top of page

Resilient Trust™ Identity Models

Synthetic Identity Fraud Attacks Classifications

An authentic digital identity is a collection of identity elements:
  • Biometrics, representing a physical human being.

  • Personally Identifiable Information (PII), representing foundational, biographical, and contextual descriptions of that person.

 

Synthetic identities are created by bad actors through means of counterfeiting one or more of those identity elements, thereby creating a digital representation of a human without a real world counterpart. Even though most synthetic identities do contain some authentic identity elements—a real face, a real name, a real address—authentic identity is the sum of all its parts, and one counterfeit element is all it takes to sever the link between a digital identity and its corresponding carbon-based life form.

Synthetic Fraud Attacks_v4b.png
On a fundamental level, synthetic identities take up space in databases and undermine the integrity of a system. Most commonly, they are used to commit types of benefits fraud or economic scams, funneling health insurance or social security to a bad actor, or building up credit until they can take out loans. According to Deloitte, the average synthetic identity has a credit score of about 650, which is considered slightly better than average for authentic humans, scoring fraudsters approval on $15,000 loans for non-existent people.

As the diagram above illustrates. The Prism Project divides synthetic identity into three broad classifications:

Full Synthetic Identity

 

A Full Synthetic Identity is the purest form of digital doppelganger, made up entirely of counterfeit identity elements, generated by machine learning tools. A counterfeit deepfake image of a face on a fake identity document using completely invented PII—a convincing Full Synthetic Identity will be particularly difficult to weed out of a database on account of it not using duplicate images or data.

Partial Synthetic Identity

Partial Synthetic Identities combine one authentic identity element with a counterfeit identity element.

• Fake Face Partials use authentic PII and counterfeit image or video deepfakes to create a synthetic identity rooted to the legitimate government record but with a different face.

• Fake Data Partials use authentic biometrics and counterfeit PII to create a completely new record in a system with fake foundational, biographical, and contextual data bound to a real human face.

Hybrid Synthetic Identity

 

Hybrid Synthetic Identities are a special configuration in which either:

• Authentic biometrics and PII are supplemented with counterfeit PII.

• Incomplete or limited PII is supplemented with deepfakes and counterfeit PII to build out a synthetic ID.

• Authentic biometric and PII identity elements are blended with deepfakes and counterfeit PII.

While the components of each configuration are unique, thereby making the synthetic identity problem a many-headed beast they all effectively reduce to the same core issue: digital identities with no rightly corresponding human being. While their face, voice, or PII might represent or describe a real person, they are Frankenstein monsters stitched together to create a digital representation without a physical analog—ghosts in the machine.

To learn more about Synthetic Identity Fraud Attacks, download these reports.

Click on a report image to download.

Identity Verification and Authentication Process

Threats and Vulnerabilities to Trust and Resilience​​
 

Understanding how verification and authentication work at a technical and procedural level is therefore essential. It is only by mapping the identity elements as they move through the system that we can see where privacy and compliance vulnerabilities erode trust, and where deepfake and synthetic identity attacks undermine resilience.

​How Identity Verification and Authentication Work
​As the diagram above illustrates, individuals interact with identity systems in two primary ways: automated and manual.
 
  • In automated flows, users initiate verification themselves by submitting biometric, biographical, and contextual identity elements via edge devices—smartphones, laptops, or kiosks—using sensors such as cameras, microphones, and document scanners.
  • In manual flows, a human reviewer initiates the process, interacting with the user through video, voice, or in-person meetings; this can either stand alone or serve as a backup for users who opt out of or fail automated checks.
 
Both approaches can be used in remote or on-site environments such as bank branches, government offices, or retail locations​​ At the simplest level, identity verification and authentication follow a four-step sequence:

  • Data Capture, where biometric identity elements (face, voice, etc.), biographical identity elements (Identity documents, credentials, and PII), and contextual identity elements (location, device, behavior, etc.) are collected.

  • Signal Processing, where these elements are transformed and transmitted for evaluation, either exclusively on the device, exclusively on the host system, or via a hybrid on-device, server model.

  • Reference Comparison, where captured identity elements are checked against reference databases, government records, watchlists, and behavioral profiles.

  • Decision, where the system either grants or denies verification, triggers step-up measures, or routes the user to human review.

 

This process involves two interconnected systems:

  • End User System (Edge Device), which captures and sometimes locally processes identity elements.

  • Host System, which houses IDV software, reference databases, risk engines, and decision logic—often including human reviewers.

​Every step and every channel in this pipeline is simultaneously a trust surface (where privacy and compliance must be upheld) and a resilience surface (where deepfake and synthetic identity attacks try to inject counterfeit identity elements). The most trusted and resilient systems encrypt all data in transit and can complete comparison operations with fully encrypted data.

To learn more about Identity Verification and Authentication, download these reports.

Click on a report image to download.

bottom of page