Synthetic Identity Fraud
This one is patient and quiet. A criminal pairs your real Social Security number with a fabricated name and birthdate to build a brand-new "person," then uses it to open credit. Standard credit monitoring will not catch it, because the name is not yours. The damage can sit for years — US lenders carried $3.3 billion in exposure in 2025 alone — and a child's unused SSN is the prize.
How It Works
Warning Signs & Red Flags
- You receive credit denial letters for accounts you never applied for
- IRS rejects your tax return saying your SSN was already used
- You receive bills, collection notices, or credit cards in names you don't recognize
- Your child receives pre-approved credit offers or collection calls
- Strange addresses or employers appear on your credit report
- A credit freeze request reveals existing accounts you didn't open
- Medical bills arrive for treatments you never received
- Your Social Security statement shows earnings you didn't make
- Background check reveals criminal records under your SSN but different name
- Government benefit applications are rejected because your SSN is "already in use"
Real-World Example
"A Florida man used my Social Security number with the name "Gaylord Focker," a completely different address, date of birth, and phone number—and received a credit card with a $9,000 limit. Because the name wasn't mine, I had no idea until I was denied for a mortgage years later. My fraud alerts and credit monitoring caught nothing."
— FTC Testimony on Synthetic Identity Theft
How to Protect Yourself
- Freeze credit at ALL THREE bureaus (Equifax, Experian, TransUnion) plus ChexSystems and NCTUE
- Freeze your children's credit—even newborns can be victims
- Create a my Social Security account at ssa.gov to monitor earnings
- Request your free annual credit reports from annualcreditreport.com
- Monitor databases beyond credit bureaus—synthetic fraud creates sub-files that don't show on standard reports
- Set up IRS Identity Protection PIN to prevent tax fraud
- Minimize sharing your SSN—ask if it's truly required
- Consider identity monitoring services that scan dark web and data broker databases
- File an identity theft report at IdentityTheft.gov if you suspect compromise
- Regularly check Social Security statements for unknown earnings
What To Do If You're a Victim
- 1Request your full credit file (not just report) from all bureaus—this reveals sub-files
- 2File an Identity Theft Report at IdentityTheft.gov—this creates legal documentation
- 3Place extended fraud alerts (7 years) with all credit bureaus
- 4Contact Social Security Administration if your SSN is compromised
- 5File IRS Form 14039 (Identity Theft Affidavit) to protect your tax account
- 6Report to FBI IC3 at ic3.gov
- 7Report to FTC at ReportFraud.ftc.gov
- 8Request a free credit freeze at all bureaus—this is your right by law
- 9Dispute fraudulent accounts directly with creditors using your Identity Theft Report
- 10Keep detailed records—synthetic identity cases can take years to fully resolve
- 11Consider consulting an identity theft specialist or attorney for complex cases
Frequently Asked Questions
What is Synthetic Identity Fraud?
What are the warning signs of Synthetic Identity Fraud?
How do I protect myself from Synthetic Identity Fraud?
What should I do if I'm a victim of Synthetic Identity Fraud?
How serious is this threat?
Can I get my money back?
How do I report Synthetic Identity Fraud?
AI-Enhanced Phishing
Phishing used to give itself away with broken grammar. AI fixed that. The emails are now clean, personalized, and plausible, which means the old "look for typos" advice is dead. Verify any request through a channel you control, not the one that contacted you.
SIM Swap Attack
An attacker convinces your carrier to move your number to their SIM, and suddenly your texts — including two-factor codes — are theirs. From there they drain bank and crypto accounts in minutes. Lock your account with the carrier and move off SMS-based two-factor where you can; app-based codes do not travel with a stolen number.
Fake Data Breach Notification
A phishing email impersonates a breach alert — "your data was exposed, reset your password here" — and the link goes to a fake login or "identity protection" page built to capture credentials. The irony is the point: it weaponizes your fear of being hacked. Go to the real site directly, never through the email's link.
Think you've encountered this scam?
Use the free AI scanner to analyze suspicious messages, websites, or phone numbers.
Scan Now — It's Free