Also called: Frankenstein fraud · synthetic ID fraud · credit privacy number scam · CPN fraud · bust-out fraud
Synthetic identity fraud combines a real Social Security number — often a child's, an incarcerated person's, or someone deceased — with a fabricated name and date of birth to build a credit profile that belongs to no one. Rings season the profile for months or years with piggybacked credit history, then max out real credit lines and default, a "bust-out" that leaves banks, not the SSN's real owner, to absorb the loss.
What it is
A synthetic identity is a person who does not exist. It is built from a real Social Security number —
usually one belonging to someone unlikely to be using it, like a child, an incarcerated person or someone
who has died — combined with a made-up name, date of birth and address. No real person’s full identity is
stolen. Instead, one genuine piece of it is grafted onto a fiction, and the fiction is patient enough to
wait years before it costs anyone anything.
The US Government Accountability Office convened a panel of 14 fraud experts in 2017 specifically because
this scheme does not look like fraud from the inside. When the credit line finally gets maxed out and
defaulted on, a bank typically records it the same way it would record an ordinary customer who fell
behind on payments — a credit loss, not a crime. That single fact, more than any technical sophistication,
is why synthetic identity fraud can run for years before anyone notices.
How it actually works
Choosing a Social Security number nobody is watching
Rings prefer SSNs belonging to children, incarcerated people, the deceased or the elderly — anyone
unlikely to apply for credit or check a report any time soon. Numbers issued since 2011, when the Social
Security Administration began randomising assignment, are especially prized: they can no longer be
checked against public birth-record data the way older, sequentially-issued numbers could.
Bolting on a fake name and birthday
The real SSN is combined with fabricated identifying details — a name, date of birth, address, phone
number — to create a synthetic identity that is not associated with any real person. Some rings sell this
as a “Credit Privacy Number,” falsely marketed as a legal alternative to a Social Security number.
The rejected application that isn’t actually rejected
The synthetic identity applies for its first line of credit. The bank has no file on it and usually
declines the application — but the credit inquiry itself is enough to generate a credit bureau file for
that identity, seeding a profile the fraudster can now build on.
Where it could have stopped
According to the GAO’s 2017 forum, a credit bureau opens a file the moment a bank submits a credit inquiry — even for an application that gets rejected. An identity that should not exist gets a foothold in the credit system through the exact process meant to screen it out.
Piggybacking to build a credit score
The synthetic identity is added as an “authorized user” on a real account in good standing, inheriting
its positive payment history. In the largest documented cases, rings instead register shell companies
that report fabricated tradelines directly to the credit bureaus and backdate them to simulate years of
on-time payments.
Seasoning the file for months or years
Small credit lines are opened and paid on time, gradually qualifying the identity for larger limits and
more cards. Mail — statements, cards, PINs — is redirected to a commercial mail-receiving address or
forwarded through the US Postal Service to an address the ring controls, keeping the real cardholder
invisible.
Scaling across many identities and many banks at once
A single operator submits hundreds of applications across dozens of financial institutions using
different synthetic identities in parallel — one documented case involved more than 750 credit cards
from a single issuer; another spread more than 20 identities across 19 different banks and credit unions.
The bust-out
Every card and line tied to the synthetic identity is drawn down to its limit at once, and the balance
is never repaid. Money is sometimes moved between the ring’s own accounts first, both to extract maximum
cash and to obscure which accounts were involved.
The bill lands on whoever actually owns that number
Because financial institutions generally treat the first user of a Social Security number as its
“owner,” the real person — often a child who is now an adult applying for their first car loan or credit
card — can find their own genuine application rejected as a duplicate, years after the fraud actually
happened and often long after anyone involved has been caught.
Why it works
There is usually no live victim to notice anything. Traditional identity theft has a person checking
a statement or getting a fraud alert. Synthetic identity fraud, by design, targets Social Security numbers
belonging to people who are not using them — so nothing changes in anyone’s day-to-day life while the
scheme runs.
The credit system’s own onboarding process does the seeding. A bureau creating a file from a rejected
application is a feature built for legitimate new-to-credit consumers, and it works exactly as intended —
it just does not check whether the applicant is a real, coherent person before doing so.
A 2011 policy change removed a verification shortcut. Randomised Social Security numbers, in place
since 2011, cannot be checked against the geographic and age-group codes older SSNs once encoded — a
change made to stop criminals from reconstructing numbers from public records, which also removed a way
banks used to catch a mismatched name and birthdate.
Losses hide inside ordinary bad debt. GAO panelists told investigators that a bust-out typically looks
identical to a normal customer falling behind on payments and eventually being charged off — which is
also why total losses to the financial industry remain, by the GAO’s own account, unknown rather than
merely large.
And scale multiplies quietly. A single ring can run dozens of synthetic identities against dozens of
institutions in parallel, each one individually unremarkable, with no single bank positioned to see the
pattern across all of them.
Where it comes from
Domestic, systemic, and concentrated in the credit reporting infrastructure itself rather than any single
company or country.
This is a byproduct of how the US credit system verifies identity, not a foreign operation. Every
documented case on this page was run from inside the United States, using US Social Security numbers, US
credit bureaus and US banks — there is no cross-border laundering chain typical of many scams on this
site.
Scale ranges from a handful of accounts to industrial operations. GAO panelists described one 2013
bust-out scheme involving 19 perpetrators managing 7,000 synthetic identities and more than 25,000 credit
cards, with losses exceeding $200 million — at the other end, Charles Whitlock ran roughly 750 credit
cards from a single South Carolina address before he was caught.
Government benefit programmes are exposed the same way banks are. Panelists told the GAO that any
programme that pays a claim first and verifies later — they specifically named unemployment insurance,
Medicare, Medicaid and SNAP — is vulnerable to the same fabricated-identity mechanism used against banks,
and one panelist cited $200 million in improper unemployment payments traced to synthetic identities in a
single state.
Enforcement is a mix of federal prosecution and, in at least one large case, state prosecution. The
Suffolk County District Attorney’s office in New York pursued its own synthetic identity fraud
prosecution independent of any federal case, while the Griffin and Cato cases were prosecuted federally by
US Attorney’s offices with the FBI, IRS Criminal Investigation, US Postal Inspection Service and Homeland
Security Investigations all involved across the documented cases here.
Real cases
2022 US Sentenced $1.9m
Corey Cato, 41, of Atlanta, was sentenced in September 2022 to more than seven years in federal prison for his role in a nationwide fraud ring that used stolen Social Security numbers — including numbers belonging to children — to build synthetic identities, open bank and credit card accounts, and steal nearly $2 million. Cato maintained a commercial mail-receiving address to intercept account correspondence and used a fake driver's licence and rental alias to insulate himself from detection.
Read the case file ·
1 source
2021 US Convicted $1.0m
A Suffolk County, New York, investigation unravelled a 13-person, three-corporation ring that created more than 20 synthetic identities using the Social Security numbers of children, recent immigrants, the deceased, the elderly and incarcerated people, then used shell companies to report years of fabricated, backdated credit history to the major bureaus before defrauding 19 financial institutions of more than $1 million. Adam D. Arena, who ran the shell companies at the centre of the scheme, pleaded guilty in March 2021.
Read the case file ·
1 source
2021 US Sentenced $412,885
Michael Griffin ran a purported credit repair business out of Raleigh and Knightdale, North Carolina, that in reality created fictitious credit profiles for clients using stolen and synthetic Social Security numbers, then defrauded Synchrony Bank, Capital One and Discover by opening and maxing out credit accounts in those fabricated identities. He was sentenced in December 2021 to 100 months in federal prison.
Read the case file ·
1 source
Red flags
- A federal SSN randomisation date does not protect a child’s number from misuse — a randomised SSN is actually preferred by fraudsters because it cannot be independently verified against public records.
- Any pitch for a “Credit Privacy Number” or “CPN” as a legal way to build a second credit file — this is a synthetic identity, and using one is a federal crime, not a workaround.
- An unexpected letter from a lender or collector addressed to a child, or a credit report that exists for someone too young to have opened any account.
- Being asked to “add someone as an authorized user” on your account by someone you do not actually know, in exchange for payment.
- A genuine credit or loan application rejected as a “duplicate” when you have never applied for credit before under your own Social Security number.
- Mail related to accounts you do not recognise being forwarded to an address you do not control, or a commercial mail-receiving business listed as your own address without your knowledge.
If it’s happening to you
- Check whether your child, or another dependent, already has a credit file. A minor should have no
credit report at all; if one exists, that alone indicates their SSN is likely already in use.
- Request a credit freeze, not just a fraud alert, at Equifax, Experian and TransUnion — a freeze
blocks new accounts from being opened using that SSN at all, which fraud alerts do not fully do.
- If a genuine application is rejected as a “duplicate,” ask the lender directly why, and request the
specific reason in writing — this is one of the few ways synthetic identity fraud surfaces to its real
victim at all.
- Report it to the Federal Trade Commission at IdentityTheft.gov, which will generate a personal
recovery plan, and to the Social Security Administration’s Office of the Inspector General at
oig.ssa.gov if the misuse involves your Social Security number specifically.
- File a police report and keep the report number — it strengthens any dispute you later need to
file with a credit bureau or a lender.
- Report it at ReportFraud.ftc.gov or ic3.gov. See where to report for other
countries.
Where the money goes
There is no overseas transfer to trace in any case on this page — the loss is a domestic bank absorbing a
maxed-out, defaulted credit line, dressed up to look exactly like an ordinary bad debt.
The money only becomes real at the very end of a long process. Everything before the bust-out — building
the identity, seeding the credit file, piggybacking tradelines, seasoning the account — costs the ring
almost nothing and produces no loss for anyone. The loss appears all at once, when real credit that a bank
actually extended is drawn down to its limit and never repaid. In the largest documented rings, that cash
or the goods bought with it move briefly between the ring’s own shell companies and accounts before being
kept, which is also the point at which state and federal money laundering charges get added to the
underlying bank fraud counts.
By the numbers
No published dataset breaks this scheme out as its own category yet, so there is no chart to show.
The data page explains which agency categories exist and why some schemes are
invisible in official statistics.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.