Skip to content
KEDBYTE
How Identity Works
Chapter
57

When Identity Is Stolen

Part V · Identity, Society and the Law|13,886 words|about 60 min read|Volume 5
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

57.0 What this chapter gives you#

  1. You will be able to place any real fraud case into one of four categories - account takeover, new-account fraud, synthetic identity fraud, or first-party fraud - by asking three questions in a fixed order, and say why the answer changes which defence works.
  2. You will be able to describe how a fabricated person is built and credit-seasoned, month by month, from the creation of the first credit file to the bust-out, using the mechanisms the Federal Reserve documented in its white papers of July 2019, October 2019 and July 2020.
  3. You will be able to explain why every detection system that depends on a victim reporting harm has structurally no chance of finding synthetic identity fraud, and what has to replace it.
  4. You will be able to state both sides of the first-party fraud dispute between lenders, regulators and consumers, and name the accounting incentive that keeps it unresolved.
  5. You will be able to quote real loss figures with the source and the year attached, and say why the figures from the Federal Trade Commission, UK Finance, Cifas, the Bureau of Justice Statistics and commercial surveys must not be added together.
  6. You will be able to list the four families of detection signal - device, behaviour, velocity and graph - say which category of fraud each one actually catches, and do the base-rate arithmetic that decides whether a model can be deployed at all.
  7. You will be able to advise a person in the United States, the United Kingdom or India on what to freeze, flag or lock, with the correct statutory clocks and the correct names for the tools.
  8. You will be able to write out a victim’s remediation sequence in order, with each statutory deadline attached, and explain why real recovery time is governed by discovery rather than by process.
  9. You will be able to rank design changes by the strength of the evidence behind them, and say honestly which of them have measured evidence and which have only a plausible mechanism.
  10. You will be able to tell a colleague, in one sentence, why buying a single “identity theft solution” is a category error.

The phrase “identity theft” is doing too much work. It is used for a stolen card number, for a mortgage taken out in a dead man’s name, for a teenager who discovers at eighteen that somebody has been running a credit file on his national insurance number since he was six, and for a customer who buys a sofa on credit and never intended to pay for it. Those four things share almost nothing. They have different perpetrators, different victims, different money flows, different detection methods, different laws and different remedies. Treating them as one problem is the reason so many defences fail: an organization installs a control that works beautifully against one of them and is then astonished to find its losses unchanged, because the losses were coming from a different one.

This chapter separates them. It builds four categories, defines each precisely enough to count, and then shows what actually stops each. The central claim, and the thing to carry away if you carry away nothing else, is that the defences are mostly not interchangeable. A credit freeze is close to perfect against one category and completely useless against two others. A hardware security key is close to perfect against one category and irrelevant to the rest. Consortium graph analysis finds the category that nothing else finds and produces four false accusations for every true one. There is no single purchase, no single regulation and no single habit that covers the ground.

We will do the money honestly. Every figure in this chapter carries the organization that produced it and the year it refers to, because fraud statistics are the most casually misquoted numbers in the industry. The Federal Trade Commission counts consumer reports. UK Finance counts member banks’ confirmed losses. Cifas counts filings to a shared database. The Bureau of Justice Statistics counts survey answers. Commercial studies count survey answers and then extrapolate. These are four different measuring instruments pointed at four overlapping populations, and adding their outputs produces a number that means nothing at all.

Two neighbouring chapters share a border with this one and we will not cross it. Chapter 58 handles the specific breaches - the Office of Personnel Management, Equifax, LastPass and the rest - that put the raw material for all of this into circulation, and where a breach appears here it gets one line and a pointer. Chapter 56 handles the argument about whether a society should be able to identify everybody at all. This chapter takes the systems as they are and asks what happens when somebody wears your name.

The plain version#

Four different burglaries that share a name#

Imagine a street of houses. Each house is somebody’s financial life: the accounts they hold, the credit they can get, the money that flows in and out. Now imagine four things that can go wrong on that street, all of which the newspapers will describe as “identity theft”.

The first is that somebody copies your front door key and lets themselves in. Your house, your furniture, your address on the letters. The intruder does not build anything and does not pretend to be a new resident; they simply use the house that already exists. They open your fridge, take your things, and if they are careful they change the locks behind them so you cannot get back in. This is account takeover. The house is an account you already hold. The key is your password, or the code sent to your phone, or the answer to a question about your mother’s maiden name.

The second is that somebody goes to a builder in a town four hundred miles away, gives your name and your date of birth and your national number, and has a whole new house built on credit. You never see the house. You never see the builder. The first you hear of it is when the bill arrives, or when you apply for something yourself and are told that you already owe a great deal of money. This is new-account fraud. Your identity is real, the account is new, and the person who opened it was not you.

The third is stranger and much harder to picture. Somebody takes one brick from your house - the number, say, and nothing else - and combines it with an invented name, an invented birthday, a post box for an address and a telephone that answers to nobody. They then build a house out of these parts. At first it is a shed. But they get it connected to the water supply, then the electricity, then the post. Each connection makes the next one easier, because the shed now has a record of being a house. After two years the shed has a bank account, three credit cards and a car loan, and it is a perfectly respectable member of the street, except that no human being has ever lived in it. Then one morning everything in it is sold and the shed disappears. This is synthetic identity fraud, and the reason it is the hardest of the four is that there is nobody to notice. There is no householder to open a letter and say, that is not mine.

The fourth is that the person who lives in the house does it themselves. They order the sofa on credit and never pay. They tell the insurer their teenage son is a named driver when he is the main driver. They buy something, receive it, and then tell the card company it never arrived and they want their money back. Nobody’s identity has been stolen. This is first-party fraud, and it is in this chapter because it looks identical to the other three from the outside, it is frequently counted with them, and lenders and regulators cannot agree on whether it should be called fraud at all.

Four burglaries. One word. Almost nothing in common.

Three files on one desk#

To keep this concrete we will follow one fraud desk through one Tuesday. The bank is Kestrel Bank, a regional lender in the United States with 1.4 million customers, and it is not a real bank; it is a worked example built out of real mechanisms and real published figures, and every number attached to it is either arithmetic you can check or a benchmark from a named source. Three files land on the desk in the same hour, and they will be with us for the rest of the chapter.

File A belongs to Diane Okafor, aged forty-four, a customer for eleven years. Overnight, somebody logged into her online banking from a device the bank had never seen, changed the telephone number on the account, added a new payee, and moved 8,400 dollars out in three transfers. Diane was asleep. Her phone had shown “no service” since about eleven at night, which she assumed was a network problem.

File B belongs to Walter Reese, aged eighty-one, who has been a customer since 1979 and has not borrowed money since 1994. An application for a car loan of 31,000 dollars has arrived in his name from a dealership in another state. His date of birth is correct. His national number is correct. His address is not his address.

File C belongs to Ellis Moray, aged thirty-nine according to the application, a customer of two years and two months, who has never missed a payment on anything. Overnight, Ellis Moray drew the full balance on three credit cards and took a cash advance on a fourth, and this morning the personal loan payment bounced. The telephone number does not answer. The employer named on the file has never heard of him. Ellis Moray does not exist and never did.

Diane is account takeover. Walter is new-account fraud. Ellis is synthetic. The bank’s total exposure across the three is 8,400 dollars, nothing yet, and 41,300 dollars respectively. And here is the thing to notice before any of the technical detail: the bank found out about Diane because Diane rang up, it found out about Walter because Walter’s dealer application tripped a check, and it found out about Ellis because the money stopped arriving. Nobody reported Ellis. Nobody could have.

Why the third one is invisible#

Almost every protection an ordinary person has against identity theft is built on the same assumption: that a human being will notice something wrong and say so. You look at your statement and see a charge you did not make. You get a letter about a loan you did not take. You check your credit report and find an account you do not recognize. Every one of these begins with a person recognizing that a record is not about them.

Now think about what a synthetic identity is. It is a record that is not about anybody. There is no person who could look at Ellis Moray’s credit file and say “that is not mine”, because it is not anybody’s. The four credit cards are not on any real person’s statement. The address receives post for nobody. The number at the centre of it might belong to a child who is nine years old and will not apply for anything for another decade, or to somebody who died in 2003, or to nobody at all.

So the entire consumer-protection machinery - the fraud alert, the credit freeze, the dispute, the report to the regulator - passes straight over synthetic identity without touching it. Those tools are triggered by victims. A synthetic has none, or rather it has one who will not find out for years. This is not a weakness in the tools. It is what the tools are for. But it means that if you measure identity theft by counting victim reports, synthetic identity fraud is invisible in your figures, and if you defend against identity theft by helping victims react, you have built no defence against it whatsoever.

Seasoning, in plain words#

The trick that makes a synthetic identity valuable is patience, and it has a name borrowed from cooking: seasoning.

When a credit file is brand new it is worth almost nothing. No lender will hand thirty thousand dollars to a name that appeared six weeks ago with no history. So the file has to be aged, and made to look as though it has been paying its bills for years. There are four common ways.

The first is simply to apply for something and be refused. Most people assume a refused application leaves no trace. It leaves a very important one: in order to refuse you, the lender asked a credit bureau about you, and the bureau, finding nobody, created a file to record the question. The fabricated person now exists in the one place that matters. The Federal Reserve’s white paper of October 2019 makes exactly this point: synthetic identities typically first appear through a credit bureau rather than through a birth, a licence or a passport.

The second is to buy a place on somebody else’s good account. In many credit systems, if you are added to an existing card as an extra cardholder, that card’s whole payment history appears on your file as though it were yours, and there is an open trade in selling such slots.

The third is to use products designed for people with no history: a secured card where you put down a deposit and get a card with the same limit, or a small credit-builder loan. These are honest products intended to help real people start out, and they work just as well for people who do not exist.

The fourth is time and good behaviour. Small purchases, paid off in full, month after month, nothing dramatic. This is why detection is so hard: for most of its life the fabricated person is a model customer, and by the ordinary tests it is a better customer than most real ones.

Then, when the limits are high enough and enough lenders are exposed at once, everything is drawn down in a day or two and the person evaporates. The industry word for that final day is the bust-out.

A person can be their own burglar#

The fourth category unsettles people, so it is worth putting plainly.

Suppose a man walks into a shop, applies for a store card in his own name, with his own documents, passing every check because everything he says is true, and buys a television he never intends to pay for. No identity has been stolen. He is exactly who he claims to be. But he has obtained goods by a lie - the lie being about his intention - and that is a fraud.

Now suppose the same man buys a television, receives it, and tells his card company that it never arrived. Again, no stolen identity. Again, a lie, this time about a fact rather than an intention.

Now make it harder. Suppose a woman applies for a loan and overstates her income by twenty per cent because she is sure she can manage the payments, and then loses her job and cannot. Was that fraud, or was it optimism followed by misfortune? The application was false. The intention is unknowable. The lender has to decide, and its decision determines whether the loss is written down as a bad debt or reported as a crime, and whether the woman is recorded on a shared database that will make it hard for her to open a bank account for the next six years.

This is genuinely difficult, it is not a matter of anybody being stupid, and there is no agreed answer. We will come back to it properly.

What a victim actually has to do#

Here is the last piece of the plain version: what it is actually like to be Diane or Walter.

Diane’s problem is bounded. There is one bank, one account, a defined set of transactions and a legal framework that in most countries puts the loss on the bank unless she was negligent. She rings up, the account is frozen, the transfers are reversed or not, and there is an argument about the ones that are not. It is unpleasant and it takes hours, not months.

Walter’s problem is unbounded, and that is the crucial difference. He does not know how many accounts exist in his name. He knows about one because a dealer’s check bounced back to his bank. There may be six others. Every time he finds one he starts the process again: report it, prove who he is, get it removed, check whether the removal happened, deal with the debt collector who bought the debt and has not been told. He also has to stop the next one, which means going to each credit bureau separately, and to the specialist bureaus that most people have never heard of, and to the tax authority, and to the telephone company.

The length of Walter’s ordeal is not set by how fast the paperwork moves. Most of the paperwork has a legal deadline measured in days. It is set by how long it takes to discover everything, and there is no process that tells him when he has found the last one. That is the single most important thing to understand about victim remediation, and we will put real numbers on it later.

Where the plain version stops being true#

The four categories bleed into one another#

The four-box picture is the right way to start and it is not how real cases behave. Cases move between boxes, and often a single crime is two categories in sequence.

The most common sequence is that account takeover is used to commit new-account fraud. The attacker takes over an email account, not a bank account, because the email account is where every password reset and every “was this you?” message lands. From there they take over the telephone account, because the phone number is where the codes go. Only then do they touch the money. Diane’s file looks like a single bank incident. It is more likely the third step in a chain that began somewhere with no money in it at all.

The second common blend is that a synthetic identity is grown around a real person’s number. The number is real and belongs to a nine-year-old. The name, the date of birth and the address are invented. So is this synthetic identity fraud or is it identity theft from a child? It is both, and which one your systems record it as depends entirely on which field they key on. If you key on the number you have one story; if you key on the name you have another.

The third blend is that account takeover and first-party fraud are indistinguishable in the data. A customer says “somebody else made these transactions”. Sometimes that is true. Sometimes the customer made them and regrets it. Sometimes the customer gave their credentials to a relative. The bank sees the same evidence in all three cases.

The honest version: the four categories are an analytic tool for choosing defences, not a natural classification of events. Real cases have components in more than one box, and the value of the framework lies in forcing you to ask which components you are actually defending against, not in producing a tidy label for each incident.

“Victimless” is wrong, twice#

You will hear synthetic identity fraud called victimless, on the grounds that no real person’s accounts were touched. This is wrong in two separate ways and it is worth separating them.

It is wrong first because there usually is a real person somewhere in the fabrication. The number at the centre of it is often a real number belonging to a real human: a child, a person who has died, a prisoner, a person with no fixed address. The Federal Reserve’s October 2019 paper is explicit that fraudsters deliberately choose the details of people unlikely to check their credit, precisely so that the fabrication is not disturbed. The harm to those people is real and delayed. A child whose number has been in use since they were six discovers it at eighteen, at exactly the moment they need credit for the first time, and finds a decade of defaults attached to a name that is not theirs. Untangling that is worse than untangling an ordinary theft, because the file has years of apparently legitimate history behind it.

It is wrong second because losses do not evaporate. When a lender writes off 41,300 dollars, that money is recovered from the price of credit for everybody else. Calling a loss victimless because it is diffuse is the same reasoning that would call shoplifting victimless.

The honest version of the credit freeze#

The plain version implied that if you freeze your credit you are safe. That is much too strong, and this is the most common practical misunderstanding in the whole subject.

The honest version: a freeze stops one thing. It prevents a credit bureau from disclosing your file to a lender who does not already have a relationship with you, which means an application in your name will usually fail at the point where the lender pulls the file. That is exactly the defence you want against new-account fraud, and it is genuinely strong.

It does nothing at all about account takeover. Your existing accounts are untouched by a freeze; the bank does not check your credit file to let you log in. It does nothing about synthetic identity fraud, because a synthetic is not you and has no file of yours to freeze. It does nothing about first-party fraud by definition. It does not cover the specialist databases used for telephone contracts, utility accounts, current-account openings and insurance unless you freeze those separately, and most people have never heard of them. And it does not apply retroactively to accounts already open.

So the freeze is the right tool for one of the four boxes, and it is close to useless for the other three. That is the pattern of this whole chapter in miniature.

First-party fraud: the dispute is real and both sides have a case#

The plain version presented first-party fraud as a difficulty. It is more than a difficulty; it is an open dispute in which serious people take opposite positions, and it is worth setting out fairly.

The lenders’ position is that intent is unobservable and that treating every default as potential fraud would be both wrong and cruel. Most people who fail to repay are not criminals; they lost a job, got ill, or misjudged. Building a fraud case on inference about somebody’s state of mind at the moment of application is exactly the sort of thing that produces false accusations against poor people. There is also a practical point: if you record fraud, you are making a serious allegation with serious consequences for the customer, and you need evidence you could defend.

The critics’ position, argued by fraud practitioners and by some regulators, is that lenders have a strong incentive to under-record it, and that the incentive is structural rather than dishonest. A loss classified as a credit loss is an ordinary cost of lending, absorbed by the credit-risk model. A loss classified as fraud goes into operational-loss reporting, may attract regulatory attention, may require customer reimbursement, and appears on a different line of the accounts. Experian, which sells detection for it, puts the point bluntly in its own material: first-party fraud is often miscategorized as credit loss and written off as bad debt, which masks true fraud exposure and distorts credit-risk forecasting. That is a vendor with an interest, but the mechanism it describes is real and is not disputed by the people on the other side.

There is a third party to the dispute, which is the customer, and the customer’s stake is enormous. In the United Kingdom, a lender that decides a case is first-party fraud may file a “misuse of facility” marker to the Cifas National Fraud Database, where it stays for six years and is visible to more than seven hundred member organizations. A person carrying such a marker may find it very hard to open a bank account. A wrong marker is a severe and lasting harm inflicted on the basis of an inference about intention.

The honest version: nobody has a principled test that separates fraudulent intent from misfortune at the moment of application, everybody’s classification is therefore partly a policy choice, and the incentives on that policy choice are not neutral.

The loss numbers do not add up, and should not#

The plain version quietly implied that there is a number for how much identity theft costs. There is not. There are several numbers, produced by different instruments, and combining them is a mistake made in almost every article on the subject. The Federal Trade Commission counts complaints. The Bureau of Justice Statistics counts survey recollections. The Financial Crimes Enforcement Network counts flagged suspicious flows, most of which involved no loss to anybody. Commercial studies count survey answers and scale them to the population. We give the figures with their sources in the technical half; the point here is simply that they range across an order of magnitude and that none of them is wrong.

The honest version: when you quote a fraud figure, quote the instrument and the year, and never add two instruments together.

Recovery is not one phone call#

The plain version said Diane’s problem is bounded and Walter’s is not. That is right in structure and understated in scale.

The most cited figure on recovery time is reassuring, and it is also a statistical artefact. The Bureau of Justice Statistics found that 55.8 per cent of identity theft victims in the United States in 2021 spent one day or less resolving the financial and credit problems arising from their most recent incident. But the same survey found that the most recent incident was misuse of an existing credit card for 30.5 per cent of victims and of an existing bank account for 23.7 per cent, while new-account fraud accounted for 3.2 per cent. Existing-account misuse is the easy case: one institution, one relationship, one reversal. The tail is where the misery is, and the tail is disproportionately made of new-account cases with an unknown number of counterparties.

The honest version: the median recovery is a day, the experience of the cases this chapter is really about is measured in months, and quoting the median as though it described identity theft in general is misleading.

The technical version#

A taxonomy precise enough to count with#

A taxonomy is only useful if two analysts given the same case put it in the same box. The following three questions, asked in this order, do that for almost every case.

Question one: at the moment of the fraud, did an account already exist in the relationship? If yes, it is takeover of something. If no, it is origination of something.

Question two: is there a real, living, identifiable natural person whose attributes were used? If yes, whose? If the attributes belong to a single real person and that person did not consent, it is third-party. If they belong to the person doing it, it is first-party. If the person is knowingly lending their attributes to somebody else, it is second-party. If the attributes are a mixture and no single real person corresponds to the combination, it is synthetic.

Question three: at the moment of application or transaction, was the intention to perform as promised? This question only matters for the first-party branch, and it is the one that cannot be answered from evidence available at the time.

Category Account Whose identity
Account takeover Existing Real, not consenting
New-account fraud New Real, not consenting
Synthetic identity New Fabricated composite
First-party fraud Either The perpetrator’s own
Second-party fraud New Real, consenting

The definitions in use by the main data sources map onto this, imperfectly, as follows. The Federal Reserve convened a cross-industry focus group of twelve fraud experts and published an industry-recommended definition in 2021: synthetic identity fraud is “the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain”. Note carefully what that definition is. It is a convention, adopted to make classification consistent across firms. The Federal Reserve states explicitly that it is not intended to create any regulatory or reporting requirement, to imply any liability for fraud loss, or to confer any legal status or legal rights. It is not a standard in the sense of a specification you can be audited against, and it is not a statutory definition anywhere.

Cifas, which operates the United Kingdom’s National Fraud Database, uses operational case types that cut the space differently: identity fraud, facility takeover, misuse of facility, false application, and, since 2025, a distinct money-mule filing reason. In Cifas terms, our four categories map to identity fraud (new-account, third-party), facility takeover (account takeover), and misuse of facility plus false application (first-party, split by whether the deceit was at application or afterwards). Synthetic identity fraud has no separate Cifas case type at all; it appears inside identity fraud under the filing reason “false identity”, which is one reason the United Kingdom has no good measurement of it.

The Federal Trade Commission’s Consumer Sentinel categories are different again, being organized by what the fraudster obtained: credit card, bank, loan or lease, government documents or benefits, employment or tax-related, phone or utilities, and other, each split into new and existing accounts.

Account takeover is a chain, and the useful discipline is to enumerate the links, because a control that breaks any one link stops the whole chain, and most organizations defend only the middle.

  credential source      second-factor defeat     monetization
  -----------------      --------------------     ------------
  breach corpus     ->   SMS OTP intercept   ->   change contact
  infostealer log   ->   real-time proxy     ->   suppress alerts
  phishing kit      ->   push fatigue        ->   add payee
  reused password   ->   helpdesk reset      ->   raise limits
  session cookie ---------- bypasses both -------> order card

Link one is credential acquisition. Three sources dominate. Credential corpora assembled from past breaches, which work only because people reuse passwords. Information-stealing malware on the user’s own machine, which harvests saved passwords and, importantly, session cookies. And phishing pages, which today are usually not static copies but reverse proxies that sit between the victim and the real site.

Link two is validation at scale, generally called credential stuffing: taking a list of email and password pairs and trying them against a target. The economics are brutal and simple. A success rate of one in a thousand is a good day, and one in a thousand is entirely sufficient when the list has ten million rows.

Link three is defeating the second factor, and this is where the design decisions of the last decade come home. A one-time code sent by text message can be defeated three ways: by intercepting the message through a SIM swap, by asking the victim for it on a page that looks like the bank, or by relaying it in real time. A reverse-proxy phishing kit does the last of these automatically: the victim types the code into the attacker’s page, the attacker’s server types it into the real bank within seconds, and the attacker receives a valid session. Push-approval prompts are defeated by repetition, sending approval requests until the victim taps to make them stop. Knowledge questions are defeated by looking up the answers, which are in the breach corpora.

The SIM swap path deserves its own paragraph because it is growing fast and because it converts a telecommunications weakness into a banking loss. The attacker persuades a mobile operator, or a shop assistant acting for one, to move the victim’s number to a new SIM. Every code then arrives at the attacker’s handset. Diane Okafor’s file, in our worked example, shows this exactly: her phone lost service at about eleven at night, and the transfers began forty minutes later. Cifas recorded a 38 per cent rise in unauthorized SIM swap filings in the United Kingdom in 2025, and in the first six months of 2026 the rise was 402 per cent, taking SIM swap from 2 per cent to 10 per cent of all account takeover filings. In the United States, the Federal Communications Commission adopted rules in Report and Order 23-95 requiring wireless providers to use secure authentication before performing SIM changes and number ports, with a compliance date of 8 July 2024.

Link four is the session, and it is the link most often forgotten. If an attacker obtains a valid session cookie - from an information stealer, or from a reverse proxy - then the login step has already happened and no authentication control of any kind is consulted again. This is why “we have multi-factor authentication” is an incomplete answer to account takeover. It protects the door. It says nothing about somebody who arrives holding a ticket already stamped.

Link five is monetization, and every serious attacker performs the same housekeeping first: change the contact details so alerts go elsewhere, disable notifications, and only then move money. Cifas reports that the leading filing reasons for account takeover in 2025 were unauthorized addition of a facility and unauthorized change of security or personal details, which is the housekeeping showing up in the statistics.

The sectoral shape of account takeover is not what most people expect. In the United Kingdom in 2025, Cifas recorded 78,387 account takeover cases, 18 per cent of all filings to the National Fraud Database and 6 per cent more than 2024, and the telecommunications sector accounted for 62 per cent of them, driven by mobile phone products. Banks are not the main target; the phone is, because the phone is the key to the bank.

New-account fraud: what an application actually asserts#

An application for credit makes two separate assertions, and firms routinely check one and assume the other.

The first assertion is identity: I am the person these attributes describe. The second is capacity and intent: this person can and will repay. Credit underwriting is very good at the second and historically weak at the first, because for decades the first was checked by matching the attributes against a credit bureau. Matching is not verifying. If the name, date of birth, address and national number on the application agree with the bureau’s record, the applicant has demonstrated knowledge of those four facts and nothing more. After two decades of breaches, knowledge of those four facts is not evidence of anything. Chapter 58 sets out where that data came from.

The practical consequences are visible in the sector data. In the United Kingdom in 2025 Cifas recorded 242,003 identity fraud cases, 54 per cent of all filings to the National Fraud Database, down 3 per cent on 2024. Plastic cards were the most affected sector at 36 per cent of all identity fraud, and within that, personal credit cards were 92 per cent of filings. The loans sector rose 49 per cent, an increase of 3,484 cases, driven largely by personal loans with deferred repayment, which is exactly the product shape a fraudster wants: money now, first payment far away. The leading filing reason was impersonation using the victim’s current address, up 12 per cent, which tells you that the attacker has enough data not to need a redirection.

There is a design lesson buried in that last figure. Address mismatch is the oldest new-account fraud signal there is, and the attackers have simply stopped triggering it. Walter Reese’s file has the wrong address, which is why it was caught; a better-resourced attacker would have used his real address and arranged interception, and the application would have passed.

Synthetic identity: construction and seasoning, with a ledger#

Building a fabricated person has four stages: assembling the parts, creating the file, seasoning the file, and the bust-out.

Assembling the parts means acquiring a national number, a name, a date of birth, an address, a telephone number and an email address, each with the right properties. The number is the constraint. In the United States, the Social Security Administration began assigning numbers randomly on 25 June 2011, which removed the geographic and chronological structure that the first five digits used to carry. Before randomization, a number implied a state and an approximate era of issue, and a mismatch between the number and the claimed date of birth was a cheap and effective check. After randomization that check stopped working, and the Federal Reserve’s July 2019 paper cites research finding that nearly 40 per cent of synthetic identities use randomized numbers. The same paper cites a finding by LexisNexis that the number of new identities first reported by a credit bureau rose by 800 per cent in 2015, after randomization began.

The number itself is obtained by using an unissued number, by using a real number belonging to somebody who will not check, or by buying what is marketed as a “credit privacy number” from a seller who claims it is a lawful alternative to a national number. It is not; in the great majority of cases it is a real number belonging to a child.

Creating the file is the step people underestimate. It is done by applying for something and being declined. The inquiry causes the bureau to open a record. From that moment the fabrication has a credit file, and a credit file is treated by the rest of the system as evidence that a person exists.

Seasoning is the long middle. Here is the ledger for Ellis Moray, our third file, constructed from the mechanisms the Federal Reserve documented and priced at plausible values. Every line is a real technique.

month  event                                 limit    cost
-----  ------------------------------------  -------  ------
  0    store card application, declined         0        0
  1    prepaid mobile plus mail-drop addr       0       95
  2    authorized-user tradeline purchased      0    1,200
  4    secured card, deposit 300              300      300
  9    retail store card approved             500        0
 14    unsecured card approved              1,500        0
 18    limit increases across three lines   6,800        0
 20    second bank current account opened       0        0
 22    fourth card approved                 9,500        0
 24    personal loan approved              12,000        0
 26    bust-out across all lines           41,300        0

Two features of that ledger matter more than the numbers. First, the total cost of construction is 1,595 dollars against an eventual take of 41,300 dollars, a return of about twenty-six to one, and the only scarce input is patience. Second, from month 4 to month 25 the file is a good customer. It pays on time. It is exactly what a credit risk model is designed to reward.

The 41,300 dollar figure in our example is deliberately set well above the industry benchmark, because our example is a mature operation. For the benchmark: the Federal Reserve’s July 2019 paper cites Auriemma Consulting Group’s finding that synthetic identity fraud cost United States lenders 6 billion dollars in 2016, that the average charge-off balance was 15,000 dollars, and that synthetics accounted for 20 per cent of credit losses that year.

The bust-out is coordinated because the credit reporting cycle is slow. Drawing down four lines on the same day means none of the four lenders sees the others’ losses before their own occurs.

There is a fifth stage that is less well known: credit washing. After the bust-out, the fabricated identity’s file is cleaned by disputing every derogatory entry as identity theft, so that the same fabrication can be reused. The Federal Reserve’s July 2020 paper identifies the 2017 simplification of the dispute process as an unintended enabler of exactly this.

Why victim-report detection has no chance against synthetics#

It is worth stating this as a general property of measurement systems rather than as a fact about fraud, because the general form makes the consequence obvious.

If a detection system’s input is the set of reports filed by individuals who believe a record misdescribes them, then the system can only detect events for which such an individual exists and has noticed. Synthetic identity fraud is defined by the absence of such an individual. Therefore the system’s recall against synthetic identity fraud is not low; it is structurally zero for as long as no real person is harmed in a way they can perceive.

Every consumer-facing control in this chapter has that input. The fraud alert requires you to assert that you may be a victim. The extended alert requires an identity theft report. The block under the United States Fair Credit Reporting Act requires you to identify the information and state that it is not yours. The Consumer Sentinel report requires you to report. All are excellent, and all are silent on Ellis Moray.

Three consequences follow, and all three are visible in real data.

The first is that published identity theft counts do not contain synthetics. When the Federal Trade Commission reports 1,135,291 identity theft reports in 2024, that number is a count of people who complained. Synthetics are not in it, not because the Commission is careless but because there is nobody to file.

The second is that the losses land in the wrong ledger. When the fabrication stops paying, the lender’s collections process runs, finds no one, and eventually writes the balance off as a bad debt. Unless the lender has a specific process to reclassify, the loss is recorded as credit risk. This is the accounting mirror image of the first-party fraud problem, and it means that a bank’s own fraud numbers systematically understate synthetic losses.

The third is that detection has to be population-level rather than case-level. You cannot find a synthetic by examining its file, because its file looks good. You find it by looking at the relationships between files: which files share an address, a device, a telephone number, an employer, a beneficiary account. A fabricated person is cheap to make but not free, so the same scarce components get reused, and reuse is visible in a graph and invisible in a row.

First-party fraud and the definitional dispute, with the money attached#

The categories inside first-party fraud are worth naming because they behave differently.

Chargeback abuse, often called friendly fraud, is a dispute of a genuine transaction. Goods-lost-in-transit claims assert non-delivery of delivered goods. Application misstatement is a false claim about income, employment, address or occupancy; in motor insurance the specific version where an experienced driver is named as the policyholder for a car actually driven by an inexperienced one is called fronting. Evasion of payment is taking a product with no intention to pay. Bust-out is the same shape as the synthetic bust-out but performed under a real identity. Credit washing is disputing genuine debts as fraud to clean a file.

The scale, as measured in the United Kingdom, is large and growing fast. Cifas recorded 106,497 misuse of facility cases in 2025, an increase of 43 per cent on 2024, making it the second largest case type after identity fraud. The bank account sector was 82 per cent of those filings. Payment fraud within misuse rose 239 per cent during 2025 and now accounts for 40 per cent of all misuse filings. Evasion of payment rose 22 per cent. Cifas also reports its own research finding a growing social acceptance of first-party fraud, with those aged 25 to 34 most likely to engage in it.

A widely quoted commercial figure holds that first-party fraud reached 36 per cent of all fraud globally, up from 15 per cent the year before, according to the LexisNexis Risk Solutions Cybercrime Report published in May 2025. Treat that as a marketing claim in the technical sense: it comes from a vendor’s proprietary network under a proprietary definition, and it is not comparable with any official statistic. The direction it reports is corroborated by Cifas; the magnitude is not independently checkable.

The dispute has now acquired real money in two jurisdictions, in opposite directions.

In the United States, the Consumer Financial Protection Bureau sued Early Warning Services, the operator of the Zelle network, together with JPMorgan Chase, Bank of America and Wells Fargo, in December 2024, alleging that customers had lost more than 870 million dollars to fraud on the platform over seven years. On 4 March 2025 the Bureau filed a notice voluntarily dismissing the action against all defendants with prejudice, and the court dismissed it on 5 March 2025. On 13 August 2025 the New York Attorney General filed a separate action against the operator alleging losses of more than 1 billion dollars.

In the United Kingdom the Payment Systems Regulator went the other way. From 7 October 2024, payment service providers have been required to reimburse victims of authorized push payment scams on Faster Payments, up to a maximum of 85,000 pounds per claim, normally within five business days, with the ability to stop the clock for further information provided a final decision is reached within 35 business days. Firms may apply an excess of up to 100 pounds, which may not be charged to vulnerable consumers, and consumers have 13 months from the payment to claim.

That mandate forces the classification. If a firm must reimburse a third-party scam but not a first-party fabrication, then every claim requires a determination of which it was, with money attached to the answer. The early evidence is sobering: UK Finance’s Annual Fraud Report 2026, published on 15 June 2026, shows authorized push payment losses in 2025 rising 19 per cent to 576.4 million pounds across 248,070 cases, with 354.3 million pounds - 61 per cent of losses - reimbursed. The reimbursement regime redistributed the loss. In its first full period it did not reduce it.

The loss figures, with instruments and years attached#

Here are the figures this chapter relies on, each with its source and the year it describes.

Source Year Headline
FTC Sentinel 2024 USD 12.5bn fraud losses
FTC testimony 2025 USD 15.9bn, 3m reports
FTC Sentinel 2024 1,135,291 ID theft reports
BJS survey 2021 23.9m victims, USD 16.4bn
FinCEN BSA analysis 2021 1.6m filings, USD 212bn
Auriemma via Fed 2016 USD 6bn synthetic, lenders
UK source Year Headline
UK Finance 2025 GBP 1.28bn payment fraud
UK Finance 2025 GBP 703.4m unauthorized
UK Finance 2025 GBP 576.4m APP scams
Cifas NFD 2025 444,993 cases filed
Cifas NFD 2025 242,003 identity fraud
Cifas NFD 2025 78,387 facility takeover

The United States identity theft report count has fallen for three consecutive years, and the shape of that fall is instructive.

Year ID theft reports Change
2020 1,247,309 -
2021 1,435,874 up 15%
2022 1,429,676 down 0.4%
2023 1,388,532 down 3%
2024 1,135,291 down 18%

Do not read that fall as a fall in identity theft. The 2020 and 2021 peaks were driven by pandemic unemployment benefit fraud, a specific and temporary opportunity, and its decline dominates the series. Over the same period, reported fraud losses rose from 12.5 billion dollars in 2024 to about 16 billion dollars in 2025, the highest on record and an increase of about 25 per cent, according to a Federal Trade Commission release of June 2026. Reports fell and money rose, which means the per-case severity rose sharply.

The reason these tables are split by country rather than combined is that the instruments differ. UK Finance counts confirmed losses reported by member banks. Cifas counts filings to a shared database by member organizations, which is a count of suspicions recorded, not of losses. The Federal Trade Commission counts consumer complaints, which are unverified by design; its own data book states this on the first page. Javelin counts survey answers scaled to the population. A single “global cost of identity theft” number built by adding these is arithmetic performed on incompatible units.

Detection signals: four families and what each one can actually see#

There are four families of signal, and the important discipline is to know which category each family detects, because teams routinely deploy the family that fits their vendor’s demo rather than the family that fits their losses.

Family Best against Blind to
Device Automated takeover Human farms
Behaviour Takeover, coached victim Patient operators
Velocity Bulk application fraud Slow synthetics
Graph Synthetic, organized rings Lone first-party

Device signals are attributes of the client: browser and operating system fingerprint, hardware characteristics, whether the device has been seen before on this account, how many accounts this device has touched, and whether the network path shows a residential proxy or a data centre. Device reputation shared across a consortium is far stronger than device reputation held by one firm. Device signals are excellent against credential stuffing and useless against a fraudster sitting at a clean laptop.

Behavioural signals are attributes of the interaction rather than the actor: typing cadence, pointer movement, how long the applicant dwells on each field, and above all whether personal data is typed or pasted. A real person types their own date of birth from memory, quickly, without correction. Somebody working from a list pastes it, or types it slowly with corrections. Behavioural signals are also the best available detector of a victim being coached through a payment by a criminal on the telephone, because a coached victim behaves differently from a person paying a bill.

Velocity signals are counts over time windows across a shared key. The keys that matter are the ones that are expensive for the fraudster to vary.

key                          window    threshold
---------------------------  --------  ----------
applications per device       24 h       3
applications per address      30 d       4
distinct names per national   ever       2
   identifier
distinct nationals per        ever       2
   name plus date of birth
accounts per beneficiary      7 d        5
file age under 24 months      n/a        applicant
   with claimed age over 30            age check

The last row of that table is the single cheapest synthetic detector in existence and it is still not universally deployed: a thirty-nine-year-old applicant whose credit file was created twenty-six months ago is either a recent immigrant, a person who has genuinely never borrowed, or a fabrication, and those three are separable with one further question.

Graph signals treat every application as a node and every shared attribute as an edge: address, telephone number, email root, device, employer, beneficiary account, internet address, and the national identifier itself. What you look for is not a single bad node but structure: the size of the connected component a node sits in, how tightly connected that component is, and the shortest path from this node to a node already known to be bad.

      addr:1147 Pell St
        /      |      \
   ELLIS    R. VANN   T. OYE      three "people"
     |         |         |        one address
   dev:a91   dev:a91   dev:c02    two devices
      \       /            \
       phone:+1-555-0143   phone:+1-555-0188
              |
        beneficiary acct 8831  <- also linked to
                                  nine other files

That picture is why graph analysis is the only family that reliably finds synthetics. A fabricated person is cheap but not free, and the components that cost real money - a controlled address, a device, a mule account to receive the proceeds - get reused. Reuse is invisible in a single row and glaring in a graph.

The Federal Reserve’s July 2020 paper makes the same point institutionally: it reports experts concluding that consortium data is better than organization-level data at detecting these trends, and describes a service provider that analyses account data across hundreds of financial institutions to find links to known synthetic accounts. It also reports a credit union whose machine learning tool flagged approximately 85 per cent of credit applications originating from synthetic identities in beta testing, against the same paper’s finding that traditional fraud models were ineffective at catching 85 to 95 per cent of likely synthetics. Treat the 85 per cent as a single case study, not as a benchmark.

Here is what a decision payload looks like when these families are combined. This is Kestrel Bank’s record for the Ellis Moray application at month 22, four months before the bust-out.

{
  "application_id": "KB-2024-0918-44127",
  "decision": "approve",
  "score": 41,
  "signals": {
    "device_seen_before": true,
    "device_distinct_accounts_90d": 3,
    "pii_fields_pasted": 4,
    "file_age_months": 22,
    "claimed_age_years": 39,
    "file_age_vs_age_flag": "AMBER",
    "authorized_user_tradelines": 1,
    "address_distinct_applicants_ever": 3,
    "graph_component_size": 11,
    "graph_hops_to_known_bad": 4
  },
  "suppressed_by": "thin_file_inclusion_policy"
}

Every signal needed to stop it was present. The score was 41 on a scale where 60 triggers review. The last field is the one that matters in practice: the bank had a policy of not penalizing thin files, adopted for the entirely good reason that thin files are also what recent immigrants and young adults have, and that policy suppressed the amber flag.

The base rate, and why good models get rejected#

Detection discussions collapse without the arithmetic, so here it is on our worked example.

Kestrel Bank receives 22,000 new credit applications a month. Assume, generously to the model, a synthetic prevalence of 0.3 per cent, so 66 of those 22,000 are fabrications and 21,934 are real. Assume a model that catches 90 per cent of synthetics and falsely flags 1 per cent of genuine applicants.

The model catches 59 synthetics. It also flags 219 genuine applicants. Of 278 flagged cases, 59 are right: a precision of 21 per cent. Four out of every five people the model accuses are innocent.

Quantity Value
Applications per month 22,000
Synthetics at 0.3% 66
Caught at 90% recall 59
Genuine flagged at 1% 219
Precision 21%

This is not a bad model. A 90 per cent recall against synthetic identity fraud would be an outstanding model. The arithmetic is a property of the base rate, not of the model, and it is why every real deployment has a manual review queue and why the size of that queue, not the accuracy of the model, is usually what decides whether the project survives. At 278 flags a month and twenty minutes per review, that queue is 93 hours of analyst time, which is about two-thirds of one full-time person. That is affordable. Halve the threshold to catch more and the queue quadruples, and it is not.

Freezes, alerts and their equivalents by jurisdiction#

The consumer-side controls differ substantially by country, and the names do not travel.

In the United States, the relevant provisions are in the Fair Credit Reporting Act. Fraud alerts and active duty alerts are at 15 U.S.C. 1681c-1, generally cited as FCRA section 605A. An initial fraud alert lasts not less than one year; before the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018 it lasted 90 days, and the extension took effect on 21 September 2018. An extended fraud alert lasts seven years and requires an identity theft report. An active duty alert lasts not less than twelve months. A national security freeze is at 15 U.S.C. 1681c-1(i): it is free, it must be placed within one business day of a request made by toll-free telephone or secure electronic means and within three business days of a request by post, and it must be removed within one hour of an electronic or telephone request and within three business days of a postal one. Blocking of information resulting from identity theft is at 15 U.S.C. 1681c-2, FCRA section 605B: on receipt of proof of identity, a copy of an identity theft report, identification of the information and a statement that it is not the consumer’s, the agency must block within four business days. The block may be declined or rescinded if it was requested in error, was based on a material misrepresentation, or if the consumer obtained goods, services or money from the transaction.

The freeze was a state innovation before it was federal. California Senate Bill 168, chaptered on 11 October 2001, required credit reporting agencies to place a security freeze from 1 January 2003, the first such law in the United States. Other states followed one at a time over the next fifteen years, with a patchwork of fees, until the 2018 federal act preempted them and made freezes free everywhere from 21 September 2018.

Three American controls sit outside the credit bureaus and are routinely forgotten. The Internal Revenue Service issues an Identity Protection PIN, a six-digit number valid for one calendar year that must appear on a tax return, which defeats refund fraud; it is opt-in. The specialist consumer reporting agencies - for cheque-account openings, telecommunications and utilities, insurance claims and employment screening - each hold separate files and each must be frozen separately. And free weekly credit reports from the three nationwide agencies, introduced as a temporary pandemic measure, were made permanent, as the Federal Trade Commission confirmed in a consumer alert of 13 October 2023.

The United Kingdom has no credit freeze. It has two different instruments. Cifas Protective Registration places a warning flag against a person’s details in the National Fraud Database; it costs 30 pounds for two years and it does not block anything, it obliges member organizations to carry out extra checks, which means genuine applications are slower. A Notice of Correction is a short statement the person adds to their file at each credit reference agency. Reports go to Action Fraud. A Cifas marker recorded against a person, including a misuse of facility marker, is retained for six years, and a person can find out what is held by making a subject access request to Cifas, must take a dispute first to the organization that filed it, and can then ask Cifas for an independent review.

India has no credit freeze either, and its equivalents are spread across three authorities. The Unique Identification Authority of India allows an Aadhaar number holder to lock the number itself, so that no authentication can be performed with it, and to unlock it later using a Virtual ID; there is a separate biometric lock. The Virtual ID mechanism also allows the number to be withheld from a service that only needs verification. The Department of Telecommunications operates the Sanchar Saathi portal, whose TAFCOP facility lets a person see every mobile connection issued against their identity documents and report the ones they did not take, which is the single most useful control against the SIM swap chain described earlier. And the Reserve Bank of India’s circular of 6 July 2017 on limiting the liability of customers in unauthorized electronic banking transactions gives the customer zero liability where the loss arises from a third-party breach and is reported within three working days, a limited and capped liability where it is reported within four to seven working days, and requires the bank to credit the reversed amount within ten working days.

Country Blocking tool Duration
United States Security freeze Until lifted
United States Initial fraud alert 1 year
United States Extended fraud alert 7 years
United Kingdom Protective Registration 2 years
India Aadhaar lock Until unlocked
India TAFCOP disconnection Permanent

The pattern across the three is that the United States has the strongest tool against new-account fraud and no tool against the others; the United Kingdom has a weaker tool against new-account fraud and better shared intelligence; and India has the best tool against the telecommunications link in the takeover chain and nothing at all against credit applications. None of the three has any consumer-side control that touches synthetic identity fraud, because there is no consumer to operate it.

Remediation: the sequence, the clocks and the real duration#

Here is Walter Reese’s remediation, in order, with the statutory clock beside each step and the realistic elapsed time.

day  action                            clock      real
---  --------------------------------  ---------  -----
  0  report to the FTC, obtain the     immediate  1 h
     identity theft report
  0  initial fraud alert at one        1 year     15 min
     bureau; it notifies the other two
  1  security freeze at all three      1 bus day  1 h
  2  pull all three credit reports     free       2 h
  3  freeze specialist agencies:       varies     3 h
     cheque, telecom, insurance
  4  dispute and block each account    4 bus days 30 min
     under FCRA 605B                              each
  7  police report where a creditor    varies     2 h
     insists on one
 12  IRS identity protection PIN       1 year     30 min
 30  FCRA reinvestigation deadline     30 days    -
 45  first debt collector appears on   -          repeat
     an account nobody told him about            steps
 90  second unknown account found      -          repeat
     via a new credit report                     steps

Total hands-on time in this reconstruction is roughly eleven hours. Total elapsed time is at least ninety days and open-ended, and the reason is entirely contained in the last two rows: the clocks are short and the discovery is unbounded. Everything with a legal deadline finishes quickly. Everything that depends on finding out what exists does not finish at all, it merely stops producing surprises.

The published averages support this shape. The Bureau of Justice Statistics found for 2021 that 55.8 per cent of victims resolved matters in one day or less and 18.6 per cent in two to seven days, with 1.0 per cent taking six months or more; and about 10 per cent reported severe emotional distress. Javelin’s 2026 study, published on 21 April 2026, reported that account takeover victims spent an average of about 17.8 hours resolving the fraud.

Duration Share of victims
1 day or less 55.8%
2 to 7 days 18.6%
8 days to 1 month 15.0%
1 to 3 months 7.0%
3 to 6 months 1.9%
6 months or more 1.0%

There is one more thing a victim must be told, and it is rarely in the official guidance. The single highest-value action is not any of the steps above. It is to secure the email account and the telephone number first, before anything else, because both are recovery channels for everything else. Freezing your credit while an attacker still controls your email is closing the second door.

Design changes, ranked by the evidence behind them#

This is the section that the thesis of the chapter demands: which changes actually reduce which category, ranked honestly by evidence rather than by enthusiasm.

The strongest evidence in the whole of identity engineering attaches to phishing-resistant authenticators against account takeover. Google required physical security keys for all staff from early 2017, and reported in July 2018 that it had had no reported or confirmed account takeovers among its more than 85,000 employees since. A study by Google with New York University and the University of California, San Diego, published in May 2019, measured the effect on ordinary consumer accounts: an on-device prompt blocked 100 per cent of automated bots, 99 per cent of bulk phishing attacks and 90 per cent of targeted attacks, while a code sent by text message blocked 100 per cent of automated bots, 96 per cent of bulk phishing and 76 per cent of targeted attacks. Security keys blocked all three categories completely. That is measured, at scale, with a control group, and nothing else in this chapter has evidence of that quality.

Second, removing the telephone number as an account recovery channel. The mechanism is beyond dispute, since the number is the weak link in the chain drawn earlier. The evidence that regulation of the carriers fixes it is weaker: the Federal Communications Commission’s rules took effect on 8 July 2024, and Cifas nevertheless recorded a 402 per cent rise in unauthorized SIM swap filings in the first half of 2026. Either the rules are not yet working, or attacker volume rose faster than the control, and the published data cannot distinguish those.

Third, verifying the national identifier at its source rather than against a bureau. In the United States this is the electronic Consent Based Social Security Number Verification service, authorized by the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018, announced for an initial enrolment period in a Federal Register notice of 7 June 2019, rolled out to a limited set of users from June 2020, with open enrolment for permitted entities beginning on 21 February 2022. It answers one question - do this name, number and date of birth match the Administration’s record - which is precisely the question that defeats a fabricated composite. Its limitations are set out in the Federal Reserve’s own July 2020 paper: it is restricted to permitted entities, applies to new account validation rather than existing accounts, and is not a continuously available service.

Fourth, consortium graph analysis for synthetic and organized fraud. The mechanism is sound and explained above. The evidence is case-study evidence: the Federal Reserve’s July 2020 paper reporting consortium data as better than single-firm data, and one credit union’s beta result of approximately 85 per cent of synthetic applications flagged. There is no controlled published comparison.

Fifth, universal free credit freezes against new-account fraud. The mechanism is close to airtight within its scope. The evidence of population effect is weak because uptake is not systematically published and because the tool is useless against the other three categories.

Sixth, step-up verification on the account-change events rather than on the login. Requiring a fresh, phishing-resistant confirmation before a contact detail change, a payee addition or a limit increase, and imposing a delay before new payees can be used at full value, attacks link five of the takeover chain rather than link three. This is a design convention in mature banks rather than a standard, and it is not measured publicly, but it is the change that would have stopped Diane Okafor’s loss even after her SIM was swapped.

Seventh, reimbursement mandates that move the loss to the party best placed to prevent it. The United Kingdom’s requirement from 7 October 2024 is the clearest natural experiment anywhere. The result after its first substantial period is that authorized push payment losses rose 19 per cent in 2025 to 576.4 million pounds while 61 per cent of losses were reimbursed. The mandate demonstrably changed who bore the loss; it has not yet demonstrably changed the loss.

Eighth, and last because it is a removal rather than an addition, abandoning knowledge-based verification as evidence of identity. Asking an applicant which of four streets they have lived on tests possession of data that is in every breach corpus. The current United States guidance, NIST Special Publication 800-63 revision 4, published on 31 July 2025 and superseding revision 3 from 1 August 2025, treats identity proofing as a matter of validating and verifying evidence rather than of quizzing the applicant. [UNVERIFIED: the exact section of NIST SP 800-63A-4 that restricts knowledge-based verification]

Change Category reduced Evidence
Phishing-resistant keys Takeover Measured
Remove phone recovery Takeover Mechanism
Verify number at source New account, synthetic Mechanism
Consortium graph Synthetic, rings Case study
Credit freeze New account Mechanism
Step-up on changes Takeover Convention
Reimbursement mandate Reallocates loss Measured null
Drop knowledge questions New account Standard

The law, briefly, and what it can and cannot reach#

Criminal law arrived late and unevenly. In the United States, the Identity Theft and Assumption Deterrence Act, Public Law 105-318, enacted on 30 October 1998, added paragraph (a)(7) to 18 U.S.C. 1028 and made it a federal offence to transfer or use another person’s means of identification without lawful authority. The Identity Theft Penalty Enhancement Act, Public Law 108-275, enacted on 15 July 2004, added 18 U.S.C. 1028A, aggravated identity theft, carrying a mandatory two-year sentence to be served consecutively to the underlying offence.

Section 1028A was applied very broadly for nearly two decades, until the Supreme Court narrowed it in Dubin v. United States, decided on 8 June 2023. The Court held that a defendant “uses” another person’s means of identification in relation to a predicate offence only when that use is at the crux of what makes the conduct criminal, rather than an ancillary feature of a billing method. The practical effect is that ordinary fraud which happens to involve somebody’s name on an invoice is no longer automatically aggravated identity theft. Prosecutors must now show that the identity was, in the Court’s phrase, a key mover in the criminality.

In the United Kingdom there is no offence called identity theft. The conduct is prosecuted under the Fraud Act 2006, principally section 2, fraud by false representation, with unauthorized access to an account falling under the Computer Misuse Act 1990. In India, section 66C of the Information Technology Act 2000 creates an offence of identity theft and section 66D an offence of cheating by personation using a computer resource, alongside the general offences of cheating and cheating by personation, at sections 318 and 319 of the Bharatiya Nyaya Sanhita 2023.

Note the structural gap that all three share. Every one of these offences requires a victim whose identity was used. A purely fabricated identity, assembled from an unissued number and invented attributes, is prosecuted as ordinary fraud against the lender, if at all. The law of identity theft, like the consumer protections, is built around a person who was impersonated.

What we do not know#

Honesty requires a list of the things this chapter cannot tell you.

No jurisdiction counts synthetic identity fraud. The Federal Reserve’s definition is a voluntary convention with no reporting obligation attached, and it says so. Every published estimate of the scale of the problem descends from a small number of vendor studies, several of them now a decade old; the 6 billion dollar figure that circulates most widely describes 2016.

Nobody knows what share of charged-off consumer credit is actually fraud, because the first-party and synthetic categories both push losses into the credit-loss line and no supervisor requires a reconciliation. Nobody knows how much new-account fraud freezes prevent, because there is no published series showing what proportion of the eligible population has one in place. Detection model performance is not comparable across firms, because prevalence differs, definitions differ, and no firm publishes its base rate. And the relationship between reimbursement mandates and loss levels is unresolved after a single reporting period, which is not enough data to conclude anything at all.

57.98 Common wrong ideas#

Wrong: Identity theft is one crime, so one product can protect you from it. Right: It is at least four distinct crimes with different perpetrators, different money flows and different remedies, and the protections are mostly not interchangeable; a credit freeze is close to airtight against new-account fraud, does nothing about account takeover, and cannot touch synthetic identity fraud at all.

Wrong: Freezing your credit protects your existing accounts. Right: A freeze stops a credit reporting agency disclosing your file to a lender who does not already have a relationship with you, which blocks new applications; your existing accounts are not consulted through the credit file, so a freeze has no effect on somebody logging into the bank you already use.

Wrong: Synthetic identity fraud is victimless because no real person’s accounts are touched. Right: The national identifier at the centre of the fabrication usually belongs to a real person chosen precisely because they will not check - a child, a person who has died, a prisoner - and that person discovers a decade of defaults at the moment they first need credit; the written-off balances are recovered from everyone else through the price of borrowing.

Wrong: Multi-factor authentication stops account takeover. Right: It raises the cost of one link in a five-link chain, and the common defeats are already deployed at scale: a one-time code can be intercepted by a SIM swap or relayed in real time by a reverse-proxy phishing page, a push prompt can be defeated by repetition, and a stolen session cookie bypasses authentication entirely because the login already happened.

Wrong: If you have not been notified, nothing has happened in your name. Right: Notification depends on a lender knowing where to reach you, and an application made in your name at a different address, or a fabricated identity built on your identifier, generates no letter to you at all; the only reliable check is reading your own credit file at every agency, which in the United States is free every week from each of the three nationwide agencies.

Wrong: First-party fraud is not really fraud, just people who could not pay. Right: Obtaining goods or credit with no intention of performing is a fraud in every jurisdiction discussed here, and the genuinely hard part is not the principle but the proof, because intention at the moment of application cannot be observed and lenders have an accounting incentive to record the loss as a bad debt rather than as fraud.

Wrong: The total cost of identity theft is a known figure you can look up. Right: There are several figures produced by incompatible instruments - complaint counts, bank loss returns, database filings, household surveys and vendor extrapolations - measuring different populations over different periods, so any single global number is an artefact of adding units that do not add.

Wrong: A fraud detection model with 90 per cent accuracy is ready to deploy. Right: At a base rate of three synthetics per thousand applications, a model catching 90 per cent of them while falsely flagging one per cent of genuine applicants produces four wrong accusations for every right one, and the operational question is not the model’s accuracy but whether the review queue it generates can be staffed.

Wrong: The first thing a victim should do is freeze their credit. Right: The first thing is to regain sole control of the email account and the telephone number, because both are recovery channels for everything else, and freezing the credit file while an attacker still receives your password resets and your one-time codes secures the wrong door.

Wrong: Regulation that forces banks to reimburse victims will reduce fraud. Right: It reliably reallocates the loss, which is a legitimate policy aim in itself, but the first substantial measurement of the United Kingdom’s mandatory reimbursement requirement showed authorized push payment losses rising 19 per cent in 2025 while 61 per cent of losses were reimbursed, so the effect on the amount stolen is unproven.

57.99 Chapter summary in 20 lines#

  1. Identity theft is not one crime but at least four - account takeover, new-account fraud, synthetic identity fraud and first-party fraud - and the defences for each are different and mostly not interchangeable.
  2. Three questions separate them: did an account already exist, whose attributes were used, and was there an intention to perform.
  3. Account takeover is a five-link chain running from credential acquisition through second-factor defeat and session theft to the housekeeping that hides the theft, and breaking any single link stops it.
  4. Cifas recorded 78,387 facility takeover cases in the United Kingdom in 2025, 18 per cent of all filings to the National Fraud Database, with the telecommunications sector accounting for 62 per cent of them.
  5. New-account fraud succeeds because matching an applicant’s details against a credit bureau tests knowledge of those details rather than possession of the identity, and that knowledge has been in circulation since the large breaches of the 2010s.
  6. Synthetic identity fraud fabricates a composite person, and the Federal Reserve’s industry focus group defined it in 2021 as the use of a combination of personal information to fabricate a person or entity for dishonest gain, a convention that carries no legal status.
  7. A fabricated identity acquires a credit file by being declined for something, because the enquiry causes a bureau to create a record, after which the record itself is treated as evidence that the person exists.
  8. Seasoning is done with purchased authorized-user tradelines, secured cards and two years of small on-time payments, and the Federal Reserve’s July 2019 paper cites research that nearly half of synthetic identities use the tradeline technique.
  9. Randomization of United States Social Security number assignment from 25 June 2011 removed the geographic and chronological structure that had made number-to-birthdate checks cheap and effective.
  10. Every consumer-facing protection is triggered by a person noticing that a record misdescribes them, so all of them have structurally no chance against a fabrication that describes nobody.
  11. Synthetic losses therefore land in the credit-loss ledger rather than the fraud ledger, which means a firm’s own fraud figures systematically understate them.
  12. First-party fraud is disputed because intention at the moment of application cannot be observed, and because classifying a loss as credit risk rather than as fraud is cheaper for the lender in reporting terms.
  13. Cifas recorded 106,497 misuse of facility cases in 2025, up 43 per cent on 2024, with payment fraud within that category up 239 per cent.
  14. Loss figures from the Federal Trade Commission, UK Finance, Cifas, the Bureau of Justice Statistics and commercial surveys measure different things and must never be added together.
  15. There are four families of detection signal - device, behaviour, velocity and graph - and only graph analysis over shared attributes reliably finds fabricated identities, because reuse of scarce components is invisible in a row and glaring in a network.
  16. At a realistic base rate a strong model produces about four false accusations per true one, so the size of the manual review queue, not the accuracy of the model, decides whether a detection programme survives.
  17. In the United States a security freeze must be placed within one business day of an electronic request and lifted within one hour, and an identity theft block under the Fair Credit Reporting Act must take effect within four business days.
  18. The United Kingdom has no freeze and instead offers Cifas Protective Registration at 30 pounds for two years, while India offers Aadhaar locking and the Sanchar Saathi portal for finding mobile connections issued in your name.
  19. Victim remediation has short statutory clocks and unbounded discovery, so the elapsed time is governed by how long it takes to find every account rather than by how long each removal takes.
  20. The only design change in this chapter with measured, controlled, large-scale evidence behind it is the phishing-resistant security key, which Google reported eliminated confirmed account takeovers among its 85,000 staff after early 2017 and which blocked every category of attack in the 2019 study it published with New York University and the University of California, San Diego.

Chapter sources: Federal Reserve, “Synthetic Identity Fraud in the U.S. Payment System: A Review of Causes and Contributing Factors”, July 2019, and “Detecting Synthetic Identity Fraud in the U.S. Payment System”, October 2019, and “Mitigating Synthetic Identity Fraud in the U.S. Payment System”, July 2020, together with the industry focus group definition of synthetic identity fraud published in 2021 and the Synthetic Identity Fraud Mitigation Toolkit released in early 2022; Federal Trade Commission, Consumer Sentinel Network Data Book 2024, published March 2025, and the Commission’s testimony to the Joint Economic Committee of 25 March 2026 and its press releases of 27 April 2026 and June 2026 on 2025 loss totals; Bureau of Justice Statistics, “Victims of Identity Theft, 2021”, published October 2023; Financial Crimes Enforcement Network, Financial Trend Analysis on identity-related suspicious activity in Bank Secrecy Act reports for calendar year 2021, published January 2024; UK Finance, Annual Fraud Report 2026, published 15 June 2026, covering calendar year 2025; Cifas, Fraudscape 2026 covering calendar year 2025 and the Fraudscape 2026 six-month update covering January to June 2026; Javelin Strategy and Research, “2026 Identity Fraud Study: The Illusion of Progress”, published 21 April 2026, surveying 5,010 United States adults between 10 November and 3 December 2025; Fair Credit Reporting Act sections 605A and 605B, codified at 15 U.S.C. 1681c-1 and 1681c-2, as amended by the Economic Growth, Regulatory Relief, and Consumer Protection Act of 2018, Public Law 115-174, effective 21 September 2018; California Senate Bill 168, chaptered 11 October 2001, security freeze effective 1 January 2003; Identity Theft and Assumption Deterrence Act, Public Law 105-318, 30 October 1998, 112 Stat. 3007; Identity Theft Penalty Enhancement Act, Public Law 108-275, 15 July 2004, 118 Stat. 831, creating 18 U.S.C. 1028A; Dubin v. United States, decided 8 June 2023; Social Security Administration, randomization of number assignment from 25 June 2011 and the electronic Consent Based Social Security Number Verification service, Federal Register notice of 7 June 2019, limited rollout June 2020, open enrolment for permitted entities from 21 February 2022; Federal Communications Commission Report and Order 23-95 on SIM swap and port-out fraud, compliance date 8 July 2024; Payment Systems Regulator policy statement PS24/7 and the Faster Payments reimbursement requirement in force from 7 October 2024 with a maximum of 85,000 pounds; Consumer Financial Protection Bureau action against Early Warning Services, Bank of America, JPMorgan Chase and Wells Fargo filed December 2024 and dismissed with prejudice on 5 March 2025, and the New York Attorney General’s action of 13 August 2025; Reserve Bank of India circular of 6 July 2017 on limiting the liability of customers in unauthorised electronic banking transactions; Unique Identification Authority of India guidance on Aadhaar lock and unlock and Virtual ID; Department of Telecommunications Sanchar Saathi TAFCOP facility; Information Technology Act 2000 sections 66C and 66D and Bharatiya Nyaya Sanhita 2023 sections 318 and 319; Fraud Act 2006 section 2 and Computer Misuse Act 1990; NIST Special Publication 800-63 revision 4, published 31 July 2025, superseding revision 3 on 1 August 2025; Google Online Security Blog, “New research: How effective is basic account hygiene at preventing hijacking”, May 2019, and the July 2018 reporting of Google’s internal security key deployment; LexisNexis Risk Solutions Cybercrime Report of May 2025, cited as a vendor figure; Federal Trade Commission consumer alert of 13 October 2023 on permanent free weekly credit reports.