A compliance team at an Indian NBFC ran a routine audit last year and found something strange in their loan book.
Six thousand approved applications. Real PAN numbers. Real mobile numbers linked to Aadhaar. Real addresses tied to actual buildings with actual residents. Every document passed verification. Every applicant existed, technically, on paper.
None of the six thousand people had ever applied for a loan.
Their identity fragments - PAN, phone number, address history - had been harvested and recombined into personas that had never lived anywhere as a single, coherent person. Each fragment was genuine. The person assembled from them was not.
This is a synthetic identity. Most fraud detection systems are not built to catch it - because they were never asked to solve this particular problem.
Identity verification, as most systems perform it, asks one question: does this person exist?
PAN checks confirm the PAN database. Aadhaar-linked checks confirm the mobile number. Address verification confirms the address is real. A synthetic identity passes all of these - because every individual component is real. The fraud is in the combination, not the components.
Traditional identity theft uses one real person's complete identity without consent. Detection systems have spent two decades getting good at catching this - checking for prior use, flagging velocity, cross-referencing compromised records.
Synthetic identity fraud is different. It builds a new identity from real fragments belonging to different people, or blends real fragments with fabricated ones. There is no single victim. There is no prior fraud record, because this identity has never existed before. It looks, to the system, like a first-time applicant with clean documents.
A system built to answer "does this person exist" has no answer for "was this person assembled."
Document checks and bureau lookups will not find a synthetic identity, because the documents and records are individually genuine. Detection has to shift from verifying components to analyzing the relationships between them.
Identity graph construction: Mapping every applicant's phone, device, address, and bank account as a connected network surfaces the fragment reuse that isolated checks miss. A synthetic ring looks, in graph form, like an unusually dense cluster of shared attributes across people who should be unrelated. This is where graph-native network risk intelligence creates a structural detection advantage over document-based KYC stacks.
Verafye treats synthetic identity risk as a network and behavioural signal problem - not a document verification problem.
When a new applicant or merchant is onboarded, Verafye's graph-native network risk intelligence layer maps their identity fragments - phone, device, address, account, behavioural fingerprint - against the existing network of resolved entities across your portfolio. Fragment reuse surfaces immediately. A phone number that has appeared under three other names in the past six months connects the new applicant to those records before any document check can.
When multiple synthetic identities share a device fingerprint or an incubation pattern, mule account detection and identity graph analysis surface the cluster - not one suspicious application, but the ring behind it.
The case that results is already assembled when the analyst opens it: the fragment overlap, the network connections, the behavioural clustering, and the investigation trail from signal to decision. For regulated platforms, that trail is also what satisfies examination requirements.
For lenders, PSPs, and payment aggregators rethinking how they approach identity risk, the Verafye Risk Shadowing Review is a scoped starting point - showing where synthetic identity patterns exist in your current portfolio that document-level verification has not surfaced.
India's identity infrastructure is unusually strong - and that strength is part of the exposure. Aadhaar, PAN, and mobile-linked KYC create a large pool of verifiable, high-trust fragments, which makes each fragment more valuable to a fraud ring and more convincing once recombined.
The growth of digital lending and merchant onboarding - often under pressure to keep approval times short - has compressed verification windows in ways that favour fragment checks over relationship analysis. Loan app fraud networks in India's digital lending ecosystem increasingly rely on synthetic identities precisely because they defeat document-level verification.
The same dynamic is visible across Southeast Asia, the UK, and the US, wherever digital onboarding has outpaced identity graph infrastructure.
KYC frameworks were built to verify real individuals. They were not built to catch identities assembled from real parts.
Not "can we verify this PAN" or "can we confirm this address." Those checks pass every time, because the fragments are real.
The real question: does our system know if this phone number, device, or address pattern has appeared across other applicants who are supposedly unrelated?
If the honest answer is "no" or "we would have to check manually," the system can see stolen identities. It cannot see synthetic ones. That is the narrower, shrinking category of the two - and the faster-growing source of fraud losses.
A synthetic identity is a fabricated person built from real identity fragments - PAN numbers, phone numbers, addresses, device fingerprints - typically harvested from multiple real individuals. Unlike traditional identity theft, there is no single victim, no prior fraud record, and no single document that fails verification. The fraud is in the combination of fragments, not in any one component.
Standard KYC verifies that individual identity components are real - the PAN exists, the phone is Aadhaar-linked, the address is valid. Synthetic identities are built from real components, so they pass every document check. Catching them requires analyzing whether those components appear together across other applications in suspicious patterns - which is a relationship question, not a document verification question.
Effective detection requires cross-application fragment analysis (does this phone number appear under different names?), identity graph construction (mapping all applicants into a connected network to surface fragment reuse), device and behavioural clustering (identifying the same device or behavioural fingerprint across supposedly unrelated applicants), and velocity pattern analysis (detecting artificially linear credit histories).
Payment aggregators face synthetic identity risk at merchant onboarding - where fabricated businesses are onboarded to process fraudulent transactions - and at the customer account level. A synthetic merchant can pass KYC, process payments for months, and exit cleanly before the pattern becomes visible. The damage is in the settlements already cleared.
Yes. India's strong identity infrastructure - Aadhaar, PAN, mobile-linked KYC - creates a large pool of high-trust, verifiable fragments, which makes synthetic identity construction both more viable and more convincing. The rapid growth of digital lending and payment aggregation has created onboarding environments under time pressure, which compresses the verification window that relationship-based analysis needs to catch fragment reuse.
Sudeendra
Co-Founder & COO, Verafye
Verafye is a graph-native network risk intelligence platform built for lean fraud, AML, and risk teams at payment aggregators, PSPs, MSBs, and regulated fintech platforms.
See where your monitoring stack has blind spots
The Risk Shadowing Review maps your current coverage against relationship-level gaps.