RankShield
RANKSHIELD NETWORK Get started

Synthetic Identity Fraud at Checkout: How to Spot Customers Who Never Pay

Some of your worst customers were never real people. A synthetic identity passes every check and then never pays. Here is what it looks like at checkout and how to catch it.

August 2, 2026 · 12 min read · synthetic identity fraud at checkout
Share

Some of your worst customers were never real people. Synthetic identity fraud at checkout is the use of a fabricated person, a real Social Security number stitched to a made-up name, date of birth, and address, to open an account or place an order and then never pay, and because the underlying data is real and internally consistent, it passes the checks most stores rely on. The Federal Reserve calls synthetic identity fraud the fastest-growing financial crime in the United States, and TransUnion put lender exposure to suspected synthetic identities at a record 3.3 billion dollars (TransUnion2). That figure is lending exposure, not merchant losses, so the honest translation for a store is different: you almost never see the macro number, you see an order that clears every check and then defaults or charges back. I build fraud tooling at RankShield, and the thing merchants miss is that synthetic identity is not a data problem you can validate your way out of; it is a fabricated person your validation confirms as consistent. What this guide does is show what synthetic identity actually looks like at your checkout, why your checks pass it, and the point-of-transaction signals, especially the first-payment-default signature, that reveal it before the loss lands. One honest note first: no signal proves an identity is synthetic with certainty, so these are risk signals to weigh and act on, not a verdict.

What is synthetic identity fraud?

Synthetic identity fraud is the use of a combination of personal information to fabricate a person who does not exist, in order to commit fraud, which is the definition the Federal Reserve established to standardize how the industry measures it (Federal Reserve1). The key ingredient is that it mixes real and fake: typically a legitimate, unused Social Security number, often one belonging to a child or someone with no credit history, combined with a fabricated name, date of birth, and address. The result is an identity that is partly real, which is exactly what makes it hard to catch.

What makes it different from stolen-identity fraud is that there is no victim calling to report it, because the person is invented. With a stolen identity, the real person eventually notices and disputes the activity; with a synthetic identity, no one is watching the fabricated person, so the fraud can operate quietly for a long time. That patience is a feature of the scheme, not an accident, and it is why synthetic identities are built and aged before they are used.

The scale is real, and it is worth being precise about where it shows up. Synthetic identity fraud is concentrated in lending, auto loans, credit cards, and personal loans, where TransUnion found lender exposure at record highs (TransUnion2), because that is where a fabricated identity with built-up credit can borrow and disappear, and it sits within a broader fraud picture the FBI’s Internet Crime Complaint Center put at 16.6 billion dollars in reported losses in 2024 (FBI IC33). For a merchant, the same fabricated identities reach you through new accounts, buy-now-pay-later, and orders that rely on the identity being creditworthy, which is why understanding the lending version helps you recognize the checkout version.

DOWNLOADABLE INFOGRAPHIC

How a synthetic identity is built

RANKSHIELD // A PERSON WHO NEVER EXISTED How a synthetic identity is built 1. Real seed A legitimate, unused SSN often a child’s or dormant one 2. Fabricated shell Made-up name, DOB, address attached 3. Aged Small accounts, on-time payments build credit 4. Passes your checks Real SSN + consistent history = looks like a creditworthy customer 5. Cashes out Maxes out, never pays, first-payment default / chargeback You cannot validate your way out of it: the data is real. Watch behavior and the first-payment-default signature. Source: Federal Reserve synthetic identity definition; TransUnion. Illustrative of the common pattern.
A real SSN plus fabricated details, aged into a creditworthy "person," then cashed out. Free to share with attribution.

Why do your identity checks pass a synthetic identity?

Because your checks confirm that the information is real and consistent, not that the person actually exists, and a synthetic identity is built to satisfy exactly that. The Social Security number is genuine, the name, address, and date of birth are internally coherent, and by the time the identity is used it usually has a real credit history from months or years of small, well-behaved accounts. A verification that asks "does this data match and check out" gets a yes, because everything it can see is legitimate. The one thing it cannot see is that no human stands behind the data.

This is the trap in leaning harder on data validation. Adding more identity checks, more document verification, and more data matching raises the bar against sloppy fraud, but a well-built synthetic identity is not sloppy; it is engineered to pass those checks, and the aging process exists precisely to give it the history that makes it look real. You can validate a synthetic identity all day and it will keep passing, because you are confirming attributes it was designed to have.

That is why the detection has to move from the data to the behavior and the relationships around it. Instead of asking "is this identity valid," which a synthetic passes, you ask questions it struggles with: how old and how coherent is this identity’s footprint over time, how many identities share this device or payment instrument, and does the identity behave like a real customer once it is transacting. Those are point-of-transaction and relationship signals, and they are where a fabricated person, however well aged, starts to look wrong.

What does synthetic identity fraud look like at checkout?

At checkout it looks like a clean order from a thin or oddly-shaped identity that behaves a little too conveniently, and then does not pay. Because you are not a lender pulling a full credit file, the signals you can actually see are about the identity’s footprint and behavior: a very young or sparse identity history relative to the claimed person, a real Social Security number with a surprisingly short or inconsistent association to the name, and a device or payment instrument that is linked to more identities than a real household would have. Any one of these can be innocent; together they form a pattern.

Behavioral coherence is the other tell. A real customer’s activity hangs together over time, browsing, prior orders, consistent shipping and device, whereas a synthetic identity often arrives assembled, with a profile that is technically valid but lacks the messy continuity of a real person. Fraud operators run many synthetic identities, so the same device, network, or subtle behavioral fingerprint shows up across accounts that are supposedly unrelated strangers, which is a relationship signal no single identity check would surface.

The honest framing is that none of this is proof, and treating it as proof is how you false-decline real thin-file customers, a young adult or a recent immigrant with a genuinely sparse history looks superficially similar. So these are risk signals that should raise scrutiny and trigger verification, not an automatic block. As we covered in handling high-risk orders on Shopify, the right response to a risky-but-ambiguous order is to verify or hold it, not to reject a potentially real customer outright.

REAL VS SYNTHETIC

What separates a real customer from a synthetic identity

SignalReal customerSynthetic identity
Identity footprint over timeCoherent, messy, longThin or recently assembled
SSN-to-name associationLong, consistentReal SSN, short or odd link
Device-to-identity ratioFew identities per deviceMany identities per device
Behavioral continuityBrowsing, history, returnsArrives assembled, too clean
First paymentPays, behaves normallyDefaults or charges back fast

Any one signal can be innocent (thin-file real customers look similar). Weigh them together and verify, do not auto-block.

What is the first-payment-default signature?

First-payment default is the moment a synthetic identity stops pretending: the account or order passes every check, then misses its very first payment or charges back almost immediately, because paying was never the plan. It is the single most useful merchant-observable signal for synthetic identity and bust-out fraud, because it separates a fabricated identity from a real customer who has an occasional problem. A real customer usually pays for a while and then has trouble; a synthetic identity’s entire purpose is to obtain goods, credit, or a payout and default, so the default comes at the very start.

The pattern is especially clear across a cohort. If you look at new accounts or first orders and find a cluster that all default on the first payment, share subtle device or network characteristics, and were opened in a similar window, you are very likely looking at a batch of synthetic identities cashing out together, not a run of unrelated bad luck. Tracking first-payment-default rate by cohort turns an invisible loss into a measurable signal you can act on and tie back to the accounts that produced it.

This is why the fix is as much about monitoring after the sale as screening before it. You cannot always tell a well-aged synthetic identity from a real thin-file customer at the instant of checkout, but first-payment default reveals it quickly and lets you stop the second, third, and tenth order from the same operation. Feeding that outcome back into your screening, so identities and devices linked to first-payment default are scored higher on the next attempt, is what turns a single loss into a closed door.

What should you add to your checkout to catch it?

Add the point-of-transaction and relationship signals that a fabricated identity cannot easily satisfy, and pair them with first-payment-default monitoring so the ones that slip through are caught fast. In practice that means device and network intelligence to see when many "different" customers share one device, identity-graph and footprint age to flag identities that are thin or freshly assembled, velocity checks across identities and payment instruments, and a step-up verification for high-risk thin-file orders rather than an automatic decline. The goal is to make the fabricated relationships visible, not to validate the identity data harder.

Just as important is closing the loop after the sale. Monitor first-payment default as a named metric, tie each default back to the device, network, and identity signals present at checkout, and feed that outcome into your risk scoring so the next order from the same fingerprint faces more scrutiny. This is what lets you catch a synthetic operation on its second attempt even when its first got through, and it is the difference between absorbing repeated losses and shutting an operation down.

Keep the honesty guardrail in place while you do it, because the failure mode here is false-declining real customers. Thin-file, young, or newly-arrived customers are real revenue and look superficially like synthetics, so the right action for an ambiguous order is to verify or hold, not to reject. A tool that combines device intelligence, identity-footprint signals, and first-payment-default monitoring, and that verifies rather than blindly blocks, is what RankShield’s fraud protection for Shopify is built to provide.

RISK CHECK

Could a synthetic identity clear your checkout?

  1. Do you monitor first-payment default as a named metric?
  2. Can you see when many identities share one device or payment method?
  3. Do you weigh identity-footprint age, not just whether the data is valid?
  4. For a risky thin-file order, what do you do?
  5. Do first-payment defaults feed back into your risk scoring?

How do you stop customers who were never real?

You stop them by changing what you look at, because you cannot validate your way out of a fabricated person. A synthetic identity is a real Social Security number wrapped in a made-up name, date of birth, and address, aged with real credit history until it passes every check, which is why the Federal Reserve calls it the fastest-growing financial crime in the country and why more identity validation does not help: you are confirming attributes the identity was engineered to have. The dollar figures are largest in lending, where TransUnion measured record exposure, but at your checkout the same fabricated identities arrive as orders that clear and then never pay.

The signals that actually reveal them are about behavior and relationships, not data: a thin or freshly-assembled identity footprint, a device or payment instrument shared across many supposed strangers, and above all the first-payment-default signature, the account that passes everything and then defaults immediately. Watch those, verify the ambiguous middle rather than false-declining real thin-file customers, and feed every default back into your scoring so the operation is shut down on its next attempt. Be honest that none of it is certainty, so these are risk signals to act on, not verdicts. To put device intelligence and first-payment-default monitoring on your own store, see how RankShield protects your checkout.

FREQUENTLY ASKED

Questions, answered.

Jamie Kloncz
Jamie KlonczCEO, RankShield · online

What is synthetic identity fraud?

Jamie Kloncz

Synthetic identity fraud is the use of a combination of personal information to fabricate a person who does not actually exist, in order to commit fraud, which is the definition the Federal Reserve established so the industry could measure it consistently. The defining feature is that it mixes real and fake information: typically a legitimate, unused Social Security number, often one belonging to a child or someone with no credit history, combined with a made-up name, date of birth, and address. Because part of the identity is genuine and the whole thing is internally consistent, it passes checks designed to confirm that data is real and matches. What makes it different from stolen-identity fraud is that there is no real victim to notice and dispute the activity, since the person is invented, so the fraud can operate quietly for a long time. That patience is deliberate: synthetic identities are usually built and aged with small, well-behaved accounts before they are used, which is what gives them the credit history that makes them look like real, creditworthy customers.

Why do my identity checks not catch synthetic identities?

Jamie Kloncz

Because your checks confirm that the information is real and consistent, not that a real person stands behind it, and a synthetic identity is engineered to satisfy exactly that. The Social Security number is genuine, the name, address, and date of birth are coherent, and by the time it is used the identity usually has a real credit history from months or years of small accounts, so a verification that asks whether the data matches and checks out gets a yes. Adding more identity validation, document checks, and data matching raises the bar against sloppy fraud, but a well-built synthetic is not sloppy; the aging process exists precisely to give it the history that passes those checks. That is why leaning harder on data validation does not solve it, because you are confirming attributes the identity was designed to have. The detection has to move from the data to behavior and relationships: how old and coherent the identity’s footprint is, how many identities share a device or payment instrument, and whether the identity behaves like a real customer, which are the questions a fabricated person struggles to answer.

What is first-payment default and why does it matter?

Jamie Kloncz

First-payment default is when an account or order passes every check and then misses its very first payment or charges back almost immediately, and it matters because it is the single most useful merchant-observable signal of synthetic identity and bust-out fraud. The logic is simple: a real customer typically pays for a while and only later runs into trouble, whereas a synthetic identity exists to obtain goods, credit, or a payout and then disappear, so the default comes right at the start because paying was never the plan. The signal is especially strong across a cohort. If a batch of new accounts or first orders all default on the first payment, share subtle device or network characteristics, and were opened in a similar window, that is very likely a group of synthetic identities cashing out together rather than unrelated bad luck. Tracking first-payment-default rate by cohort turns an otherwise invisible loss into a measurable signal, and feeding those defaults back into your risk scoring lets you catch the same operation on its next attempt even if the first order got through.

How is synthetic identity fraud different from stolen identity fraud?

Jamie Kloncz

The core difference is whether a real victim exists. In stolen identity fraud, a criminal uses a real person’s actual identity, so that person eventually notices the unauthorized activity, reports it, and disputes it, which puts a natural time limit on how long the fraud can run and often triggers chargebacks and investigations. In synthetic identity fraud, the person is fabricated, a real Social Security number combined with a made-up name, date of birth, and address, so there is no real victim watching the account and no one to report it. That absence is what makes synthetic identity so durable and so hard to detect: the fraud can operate quietly for months or years while the identity is aged into looking creditworthy, and when it finally defaults there is no victim, just a person who never existed. For detection, the implication is that you cannot rely on a victim’s dispute to flag synthetic fraud the way you sometimes can with stolen identities; you have to catch it through behavioral and relationship signals and the first-payment-default pattern instead.

Can synthetic identity fraud hit an ecommerce store, or just lenders?

Jamie Kloncz

It can hit an ecommerce store, though the largest measured dollar figures are in lending. Synthetic identity fraud is concentrated in auto loans, credit cards, and personal loans, where TransUnion found record lender exposure, because that is where a fabricated identity with built-up credit can borrow large amounts and vanish. But the same fabricated identities reach merchants through the doors that depend on the identity being creditworthy or trustworthy: new-account signups, buy-now-pay-later, financing, and orders where the store effectively extends trust before being paid. At a store, the fraud shows up not as a scary macro number but as an order that clears every check and then defaults or charges back, and as clusters of new accounts that share devices and default on their first payment. So the honest framing is that lending carries the biggest exposure, but any merchant that grants credit, offers pay-later options, or ships before guaranteed payment can be a target, and the checkout signals, thin footprint, device-to-identity ratio, and first-payment default, are how a store sees it.

How do I catch synthetic identities without rejecting real thin-file customers?

Jamie Kloncz

The key is to treat thin-file and unusual-footprint signals as reasons to verify rather than to decline, because real customers who are young, recently arrived, or simply new to credit look superficially like synthetic identities. Start by adding the signals a fabricated identity struggles with: device and network intelligence to see when many supposedly different customers share one device, identity-footprint age to flag thin or freshly-assembled identities, and velocity checks across identities and payment instruments. Then, crucially, route the ambiguous ones to a step-up verification, a confirmation to the account holder, an extra check, or a temporary hold, instead of an automatic block, so a real thin-file customer can prove themselves and complete the purchase. Pair all of this with first-payment-default monitoring so the synthetics that do slip through are caught quickly and fed back into your scoring. Done this way, you raise scrutiny on the risky middle without turning away good revenue, which is the balance that matters: false-declining real customers is a real and often larger cost than the fraud itself, so verification, not blanket rejection, is the right tool.

Try one of the suggested questions above.

References

  1. Federal Reserve (FedPayments Improvement). Synthetic Identity Fraud (standardized definition: a combination of PII used to fabricate a person; reported fastest-growing financial crime in the US).
  2. TransUnion. Analysis finds synthetic identity fraud growing to record levels (record lender exposure to suspected synthetic identities, ~US$3.3B; concentrated in auto finance).
  3. FBI Internet Crime Complaint Center (IC3). 2024 Internet Crime Report ($16.6B in reported losses; macro fraud context).
Jamie Kloncz
WRITTEN BY

Jamie Kloncz

Founder & CEO, RankShield

Jamie Kloncz is the founder and CEO of RankShield, the verifiable AI and quantum security platform. He started the company after two attacks landed in a single week: his phone was cloned, and his business was hit by a click-fraud campaign. One targeted him as a person, the other his livelihood, and no single tool defended both. That experience, together with surviving an AI voice-clone scam, shaped RankShield’s core belief: the threats of the AI age are personal first, and trust should be something you can check, not just extend.

Make every AI action provable.

RankShield is the verifiable, quantum-safe AI security platform — protection you can check, not just trust.