Synthetic identity fraud rarely depends on one obviously fake attribute. Fraudsters may combine real and fabricated personally identifiable information, create apparently plausible profiles, and gradually build account credibility before committing fraud.
The Federal Reserve defines synthetic identity fraud as using a combination of personally identifiable information to fabricate a person or entity for dishonest personal or financial gain. It also notes that traditional fraud models may miss synthetic identities because those models often assume the applicant represents a real person. Federal Reserve: Synthetic Identity Fraud
Device intelligence helps challenge that assumption. By examining how accounts are created, accessed, and connected, businesses can identify coordinated activity that is difficult to see when reviewing each identity separately.
1. Why Synthetic Identities Can Pass Individual Checks
A synthetic identity may contain information that appears valid when evaluated field by field. A name, address, phone number, or identity number may exist, but the complete combination may not correspond to one genuine person.
Fraudsters can also separate activity across time:
- Create several accounts with different identity details.
- Use each account conservatively during an initial period.
- Build payment or credit history.
- Coordinate activity through shared infrastructure.
- Exploit multiple accounts after trust has been established.
Document and database checks remain important, but they may not reveal that several apparently unrelated applicants are controlled by the same operator. Device intelligence adds a relationship layer to the verification process.
2. Which Device Signals Can Indicate Coordination?
A single device anomaly is rarely conclusive. The strongest indicators usually emerge from repeated relationships between devices, identities, accounts, and events.
Device reuse: One device creates or accesses many identities within an unusual period.
Identity-to-device expansion: One claimed identity appears across an unexpectedly large number of devices, especially when other attributes also change.
Environment similarity: Separate accounts share highly similar operating-system, browser, hardware, display, language, or configuration characteristics.
Integrity risk: Rooting, jailbreaking, emulation, application cloning, hooking, or virtualized environments may reduce confidence in the capture environment.
Network overlap: Accounts repeatedly use related IP addresses, proxies, hosting infrastructure, or unusual network routes.
Session behavior: Applications follow similar navigation sequences, input timing, retry patterns, or verification failure patterns.
Capture-source anomalies: Injected media, virtual cameras, screen recapture, or reused evidence may indicate that the device is not providing trustworthy live input.
FinAuth can combine these signals through Device & Session Intelligence without treating any individual technical characteristic as automatic proof of fraud.

3. Look for Networks, Not Only Individual Devices
Fraud rings do not always reuse one device directly. They may rotate devices, reset identifiers, change networks, or divide activity among multiple operators.
Detection should therefore examine multiple relationship types:
- Device connected to several accounts
- Face associated with different identity records
- Document reused across unrelated applications
- Contact detail shared by multiple applicants
- Beneficiary receiving funds from separate accounts
- Transaction flow linking otherwise independent profiles
- Several devices sharing the same high-risk environment pattern
Indirect connections also matter. Account A and Account B may never share a device, but both may connect to the same beneficiary or use documents associated with a third account. Graph analysis can reveal these multi-hop relationships.
FinAuth’s Risk Engine can combine identity, biometric, device, behavioral, and transaction evidence to assess both the individual session and its surrounding network.
4. Separate Normal Sharing from Coordinated Fraud
Shared technology is not inherently suspicious. Families may use one device. Employees may access services through corporate networks. Public connectivity, device replacement, and assisted onboarding can also create legitimate overlaps.
A practical workflow should evaluate context:
Frequency: How many identities or accounts are connected?
Velocity: How quickly were they created or accessed?
Diversity: Do the accounts claim unrelated names, locations, or customer profiles?
Risk concentration: Are document, face, capture-integrity, or transaction anomalies present?
Sequence: Did the accounts appear, mature, and transact in a coordinated pattern?
History: Has the device or related cluster previously been associated with confirmed fraud?
A shared device with two related household members may be low risk. The same device linked to dozens of unrelated identities, repeated liveness failures, and common beneficiaries should receive substantially higher priority.
5. Build a Multi-Signal Synthetic Identity Workflow
The Federal Reserve recommends a layered approach combining technological and manual data analysis because no single control can reliably identify every synthetic identity. Federal Reserve: Mitigating Synthetic Identity Fraud
A scalable FinAuth workflow can follow five stages:
First, verify the submitted evidence. Extract identity data, assess document authenticity, and cross-check relevant fields.
Second, verify the presenter. Compare the applicant’s face with the document portrait and confirm genuine presence through Liveness Detection.
Third, assess device and capture integrity. Identify risky environments, automation, injection, recapture, and abnormal session behavior.
Fourth, resolve relationships. Link accounts through shared devices, faces, documents, contacts, beneficiaries, and transaction behavior.
Fifth, apply proportionate actions. Allow trusted applications to continue, request additional evidence for uncertain cases, and route strong coordinated-risk clusters to review or restriction.
The Federal Reserve’s mitigation toolkit similarly emphasizes detection and identity validation across the customer lifecycle rather than relying only on one onboarding check. Synthetic Identity Fraud Mitigation Toolkit

6. Monitor Accounts After Onboarding
Synthetic identities may be designed to appear legitimate initially. Important signals may emerge only after multiple applications, device changes, credit-building activity, or coordinated transactions.
Ongoing monitoring should evaluate:
- New device and account relationships
- Sudden expansion of connected identities
- Repeated changes to contact information
- Shared beneficiaries or payment instruments
- Coordinated transaction timing
- Dormant accounts becoming active together
- Previously unknown links to confirmed fraud clusters
FinAuth can use new events to update network risk and trigger proportionate reverification, enhanced checks, investigation, or account restrictions.
7. Synthetic Identity Detection Q&A
Can one shared device prove synthetic identity fraud?
No. Device sharing has legitimate explanations. Risk should reflect the number, velocity, diversity, and behavior of connected accounts, together with identity and transaction evidence.
Can fraudsters bypass device fingerprinting?
They may alter or rotate observable attributes. Detection should therefore combine device characteristics with integrity, network, biometric, behavioral, and graph signals instead of relying on a permanent device identifier.
Why are graph connections useful?
Graphs reveal shared and indirect relationships between accounts. They can expose coordinated structures that remain hidden when applications are assessed independently.
How does FinAuth detect synthetic identities?
FinAuth combines Document Verification, Face Verification, Liveness Detection, Device & Session Intelligence, behavioral signals, and connected-entity risk within its Risk Engine. This supports decisions based on the complete evidence pattern.
8. Conclusion
Device intelligence strengthens synthetic identity detection by revealing how apparently independent accounts may share infrastructure, behavior, and control.
The strongest approach does not block users because of one device attribute. It combines device evidence with document authenticity, face and liveness results, account relationships, and transaction behavior. FinAuth enables this layered model, helping businesses identify coordinated fraud while preserving efficient onboarding for legitimate customers.
