accounts
- The shared identifiers (device IDs, addresses, phone numbers)
- The pattern of credit cultivation and bust-out
Intelligence Sharing
Lenders should share information about synthetic identity fraud patterns to identify threats before they materialize. In India, the RBI’s Cyber Security and IT Examination (CSITE) framework supports industry intelligence sharing .
Regulatory Expectations
Regulators expect financial institutions to have robust KYC and due diligence processes, including for synthetic identity fraud. In India, the RBI has mandated specific measures including MNRL checks, eCBSV integration, and Early Warning Systems .
8. Conclusion: Closing the Gap
Synthetic identity fraud is the fastest-growing financial crime, and India’s digital fraud rate is nearly double the global average. Most compliance teams still don’t see it coming until after the loss. The fraud sits at the boundary between fraud and AML, and if your fraud and AML functions are still operating in silos on this typology, that’s a structural gap worth closing.
Key takeaways:
- There’s no victim filing a complaint—the person doesn’t exist
- Static document checks at onboarding won’t catch this
- The signals that work are network-level (shared device IDs, overlapping address histories, common phone numbers)
- SAR narratives need to reflect the network, not just the individual account
- Fraud and AML functions must collaborate to identify synthetic identities before the bust-out
- In India, RBI mandates including eCBSV integration and MNRL checks must be implemented
9. Frequently Asked Questions (FAQs)
Q1: What is synthetic identity fraud?
A fraudster takes a real identity number and pairs it with fabricated biographical details to create a “person” who doesn’t exist, then builds credit and busts out.
Q2: Why is synthetic identity fraud hard to detect?
There is no victim filing a complaint (the person doesn’t exist). Static document checks at onboarding won’t catch it. The signals that work are network-level.
Q3: What are the four stages of synthetic identity fraud?
(1) Acquire the seed data (real identity number), (2) Build the synthetic profile (real ID + fake details), (3) Cultivate the credit (on-time payments, low utilization), (4) The bust-out (max out credit across lenders and vanish).
Q4: What is India’s digital fraud rate?
India’s suspected digital fraud rate was 7.1% in 2025, nearly double the global average of 3.8% .
Q5: What are the RBI mandates to combat synthetic identity fraud?
RBI has mandated eCBSV integration, Mobile Number Revocation List (MNRL) checks, Early Warning Systems, and behavioral biometrics .
Q6: Why should fraud and AML teams collaborate?
Synthetic identity fraud sits at the boundary between fraud and AML. Fraud teams see the loss event; AML teams see the suspicious pattern. Neither has the full picture. Collaboration closes the gap.
Q: Why do fraudsters often use the Social Security numbers of children? Ans: Children’s SSNs are typically dormant; they have no credit history and their parents usually do not monitor their credit reports for years. This creates the perfect “blank slate” to cultivate a synthetic credit profile without triggering red flags.
Q: How can I change the SAR narratives at my institution to better capture this fraud? Ans: You must move away from account-specific narratives. Your SARs should focus on the “Network Indicator.” Mention the shared device IDs, common IP ranges, or identical physical addresses across multiple accounts. The goal is to provide the FIU-IND or other regulators with a “cluster” view so they can see the wider syndicate footprint.
Q: Is it enough to just use a high-quality third-party KYC vendor? Ans: No. High-quality KYC is a baseline, not a complete defense. Third-party vendors are excellent at document authentication, but they are often blind to the network-level behavior that defines SIF. Your internal systems must perform the correlation between the data provided by the KYC vendor and the transactional network activity of the accounts.
KNOWLEDGE CHECK QUIZ
Q: Why is synthetic identity fraud harder to detect than traditional ID theft? Ans: Because the victim does not exist. There is no real person to file a fraud complaint, meaning the fraud can go undetected for months or years, often being misclassified as “Gross NPAs” in the Indian context.
Q: What is “Credit Warming” in the context of synthetic identities? Ans: It is the patient cultivation of a credit profile. Fraudsters open secured cards and make small, consistent on-time payments over several months to build a high CIBIL score (often 750+) before executing a “bust-out.”
Q: What is the Fraud-AML Structural Gap? Ans: It is the organizational failure where Fraud teams focus on credit losses and AML teams focus on transaction patterns, neither looking at the integrated network-level signals (shared device IDs, common phone numbers) that would identify the synthetic ring.
Q: What specific RBI mandate helps flag reassigned phone numbers used by fraudsters? Ans: The Mobile Number Revocation List (MNRL) check, which mandates checking if a mobile number has been recently reassigned, preventing fraudsters from using “recycled” numbers to pass verification.
Adv. Shoeb Hakim
Financial Crime & AML Advisor
📌 Follow me on LinkedIn for daily financial crime and AML insights: https://www.linkedin.com/in/shoebhakim
📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in
♻️ Share this article with your network.
Disclaimer: This article is for informational purposes only and does not constitute legal advice.
Hashtags: #AdvShoebHakim #SyntheticIdentityFraud #FinancialCrime #AML #FraudPrevention #IdentityTheft #BustOut #Compliance #RiskManagement #India #DigitalFraud #RBI #Aadhaar #UPI #FinCrime #SAR #KYC #CDD #FraudAML #NetworkAnalysis #DataIntegration #IntelligenceSharing #RegulatoryReporting #Banking #Lending #CreditFraud #Cybercrime #IdentityVerification


