Synthetic identity fraud

Also called: Frankenstein fraud · synthetic ID fraud · credit privacy number scam · CPN fraud · bust-out fraud

Synthetic identity fraud combines a real Social Security number — often a child's, an incarcerated person's, or someone deceased — with a fabricated name and date of birth to build a credit profile that belongs to no one. Rings season the profile for months or years with piggybacked credit history, then max out real credit lines and default, a "bust-out" that leaves banks, not the SSN's real owner, to absorb the loss.

Key facts

Category
Identity theft
First documented
2011
Typical loss
$400k–$1900k USD, per victim
Main channels
stolen Social Security numbers bought online, credit bureau file-creation on a rejected application, authorized-user tradeline piggybacking, shell companies reporting fabricated tradelines, commercial mail-receiving agencies and USPS mail forwarding
Who is targeted
Children, especially those born after 2011 — the year the Social Security Administration began issuing randomised SSNs that can no longer be checked against birth records — who won't apply for their own credit for another 18 years; Incarcerated people, the deceased, the elderly and the unbanked — anyone whose SSN is unlikely to be actively monitored; Banks and card issuers, who typically absorb a bust-out as an ordinary credit charge-off rather than recognising it as fraud at all; Government benefit programmes — unemployment insurance, Medicare, Medicaid and SNAP among them — that pay a claim first and verify it later
Documented origins
United States
Main targets
United States
Case files
3 documented cases
Last reviewed
2026-09-13
Anatomy of synthetic identity fraudAnatomy of synthetic identity fraud. A real Social Security number, a fake name and birthday, aged for years until a bank finally believes it. 1. Choosing a Social Security number nobody is watching: Numbers belonging to children, incarcerated people, the deceased or the elderly are preferred — especially those issued since 2011, which are randomised and can no longer be checked against public birth-record data. 2. Bolting on a fake name and birthday: The real SSN is combined with a fabricated name, date of birth and address to create an identity that belongs to no one — sometimes sold as a 'Credit Privacy Number.' 3. The rejected application that isn't actually rejected: A first credit application is usually declined, but the credit inquiry itself generates a bureau file for the synthetic identity. 4. Piggybacking to build a credit score: The synthetic identity is added as an authorized user on a real account, or a shell company reports fabricated, backdated tradelines directly to the bureaus. 5. Seasoning the file for months or years: Small balances are paid on time to qualify for larger limits, while statements and cards are redirected to a mail drop the ring controls. 6. Scaling across many identities and banks at once: One documented ring ran more than 750 credit cards from a single issuer; another spread over 20 identities across 19 institutions. 7. The bust-out: Every card and line tied to the identity is drawn down to its limit at once and never repaid, sometimes after moving money between the ring's own accounts first. 8. The bill lands on whoever actually owns that number: Banks generally treat the first user of an SSN as its owner — so the real person, often a child now grown, can find their own first real application rejected as a duplicate. The diagram marks stage 3 as the point where the scheme can still be stopped: A credit bureau opens a file the moment a bank submits a credit inquiry, even for a rejected application. An identity that should not exist gets a foothold through the exact process meant to screen it out.Anatomy of synthetic identity fraudA real Social Security number, a fake name and birthday, aged for years until a bank finally believes it.1Choosing a SocialSecurity numbernobody is watchingNumbers belonging tochildren, incarceratedpeople, the deceased or theelderly are preferred —especially those issuedsince 2011, which arerandomised and can nolonger be checked againstpublic birth-record data.Days2Bolting on a fakename and birthdayThe real SSN is combinedwith a fabricated name,date of birth and addressto create an identity thatbelongs to no one —sometimes sold as a 'CreditPrivacy Number.'Minutes3The rejectedapplication thatisn't actuallyrejectedA first credit applicationis usually declined, butthe credit inquiry itselfgenerates a bureau file forthe synthetic identity.Days4Piggybacking to builda credit scoreThe synthetic identity isadded as an authorized useron a real account, or ashell company reportsfabricated, backdatedtradelines directly to thebureaus.Weeks to months5Seasoning the filefor months or yearsSmall balances are paid ontime to qualify for largerlimits, while statementsand cards are redirected toa mail drop the ringcontrols.Months to years6Scaling across manyidentities and banksat onceOne documented ring ranmore than 750 credit cardsfrom a single issuer;another spread over 20identities across 19institutions.Ongoing7The bust-outEvery card and line tied tothe identity is drawn downto its limit at once andnever repaid, sometimesafter moving money betweenthe ring's own accountsfirst.Days8The bill lands onwhoever actually ownsthat numberBanks generally treat thefirst user of an SSN as itsowner — so the real person,often a child now grown,can find their own firstreal application rejectedas a duplicate.Years laterWhere it can still be stopped — stage 3A credit bureau opens a file the moment a bank submits a credit inquiry, even for a rejected application. An identity that should not exist gets a footholdthrough the exact process meant to screen it out.Stages drawn from the GAO's 2017 forum on synthetic identity fraud (GAO-17-708SP) and three sentenced or convicted synthetic identity fraud prosecutions documented on this site's case pages.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

A synthetic identity is a person who does not exist. It is built from a real Social Security number — usually one belonging to someone unlikely to be using it, like a child, an incarcerated person or someone who has died — combined with a made-up name, date of birth and address. No real person’s full identity is stolen. Instead, one genuine piece of it is grafted onto a fiction, and the fiction is patient enough to wait years before it costs anyone anything.

The US Government Accountability Office convened a panel of 14 fraud experts in 2017 specifically because this scheme does not look like fraud from the inside. When the credit line finally gets maxed out and defaulted on, a bank typically records it the same way it would record an ordinary customer who fell behind on payments — a credit loss, not a crime. That single fact, more than any technical sophistication, is why synthetic identity fraud can run for years before anyone notices.

How it actually works

  1. Choosing a Social Security number nobody is watching

    Rings prefer SSNs belonging to children, incarcerated people, the deceased or the elderly — anyone unlikely to apply for credit or check a report any time soon. Numbers issued since 2011, when the Social Security Administration began randomising assignment, are especially prized: they can no longer be checked against public birth-record data the way older, sequentially-issued numbers could.

  2. Bolting on a fake name and birthday

    The real SSN is combined with fabricated identifying details — a name, date of birth, address, phone number — to create a synthetic identity that is not associated with any real person. Some rings sell this as a “Credit Privacy Number,” falsely marketed as a legal alternative to a Social Security number.

  3. The rejected application that isn’t actually rejected

    The synthetic identity applies for its first line of credit. The bank has no file on it and usually declines the application — but the credit inquiry itself is enough to generate a credit bureau file for that identity, seeding a profile the fraudster can now build on.

    Where it could have stopped

    According to the GAO’s 2017 forum, a credit bureau opens a file the moment a bank submits a credit inquiry — even for an application that gets rejected. An identity that should not exist gets a foothold in the credit system through the exact process meant to screen it out.

  4. Piggybacking to build a credit score

    The synthetic identity is added as an “authorized user” on a real account in good standing, inheriting its positive payment history. In the largest documented cases, rings instead register shell companies that report fabricated tradelines directly to the credit bureaus and backdate them to simulate years of on-time payments.

  5. Seasoning the file for months or years

    Small credit lines are opened and paid on time, gradually qualifying the identity for larger limits and more cards. Mail — statements, cards, PINs — is redirected to a commercial mail-receiving address or forwarded through the US Postal Service to an address the ring controls, keeping the real cardholder invisible.

  6. Scaling across many identities and many banks at once

    A single operator submits hundreds of applications across dozens of financial institutions using different synthetic identities in parallel — one documented case involved more than 750 credit cards from a single issuer; another spread more than 20 identities across 19 different banks and credit unions.

  7. The bust-out

    Every card and line tied to the synthetic identity is drawn down to its limit at once, and the balance is never repaid. Money is sometimes moved between the ring’s own accounts first, both to extract maximum cash and to obscure which accounts were involved.

  8. The bill lands on whoever actually owns that number

    Because financial institutions generally treat the first user of a Social Security number as its “owner,” the real person — often a child who is now an adult applying for their first car loan or credit card — can find their own genuine application rejected as a duplicate, years after the fraud actually happened and often long after anyone involved has been caught.

Why it works

There is usually no live victim to notice anything. Traditional identity theft has a person checking a statement or getting a fraud alert. Synthetic identity fraud, by design, targets Social Security numbers belonging to people who are not using them — so nothing changes in anyone’s day-to-day life while the scheme runs.

The credit system’s own onboarding process does the seeding. A bureau creating a file from a rejected application is a feature built for legitimate new-to-credit consumers, and it works exactly as intended — it just does not check whether the applicant is a real, coherent person before doing so.

A 2011 policy change removed a verification shortcut. Randomised Social Security numbers, in place since 2011, cannot be checked against the geographic and age-group codes older SSNs once encoded — a change made to stop criminals from reconstructing numbers from public records, which also removed a way banks used to catch a mismatched name and birthdate.

Losses hide inside ordinary bad debt. GAO panelists told investigators that a bust-out typically looks identical to a normal customer falling behind on payments and eventually being charged off — which is also why total losses to the financial industry remain, by the GAO’s own account, unknown rather than merely large.

And scale multiplies quietly. A single ring can run dozens of synthetic identities against dozens of institutions in parallel, each one individually unremarkable, with no single bank positioned to see the pattern across all of them.

Where it comes from

Domestic, systemic, and concentrated in the credit reporting infrastructure itself rather than any single company or country.

This is a byproduct of how the US credit system verifies identity, not a foreign operation. Every documented case on this page was run from inside the United States, using US Social Security numbers, US credit bureaus and US banks — there is no cross-border laundering chain typical of many scams on this site.

Scale ranges from a handful of accounts to industrial operations. GAO panelists described one 2013 bust-out scheme involving 19 perpetrators managing 7,000 synthetic identities and more than 25,000 credit cards, with losses exceeding $200 million — at the other end, Charles Whitlock ran roughly 750 credit cards from a single South Carolina address before he was caught.

Government benefit programmes are exposed the same way banks are. Panelists told the GAO that any programme that pays a claim first and verifies later — they specifically named unemployment insurance, Medicare, Medicaid and SNAP — is vulnerable to the same fabricated-identity mechanism used against banks, and one panelist cited $200 million in improper unemployment payments traced to synthetic identities in a single state.

Enforcement is a mix of federal prosecution and, in at least one large case, state prosecution. The Suffolk County District Attorney’s office in New York pursued its own synthetic identity fraud prosecution independent of any federal case, while the Griffin and Cato cases were prosecuted federally by US Attorney’s offices with the FBI, IRS Criminal Investigation, US Postal Inspection Service and Homeland Security Investigations all involved across the documented cases here.

Real cases

A fake driver's licence, a rented alias, and a mail drop for stolen credit

2022 US Sentenced $1.9m

Corey Cato, 41, of Atlanta, was sentenced in September 2022 to more than seven years in federal prison for his role in a nationwide fraud ring that used stolen Social Security numbers — including numbers belonging to children — to build synthetic identities, open bank and credit card accounts, and steal nearly $2 million. Cato maintained a commercial mail-receiving address to intercept account correspondence and used a fake driver's licence and rental alias to insulate himself from detection.

Read the case file · 1 source

Shell companies built years of fake credit history for identities that didn't exist

2021 US Convicted $1.0m

A Suffolk County, New York, investigation unravelled a 13-person, three-corporation ring that created more than 20 synthetic identities using the Social Security numbers of children, recent immigrants, the deceased, the elderly and incarcerated people, then used shell companies to report years of fabricated, backdated credit history to the major bureaus before defrauding 19 financial institutions of more than $1 million. Adam D. Arena, who ran the shell companies at the centre of the scheme, pleaded guilty in March 2021.

Read the case file · 1 source

A 'credit repair' front that built fake credit files instead

2021 US Sentenced $412,885

Michael Griffin ran a purported credit repair business out of Raleigh and Knightdale, North Carolina, that in reality created fictitious credit profiles for clients using stolen and synthetic Social Security numbers, then defrauded Synchrony Bank, Capital One and Discover by opening and maxing out credit accounts in those fabricated identities. He was sentenced in December 2021 to 100 months in federal prison.

Read the case file · 1 source

Red flags

  • A federal SSN randomisation date does not protect a child’s number from misuse — a randomised SSN is actually preferred by fraudsters because it cannot be independently verified against public records.
  • Any pitch for a “Credit Privacy Number” or “CPN” as a legal way to build a second credit file — this is a synthetic identity, and using one is a federal crime, not a workaround.
  • An unexpected letter from a lender or collector addressed to a child, or a credit report that exists for someone too young to have opened any account.
  • Being asked to “add someone as an authorized user” on your account by someone you do not actually know, in exchange for payment.
  • A genuine credit or loan application rejected as a “duplicate” when you have never applied for credit before under your own Social Security number.
  • Mail related to accounts you do not recognise being forwarded to an address you do not control, or a commercial mail-receiving business listed as your own address without your knowledge.

If it’s happening to you

  1. Check whether your child, or another dependent, already has a credit file. A minor should have no credit report at all; if one exists, that alone indicates their SSN is likely already in use.
  2. Request a credit freeze, not just a fraud alert, at Equifax, Experian and TransUnion — a freeze blocks new accounts from being opened using that SSN at all, which fraud alerts do not fully do.
  3. If a genuine application is rejected as a “duplicate,” ask the lender directly why, and request the specific reason in writing — this is one of the few ways synthetic identity fraud surfaces to its real victim at all.
  4. Report it to the Federal Trade Commission at IdentityTheft.gov, which will generate a personal recovery plan, and to the Social Security Administration’s Office of the Inspector General at oig.ssa.gov if the misuse involves your Social Security number specifically.
  5. File a police report and keep the report number — it strengthens any dispute you later need to file with a credit bureau or a lender.
  6. Report it at ReportFraud.ftc.gov or ic3.gov. See where to report for other countries.

Where the money goes

There is no overseas transfer to trace in any case on this page — the loss is a domestic bank absorbing a maxed-out, defaulted credit line, dressed up to look exactly like an ordinary bad debt.

The money only becomes real at the very end of a long process. Everything before the bust-out — building the identity, seeding the credit file, piggybacking tradelines, seasoning the account — costs the ring almost nothing and produces no loss for anyone. The loss appears all at once, when real credit that a bank actually extended is drawn down to its limit and never repaid. In the largest documented rings, that cash or the goods bought with it move briefly between the ring’s own shell companies and accounts before being kept, which is also the point at which state and federal money laundering charges get added to the underlying bank fraud counts.

The other half of this story

Our sibling site Clean on Paper explains how a shell company manufactures a paper trail convincing enough to fool a bank — the same technique the Suffolk County case on this page used to fabricate years of fake credit history.

By the numbers

No published dataset breaks this scheme out as its own category yet, so there is no chart to show. The data page explains which agency categories exist and why some schemes are invisible in official statistics.

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Leader in synthetic identity fraud ring sentenced to prison for bank fraud. US Internal Revenue Service, Criminal Investigation. Accessed 2026-09-13. Supports: The Griffin case: the credit-repair-services front, the fictitious police reports and credit profiles, the family co-conspirators, the 100-month sentence, the $412,885.17 restitution, and the US Attorney's quote about credit profile numbers.
  2. Suffolk DA: Great Valley Man, 3 Corporations Plead Guilty in Connection with Nation-Wide Synthetic Identity Fraud Scheme. Long Island Business News, reproducing the Suffolk County District Attorney's press release. Accessed 2026-09-13. Supports: The Arena case: the shell corporations reporting fabricated tradelines, the backdated credit histories, the authorized-user piggybacking, the 'bust-out' cashout method, the 20-plus identities across 19 institutions, and District Attorney Sini's quote.
  3. HSI investigates synthetic identities scheme that defrauded banks nearly $2M. US Immigration and Customs Enforcement, Homeland Security Investigations. Accessed 2026-09-13. Supports: The Cato case: the commercial mail-receiving agency, the fake driver's licence and rental alias, the $1,908,481 restitution, the more-than-seven-year sentence, and the prosecutors' sentencing memorandum quote.
  4. Highlights of a Forum: Combating Synthetic Identity Fraud. US Government Accountability Office. Accessed 2026-09-13. Supports: The definition of synthetic identity fraud, the five-step process to create and use one, the credit-bureau file-creation-on-rejection loophole, the 2011 SSN randomisation background, the CPN explanation, the bust-out definition, the $50–250 million-a-year and $1 billion 2016 credit card loss estimates, the 2013 syndicate example (19 perpetrators, 7,000 identities, 25,000 cards, over $200 million), and the vulnerable-population findings.
  5. Social Security Administration's Role in Combatting Identity Fraud (testimony). Social Security Administration, Office of the Inspector General. Accessed 2026-09-13. Supports: The definition reiteration, the particular harm to children and the elderly, the roughly 700-identity San Antonio shell-company and PPP-fraud example, and the SSA OIG audit figures on SSN misuse.
  6. Synthetic Identity Payments Fraud. Federal Reserve, FedPayments Improvement. Accessed 2026-09-13. Supports: The characterisation of synthetic identity fraud as the fastest-growing US financial crime, the industry-recommended definition developed by the Federal Reserve's focus group, and the existence of the Fed's dedicated mitigation initiative since 2018.

Common questions

Is a Credit Privacy Number (CPN) a legal alternative to using my own Social Security number?

No. The GAO's 2017 synthetic identity fraud forum found that so-called CPNs are simply fictitious Social Security numbers marketed to credit-repair customers, some of whom do not realise that using one is itself synthetic identity fraud. Providing any number other than your own SSN on a credit application is a false statement, and panelists described websites falsely claiming otherwise.

Why do criminals specifically target children's Social Security numbers?

Because nobody is watching. A child's SSN is issued at birth but typically not used for credit for around 18 years, giving a fraudster nearly two decades to build and drain a credit profile before anyone checks. SSNs issued since 2011 are also randomised, meaning a bank can no longer verify one against public birth-record data the way it once could.

If a bank rejects the first credit application, is the fake identity dead?

No — and this is the mechanism's central flaw. According to the GAO, a credit bureau generates a credit file for an applicant the moment a bank submits a credit inquiry, even if the application is rejected. That rejected inquiry is enough to seed a file the fraudster can then build on with further applications and piggybacked tradelines.

How would someone find out their Social Security number is being used this way?

Often only by accident, and only years later. Unlike most identity theft, there is frequently no live victim checking a statement or noticing a missed charge — the SSA and GAO both note synthetic identity fraud can run for years before anyone applies for credit under the real name attached to that number and gets flagged as a 'duplicate' user of an SSN someone else has been using.

Can a bust-out ever be reversed once it happens?

No. Once cards are maxed out and the balance is defaulted on, a bank records it as a routine credit charge-off, not a fraud claim to dispute like a bank transfer. That is also why federal panelists told the GAO synthetic identity losses are so hard to even measure — they look identical to ordinary bad debt unless someone goes looking for the underlying fabricated identity.

Where the loss actually appearsWhere the loss actually appears. Nothing costs anyone anything until the very last step. Where the loss actually appearsNothing costs anyone anything until the very last step.A real SSN combinedwith a fabricated nameand birthdayThe synthetic identityis seasoned for monthsor years withpiggybacked orfabricated credithistoryPiggybackedauthorized-userhistory, or shellcompanies reportingfake tradelinesA strong-lookingcredit file persuadesa real bank or cardissuer to approve realcredit linesA real bank or cardissuer, persuaded by aseasoned credit fileEvery card is drawndown to its limit atonce and the balanceis never repaidCards maxed out anddefaulted — a loss thebank absorbs as abust-outReversibilityStolen details cannot be recalled at all. Assume they have been sold and will be used later by someone else, and act on the account rather than on the charge.How a shell company manufactures a paper trail convincing enough to fool a bank — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/shell-companies/In the largest documented rings, the cash or goods obtained in the final step move briefly between the ring's own shell companies before being kept — the point at which money laundering charges get added to the underlying bank fraud. There is no recall window here: once a bust-out balance is charged off, it is a bank's write-off, not a transaction anyone can reverse.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.