Synthetic identity
Real and invented attributes are combined into a profile that may pass shallow consistency checks.
Effective account opening fraud prevention protects growth by keeping synthetic identities, stolen credentials, and fraud rings out while letting genuine applicants move forward. Programs that work in production combine identity verification, enrichment of company profile and directors/UBOs, risk signals, and real-time decisioning so teams can spot patterns early and act with confidence. This page offers a practitioner's blueprint for blocking new account fraud across fintech, banking, crypto, and payments, with concrete patterns, pitfalls to avoid, and an implementation sequence you can defend to auditors. With Ondorse, these practices map directly to policy and day-to-day operations.

Signup abuse does not come as a single adversary. It is a mix of tactics that evolve as soon as controls change. Treat fraud prevention like a portfolio of defenses, not a single rule, so you adapt without rewriting flows.
The patterns below are common because they exploit blind spots in naive KYC setups.
Synthetic identity: stitched profiles that pass weak checks, age quietly, then monetize. They exploit inconsistent name-DOB-address ties and shallow document checks.
Stolen identity: real PII and captured document images. Attackers bet on shallow liveness and permissive selfie thresholds.
Mule recruitment: legitimate people opening accounts on behalf of others. Signals look fine until you correlate with downstream activity.
Farmed signups: scripted or semi-manual creation using emulators, residential proxies, recycled devices, or recycled artifacts like SIMs and bank tokens.
Referral and bonus abuse: genuine identities gaming incentives with rings and cooldown evasion.
.webp)
.webp)
Not all data points deserve equal weight. Prioritize signals with predictive power and interpret them as a system rather than in isolation.
Blend these categories to form a decision you can explain, replicate, and audit.
Identity integrity: document authenticity, MRZ checks, selfie similarity, and proof-of-address validation.
Device and environment: rooted or virtualized devices, sensor gaps, clipboard anomalies, reused cameras across signups.
Network: IP to country mismatch, proxy and ASN ranges, rapid subnet hopping, and velocity by prefix.
Behavioral: cadence outliers, paste patterns, identical flows across accounts, unusual inter-step times.
Graph signals: one device or phone opening many accounts, shared bank tokens, recycled addresses or emails across applicants.
External risk: domain age, phone reputation, data breach exposure on submitted artifacts.
The goal is simple: keep genuine users moving while raising the bar for attackers. The lever is risk-based decisioning, not blanket strictness.
Calibrate paths so controls scale with risk, not with your appetite for features.
Light: minimal document capture plus quick screening for clean histories and low-risk markets.
Standard: stronger liveness, selfie match, and targeted KBA or proof of address when inconsistencies appear.
Enhanced: manual review, additional documents, short cooling-off windows, and video when signals justify it.
Long checklists are tempting and often counterproductive. Start with measures that tend to survive contact with real attackers.
These moves are practical, measurable, and reversible when they miss the mark.
Guided capture with glare and blur tips to lift first-try success and reduce fake ID retries.
Selfie liveness and document anti-tamper tuned by document family and device profile.
Device binding early to track retries and cap accounts spawned from one device.
Phone and email reputation combined with velocity limits per artifact.
IP reputation and ASN rules that escalate checks for proxy ranges and suspicious prefixes.
Name-DOB-address fuzzy consistency to catch synthetic blends.
Payment instrument pre-validation where permitted to detect recycled cards at signup.
Cooling-off windows that slow farmed attempts without trapping legitimate users.
Referral integrity that defers rewards until risk cools or usage criteria are met.
Post-onboarding monitoring to catch delayed fraud once an account is warmed.
A few realistic examples help align teams on how decisions evolve step by step.
Clean cohort: domestic ID, known device, stable IP, selfie match passes. Route to light path and complete in minutes with full audit trail.
Suspicious cohort: foreign ID plus proof-of-address mismatch and proxy ASN. Escalate to enhanced path with extra documents and manual review when needed.
Provider instability: IDV A times out for a country-device slice. Orchestration falls back to IDV B, keeps the lineage of both attempts, and decision quality is preserved.
Signup defense should not become a separate island. It shares data and outcomes with verification, risk scoring, monitoring, and investigations across your KYC/AML stack.
KYC workflow with evidence retention and reason codes per decision.
KYC orchestration to switch vendors, define fallbacks, and run A-B or shadow tests.
Customer risk assessment that updates scores as new signals arrive.
AML case management for investigations, maker-checker, and SAR preparation where applicable.
Data warehouse and BI to analyze losses, false positives, and step-level drop-offs over time.
Keep the metric set small and stable so trends mean something. Review them weekly with product, risk, and compliance together.
Acceptance rate for legitimate signups by country and device profile.
Fraud catch rate and false positive rate on escalations and declines.
Time to decision at signup, including manual review queues.
Loss per new account and cost per successful verification.
Big-bang releases increase risk. A phased rollout proves impact and limits surprises.
Use a narrow start and expand on evidence, not on hopes.
Define risk segments and required checks, plus evidence to store for each outcome.
Integrate one vendor per control first and set clear timeouts and fallbacks.
Instrument events and webhooks so analytics, support, and compliance share the same clock.
Choose a test method: A-B when you want allocation control, shadow mode when you need safety without traffic split.
Maintain a change log with rationales so audits are fast and repeatable.
Good defense feels simple. You can be strict and still be clear.
Inline, localized guidance for document capture and selfie steps.
Smart retries that offer the next best document instead of restarting from zero.
Plain language status and typical review times when a case enters manual review.
Accessible flows that hold up on mid-range phones and variable bandwidth.
Controls matter as much as checks. Express rules as policy-as-code with versioning and approvals, and keep a clear audit trail for every change.
Encryption in transit and at rest with managed key rotation.
Data minimization with deletion flows that run on schedule.
RBAC with SSO and least-privilege access to evidence and raw images.
Regional data residency when law or contracts require it.
Data lineage for inputs, decisions, and vendor calls so you can explain outcomes step by step.
Updated October 2025. Reviewed by a compliance lead and aligned with public guidance from FATF and European supervisory bodies.
If you are building account opening fraud prevention, start by mapping segments and the signals you trust. Choose a platform that supports risk-based orchestration, clear reason codes, and native handover to AML case management. Ondorse provides policy-as-code, portable vendor integrations, and evidence-first decisioning so teams can fight fraud without losing speed.
Teams often ask how to be tough on abuse without crushing conversion. These answers reflect what works in production.
Not always. Use risk-based onboarding. Run lighter checks on clean segments and escalate when signals justify it. Keep evidence and reason codes either way.
Combine device intelligence, velocity limits, and consistency checks on Name-DOB-address. Add liveness and selfie similarity for new accounts and re-screen at activity milestones.
Bind devices, enforce cooldowns, and delay payouts until risk cools or usage criteria are met. Track referral graphs and revoke rewards from rings.
Combine identity, device, network, behaviour and relationship signals during onboarding. Challenge suspicious applications with the next useful control while legitimate customers continue through a lower-friction path.
Looking for journey optimisation? See customer onboarding software.
Account-opening fraud is the use of false, stolen, manipulated or legitimately controlled identities to create an account for deceptive, abusive or criminal purposes.
The identity may be entirely fabricated, assembled from real data, stolen from another person or willingly presented by a recruited mule. Fraud may also involve genuine customers creating coordinated accounts to exploit promotions, credit or platform rules.
KYC and fraud prevention overlap, but they are not identical. KYC software supports identification and compliance decisions. Fraud prevention adds behavioural, device, network, velocity and relationship signals designed to identify deception and coordinated abuse.
Different attacks need different controls. A single document or risk-score threshold will not address every pattern reliably.
Real and invented attributes are combined into a profile that may pass shallow consistency checks.
Valid personal information or document images are used without the subject’s permission.
A real person opens or lends an account for someone else, sometimes under deception or coercion.
Operators reuse devices, networks, contact details, documents or payment instruments across many attempts.
A genuine person misrepresents intent or coordinates accounts to exploit product economics.
A legal entity or representative conceals its actual activity, control or intended account use.
This fictional example shows why context from several stages matters more than one isolated signal.
Several applications use valid-looking identity data. Each appears plausible alone. Device, network and contact relationships reveal that they are part of one signup cluster.
Applications arrive from different names but the same narrow device and browser configuration.
Documents pass basic format checks, but images and contact artefacts repeat across attempts.
Requests rotate through proxy addresses while maintaining similar timing and navigation behaviour.
Phone, device and payout relationships connect the applications to previously confirmed abuse.
The combined pattern triggers a controlled challenge or specialist review instead of blanket approval.
Illustrative scenario only. Signals must be validated on the organisation’s own data and assessed in context.
No signal should be treated as proof of fraud on its own. Evaluate reliability, context, correlation and known bias before using it in decisions.
Authenticity results, extracted data, liveness, face comparison and cross-source consistency.
Device continuity, emulator or automation indicators, sensor context and links to prior applications.
IP geography, proxy indicators, ASN context, rapid switching and network-level velocity.
Age, reputation, reachability, reuse and relationship to previous customer outcomes.
Step timing, copy-paste activity, repeated sequences and unusual navigation or retry behaviour.
Attempts by device, network, contact, document, address or payment artefact within defined windows.
Connections between applications, known fraud, payout destinations and business ownership.
Requested limits, product type, channel, promotion and expected early-life activity.
The same network or device signal can have different meaning when combined with identity, behaviour and relationship evidence.
An applicant uses a corporate VPN while travelling, but identity evidence, device history and contact details are consistent.
Several applicants use rotating proxy addresses, one reused device pattern and contact details connected to prior abuse.
A useful fraud decision explains the action, reason and evidence. It should also define when a customer can recover or provide additional proof.
Continue the journey when required checks and fraud signals support the application.
Request one additional control that can resolve the specific uncertainty found.
Send a complete case to an authorised specialist when deterministic rules are insufficient.
Prevent activation according to the organisation’s approved policy and communication process.
Adding more checks is not automatically safer. Each control should target a defined threat and have measurable customer and fraud outcomes.
Validate documents and identity data with checks suited to the market, channel and threat model.
Assess whether the person present can satisfy the approved identity-possession controls.
Identify repeated or suspicious use without treating shared-device contexts as automatically fraudulent.
Measure attempts across several artefacts and time windows, then tune limits to real behaviour.
Connect applications to shared devices, contacts, addresses, instruments and confirmed outcomes.
Use post-activation behaviour to identify fraud patterns that cannot be proven during signup.
Mule accounts may use real identities and pass conventional verification. Relationship and early-life context can reveal the coordinated activity.
Link only data your organisation is permitted to use and define how relationships influence review. Shared attributes can have legitimate explanations.
Other applications, customers and confirmed outcomes seen on the device.
Repeated phones, emails, addresses or recovery channels.
Shared funding, payout or beneficiary artefacts where available and permitted.
Shared representatives, owners, directors or declared counterparties.
Fraud controls decay when teams cannot connect onboarding signals to later losses, disputes, account closures or confirmed good customers.
Preserve the values and model or rule version used.
Store score, reasons, evidence and human input.
Connect confirmed fraud, loss and legitimate activity.
Review false positives, misses and segment differences.
Validate revised rules or models before broad release.
A fraud catch rate is incomplete without the false-positive cost, review workload and legitimate customers lost to unnecessary friction.
Confirmed fraudulent accounts or exposure.
Known fraud caught before activation or loss.
Legitimate customers challenged or stopped.
Cases where human review changes the outcome.
Fraud loss and operational cost per new account.
The right control depends on the attack, customer segment, product exposure and quality of the underlying provider or model.
| Control | Primary question | Useful measures | Common limitation |
|---|---|---|---|
| Document verification | Does the evidence appear valid and consistent? | Completion, spoof detection, retry and false rejection | A valid document can still be stolen or misused |
| Liveness and face comparison | Is a live person consistent with the identity evidence? | Attack detection, completion and demographic performance | Does not establish the applicant’s intent |
| Device and network intelligence | Is the technical context unusual or connected? | Coverage, stability, link precision and false positives | Shared devices and privacy tools can be legitimate |
| Velocity and graph rules | Is activity coordinated across attempts or accounts? | Cluster detection, review yield and confirmed relationships | Requires enough history and reliable entity linking |
| Post-opening monitoring | Does later behaviour match the stated customer purpose? | Early loss, mule detection and time to intervention | Acts after some exposure already exists |
A broad score built without reliable labels is less useful than a narrow control evaluated against a clearly defined attack.
Name the attack, exposure, customer segment and current loss.
Assess coverage, latency, quality, bias and permitted use.
Set allow, challenge, review and stop outcomes with recovery paths.
Use retrospective analysis, shadowing or bounded traffic as appropriate.
Feed confirmed outcomes back into metrics and controlled changes.
Fraud prevention should make the next control specific to the risk signal found and give legitimate customers a realistic way to recover.
Choose a control capable of resolving the uncertainty instead of stacking generic checks.
Distinguish image quality, unsupported evidence and genuine risk rather than showing one failure message.
Where appropriate, route ambiguous cases for review and communicate whether customer action is needed.
This page owns signup fraud signals and decisions. The related pages cover customer experience, identity and business checks, workflows, routing and APIs.
Bring one confirmed attack pattern, one source of false positives and the signals currently available. Ondorse can help map a measurable decision path around them.