Language

Identity Fraud

What is identity fraud?

Identity fraud is the deceptive use of another person's identity, a fabricated identity, or false identity information to obtain money, services, benefits, or access. It can occur when an account is opened or when an existing account is misused.
The deception may concern who the applicant is, whether the claimed identity exists, or who controls the account. This includes cases where genuine identity documents are used by someone other than their rightful holder.

What forms can identity fraud take?

Common forms include:
  • Impersonation: Using another person's personal information or documents to apply for an account, loan, or service
  • Synthetic identity fraud: Creating a fictitious identity from a combination of personal information, which may include real and fabricated details
  • Document-based deception: Submitting counterfeit or altered identity documents to support a false claim
  • Account takeover: Gaining unauthorized control of an existing account and acting as its owner
These categories can overlap. A criminal may use a forged document containing stolen details during account recovery. Synthetic identities can also incorporate information belonging to real people.

How can businesses detect identity fraud?

Detection starts by testing the identity claim and considering the circumstances of the application:
  • Document checks examine authenticity and consistency of the submitted identity evidence
  • Biometric verification compares the applicant with a trusted reference, with liveness and capture-security controls supporting remote checks
  • Source checks corroborate attributes against suitable issuer records or other reliable sources where available
  • Account and device analysis looks for suspicious reuse, coordinated applications, and changes in account control
For example, a genuine passport may pass document checks even when the applicant is impersonating its owner. Comparing the applicant with the document portrait addresses that separate risk. Later activity may still require investigation if the verified person lets someone else use the account.

How can Regula help with identity fraud?

Regula Document Reader SDK examines identity documents for signs of alteration or counterfeiting and checks consistency between available data sources.
Regula Face SDK compares the applicant's facial image with the document portrait and supports active or passive liveness detection.
Organizations can combine these results with account history and other fraud checks. Regula IDV Platform supports configurable verification processes and session review so teams can examine the evidence behind a decision.

FAQ

How should a business distinguish identity fraud from identity theft?

Identity theft concerns unauthorized use of a real person's identity information. Identity fraud also covers fabricated identities and other deceptive identity claims. Case records can use both labels when stolen information is used fraudulently; the categories are not mutually exclusive.

Does reusing an identity document prove fraud?

No. A customer may legitimately apply for several products or retry verification. Review whether the document is associated with conflicting names, different applicants, or suspicious account activity before treating reuse as fraud.

Can identity fraud occur after successful KYC?

Yes. Credentials may be stolen, recovery procedures manipulated, or account access transferred after onboarding. Customer due diligence and fraud monitoring need to consider subsequent activity, including changes in ownership, control, and expected account use.

When should an identity fraud alert receive manual review?

Review is useful when the evidence is conflicting, an automated result is inconclusive, or rejection could affect a legitimate applicant. Reviewers need the specific reason for the alert and a defined way to obtain additional evidence or correct the decision.

How should businesses measure identity fraud controls?

Measure confirmed fraudulent applications accepted, legitimate applications incorrectly flagged, review workload, and resulting losses. Report biometric false matches and false non-matches separately. Approval rates alone cannot distinguish successful verification from undetected fraud.

What should a business do after confirming identity fraud?

Protect affected accounts, preserve relevant evidence, and investigate connected activity. Correct inaccurate customer records and coordinate fraud, security, support, and compliance teams. Notifications, account restrictions, and reporting should follow the facts of the case and applicable requirements.

On our website, we use cookies to collect technical information. In particular, we process the IP address of your location to personalize the content of the site

Cookie Policy rules