β± 13 min readπ Interactiveπ Practitioner Levelπ 3 Scenarios
Two problems, one alert queue
$0B+
Annual US losses, Boston Fed estimate
Federal Reserve Bank of Boston estimate of annual US financial institution losses to synthetic identity fraud
0
Federal Reserve's definition, still current
"The use of a combination of personally identifiable information to fabricate a person or entity"
Β£21,091,300
FCA fine, Monzo, 7 July 2025
Weak onboarding controls that let customers register with implausible identity information
Two Problems, One Set of Tools
Nobody teaches the judgement once the alert is already in your queue.
Search "synthetic identity fraud detection" and you get device fingerprinting vendors, graph-clustering platforms, and biometric verification products, all explaining how their technology spots the pattern. Genuinely useful technology, and none of it tells you what to actually do once one of these alerts lands in front of you, no fabricated identity announces itself, no device cluster hands you a conclusion, and the same vendor content routinely treats two fundamentally different problems as one technique.
Synthetic identity fraud is a fabricated person, real fragments of stolen or invented data stitched into someone who does not exist. There is no single victim to call and confirm with, because the identity was never anyone's.
Device-network fraud is usually the opposite problem: a real person, correctly identified, operating multiple accounts from shared infrastructure. The identity is genuine. The question is what they are actually doing with it.
Confusing the two leads to the wrong investigation every time. This guide keeps them separate.
How to use this guide
Read the four patterns first. Then work each scenario, make your call, and read why, both for the right answer and every wrong one. The knowledge check at the end pulls the same patterns from new angles. Do not skip ahead.
Four Patterns
Four patterns, four cards
Most misread alerts trace back to one of these four shapes. Learn to recognise them before the scenarios test them.
π
The Clean File
A genuinely aged identity has noise. A fabricated one is often suspiciously tidy.
A real person's credit and account history accumulates mess over years, a late payment, a closed account, a credit inquiry that went nowhere, ordinary financial life. A synthetic identity's file is frequently the opposite: thin, or unnaturally clean for the age it claims. An analyst trained to look for red flags in negative information can miss the identity where there is suspiciously little information of any kind at all.
Trap
An absence of derogatory history reads as reassurance.
Tell
The file is thinner, or cleaner, than the claimed history would realistically produce.
Do
Weigh an unnaturally clean file as a genuine signal, not a reason to relax scrutiny.
π§΅
The Borrowed Thread
Fraudsters do not wait for a synthetic identity to age. They attach it to someone else's real history.
A common technique for accelerating a synthetic profile is authorised-user piggybacking, attaching the fabricated identity to a genuine person's existing credit account as an authorised user. The synthetic identity inherits that account's real age and payment history almost overnight, without needing years of its own. What looks like an established file may actually be borrowed history sitting on top of a fabricated identity.
Trap
Established-looking credit history reads as proof of a genuine, aged identity.
Tell
The account history's origin traces to being added as an authorised user on someone else's older account, not built independently.
Do
Check whether apparent history was built directly or inherited through an authorised-user relationship.
π±
The Shared Device
A device match is a real signal. It is not proof on its own.
Multiple accounts resolving to the same device or fingerprint is genuinely worth investigating, but it is correlation, not conclusion. Families share laptops. Shared or public devices exist. A device match becomes meaningful when it combines with other signals, accounts opened in a short window, mismatched or implausible identity details, coordinated activity, not when it stands alone.
Trap
A device match feels conclusive by itself.
Tell
The only evidence is the shared device, with nothing else corroborating coordinated or fraudulent activity.
Do
Treat a device match as one input requiring corroboration, not a finding on its own.
π
The Wrong Category
Is this a fabricated person, or one real person running several accounts? The answer changes the entire investigation.
Synthetic identity and device-network fraud get investigated as though they were the same problem because the same tools, fingerprinting, clustering, flag both. They are not the same problem. A device-network case usually involves one real, identifiable person, and there is a genuine account holder to act against. A synthetic identity case involves no such person, only assembled fragments, which changes what evidence even means and what the resolution looks like.
Trap
Both cases arrive through similar-looking network alerts and get treated with the same playbook.
Tell
Establishing whether a single real identity sits behind the accounts, or whether the identity itself doesn't resolve to a real person, changes everything downstream.
Do
Establish which category you are actually in before deciding what evidence would resolve the case.
The Core Distinction
Stolen identity versus synthetic identity
Both involve identity data that does not belong where it is being used. What differs is whether a real, identifiable victim exists behind the file.
Dimension
Stolen identity
Synthetic identity
The underlying person
A real, existing individual whose genuine data was taken without consent
No such person exists, the identity is assembled from fragments and does not resolve to any one real individual
Is there a victim to call
Yes, the real individual can usually be contacted and will confirm the fraud
No single victim exists in that sense, though a real person's fragment (an ID number, an address) may be used without their knowledge
Credit file pattern
An established, genuine file suddenly shows unfamiliar activity
A file that is new, thin, or unnaturally clean for the claimed history, see The Clean File
How it typically resolves
Victim confirms the fraud, the account is unwound, and the real individual's identity is restored to their control
No individual to restore anything to, resolution is closing the fabricated identity and tracing which real fragments were used
Common acceleration technique
Using the stolen identity immediately against its existing credit profile
Authorised-user piggybacking, see The Borrowed Thread, builds apparent history the fabricated identity never earned
π
Scenario 01 Β· Reading a file that's too tidy
The Thin, Tidy File
The Clean File
βοΈ
What do you do?Make the call
A new account application includes a genuine-looking Social Security equivalent identifier, a plausible name, and a credit file showing eighteen months of perfect payment history across two accounts, no late payments, no inquiries beyond the two accounts, nothing negative anywhere. The applicant claims to be thirty-four years old with a stable employment history.
π§΅
Scenario 02 Β· Whose history is it actually
The Authorised User
The Borrowed Thread
βοΈ
What do you do?Make the call
Investigating a flagged application, you find the credit file's apparent five-year history actually originates from the applicant being added as an authorised user on someone else's credit card account four years ago, with no independent credit relationships opened by the applicant themselves until six months ago.
π±
Scenario 03 Β· When a device match isn't the finding
The Family Laptop
The Shared Device
βοΈ
What do you do?Make the call
A device-network alert flags four accounts resolving to the same device fingerprint. Investigating further, the four accounts belong to four different named individuals at the same residential address, opened over an eighteen-month period, each with normal, unremarkable transaction activity and no other shared attributes beyond the device.
Knowledge Check
Five questions. Do you know which problem you're actually looking at?
1. What makes "The Clean File" pattern counterintuitive compared with typical fraud red flags?
2. What does authorised-user piggybacking actually do to a synthetic identity's credit file?
3. Why is a device match alone considered correlation rather than proof?
4. What is the fundamental difference between synthetic identity fraud and device-network fraud?
5. What is the central argument of this guide?
0/5
Frequently Asked
FAQ
If a device match alone isn't enough, what actually turns a device-network alert into a real case? +
Corroboration from other signals, accounts opened in a tight time window rather than spread naturally, mismatched or implausible identity details across the linked accounts, coordinated transaction timing, or behaviour inconsistent with the stated relationship between the account holders. No single additional signal is automatically decisive, but a device match plus genuine corroboration is a different case than a device match alone.
Can a synthetic identity ever be confirmed with certainty? +
Rarely with total certainty from the file alone, since a well-constructed synthetic identity is specifically built to resemble a real one. Confirmation usually comes from a specific inconsistency that cannot be explained by an innocent scenario, an identifier that resolves to a documented deceased individual, biometric data with no plausible prior history despite a claimed history, or similar concrete contradictions, rather than a single clean judgement call.
Is authorised-user piggybacking illegal on its own? +
No. It is a legitimate, common credit practice on its own. It becomes relevant to a fraud investigation only when it is being used specifically to manufacture apparent credit history for a fabricated identity, which is a question of what else is true about the underlying identity, not something the authorised-user relationship itself proves.
Why does this guide treat synthetic identity and device-network fraud as separate rather than one topic? +
Because the vendor and technology literature almost universally does not, both get flagged by similar tools (fingerprinting, clustering) and get discussed as one detection problem. But a device-network case usually has a real, identifiable person behind it, while a synthetic identity case does not, and that distinction changes what evidence resolves the case and what a correct disposition even looks like.
Quick Reference
At a glance
Four patterns, the trap that makes each one look routine, the tell that actually gives it away, and the response that fits.
π
The Clean File
A genuinely aged identity has noise. A fabricated one is often suspiciously tidy.
Trap
An absence of derogatory history reads as reassurance.
Tell
The file is thinner, or cleaner, than the claimed history would realistically produce.
Do
Weigh an unnaturally clean file as a genuine signal, not a reason to relax scrutiny.
π§΅
The Borrowed Thread
Fraudsters do not wait for a synthetic identity to age. They attach it to someone else's real history.
Trap
Established-looking credit history reads as proof of a genuine, aged identity.
Tell
The account history traces to an authorised-user relationship, not independent history.
Do
Check whether apparent history was built directly or inherited.
π±
The Shared Device
A device match is a real signal. It is not proof on its own.
Trap
A device match feels conclusive by itself.
Tell
The only evidence is the shared device, nothing else corroborates.
Do
Treat a device match as one input requiring corroboration, not a finding.
π
The Wrong Category
Is this a fabricated person, or one real person running several accounts?
Trap
Both cases arrive through similar network alerts and get the same playbook.
Tell
Whether a real identity sits behind the accounts changes everything downstream.
Do
Establish which category you are in before deciding what evidence would resolve it.
The Judgement, Not the Technology
Two different problems, two different investigations.
The technology that flags them doesn't tell you which one you're actually looking at. Scenario Lab's Fraud Detection module puts both cases in front of you directly, The Franken-ID and The Device Network, free, no signup required.
Want to practise the judgement rather than read about it?Free. No account needed. Work both cases under real conditions, in any order.