Home
Blog
Synthetic Identity Fraud: How Fraudsters Build Fake People Using Your Real Data

Synthetic Identity Fraud: How Fraudsters Build Fake People Using Your Real Data

Reviewed by
Table of Contents

Key Takeaways

Synthetic identity fraud is now the fastest-growing financial crime in the United States, and most victims don't find out until the damage is already done. Fraudsters don't need your full identity. They only need one piece of it, usually your Social Security number, to build an entirely new fake person and spend years quietly running up debt in the background.

This guide explains exactly how that process works, who gets targeted most, and what the warning signs look like. You'll also find a practical checklist of steps you can take right now to protect yourself and your family before a fraudster gets the chance.

Introduction: your social security number might already be living a double life

Picture this: your child turns 18, applies for their first credit card, and gets rejected. Not because they have no credit history. Because they already have one. Accounts opened in their name. Debts they never incurred. A person who doesn't exist, built on their Social Security number.

That's synthetic identity fraud. And it's happening right now to millions of Americans who have no idea.

This isn't the identity theft you've heard about. Nobody is pretending to be you. They're not draining your bank account or opening a store card in your name. Instead, they take one piece of you, usually your Social Security number, and use it to build an entirely new fake person. A ghost with your data at its core.

Because no real person is fully impersonated, there's often no victim to file a complaint. No fraud alert triggered. No bank flagging the account. The fake identity quietly builds credit, earns trust, and then cashes out. By the time anyone notices, the fraudster is long gone.

The scale is hard to ignore. Losses from synthetic identity fraud crossed $35 billion in 2023, according to FiVerity data cited by the Federal Reserve Bank of Boston in April 2025. That number keeps climbing.

This guide walks through exactly how it works. You'll learn how fraudsters build fake identities, why banks struggle to catch them, what warning signs to look for, where your data comes from, and what you can do right now to protect yourself and your family.

What synthetic identity fraud actually is (and why it's not regular identity theft)

Here's something most people never consider: your Social Security number could be attached to a person who has never existed, living a financial life you know nothing about. No one stole your wallet. No one is pretending to be you. But a piece of your identity is out there, stitched into a fake person a fraudster built from scratch.

That's synthetic identity fraud, and it's not the same thing as regular identity theft.

Traditional identity theft is what most people picture: a criminal gets hold of your name, SSN, and bank details, then impersonates you. They drain your accounts, open cards in your name, and you find out fast because the damage lands directly on you. It's awful, but at least you know it happened.

Synthetic identity fraud works differently. A fraudster takes one real piece of identifying information, almost always a Social Security number, and pairs it with completely made-up details: a fake name, a fake date of birth, a fake address, a fake email. The result is a person who has never existed, but whose credit file looks real enough to fool a bank.

Think of it as a Frankenstein identity: stitched together from real and fabricated parts, animated by the financial system, and almost impossible to spot.

Here's the key difference that makes synthetic fraud so much harder to catch:

Identity Theft vs Fraud
TRADITIONAL IDENTITY THEFT SYNTHETIC IDENTITY FRAUD
What's stolen Your full identity One piece of your identity (usually your SSN)
Who's impersonated You A fake person that doesn't exist
Who notices first You, when your accounts are hit Often no one, for years
Who files a complaint You Nobody, there's no obvious victim

Because there's no single real victim whose accounts are being drained, there's no one to file a police report. The fraud runs quietly for years before anyone catches on. According to the Federal Reserve Bank of Boston, synthetic identity fraud losses crossed $35 billion in 2023 and continue to climb.

Children, elderly individuals, and people with little credit history are disproportionately targeted. Their SSNs have no existing credit file to conflict with, which gives fraudsters a clean slate to build on.

Here's what makes this especially unsettling: even if you're never fully impersonated, you can still feel the damage. Equifax notes that when a synthetic identity built on your SSN generates negative history, it can attach to your real credit record as a fragmented or split credit file. Suddenly, late payments and defaulted loans you never took out are dragging down your credit score.

You weren't robbed. But you're still paying the price.

Traditional identity theft vs. synthetic identity fraud: key differences

Here's the sharpest way to understand the difference: traditional identity theft steals a real person. Synthetic identity fraud invents one.

With traditional identity theft, a fraudster takes your complete identity and impersonates you. Your accounts get drained, unauthorized charges appear, and you notice fast. You file a police report. The bank flags the fraud because the real you is raising the alarm.

Synthetic identity fraud works nothing like that. The fraudster borrows one piece of your data, usually your Social Security number, and builds a brand-new fake person around it. Different name. Different address. Different date of birth. No one is fully impersonated, so no one files a complaint.

That's the trap the financial system falls into. According to Equifax, an estimated 95% of synthetic identities pass the standard onboarding process. The fake person looks like a new customer responsibly building credit. Fraud detection systems don't flag it because, from where they're sitting, everything checks out.

  • Traditional identity theft: Real victim, fast discovery, immediate complaint, fraud flagged quickly
  • Synthetic identity fraud: No single victim, no complaint filed, credit history builds over months or years, fraud looks like normal customer behavior

The most dangerous part? To the financial system, synthetic fraud doesn't look like fraud at all. It looks like success.

Who gets targeted and why

Fraudsters aren't random. They're methodical, and they go after one specific thing: a Social Security number with no credit file attached to it. A blank slate is far easier to build on. No existing accounts to conflict with, no credit history to contradict the fake one they're constructing.

Three groups carry most of that risk:

  • Children. A child's SSN is issued at birth, but they won't apply for credit for 15 to 18 years. That's a long, undetected window. According to Carnegie Mellon's CyLab, children's SSNs are 51 times more likely to be used in synthetic identity theft than adults'. The price of entry is shockingly low: Kyndryl's 2025 Synthetic Identity Fraud report found that a child's SSN, complete with name and date of birth, can be purchased on the dark web for as little as $2.
  • Elderly individuals. Decades of responsible credit use means a strong credit score, and fraudsters want to inherit that creditworthiness. Seniors are also less likely to actively monitor their credit files, which gives a scheme more time to run.
  • People with thin or no credit files. Recent immigrants, people experiencing homelessness, and anyone who has simply never used credit all share the same vulnerability: no existing file to raise a red flag.

If you have a child under 18, their SSN is a target right now. The uncomfortable truth is that no one is watching it.

How fraudsters build a 'frankenstein identity' step by step

Meet Alex Carter. Alex has a name, an address, a date of birth, and a Social Security number. Alex also doesn't exist.

That SSN belongs to a real 7-year-old named Maya. A fraudster pulled it from a data breach, paired it with a made-up name and fake details, and Alex Carter was born.

Here's how it unfolds:

  1. Acquire a real SSN. Maya's number gets purchased on the dark web for a few dollars.
  2. Build the fake person. Alex Carter gets a name, birthday, and address. A credit application goes in.
  3. Get rejected on purpose. The rejection creates a credit file. That's the goal.
  4. Farm the credit. Over months, Alex becomes a reliable borrower. Lenders start saying yes.
  5. The bust-out. Alex maxes every account and vanishes.

This isn't smash-and-grab. According to the Federal Reserve Bank of Boston, synthetic identity fraud schemes can run for years before anyone notices. That patience is the whole point.

Step 1: acquiring a real social security number

Everything starts with nine digits. A fraudster can fabricate a name, a birthday, an address. The one thing they can't make up is a Social Security number (SSN) that actually works in the credit system. So they steal one.

Here's how they get them:

  • Data breaches: When companies storing personal records get hacked, SSNs leak by the millions. According to the Identity Theft Resource Center, Social Security numbers appeared in two-thirds of all data breach reports in 2025, and the number of breaches involving SSNs nearly doubled between 2021 and 2025.
  • Dark web marketplaces: A stolen SSN sells for as little as $1 to $8 on dark web markets, according to ITAccuracy. A complete "fullz" package, SSN, name, date of birth, and address, goes for $20 to $100. The price is low because supply is enormous, not because the risk is small.
  • Phishing attacks: Fraudulent emails, fake IRS texts, and spoofed bank websites trick people into typing their SSN directly into a form. No hacking required.
  • Physical theft: Stolen mail, discarded tax forms, and medical paperwork are still common sources. Your W-2 sitting in a recycling bin is a gift to the right person.

Children's SSNs are especially prized. They come with no existing credit file, so there's nothing to conflict with the fake identity being built on top. The Federal Reserve Bank of Boston notes that fraudsters specifically target children's SSNs knowing no one will notice for years.

The SSN is the foundation. Everything else can be invented. That's what makes protecting yours, and your children's, the single most important step you can take.

Step 2: building the fake person (identity compilation)

Once a fraudster has a real SSN, they build a person around it. Meet Alex Carter: invented name, invented date of birth, invented address, email, and phone number. None of it is real, except the Social Security number at the center.

This process has a name. Equifax calls it identity compilation: pairing a legitimate SSN with fabricated details to create a fictitious person. There's a close cousin called identity manipulation, where a fraudster takes a real person's partial details and tweaks them slightly: same SSN, different name, different date of birth, just enough to slip past a basic check.

For years, this step required manual effort. Not anymore.

Generative AI has turned identity compilation into something closer to a factory process. According to the Federal Reserve Bank of Boston (April 2025), AI can now create records of synthetic "parents" to give a fake identity a believable backstory, produce authentic-looking documents from photos found online, generate deepfake videos with unique gestures and speech patterns, and mimic a real person's texting style to trick their contacts into handing over more data.

What once took weeks of careful manual work can now be automated at scale. The fake person looks increasingly real, and that's exactly the point.

Step 3: applying for credit and getting rejected (on purpose)

Here's the part that surprises almost everyone: the rejection is the point.

Once Alex Carter exists on paper, the fraudster applies for a credit card. They know they'll be turned down. There's no credit history, no verifiable address, nothing a lender can confirm. The application gets denied in seconds.

But something happens in the background. When a lender runs a credit check on a new applicant, the credit bureau creates a file for that person, even if they've never had credit before. The denial doesn't erase that file. It creates it.

Alex Carter now has a foothold in the financial system.

Federal Reserve Bank of Boston payments fraud expert Mike Timoney calls this achieving "proof of life." Once a credit file exists, the synthetic identity is real in the eyes of lenders, bureaus, and the broader financial system. It has a record. It can be built on.

This is what separates synthetic identity fraud from smash-and-grab schemes. The fraudster isn't trying to steal anything yet. They're planting a seed. The rejection isn't a setback. It's step three of a patient, methodical plan.

Step 4: credit farming - building a legitimate-looking history

This is where the fraud gets genuinely unsettling. Alex Carter isn't rushing anything.

Over the next 12 to 24 months, the fraudster quietly tends to their fake person like a garden. They get Alex a secured credit card, make small purchases, and pay them off on time, every time. They might get Alex added as an authorized user on a real person's established account, a tactic called "piggybacking" that lets the synthetic identity inherit a positive credit history almost overnight. Plaid identifies piggybacking as one of the most common tactics used during this phase.

Then comes a small personal loan. Repaid on schedule. Then a slightly larger credit limit. Repaid again.

Alex Carter's credit score climbs. Banks start treating Alex like a valued customer. Credit limit increases arrive unsolicited. The fraudster is playing the long game, and they're playing it perfectly.

This phase can stretch anywhere from one to three years. Every signal the bank sees says: model customer. No missed payments. No red flags at all.

Here's the kicker: fraud detection systems are built to catch anomalies. But there are no anomalies here. According to Proof.com's June 2026 fraud analysis, synthetic identities are "cultivated over time to build credit histories before being used," which is precisely why they're so hard to catch before the damage is done.

Step 5: the bust-out - cashing in and disappearing

After months, sometimes years, of patient credit farming, the fraudster pulls the trigger.

In a single coordinated move, they max out every available credit line, credit cards, personal loans, lines of credit — convert what they can to cash, and vanish. "Alex Carter," the synthetic person built on Maya's SSN, ceases to exist. The lenders are left holding unrecoverable losses. And Maya, now 18 and applying for her first student loan, discovers her Social Security number has been living a double life since she was seven.

This is the bust-out. The timeline is the whole point.

From SSN acquisition to bust-out, the process typically takes two to four years. That's not a flaw in the scheme. It's the design. The longer the fraudster waits, the higher the credit limits they can access. Patience is the strategy.

The scale is hard to ignore. According to Mike Timoney of the Federal Reserve Bank of Boston, synthetic identity fraud losses crossed the $35 billion mark in 2023. That's not a niche crime affecting a handful of unlucky people. It's a systemic problem quietly draining the financial system, and the real victims often don't know they're in the story until the final chapter arrives.

Why banks and lenders struggle to catch it

Here's the uncomfortable truth: the financial system isn't built to catch this kind of fraud. That's not a criticism. It's a structural reality.

Synthetic identity fraud slips through for four specific reasons.

There's no victim filing a complaint. Traditional fraud detection is largely complaint-driven. When someone's wallet gets stolen and their credit card is used, they call the bank. With synthetic fraud, the "victim" is a fake person. Nobody reports anything, because there's nobody to report it. The fraud can run for years without triggering a single alert.

The identity looks completely legitimate. By the time a fraudster reaches the bust-out stage, their synthetic person, let's call him Alex Carterhas, a two-year credit history, on-time payments, and a solid credit score. Nothing in that file looks suspicious. Alex looks like a reliable borrower. That's the whole point.

Fraud detection systems are tuned for anomalies that don't exist here. These systems look for sudden behavioral changes, mismatches between application data and existing records, or patterns that don't fit. A synthetic identity carefully built over months shows none of those signals. It doesn't trigger anything because it was designed not to.

SSN randomization made detection harder, not easier. In 2011, the Social Security Administration changed how it assigns Social Security numbers, moving from a formula-based system to a randomized one. The goal was to prevent fraud. The unintended side effect? It made it much harder for anti-fraud algorithms to spot fake numbers. As Plaid notes, SSN assignments used to follow a predictable formula, which made it easier to flag suspicious numbers. Randomization removed that signal entirely.

The result is a fraud type that, according to BIIA, accounts for only 4% of fraud cases by frequency but drives 7% of total financial losses. A disproportionate hit that reflects just how long these schemes run before anyone notices.

Banks are getting better. But the structural gaps are real, and that's why your own awareness and proactive monitoring matter more than most people realize.

The 'no victim' problem

Here's the structural flaw that lets synthetic identity fraud run for years undetected: there's no one to call the bank.

In traditional fraud, a real person notices something wrong, files a dispute, and triggers an investigation. In synthetic identity fraud, the fake person can't complain. The real person whose SSN was borrowed often has no idea, because the fraudulent activity is attached to a different name entirely.

The only party that actually loses money is the lender. Here's the kicker: lenders typically classify these losses as bad debt charge-offs, not fraud. That means the losses don't get reported to fraud databases, and the pattern stays invisible to the systems designed to catch it.

Some have called synthetic identity fraud a "victimless crime" for exactly this reason. The Federal Reserve Bank of Boston pushes back hard on that label. Children whose SSNs are stolen can reach adulthood to find their credit already wrecked, before they've ever applied for a loan or an apartment. The costs also get passed on to everyday consumers through higher interest rates and fees.

No single victim. No fraud report. No investigation. That's not a victimless crime. It's a blind spot.

Why children's SSNs are especially valuable

A child's Social Security number is, from a fraudster's perspective, almost perfect raw material.

It's issued at birth but won't be actively used for credit for 15 to 18 years. That's a massive undetected window. There's no existing credit file to conflict with the synthetic identity being built. And because children aren't supposed to have credit reports, most parents never think to check.

A fraudster can spend years quietly building credit history under a fake name attached to your child's real SSN. By the time your child turns 18 and applies for their first student loan or apartment, they may find a credit file full of debt that has nothing to do with them.

The numbers back this up. According to security.org's 2026 Child Identity Theft report, over 33% of parents fail to follow basic steps to secure their child's identity, and 14% have already experienced theft. That's roughly one in seven families.

Checking and freezing your child's credit isn't something most parents think to do. But it's one of the most protective steps you can take, and it costs nothing. If your child has a Social Security number, they can have a credit freeze. Set it up before anyone else does.

Warning signs your data may already be part of a synthetic identity scheme

Because synthetic identity fraud doesn't fully impersonate you, the warning signs are subtle. But they're there if you know where to look. Most of these can be checked for free, right now.

  • Unexpected credit inquiries: Someone applied for credit using your SSN. Pull your free report at AnnualCreditReport.com and look for hard inquiries you don't recognize.
  • Collections notices for debts you never opened: A fraudster's bust-out has likely already happened. Dispute immediately with the bureau.
  • Your child has a credit report: Children shouldn't have one. If they do, their SSN is almost certainly compromised.
  • SSA earnings records show income you didn't earn: Check your Social Security Statement annually. Phantom wages are a clear sign your SSN is attached to a fake identity.
  • Unfamiliar accounts on your credit file: Any account you didn't open is worth investigating immediately.

Red flag #1: unexpected credit inquiries on your report

Hard inquiries happen when a lender pulls your credit report because you've applied for a loan, credit card, or line of credit. They show up on your report and stay there for two years.

If you see inquiries from lenders you've never heard of, that's not a clerical quirk to ignore. It could mean someone used your Social Security number to apply for credit, even if the application was filed under a completely different name. That's one of the earliest detectable fingerprints of synthetic identity fraud.

One unfamiliar inquiry might be a data-matching error. Multiple unfamiliar inquiries from different lenders? That's a serious red flag.

What to do: Pull your free credit reports from all three bureaus at AnnualCreditReport.com. Go straight to the inquiries section. If you spot anything you don't recognize, dispute it directly with the relevant bureau.

Red flag #2: collections notices for debts you don't recognize

A collections agency calling about a debt you've never heard of isn't always a clerical error. It could be the bust-out catching up with you.

When a fraudster defaults on credit built using your Social Security number, those unpaid debts don't disappear. According to Equifax, your SSN can end up with a split or fragmented credit file, where the fake identity's negative judgments bleed into your real credit history. You didn't borrow a cent, but your credit score takes the hit.

Don't ignore the notice, even if you're certain the debt isn't yours. Here's what to do:

  • Request a debt validation letter - the collector is legally required to provide proof the debt is yours
  • Pull your credit reports from all three bureaus and look for unfamiliar accounts
  • File a dispute with the credit bureau directly
  • Report it to the FTC at IdentityTheft.gov if you believe your SSN was used fraudulently

Acting fast limits the damage. Ignoring it won't make it go away.

Red flag #3: your child has a credit report

Kids don't have credit histories. If one exists for your child, something is wrong.

Children shouldn't have a credit report unless you've deliberately added them as an authorized user on one of your accounts. Any activity at all, accounts, inquiries, anything, almost certainly means their Social Security number has been used to build a synthetic identity.

The tricky part: most parents never think to check. There's no automatic alert. You have to go looking.

What to do right now:

  • Request a manual search from all three credit bureaus (Equifax, Experian, and TransUnion) using your child's Social Security number. Each bureau has its own process for this.
  • Place a credit freeze immediately if a file exists. This stops anyone from opening new credit in their name.
  • Report it to the FTC at IdentityTheft.gov, which walks you through recovery steps specifically for child identity theft.

The FTC's consumer.ftc.gov has a dedicated guide for exactly this situation. Use it.

Red flag #4: SSA earnings records show income you didn't earn

Every year, the Social Security Administration tracks income reported under your SSN by employers. If a fraudster has used your SSN to build a synthetic identity that's been employed, or claimed to be, that income can show up in your SSA earnings record even though you never saw a cent of it.

Here's why that matters: your future Social Security benefits are calculated from your lifetime earnings history. Phantom income distorts that calculation, and correcting it later is a headache you don't want.

Create a free account at ssa.gov/myaccount and review your earnings history once a year. Look for:

  • Employers you've never worked for
  • Income in years when you weren't employed
  • Earnings that don't match your tax records

If something looks off, contact the SSA directly to report the discrepancy. This check takes minutes, costs nothing, and most people never think to do it.

Red flag #5: unfamiliar accounts on your credit file

Here's the one that catches people completely off guard: accounts showing up on your credit report under a name that isn't yours.

This is what Equifax calls a "fragmented" or "split" credit file. When a fraudster uses your SSN to build a synthetic identity, the fake person's accounts can bleed into your credit history. You might see a credit card, a personal loan, or a line of credit you never opened, with a completely different name attached.

That detail matters. A different name tied to your SSN isn't a bureau mix-up. It's a strong indicator of synthetic identity fraud specifically.

What to do: Pull your full credit reports from all three bureaus at AnnualCreditReport.com and review the accounts section carefully. Dispute any account you don't recognize, regardless of the name on it, directly with the bureau. Document everything, then report it to the FTC at IdentityTheft.gov.

Where your data comes from: how it ends up in a fraudster's hands

Synthetic identity fraud doesn't start with a sophisticated hacker. It starts with the same everyday online activities you do without thinking: filling out a form, clicking a link, or having your data stored by a company that gets breached.

Your personal information reaches fraudsters through four main pipelines:

  • Data breaches: Companies storing your records get hacked, and your SSN goes with them
  • Phishing attacks: You're tricked into handing your details over directly
  • Malicious websites: Fake or compromised pages harvest what you type into forms
  • Dark web marketplaces: Stolen data is bought and sold in bulk, often for just a few dollars per record

Knowing where it starts is the first step to cutting it off.

Data breaches: when companies lose your information

You don't have to do anything wrong to have your data stolen. You just have to have an account with a company that gets hacked.

When a retailer, healthcare provider, bank, or government agency suffers a breach, the personal records they store get exposed in bulk. Your Social Security number, date of birth, and home address can end up in a fraudster's hands without you ever clicking a suspicious link. According to the Identity Theft Resource Center's 2025 Annual Data Breach Report, there were 3,322 data compromises in the U.S. in 2025 alone, a record high. That data flows directly to dark web marketplaces where SSNs and personal records are bought and sold in bulk.

Think about every company that has your SSN on file right now: your employer, your bank, your health insurer, your tax preparer, your mortgage lender. Any one of them could be breached tomorrow.

That's not a reason to panic. It's a reason to pay attention.

Phishing attacks: when you're tricked Into handing it over

Data breaches happen to companies. Phishing happens to you.

A fraudster doesn't need to hack a database. They just need you to click a link. A fake IRS email says your refund is on hold. A text from what looks like your bank asks you to verify your account. A message pretending to be the Social Security Administration warns of suspicious activity on your record. You follow the link, fill in your details, and hand over exactly what a fraudster needs to build a synthetic identity.

Here's the kicker: these attacks are getting much harder to spot. The Federal Reserve Bank of Boston notes that generative AI can now mimic a person's texting style by analyzing their message history, then use that to trick a friend into giving up sensitive personal information. What used to look obviously fake now reads like a message from someone you trust.

This is exactly where Guardio steps in. On your computer, the browser extension detects and blocks phishing sites and malicious links before you reach the page where your information gets stolen. The same protection runs on the Guardio mobile app, so a phishing text or email that lands on your phone gets caught too.

Malicious websites and form harvesting

Have you ever Googled a government service and clicked the first result without checking the URL? Or entered your Social Security number into a job application form on a site you found through a social media ad?

Those are exactly the moments fraudsters build their schemes around.

Fake shopping sites, counterfeit government portals, and bogus job application pages are built to look indistinguishable from the real thing. They have SSL certificates. They show a padlock in your browser. They ask for your SSN as part of a routine "verification" step. Then your data gets packaged and sold.

The FTC received more than 330,000 government impersonation complaints in 2025, a 25% jump from the previous year. Many of those scams ran through fake websites that looked entirely legitimate. No single red flag gives these sites away. They're built to pass a quick visual check.

Guardio detects and blocks these malicious sites in real time, before you've typed a single character into a form, whether you're browsing on your computer or your phone.

The dark web marketplace: where stolen data gets sold

Think of the dark web as a flea market for stolen data. Except instead of secondhand furniture, the inventory is your personal information, priced to move.

Once your data is lifted through a breach or phishing attack, it gets listed for sale on dark web marketplaces within days. A standalone SSN sells for as little as $1 to $8, according to IT Accuracy's 2025 dark web pricing research. A complete identity package, known in fraud circles as "fullz" (SSN + name + date of birth + address), goes for $20 to $100. A child's SSN can be purchased for around $2, per Kyndryl's 2025 Synthetic Identity Fraud report.

The low price isn't reassuring. It reflects how abundant stolen data has become. Your identity isn't a rare commodity. It's cheap, plentiful, and actively traded at scale.

That's why early detection matters. Guardio's Identity Breach Monitoring scans dark web markets for your personal data and alerts you the moment it appears, before a fraudster can pair your SSN with a fake name and start building credit.

How to protect yourself and catch problems early

Synthetic identity fraud sounds hard to fight. It isn't. The fraud lifecycle has weak points, and most of them are things you can address today, without any technical expertise.

The key is catching exposure early, before a fraudster has time to build a credit history around your data. That window matters. The steps below are ordered by impact: start at the top, work your way down.

If you want a real-time early-warning system running in the background, Guardio's Identity Breach Monitoring scans the dark web and alerts you the moment your personal information surfaces somewhere it shouldn't.

Step 1: freeze your credit at all three bureaus (including your children's)

A credit freeze is the closest thing to a deadbolt on your credit file. It locks your report so no lender can open a new account in your name, even if someone has your Social Security number. It's free, takes about 10 minutes per bureau, and won't affect your existing accounts or credit score. You can lift it temporarily when you need to apply for credit, then relock it.

You need to freeze your credit at all three bureaus separately:

One bureau isn't enough. Fraudsters will simply apply through whichever one isn't frozen.

If you have children, freeze their credit too. This is the single most powerful step a parent can take. As the FTC advises, if your child is under 16, you can request a free credit freeze on their behalf. Children shouldn't have a credit file at all, which means a freeze creates one and immediately locks it.

To freeze a child's credit, contact each bureau directly. You'll need proof of your identity and guardianship, such as a birth certificate and a copy of your ID. Each bureau has its own process, so check their sites for current documentation requirements.

It takes some paperwork. It's worth every minute.

Step 2: check your credit reports at all three bureaus

You're entitled to free weekly credit reports from Equifax, Experian, and TransUnion at AnnualCreditReport.com the only federally authorized free source. That's not a typo. Weekly, not annually.

When you pull your reports, look for:

  • Accounts you don't recognize: Credit cards, loans, or lines of credit you never opened
  • Inquiries from lenders you've never approached: Hard pulls from companies you've never applied to
  • Addresses you've never lived at: Fraudsters often attach a fake address to a synthetic file
  • Employers you've never worked for: A name you don't recognize is worth chasing down

Check all three bureaus separately. A fraudster may have built a file at one bureau but not the others, so a clean Equifax report doesn't mean Experian or TransUnion are clear.

Do this at least once a year. If you've been notified of a data breach, check all three right away.

For children: contact each bureau directly and request a manual search using your child's Social Security number. According to the Consumer Financial Protection Bureau, children shouldn't have a credit file at all. If one exists, that's a problem.

Step 3: monitor your social security earnings record annually

Most people never think to check this one. That's exactly why it matters.

The Social Security Administration lets you create a free account at ssa.gov/myaccount, where you can view a full history of earnings reported under your Social Security number. It takes a few minutes to set up, and it's one of the few places where synthetic identity fraud leaves a direct trace on your real records.

Here's what to look for:

  • Income from employers you've never worked for. If a synthetic identity built on your SSN was used to get a job, that employer's wage report will show up here.
  • Earnings in years when you weren't working. A gap year, a period of unemployment, or early childhood years should show zero income. Anything else is a red flag.
  • Totals that don't match your memory. Even rough discrepancies are worth investigating.

This matters beyond fraud detection. Your future Social Security benefits are calculated from this earnings record. If someone else's income gets mixed into your history, it can quietly distort what you're owed.

Log in once a year. It's free, it's fast, and it's one of the clearest early warnings you'll find.

Step 4: set up fraud alerts

A fraud alert and a credit freeze aren't the same thing. Knowing the difference helps you pick the right tool.

A fraud alert is a notice on your credit file that tells lenders to take extra steps to verify your identity before opening new accounts. It's free, and here's the part most people miss: you only need to contact one of the three bureaus. They're legally required to notify the other two. The FTC confirms that an initial fraud alert lasts one year. If you're a confirmed identity theft victim, an extended alert lasts seven years.

The key difference from a credit freeze: lenders can still access your file with a fraud alert in place. It adds a verification hurdle, not a hard block.

Here's when to use each:

  • Fraud alert: you suspect your data may be out there, but you're not certain
  • Credit freeze: you want maximum protection and don't mind the extra step of lifting it when you apply for credit

You don't have to choose. You can have both active at the same time.

Step 5: use identity breach monitoring to catch exposure before it becomes fraud

Here's the uncomfortable truth: by the time a collections notice lands in your mailbox, a fraudster may have spent two years building a synthetic identity around your Social Security number. The damage is already done.

The only way to break that cycle is to catch the problem early, not after the fact.

That's what Guardio's Identity Breach Monitoring does. It watches for your personal data appearing in breaches and dark web markets, then alerts you the moment something surfaces. Not weeks later. Not after a credit application has already been filed. Right away, while you still have time to act: freeze your credit, change your passwords, call your bank.

Think of it as the difference between a smoke alarm and a fire investigation. One stops the damage. The other documents it.

On top of that, Guardio's Browser Security Extension cuts off one of the primary ways SSNs get stolen in the first place. Phishing sites and malicious pages are a major upstream source for the personal data that ends up on dark web marketplaces. In PCMag's hands-on phishing detection testing, Guardio scored a perfect 100%, compared to 80% for Aura in the same evaluation. That gap matters when a single slipped-through phishing page could hand a fraudster your most sensitive details.

More than 1.5 million people use Guardio, according to OneRep's 2026 review, with a Trustpilot rating above 4 stars.

Synthetic identity fraud is patient. It builds slowly, quietly, and counts on you not noticing. Guardio is the early-warning layer that makes sure you do.

Quick-reference: your synthetic identity fraud protection checklist

You don't need to do all of this today. But two or three of these steps puts you ahead of most people.

  • Freeze your credit at all three bureaus. Go directly to Equifax, Experian, and TransUnion. It's free and takes about five minutes per bureau.
  • Freeze your child's credit too. If your child is under 16, contact each bureau directly to request a freeze on their behalf. Their SSN is a prime target because it has no existing credit file.
  • Pull your free credit reports. Visit AnnualCreditReport.com, the only federally authorized source, and review all three reports for unfamiliar accounts or inquiries.
  • Check your SSA earnings record. Log in at ssa.gov/myaccount and look for income you didn't earn. Someone using your SSN for employment will show up here.
  • Set up a fraud alert. Contact any one of the three bureaus, they're required to notify the other two. A fraud alert prompts lenders to take extra steps before opening new credit in your name.
  • Sign up for Guardio's Identity Breach Monitoring. Get real-time alerts the moment your personal data appears in a breach or on the dark web, before it can be used to build a fake identity.
  • Never carry your Social Security card. Leave it somewhere secure at home. Your wallet is the wrong place for it.
  • Shred documents containing your SSN. Bank statements, tax forms, medical paperwork anything with your Social Security number on it should be shredded before it hits the trash.
  • Be skeptical of unsolicited SSN requests. Government agencies rarely ask for your Social Security number by email or text. If someone does, treat it as a red flag until proven otherwise.

Frequently asked questions about synthetic identity fraud

What is synthetic identity fraud, and how is it different from regular identity theft?

Synthetic identity fraud is when a fraudster pairs a real Social Security number with fabricated details, a fake name, and a fake date of birth to create a person who doesn't actually exist. Unlike traditional identity theft, no single real person is fully impersonated. That's what makes it so hard to catch: there's no obvious victim raising the alarm.

How would I know if my SSN is being used in a synthetic identity?

You probably wouldn't, at first. The clearest signals are unexpected credit inquiries, collections notices for debts you don't recognize, or unfamiliar accounts on your credit report. Checking your reports at all three bureaus regularly, and reviewing your Social Security Administration earnings record annually, are the most reliable ways to catch it early.

Can children really be victims of synthetic identity fraud?

Yes, and they're disproportionately targeted. A child's SSN has no existing credit history, so a fraudster can attach it to a fake identity and build credit for years before anyone notices. The FTC recommends freezing your child's credit at all three bureaus if they're under 16. It's free and one of the most effective protections available.

Does a credit freeze actually stop synthetic identity fraud?

A credit freeze prevents new credit accounts from being opened using your SSN, which cuts off one of the main ways synthetic identities get exploited. It won't undo damage that's already happened, but it's a strong preventive step. Freeze your credit at Equifax, Experian, and TransUnion separately, they don't share freeze requests with each other.

How long can synthetic identity fraud go undetected?

Often years. Fraudsters build credit slowly on purpose to avoid triggering fraud alerts, a process called credit farming. FICO notes that synthetic identity profiles can persist undetected for years while the fraudster quietly builds a legitimate-looking credit history before cashing out.

What should I do if I think my SSN has been used in a synthetic identity scheme?

Start by placing a fraud alert and credit freeze at all three bureaus. Then report it to the FTC at IdentityTheft.gov and contact the Social Security Administration's Office of Inspector General. Document everything. Acting quickly limits the damage and creates a paper trail that helps with any disputes.

Can identity breach monitoring help with synthetic identity fraud?

Yes, especially as an early-warning layer. Tools like Guardio's Identity Breach Monitoring alert you when your personal data appears in a breach or on the dark web. This includes sensitive information such as your email address or Social Security number (SSN). Catching that exposure early means you can act before a fraudster has the chance to build anything with it.

Conclusion

Synthetic identity fraud is patient, methodical, and hard to spot precisely because it doesn't look like theft at first. Freezing your credit, checking your SSA earnings record, and monitoring your data for breaches are the most effective steps you can take. Don't wait for a collections notice to find out your SSN has been living a double life.

Don't wait for a collections notice to find out

Guardio's Identity Breach Monitoring alerts you the moment your personal data is compromised - before it can be used to build a fake identity in your name. Over 1.5 million people already use Guardio to stay one step ahead.

Get started with a free scan

CMS-based CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
Default CTA:
Smart protection, built for how you live online
Stay ahead of threats with real-time insights and proactive protection.
Add Guardio to BrowserTake Security Quiz
CMS-based "Did you know?" block
Did you know?
Default "Did you know?" block
Did you know?

Make sure you have a personal safety plan in place. If you believe someone is stalking you online and may be putting you at risk of harm, don’t remove suspicious apps or confront the stalker without a plan. The Coalition Against Stalkerware provides a list of resources for anyone dealing with online stalking, monitoring, and harassment.

Guardio Security Team
Guardio’s Security Team researches and exposes cyber threats, keeping millions of users safe online. Their findings have been featured by Fox News, The Washington Post, Bleeping Computer, and The Hacker News, making the web safer — one threat at a time.
Tips from the expert

Related articles

FAQs

What is synthetic identity fraud in simple terms?

Synthetic identity fraud is when a criminal takes a real Social Security number, often belonging to a child or elderly person, and pairs it with a completely made-up name, date of birth, and address to create a fake person. That fake person is then used to apply for credit, build a credit history, and eventually steal money. Unlike regular identity theft, no single real person is fully impersonated, which is why it can go undetected for years.

How do I know if my Social Security number has been used in synthetic identity fraud?

The most common warning signs are: unexpected credit inquiries from lenders you've never applied to, collections notices for debts you don't recognize, a credit report appearing for your child (children shouldn't have one), unfamiliar accounts on your credit file, and income showing up in your Social Security Administration earnings record that you didn't earn. You can check your credit reports for free at AnnualCreditReport.com and your SSA earnings record at ssa.gov/myaccount.

Can a child's identity be stolen for synthetic identity fraud?

Yes, children are among the most targeted victims because their Social Security numbers have no existing credit file, giving fraudsters a blank slate to build on. The fraud can run undetected for 15-18 years until the child tries to apply for their first credit card or student loan. Parents can protect their children by requesting a credit freeze at all three credit bureaus (Equifax, Experian, TransUnion), which is free for children under 16.

Does a credit freeze protect against synthetic identity fraud?

A credit freeze is one of the most effective protections available. It prevents new credit accounts from being opened using your SSN, even if a fraudster has your information. It's free, doesn't affect your existing accounts or credit score, and can be temporarily lifted when you need to apply for credit. However, a credit freeze alone doesn't alert you if your data has already been stolen, that's where identity breach monitoring tools like Guardio come in.

How is synthetic identity fraud different from regular identity theft?

Regular identity theft involves stealing your complete identity and impersonating you, draining your accounts, making charges in your name. You typically notice quickly because your own accounts are affected. Synthetic identity fraud borrows just one piece of your identity (usually your SSN) to build an entirely new fake person. Because nothing in your name is directly affected, you may not notice for years , until the fake identity's debts bleed into your credit file or a collections agency comes calling.

How much does a stolen Social Security number cost on the dark web?

A standalone stolen SSN sells for as little as $1-$8 on dark web marketplaces, according to ITAccuracy's 2025 dark web pricing research. A complete identity package, SSN plus name, date of birth, and address, goes for $20-$100. A child's SSN specifically can be purchased for approximately $2, according to Kyndryl's 2025 Synthetic Identity Fraud report. The low price reflects how abundant stolen data has become following thousands of data breaches.

What is 'credit farming' in the context of synthetic identity fraud?

Credit farming is the patient phase of synthetic identity fraud where the fraudster slowly builds a legitimate-looking credit history for their fake identity. They make small purchases, pay bills on time, and gradually increase their credit score over 12-24 months. This makes the fake identity appear to be a trustworthy customer, allowing them to access higher credit limits before executing the final 'bust-out', maxing out all available credit and disappearing.

Table of Contents
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now
Can You Spot a Scam Text Message?
Test your skills and learn how to protect yourself from online scams.
Take the quiz now