How synthetic identities are rewriting the rules of fraud and financial crime

24 August 2026

For years, identity fraud followed a familiar pattern. Criminals stole genuine identities, opened accounts, moved money and disappeared before anyone spotted the warning signs. Today, identity fraud remains one of the most significant threats facing regulated firms, accounting for 59% of all cases recorded to the National Fraud Database, according to Cifas’ latest Fraudscape report.

However, the nature of identity fraud is evolving. Fraudsters are increasingly using Artificial Intelligence (AI) to build convincing identities from scratch, combining real and fabricated information to create people who simply don't exist.

For regulated firms, this shift has created a new set of challenges that make it increasingly difficult to separate genuine customers from sophisticated synthetic identities.

Traditional identity verification controls were built to identify stolen identities or forged documents. But synthetic identities are designed to appear legitimate, passing many of the checks firms have relied on for years.

As AI becomes easier to access, creating convincing identities is no longer reserved for organised crime groups with specialist skills. The barriers to entry have fallen, while the financial rewards remain high.

Controls are being tested as synthetic identities are being used to facilitate money laundering, authorised push payment fraud, mule account recruitment, credit fraud and organised financial crime. That leaves regulated firms facing financial losses, regulatory pressure and reputational damage if those identities slip through the net.

Why synthetic identities are so difficult to spot

Unlike traditional identity theft, synthetic identity fraud rarely has an immediate victim reporting suspicious activity. A synthetic identity can be built over months or even years, gradually establishing a financial footprint before being used to obtain credit, move illicit funds or bypass customer due diligence.

A criminal might use a real National Insurance number, combine it with a fake name, address or date of birth, and slowly build a believable financial history. By the time that identity is used to apply for financial products, access credit or open multiple accounts, it can appear genuine.

AI has only made this even harder. Fraudsters can now create realistic identity documents, swap photographs, generate convincing faces and edit genuine documents in minutes. Many of these documents look authentic enough to pass manual reviews and older verification systems.

According to reports, synthetic identities are estimated to drive up to 80% of incidents of new account fraud and losses to businesses are expected to exceed $23 billion (nearly £17 billion) by 2030.

For compliance teams, these techniques produce identities capable of slipping through the legacy verification processes they use, as they were never designed to identify AI-assisted fraud.

The growing pressure on AML teams

Manual document reviews become less reliable when manipulated documents are almost indistinguishable from genuine originals. Database checks alone cannot identify fabricated identities built from authentic data. Even experienced analysts can struggle when every element appears to be legitimate to the naked eye.

At the same time, firms are expected to onboard clients quickly while maintaining high standards of financial crime prevention and compliance. Adding more manual reviews is undesirable and costly, slows customer acquisition and places greater pressure on already stretched compliance teams.

The new complication with synthetic identities means many legacy identity verification solutions are failing to keep up. It throws the accuracy of existing verification workflows into question, when instances of AI-fraud start rising and teams must manually check each result – adding an additional burden on team capacity.

This balancing act is becoming harder every year as criminals continue to adopt AI faster than some organisations can update their controls.

Technology is changing the balance

Undoubtedly, AI is helping criminals create synthetic identities, but when deployed securely at scale, it is also giving compliance teams new ways to defeat them.

Advanced document fraud detection can identify manipulation that would be almost impossible to spot during a visual inspection. Rather than simply confirming that an identity document matches an expected format, modern systems can confirm that a genuine physical document is actually present, rather than a screen replay, printed copy or AI-generated forgery.

ID-Pal's ID-Detect has been developed specifically to identify these increasingly sophisticated attacks. It analyses identity documents for indicators of digital manipulation, AI-generated content, screen replay attacks, portrait swaps, photocopies, and other forms of document fraud, giving compliance teams greater confidence that the document presented is genuine before onboarding continues. Testing has shown the technology can identify common document fraud techniques with extremely high accuracy while reducing unnecessary manual reviews.

Fraudsters are also moving beyond fake documents. Increasingly, they manipulate the verification session itself by injecting pre-recorded video, deepfake content or virtual camera feeds directly into biometric checks. These attacks can bypass systems that rely solely on presentation attack detection.

ID-Pal's Injection Attack Detection (IAD) addresses this growing threat by identifying software-level manipulation during remote identity verification. It detects both physical presentation attacks and software-level session manipulation, helping regulated firms identify deepfakes, virtual cameras, video replay attacks and other sophisticated biometric attacks without adding unnecessary friction for legitimate customers.

Fraud detection that keeps pace with bad actors

Synthetic identities are becoming a bigger part of organised financial crime, and the technology behind them is improving all the time.

Relying on traditional verification methods alone is becoming increasingly risky. Taking a layered approach, supported by technology like ID-Pal that can identify manipulated documents and AI-powered attacks, and gives firms a much stronger chance of stopping fraud before an account is opened.

With tools like ID-Detect and IAD, firms can verify customers’ identities with greater confidence, helping them reduce risk while supporting a smoother onboarding process for legitimate applicants.

Share:
Posted by: Sara West

Chief Commercial Officer, ID-Pal

NEXT POST
 

The Insider Threat: A Critical Challenge for Financial Crime Prevention

16 December 2025

Insider threats are no longer rare anomalies. They are now central to the fraud and financial crime landscape, affecting organisations across various sectors and jurisdictions. A recent joint briefing by Cifas and ACAMS, β€œThe Threat from Within: A Growing Concern,” explored how internal actors – whether malicious, negligent or coerced – can, and do, compromise systems, processes and controls.

CONTINUE READING
Back to blog home >
Posted by: Sara West

Chief Commercial Officer, ID-Pal

Categories