Understanding and Combating Synthetic Identity Fraud in Business
IN THIS ARTICLE
Table of Contents
Like it? Share it
Synthetic identity fraud involves the piecing together of genuine personal information and fake details to form a brand new identity, which fraudsters then use to access a business’ private information or financial accounts.
AI plays a huge role in preventing synthetic identity fraud, as do image history searches, data matching and information monitoring. Platforms like Trustpair work to prevent businesses from falling victim to payment fraudsters by detecting discrepancies in real time, and monitoring changes to the data that could indicate higher risk.
Learn how to safeguard company funds by preventing synthetic identity fraud. Book a demo to learn more!
Key Takeaways
Synthetic identity fraud combines real stolen data (such as National Insurance numbers) with fabricated details to create a new, entirely fictional identity.
It is one of the fastest-growing financial crimes globally: estimated losses reach £16–£32 billion per year worldwide, with US lenders alone facing $3.3 billion in exposure in H1 2025 (BIIA, 2026).
95% of synthetic identities pass standard verification checks, making them nearly invisible to legacy fraud detection systems (Thomson Reuters).
In a B2B context, synthetic identities are used to infiltrate procurement cycles, submit fake invoices, and divert supplier payments — often going undetected for months.
The Economic Crime and Corporate Transparency Act 2023 introduced mandatory identity verification for company directors at Companies House, directly targeting manufactured business identities.
The best defence is automated, continuous account validation that cross-references supplier details against external databases before every payment.
Trustpair has blocked 100% of payment fraud attempts for its customers since deployment.
What is synthetic identity fraud?
Synthetic identity fraud is a sophisticated financial crime in which fraudsters blend legitimate stolen data — such as National Insurance (NI) numbers or Companies House registration details — with fabricated information to construct entirely new, functional personas. This allows them to bypass traditional verification protocols and infiltrate corporate systems under the guise of legitimate entities.
For businesses, this poses a critical risk in the form of invoice fraud, where fraudulent suppliers intercept the payment chain or submit billing for unrendered services. These fabricated identities are systematically cultivated to build credibility, sometimes over months, before being used to exploit procurement vulnerabilities and then abandoned.
What makes synthetic identity fraud so dangerous is its invisibility: 95% of synthetic identities pass standard verification checks (Thomson Reuters), and since no single real individual is fully victimised, traditional red-flag systems rarely trigger.
How are synthetic identities created?
Here’s the step-by-step of synthetic identity creation:
The fraudster obtains one piece of real information — usually a National Insurance number or a legitimate company registration — typically purchased on the dark web or harvested from a data breach
They combine the real identifier with fabricated data: a false name, date of birth, address, and in a B2B context, fake director details or a cloned Companies House filing
They build a credibility profile for the identity over time, opening accounts, establishing trade references, and making legitimate payments to build trust with financial institutions and suppliers. The longer the fraudster “incubates” the identity, the more credible it appears
Once a sufficient credit or trade history is established, the fraudster exploits all available lines of credit or diverts supplier payments in one go, then immediately abandons the identity
The process is repeated — often across multiple synthetic identities simultaneously
There are two types of synthetic identities:
Manipulated
A genuine identity where only one or two items of information have been altered
Example: a sole trader falsifies their credit history to access better financing terms or extend a supplier payment period
Manufactured
A completely fake identity where none of the data corresponds to a real individual
Example: a fraudster registers a shell company at Companies House with fabricated director details and uses it to raise fraudulent invoices against real businesses
What are the key indicators of synthetic identity fraud?
One of the most challenging aspects of synthetic identity fraud is that attackers often incubate their identities and wait until the right moment to strike. In 2025, synthetic identities were implicated in 21% of first-party frauds detected across financial institutions (BIIA, 2026).
Key indicators to watch for:
Digital identity mismatch — physical details look clean but IP location, device fingerprint, or login behaviour do not align
Complaints from real customers or suppliers — a manipulated identity based on a real person may trigger alerts from the genuine victim
Lack of credit or trading history — a very thin or unusually short history for a supposedly established business or individual
Multiple accounts sharing the same contact details — same phone number or email address appearing across different identities
High-risk IP metadata — access requests originating from flagged or mismatched geographies
Inconsistencies with Companies House records — registered address, director names, or incorporation dates that do not match what the supplier has provided
Digital identity mismatch
While the physical data may not be suspicious, always use additional verification methods to validate the identity of customers and suppliers.
By applying detective controls such as assessing digital identity factors like IP address, you can determine whether an individual is contacting you from where their physical address indicates. Two-factor authentication adds a further layer: sending a text message to the associated phone number verifies both that a real person exists and that the number belongs to the right identity.
Where these factors do not align with the details provided or verified through an external database, the case warrants escalation to your fraud team.
Complaints from real customers or suppliers
Cyber fraudsters often spend weeks or months building a synthetic identity’s credibility before striking — but this creates one key vulnerability for manipulated identities. Since these are based on real people, there is a chance the genuine victim notices unusual activity and files a report, which can trigger an investigation, identify the synthetic identity, and allow the fraudster to be blocked.
How can your business detect and prevent synthetic identity fraud?
Do all the details match verified, publicly available records?
To answer these questions reliably, many companies rely on technology like Trustpair’s vendor database monitoring, which:
Collects the data that suppliers provide and compares it against trusted external sources, including Companies House and international registries
Grades each supplier as favourable or unfavourable based on real-time risk signals
Spots duplicate entries, errors, or missing data and flags these for review
Automatically blocks payments to fraudulent suppliers using customisable AI rules
Given that 67% of financial institutions saw fraud rates climb in 2025 (BIIA, 2026), manual supplier vetting processes are no longer sufficient. Automated, continuous validation is now the operational standard for UK finance teams.
How is AI used to detect and prevent synthetic identity fraud?
AI is almost always used by fraudsters to build convincing profiles at scale — often managing multiple synthetic identities simultaneously. But AI is also the most effective counter-measure available.
Generative AI can combine biological and behavioural biometrics to combat synthetic identity fraud, checking how many applications have been submitted per device, for example. It can cross-reference ID photos against known duplicate identities in real time. AI can also conduct Know Your Customer (KYC) and Know Your Business (KYB) checks on an ongoing basis — not just at onboarding.
Under the Economic Crime and Corporate Transparency Act 2023, large UK organisations are now subject to a new corporate offence of “failure to prevent fraud” (effective September 2025). This means businesses must implement reasonable procedures to prevent fraud by associated persons — making automated identity verification not just best practice, but a legal risk consideration.
As AI-generated fraud becomes more scalable and harder to detect manually, automated account validation is no longer optional for UK finance teams. It is the only reliable way to catch synthetic identities before payments leave the business.
To conclude
Synthetic identity fraud occurs when criminals combine real and fabricated information to impersonate customers or suppliers and infiltrate payment workflows. With fraud now accounting for 45% of all crime in England and Wales, and the new corporate “failure to prevent fraud” offence in force since September 2025, UK businesses face growing legal and financial pressure to strengthen their controls. Automated tools like Trustpair’s vendor monitoring platform provide the continuous oversight needed to detect synthetic identities before they cause harm.
Browse through our different sections and find the answer to your question.
How to detect synthetic identity theft?
Detecting synthetic identity theft requires cross-referencing all provided details against external, verified databases — not just checking them internally. Key signals include digital identity mismatches (IP address or device inconsistencies), multiple accounts sharing the same contact details, unusually thin trading or credit histories, and discrepancies with Companies House records for business identities. Automated platforms like Trustpair continuously validate supplier and vendor identities in real time, flagging discrepancies before any payment is released — the most reliable way to catch synthetic identities before they cause financial harm.
How to report synthetic identity theft?
If your business identifies a synthetic identity in your supplier or vendor base, report it to Action Fraud (the UK’s national fraud reporting centre) at actionfraud.police.uk or by calling 0300 123 2040. Notify your bank or financial institution immediately to freeze any affected accounts and prevent further losses. If the fraud involves a fake company registration, report it to Companies House via their report-fraud service. Document all evidence, emails, invoices, account details, transaction records, before making any report. Prompt action significantly increases the likelihood of stopping the fraud and recovering funds.
What are three types of identity theft?
The three main types of identity theft are: (1) Synthetic identity theft, blending real stolen data (such as a National Insurance number) with fabricated details to create an entirely new, fictional identity; (2) Account takeover (ATO), using stolen credentials to seize control of an existing legitimate account; (3) True name identity theft, fully impersonating a real person using their stolen PII to open new accounts, take out credit, or commit fraud in their name. In a B2B context, synthetic identity theft is the most dangerous because it bypasses standard verification checks and can go undetected for months.