Your name. Your date of birth. Your national ID number.
Individually, they are data points. Combined and weaponized, they can unlock many other forms of fraud. Identity may be personal to you, but to a criminal it can be infrastructure.
How do fraudsters exploit identity?
π€ Classic identity theft - Stolen personal data is used to open accounts, obtain credit, take over services, or impersonate a real person. The warning may arrive much later as an unfamiliar inquiry, bill, or debt. The FTC recorded 1,135,291 identity theft reports in 2024 - unverified consumer reports, not a prevalence survey.[ref]
𧬠Synthetic identity fraud - Attackers combine real information, such as a legitimate U.S. Social Security number, with fabricated names, addresses, or dates of birth. The Federal Reserve warns that these identities can evade conventional identity verification and credit screening.[ref]
ποΈ Identity farming and bust-outs - A synthetic identity may be cultivated over time through small purchases and timely repayments. Once it appears trustworthy, the criminal uses the available credit and disappears. Apparently, even fake people need time to build a good credit score.[ref]
π Document fraud - Counterfeit or altered passports, national ID cards, residence permits, and proof-of-address documents can help impostors pass onboarding checks. A genuine document may also be paired with a manipulated portrait or stolen identity data.
π Identity as a commodity - Stolen identity records can be enriched, bundled, reused, and traded. One breach may expose an email address, another a date of birth, and a phishing page the missing credentials. The criminal value often lies in the combination.
What can we do?
For individuals:
- Review your credit file and account statements, and investigate unfamiliar inquiries, accounts, bills, or benefit claims.
- Use multi-factor authentication and share identity data only when necessary.
- Where available, consider a credit freeze if you are not applying for credit.
For organizations:
- Use layered, risk-based verification rather than relying on documents or knowledge-based questions alone.
- Combine appropriate document checks, biometrics with presentation-attack and liveness controls, device and behavioral signals, and ongoing transaction monitoring.
- Look for suspicious links across identities, devices, addresses, phone numbers, and payment instruments - not only anomalies within one account.
Identity is not just who you are. It is who a fraudster may try to become.