What synthetic identity fraud is, and how it reaches your store as a chargeback


TL;DR
Synthetic identity fraud builds a person who does not exist from a mix of real and fabricated data, usually a real Social Security number with a fake name, date of birth, and address. Because no real person owns the identity, no one complains at first, so it clears basic checks, places card-not-present orders, and abuses financing or BNPL. It surfaces late, when the real SSN holder or a lender appears, and lands on a Shopify store as a card-absent chargeback under Visa reason code 10.4 that counts toward your dispute ratio and is nearly impossible to win. This is a detection and prevention problem, not a recovery one.
Synthetic identity fraud is a person who does not exist, built from a mix of real and fabricated data. The common recipe is a real Social Security number paired with a fake name, date of birth, and address, stitched into an identity that passes for real without belonging to anyone. There is no single victim to notice, which is exactly what makes it hard to catch. For a Shopify store it rarely looks like fraud at the moment of sale. It looks like a new customer, and it settles the bill months later as a chargeback.
Most pages ranking for synthetic identity fraud are written for banks and lenders, about credit files and loan applications. This one takes the merchant's side, where a fabricated identity places an order, clears your checks, and leaves you holding the dispute.
What is synthetic identity fraud?
Synthetic identity fraud is the construction of a person out of assembled data rather than the theft of a real one. The Federal Reserve's industry-recommended definition calls it "the use of a combination of personally identifiable information (PII) to fabricate a person or entity in order to commit a dishonest act for personal or financial gain" (fedpaymentsimprovement.org, checked 2026-08-10).
The mechanics behind that definition are worth naming. A fraudster takes one genuine element, most often a Social Security number that belongs to a child, a prisoner, or someone with no active credit, and wraps it in fabricated details: a name, a birth date, an address, a phone. The result is a synthetic identity, and because the anchoring number is real, it survives the checks built to spot a number that is fake or does not exist.
The patient version of synthetic fraud is worse than the fast one. Operators open thin-file accounts, make small on-time payments, and let the identity build a plausible history over months or years before they use it. By the time that identity reaches your checkout, it carries the paper trail of a real customer. This is also why you see it called synthetic identity theft: the SSN was borrowed from a real person, even though the identity wearing it is invented.
How is synthetic identity fraud different from identity theft?
The difference is who, if anyone, the identity belongs to. Traditional identity theft is third-party fraud: a real person's identity is stolen and used without their consent. That person exists, sees the charge, and disputes it, usually within a statement cycle. Synthetic identity fraud has no such owner. The identity was assembled, so there is no single real person watching a statement, and the fraud can run unnoticed for a long time.
| Dimension | Traditional / third-party identity theft | Synthetic identity fraud |
|---|---|---|
| Whose identity | A real person's, taken wholesale | A fabricated person, stitched from real and fake data |
| Is there a victim who notices | Yes, the real cardholder sees the charge and disputes quickly | Not at first, no single person owns the identity |
| How it surfaces | Fast, as an unauthorized-charge dispute | Late, when a lender writes it off or the real SSN holder appears |
| Account history | Borrowed from the victim's existing record | Built by the identity itself over months |
| What it targets at your store | One fraudulent order on a stolen card | New-account signup, financing, BNPL, and bust-out runs |
The closest relative in your own fraud mix is account takeover fraud, where a criminal signs into a real customer's real account. That is still third-party fraud with a real owner behind it. Synthetic fraud removes the owner entirely, which is why the two need different defenses and why neither is answered by fighting the chargeback after the fact.
How does synthetic identity fraud hit ecommerce merchants?
It arrives through the front door as a customer, not through a stolen card fumbled at checkout.
The account passes basic checks. An aged synthetic identity carries a consistent name, address, and payment method, so AVS and CVV clear and the order looks like any other. It is a card-not-present fraud case with none of the usual tells, because the data is internally consistent even though the person is not real.
Financing and BNPL are the richer targets. A synthetic identity with a built-up credit file can pass an installment or financing approval, take delivery, and never pay. The lender absorbs part of that, but the goods left your warehouse and the downstream dispute can still land on you.
The bust-out is the set piece. The identity places small, clean, well-behaved orders to build trust, then escalates to one large order or a burst of them, takes the goods, and disappears. The early good behavior is the setup, not a reassurance.
The chargeback is the tail. Nothing looks wrong until the real cardholder behind the borrowed number, or a lender reconciling a loss, disputes the transaction. On Visa that lands as reason code 10.4, other fraud in a card-absent environment, an unauthorized-transaction claim. The funds reverse, a fee of $15 to $25 or more lands on top, and the case counts toward your Visa VAMP ratio whether or not you contest it.
Note
There is no victim to call at first. A synthetic identity has no real person behind it to notice the fraud, which is why it surfaces late, often as a chargeback.How do you detect synthetic identity fraud?
Not from any one field, and not with certainty. The honest starting point is that a merchant cannot fully verify that a customer is a real person. What you can do is watch for the pattern where an identity looks assembled rather than lived-in.
| Red flag | What it suggests |
|---|---|
| A young account with thin history placing a high-value order | An identity built recently to look established |
| Applicant data that does not tie back to a consistent public record | Fabricated details stitched around one real number |
| The same device, address, or phone across several unrelated customers | One operator running a stable of synthetic identities |
| A financing or BNPL approval where the buyer is unreachable after delivery | An identity created to borrow and disappear |
| Small clean orders escalating suddenly to a large one | The build-then-bust shape of a bust-out |
No single row is proof, and each one has an honest explanation. New customers place big first orders. Families share a device. A shipping address repeats because it is an office. What raises the odds is several of these stacking on one order, or one address and device fanning out across accounts that claim to be different people. That is fraud screening, a different discipline from what chargeback fraud detection does once a dispute is already open.
Be precise about where a post-purchase platform helps. Reducing avoidable disputes, what Resolve is built for, works on confusion-driven and first-party volume, where a real customer disputes their own purchase. Synthetic fraud is the opposite: the customer was never real, so the lever is order-time and signup-time risk review, not post-purchase clarity. When a synthetic-identity chargeback does land, Reclaim handles representment at no cost and with no success fee, though be clear-eyed that most of these are genuine unauthorized charges with little honest evidence to answer them.
The honest part
A merchant cannot verify identity the way a bank can, and no dispute response reverses a real unauthorized charge. Treating synthetic fraud as a representment problem is how a store keeps paying for it.
Be careful with the numbers you read, because almost all of them measure the lending side. TransUnion put US lender exposure to synthetic identities at more than $3.3 billion for the year ending 2024 (newsroom.transunion.com, checked 2026-08-10), a figure drawn from credit cards, auto loans, and similar accounts, not from ecommerce carts. I have not found a credible measure of synthetic fraud as a share of Shopify orders, so I will not invent one. What I can say from the mechanics is narrower: each card-absent chargeback these identities eventually produce counts toward your 10.4 volume and your VAMP ratio the day it is filed, win or lose.
The prevention levers are real, and each has a cost. Tightening new-account and financing checks catches assembled identities and adds friction for genuine new customers. Holding orders where a device and address repeat across accounts catches operators and delays legitimate shared-household buyers. The right setting depends on your margins and volume, not a universal rule.
Frequently asked questions
What is synthetic identity fraud in simple terms?
It is a person who does not exist, built from a combination of real and fabricated data. The usual recipe is a real Social Security number, often one belonging to a child or someone with no active credit, wrapped in a fake name, date of birth, and address. Because the anchoring number is real, the identity passes checks meant to catch data that is obviously false, and because no real person owns it, no one is watching to report the fraud.
How is synthetic identity fraud different from regular identity theft?
In traditional identity theft, a real person's identity is stolen and used, so there is a victim who sees the charge and disputes it quickly. Synthetic identity fraud fabricates the identity, so there is no single owner to notice. That is why synthetic fraud surfaces late, often only when a lender writes off a loss or the real holder of the borrowed SSN finally appears, and why it tends to reach a merchant as a card-absent chargeback rather than a fast complaint.
Can a merchant win a synthetic identity fraud chargeback?
Usually not. When these disputes land on Visa as reason code 10.4, the claim is that the charge was unauthorized, and for a fabricated identity there is rarely honest evidence proving otherwise. Representment works by contradicting the cardholder's allegation, and here the allegation is effectively true. Synthetic identity fraud is a detection and prevention problem at signup and checkout, not a recovery problem in the dispute queue.
How does synthetic identity fraud abuse buy now, pay later?
A synthetic identity with a built-up credit file can pass a financing or BNPL approval, take delivery of the goods, and never pay. The build-up is deliberate: small on-time activity earns the identity a plausible history, then it is used for a larger purchase and abandoned. The lender absorbs part of the loss, but the goods have already left your warehouse and related card-absent disputes can still reach you.
What to check on your own orders
Start with your newest customers, not your dispute queue. Pull the accounts created in the last few months that placed a high-value order or cleared a financing or BNPL approval, and look for the same device, address, or phone repeating across accounts that claim to be different people.
Then lay your 10.4 disputes next to that list and mark which ones trace back to a young account with a thin history. Where those two overlap is your synthetic-identity exposure, and it is a signup and checkout problem showing up one chargeback at a time, not a backlog to work harder.