Executive Summary
In 2024, US financial institutions, particularly those in the automotive lending sector, experienced a significant surge in synthetic identity fraud, resulting in estimated damages of $3.3 billion. Cybercriminals leveraged data amassed from previous breaches to construct convincing synthetic profiles used to obtain loans and open accounts, often nurturing these fraudulent identities with legitimate activity to evade detection. Both individual and business identities were targeted, with institutions facing growing pressure to enhance detection capabilities amid an ongoing arms race with sophisticated attackers employing AI and cloud tools.
This increase in synthetic identity fraud reflects an evolving threat landscape, where attackers capitalize on remote-first processes and richer data sources to outpace traditional defenses. The accelerating adoption of digital banking and lending has heightened urgency for adaptive, real-time security controls and improved identity verification as financial firms confront complex, persistent fraud schemes.
Why This Matters Now
Synthetic identity fraud is rapidly accelerating, causing billions in losses and exploiting gaps in digital onboarding and identity validation processes. Financial firms must urgently invest in advanced risk models and deeper data analytics to keep pace with attackers leveraging AI and massive breached datasets.
Attack Path Analysis
Attackers initiated synthetic identity fraud campaigns, leveraging stolen and fabricated personal and business data to compromise finance and lending organizations via online application portals. By evading initial detection and exploiting gaps in vetting and monitoring, adversaries escalated privileges to maintain persistence within cloud-hosted identity and application systems. The attackers moved laterally across cloud and application environments, nurturing fraudulent accounts by making legitimate-appearing payments to build trust. Command and control was maintained through repeated API interactions and monitoring of account status, possibly leveraging encrypted or covert communication. Sensitive financial data and credit were exfiltrated by siphoning loan amounts or gaining access to customer data, eventually causing financial losses and reputational harm to the organizations.
Kill Chain Progression
Initial Compromise
Description
Attackers created synthetic identities and submitted them via vulnerable or insufficiently monitored online application or account registration portals, exploiting weak identity verification workflows in the cloud.
MITRE ATT&CK® Techniques
Gather Victim Identity Information
Phishing
Valid Accounts: Cloud Accounts
Create or Modify System Process: Account Manipulation
Establish Accounts: Social Media Accounts
Masquerading
Brute Force
User Execution
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Monitor and Respond to Signs of Unauthorized Activity
Control ID: 10.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Program and Policy
Control ID: 500.02, 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management, Incident Reporting
Control ID: Article 6(2), Article 10
CISA Zero Trust Maturity Model 2.0 – Continuous Identity Validation
Control ID: Identity Pillar: Identity Verification & Authentication
GLBA (Gramm-Leach-Bliley Act) – Information Security Program Requirements
Control ID: 16 CFR § 314.4
NIS2 Directive – Operational Security and Risk Management
Control ID: Article 21(2)(c)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Primary target for synthetic identity fraud with $3.3B losses, requiring enhanced zero trust segmentation and threat detection capabilities for customer verification.
Automotive
Concentrated fraud targeting auto lenders through sophisticated synthetic identities, demanding robust egress security and anomaly response systems for loan applications.
Financial Services
Faces escalating synthetic identity schemes across credit products, necessitating multicloud visibility and encrypted traffic analysis for fraud prevention infrastructure.
Insurance
Vulnerable to synthetic business identity fraud through online processes, requiring east-west traffic security and inline IPS protection against fraudulent claims.
Sources
- Plastic People, Plastic Cards: Synthetic Identities Plague Finance & Lending Sectorhttps://www.darkreading.com/cybersecurity-operations/synthetic-identities-finance-lending-sectorVerified
- TransUnion Report Indicates Suspected Digital Fraud in Nearly 14% of All Newly Created Global Digital Accounts in 2023https://newsroom.transunion.com/transunion-report-finds-nearly-14-of-all-newly-created-global-digital-accounts-to-be-suspected-digital-fraud-in-2023/Verified
- TransUnion Research Highlights Power of Public Data in Uncovering $3.3B Synthetic Identity Threathttps://newsroom.transunion.com/transunion-research-highlights-power-of-public-data-in-uncovering-33b-synthetic-identity-threat/Verified
- TransUnion Identifies Increased Risk for Tax Fraud Linked to 970 Data Breaches in 2024https://newsroom.transunion.com/transunion-identifies-increased-risk-for-tax-fraud-linked-to-970-data-breaches-in-2024/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic security, real-time egress policy enforcement, and threat anomaly detection would have sharply limited or exposed each step of the synthetic identity fraud kill chain. Integration of distributed enforcement controls—spanning microsegmentation, observability, and egress filtering—would have reduced attacker ability to evade monitoring, pivot laterally, or exfiltrate data from cloud-based financial systems.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring would flag and alert on anomalous application and registration activity.
Control: Zero Trust Segmentation
Mitigation: Identity-based policy enforcement restricts privilege escalation and lateral access.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts are detected and blocked between segmented workloads.
Control: Threat Detection & Anomaly Response
Mitigation: Anomaly-based alerting identifies suspicious persistence and covert command activity.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data theft is prevented or logged with fine-grained policy controls.
Integrated, real-time distributed policy minimizes blast radius and speeds incident response.
Impact at a Glance
Affected Business Functions
- Loan Origination
- Credit Card Issuance
- Auto Financing
Estimated downtime: N/A
Estimated loss: $3,300,000,000
Synthetic identity fraud involves the creation of fictitious identities using a combination of real and fabricated information, leading to unauthorized access to financial products and services. This can result in significant financial losses for lenders and potential exposure of sensitive consumer data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement centralized multicloud visibility to rapidly detect anomalous identity usage and account registration patterns.
- • Enforce zero trust segmentation and least privilege policies across workloads and services to block privilege escalation by synthetic identities.
- • Deploy east-west and egress filtering to halt lateral movement and unauthorized data exfiltration from cloud environments.
- • Automate threat detection and anomaly response to swiftly surface persistent or covert attacker behaviors targeting financial workflows.
- • Continuously update distributed enforcement policies within a Cloud Native Security Fabric to limit attacker impact and streamline incident response.



