Synthetic Identity Theft: The $40 Billion Fraud You've Never Heard Of
Synthetic identity theft builds a fake person from your real SSN. How to tell if your Social Security number is being used, and the free checks that catch it.
TL;DR
Synthetic identity theft is the creation of a person who does not exist, built from one real identifier, usually a Social Security number, paired with a fabricated name, date of birth, and address. Criminals force a credit file into existence, feed it small on-time payments for a year or two, borrow against it heavily, then abandon it in a "bust out". Because no real consumer is named on the accounts, nobody gets an alert, and lenders often write the loss off as bad debt instead of fraud. Children, seniors, and people who never check credit are the preferred raw material. Free credit reports, a Social Security earnings check, and freezes at all three bureaus are the fastest ways to find out if your number is in circulation.
A lender opens a file for a 23 year old applicant with four years of clean borrowing history and a score in the low 700s. The applicant does not exist: the Social Security number on the application belongs to a nine year old who has never had a bank account, and within a week the fabricated borrower drains every line and disappears. That is synthetic identity theft, and unlike a stolen wallet, no alert ever fires, because the accounts carry a name that belongs to no one.
According to the Federal Reserve, which published an industry recommended definition in 2021, synthetic identity fraud is the use of a combination of personally identifiable information to fabricate a person or entity for financial gain. The common variant, and the one this guide covers, welds one real identifier onto invented details. According to the FTC Consumer Sentinel Network Data Book covering 2024, identity theft remained one of the largest complaint categories in the country, yet synthetic cases hide inside it, charged off as ordinary credit losses rather than reported as fraud.
That undercounting is why the headline figure is a range and not a total. Industry estimates put annual global losses between $20 billion and $40 billion, while the slice lenders can actually count is a fraction of it.
Quick Answer
What Is Synthetic Identity Theft?
Classic identity theft impersonates you: someone opens a card in your exact name, the statement arrives, you dispute it. Synthetic fraud does the opposite. It takes one true fragment of you, almost always the nine digits of a Social Security number, and builds a new person around it. The name, the birth date, and the address are all invented.
That single design choice is what makes it so hard to catch. Bureaus merge records only when several identifiers agree, so a matching Social Security number paired with a name and birth date that do not match your file usually spawns a second, separate file rather than merging into yours. Fraud alerts key off your name, so they stay silent while the shadow identity rides on your number.
The preferred raw material is a number nobody is watching. Children top the list, since a minor's number sits unused for eighteen years and few parents ever check. A widely cited 2011 Carnegie Mellon CyLab report found 10.2 percent of more than 40,000 children enrolled in an identity protection service already had their number used by someone else. That sample was self selected, so the true rate is likely lower. Seniors in long term care, the incarcerated, and the deceased follow for the same reason. Our guide to identity data on the dark web covers where these numbers come from.
How Synthetic Identity Theft Works, and Why Your Credit Report Never Shows It
The process is patient and industrial. A crew running hundreds of profiles at once follows the same six steps.
- <strong>Acquire the identifier.</strong> A Social Security number is bought in bulk from breach data, phished out of a target, or guessed within a valid range and tested against an application form.
- <strong>Build the person.</strong> The number is paired with a plausible name, a birth date that makes the person a young adult, and a deliverable address.
- <strong>Force a credit file into existence.</strong> The fabricated person applies for credit and is declined, but the inquiry alone makes a bureau open a thin file. The identity now formally exists.
- <strong>Age the file.</strong> A secured card or small retail account is paid perfectly for twelve to twenty four months, and the score climbs on genuine repayment behavior.
- <strong>Piggyback for seasoning.</strong> The profile is added as an authorized user on established tradelines, often bought from brokers, grafting years of history onto a file that is months old.
- <strong>Bust out.</strong> Every line is drawn to the limit within days, often across a dozen lenders at once, and the identity is abandoned. Nobody answers the collection calls.

Red Flags: How to Check If Your Identity Is Being Used
Because the fake identity never carries your name, look for its side effects instead. Any one of these is worth a full credit review.
- <strong>Mail addressed to a name you do not recognize.</strong> Pre approved offers or collection letters for a stranger at your address are the most common first signal.
- <strong>Any credit mail addressed to your child.</strong> A minor should generate zero credit offers. One arriving means a file exists that should not.
- <strong>A minor freeze request that comes back saying a file already exists.</strong> This is the clearest confirmation of child identity fraud.
- <strong>Earnings on your Social Security record that you never made.</strong> Wages reported under your number by an employer you never worked for point straight at synthetic employment fraud.
- <strong>Unfamiliar aliases or addresses on your credit report.</strong> Bureaus list "also known as" variants, and a misspelling you never used may be the fabricated identity bleeding into your file.
- <strong>A tax return rejected because one was already filed.</strong> The IRS notice often surfaces number misuse before any lender does.
Confirming any of these costs nothing, and no paid monitoring subscription is required.
Got a message asking you to confirm your SSN, date of birth, or identity documents? Scan it with Truvizy before you answer anything.
How Truvizy Detects Synthetic Identity Fraud
Truvizy is not a credit bureau and it does not read your file. It works one step earlier, at the moment your identifiers are requested. Some fabricated identities are built on numbers stolen in a breach. Others start with a number a target typed into a fake benefits notice, a bogus onboarding form, or a lookalike bank identity check.
Paste that message, screenshot, or link into Truvizy at truvizy.app and its AI-powered detection runs a multi-layer analysis of the wording, the urgency framing, the claimed sender, and the destination, then returns a plain verdict in seconds. A Social Security number in circulation cannot be recalled, so the highest leverage moment is the one before you type it, especially on a phone where the usual tells stay hidden.
What to Do If You Suspect Synthetic Identity Theft
Move through these in order. Synthetic cases unwind slowly, because the accounts are not in your name.
Pull all three reports. Request Equifax, Experian, and TransUnion reports at annualcreditreport.com and read every alias, address, and inquiry, not just the account list.
Freeze all three bureaus. A freeze is free, reversible, and blocks new accounts on your number no matter what name the applicant uses. Do the same for every child in your household.
Check your Social Security earnings record. Ask SSA to correct any earnings that are not yours, then report the misuse itself to the SSA Office of the Inspector General. SSA fixes the record, it does not investigate the fraud.
File with the FTC, then file locally. Report at reportfraud.ftc.gov or identitytheft.gov for the recovery plan and the affidavit, then add a police report. The affidavit plus the police report is what bureaus and lenders accept when you ask them to block a fraudulent tradeline.
Report the delivery method too. If the fraud reached you online, a phishing text, a fake job posting, a spoofed lender page, add a complaint at ic3.gov. If it surfaces as wages you never earned or a rejected tax return, file IRS Form 14039 instead.
Dispute in writing and keep everything. Send disputes by mail, keep copies, and expect to repeat yourself. Our identity theft recovery guide walks through the paperwork sequence in detail.

Key Takeaways
- Synthetic identity fraud pairs one real identifier, usually a Social Security number, with a fabricated name and birth date, so it never appears on your own credit report.
- Children are the preferred target because a minor's number is clean, valuable, and almost never checked by anyone.
- The pattern is always the same: force a thin file into existence, age it with perfect payments, then bust out.
- Free checks and bureau freezes find and stop more of this than paid monitoring does.
Expert analysis note: the defining weakness of this fraud is structural, not technical. Lenders book the loss as bad debt, bureaus split rather than merge mismatched files, and the real number holder is chosen precisely because they have no reason to look. Detection almost never arrives on its own, so treating a Social Security number as a credential that can never be rotated, and verifying every request for it before answering, is the only defense that scales to a person rather than an institution.
You freeze your eight year old's credit and the bureau replies that a file already exists for them. What does that most likely mean?
- A harmless clerical duplicate at the bureau
- Someone has been using your child's Social Security number to build a credit identity
- The freeze was processed successfully
- Your own file was linked to theirs by mistake
Answer: A child with no accounts should have no credit file at all. An existing file is the clearest confirmation of synthetic identity fraud on their number. Follow it immediately with a full report request, a freeze, and a report at identitytheft.gov.
Frequently Asked Questions
How do I know if someone is using my Social Security number?
Pull your credit reports from all three bureaus at annualcreditreport.com and look for accounts, addresses, or name variations you do not recognize. Then check your earnings record inside a my Social Security account for wages you never earned, the clearest single sign of synthetic use. The FTC Consumer Sentinel Network logged roughly 1.1 million identity theft reports in 2024, so check quarterly.
How can I check if my identity is being used for free?
Free checks cover most of the ground. Weekly credit reports from Equifax, Experian, and TransUnion cost nothing at annualcreditreport.com, a security freeze at each bureau is free by law, and your earnings record is free inside a my Social Security account. Add an IRS identity protection PIN and you have the four places a fabricated identity surfaces first.
Can I check if my child's Social Security number has been used?
Yes, and the check doubles as the fix. Request a free protected consumer freeze at each bureau with proof of guardianship and identity. If no file exists, the bureau must create one purely so it can be frozen. If a bureau replies that a file already exists, that is your answer, and it is the clearest confirmation of synthetic fraud on your child's number.
Does credit monitoring catch synthetic identity fraud?
Only partly. Standard monitoring alerts you to activity attached to your name, and a synthetic identity deliberately pairs your number with a different name, so the alert may never fire. Reading the full report for unfamiliar aliases and addresses catches more of it. Freezing all three bureaus is stronger, because a freeze blocks the new account instead of reporting it afterward.
Can Truvizy tell me if a message asking for my SSN is a scam?
Truvizy checks the message, not your credit file. Paste the text, email, or link asking for your Social Security number into Truvizy and its AI-powered detection returns a plain verdict in seconds on whether the sender is impersonating a bank, a lender, or a government agency. A scam verdict tells you the request itself was manufactured, so the number was never owed to anyone.
Related reading: Social Security Scams: How Criminals Use Your SSN Against You — The calls and texts designed to extract the exact number synthetic fraud runs on
Related reading: Identity Theft Prevention: 15 Steps to Protect Your Personal Information — The full prevention checklist, from freezes to account hygiene
Related reading: Is Your Identity on the Dark Web? How to Check and What to Do — Where breached Social Security numbers go and what they cost
Frequently Asked Questions
How do I know if someone is using my Social Security number?
Pull your credit reports from all three bureaus at annualcreditreport.com and look for accounts, addresses, or name variations you do not recognize. Then check your earnings record inside a my Social Security account for wages you never earned, the clearest single sign of synthetic use. The FTC Consumer Sentinel Network logged roughly 1.1 million identity theft reports in 2024, so check quarterly.
How can I check if my identity is being used for free?
Free checks cover most of the ground. Weekly credit reports from Equifax, Experian, and TransUnion cost nothing at annualcreditreport.com, a security freeze at each bureau is free by law, and your earnings record is free inside a my Social Security account. Add an IRS identity protection PIN and you have the four places a fabricated identity surfaces first.
Can I check if my child's Social Security number has been used?
Yes, and the check doubles as the fix. Request a free protected consumer freeze at each bureau with proof of guardianship and identity. If no file exists, the bureau must create one purely so it can be frozen. If a bureau replies that a file already exists, that is your answer, and it is the clearest confirmation of synthetic fraud on your child's number.
Does credit monitoring catch synthetic identity fraud?
Only partly. Standard monitoring alerts you to activity attached to your name, and a synthetic identity deliberately pairs your number with a different name, so the alert may never fire. Reading the full report for unfamiliar aliases and addresses catches more of it. Freezing all three bureaus is stronger, because a freeze blocks the new account instead of reporting it afterward.
Can Truvizy tell me if a message asking for my SSN is a scam?
Truvizy checks the message, not your credit file. Paste the text, email, or link asking for your Social Security number into Truvizy and its AI-powered detection returns a plain verdict in seconds on whether the sender is impersonating a bank, a lender, or a government agency. A scam verdict tells you the request itself was manufactured, so the number was never owed to anyone.