Application Fraud: Detecting New Account Fraud at Onboarding

Most fraud controls work by spotting what looks abnormal, such as a login from a new device, a payment that breaks a customer's usual pattern, a sudden change in behavior. On the other hand, application fraud, also called new account fraud, has differences from all of that by happening before any pattern exists. Since the account is brand new, there is no baseline, history and nothing to compare against. A criminal using a stolen or synthetic identity looks just like a real new customer, and by the time anomaly detection would normally step in, the fraud is already done.

That is why application fraud is fundamentally an onboarding problem, not a monitoring one. Catching it means shifting the question from "is this transaction unusual" to "is this applicant who they claim to be," which is exactly what makes it the first line of defense for any institution that opens accounts.

The following topics are going to be covered in this article;

  1. What Is Application Fraud?
  2. First-Party vs Third-Party Application Fraud
  3. Synthetic Identity as the Main Vector
  4. Red Flags at Onboarding
  5. How to Detect It
  6. The Know Your Customer (KYC) and Know Your Business (KYB) Tie
  7. How Sanction Scanner Helps

Mceclip0 8

1. What Is Application Fraud?

Application fraud, also called new account fraud, is a type of fraud where a criminal opens a new account using a stolen, synthetic, or fake identity. It happens at the very start of the account-opening process, before any legitimate relationship exists, which is what makes it so hard to catch. Unlike account takeover, where a fraudster hijacks an account that already exists, application fraud creates the fraudulent account from scratch. There is no prior activity to compare against, so detection depends almost entirely on identity verification and risk scoring at onboarding. This is why stopping application fraud is the first line of defense for any institution that opens new accounts.

Synthetic identity fraud, the main vector behind application fraud, is one of the fastest-growing financial crimes in the US, with losses surpassing $35 billion in 2023, and the Federal Reserve has warned that generative AI is making these fake identities even harder to detect.

The main issue here is that when someone new signs up, there's no past behavior to look at, so we can't catch the fraud like we usually do. Instead, we have to rely on checking if the person is who they say they are, looking at the documents and devices they use, and scoring how risky they seem. This is different from how we normally catch fraud, which is by looking at patterns in transactions.

Mceclip2 6

2. First-Party vs Third-Party Application Fraud

There are two types of application fraud, first-party and third-party, and they are stopped in different ways.

Third-party application fraud, where someone uses another person’s identity to apply for credit either by stealing the real person’s identity or by creating a completely synthetic identity. In this case, the key question is identity verification: Is the real person sitting in front of the application truly the identity that has been verified?

In cases of first-party application fraud, the applicant themselves provided false information, typically regarding their income or intentions. Most notably, this type of fraud would involve the applicant’s intent to commit fraud and default on the credit they obtained. Since the identity of the applicant is not stolen (whether as a whole identity or as part of a synthetic identity), the main line of defense against first-party application fraud would consist of intent and behavioral signals as well as the corresponding credit risk models.

Bust-out fraud sits between first-party and third-party fraud, because it can start from either a synthetic identity or a real one used in bad faith. The fraudster first opens an account and keeps it in good standing, paying on time to earn higher credit limits. Once the limit is high enough, they max out every line and disappear, leaving the balance unpaid. It is one of the more common fraud types by volume, which makes it worth watching for even though it unfolds slowly.

Third-Party Fraud

First-Party Fraud

Identity used

Stolen or synthetic

The applicant's own, real identity

Core question

Is this person who they claim to be?

Does this person intend to repay?

Primary defense

Identity verification, document and biometric checks

Behavioral signals and credit risk modeling

Typical hybrid

Synthetic identity nurtured into bust-out

Real identity used for bust-out

There is also an operational distinction here. Third-party fraud tends to surface at application time, for example, a mismatched Social Security Number (SSN) or a device flagged for use by multiple identities. First-party fraud is more difficult to detect at application time, since the identity in question appears to be perfectly valid. However, the intent to commit fraud in this case is also not expressed through the identity in question (i.e. it is not that the individual is using someone else’s identity in order to commit fraud). Instead, the intent to commit fraud in cases of first-party fraud surfaces after an account has been opened through normal identity processes. Institutions rely on identity verification tools that are well-suited to catching third-party fraud and synthetic identities, but these tools cannot detect first-party fraud, where the identity itself is genuine.

3. Synthetic Identity as the Main Vector

A synthetic identity is created using a combination of real information (e.g. SSN that was stolen or not yet issued) and completely fabricated information (name, date of birth, address, etc.).

Synthetic identity fraud has no single victim. Because the identity is fabricated rather than stolen from one real person, there is no one to notice the misuse and report it. When a synthetic account is charged off, the institution usually books it as bad debt and never identifies fraud as the cause. That is why the crime is so badly undercounted. The losses are recorded as credit losses, not fraud, so reported detection stays low while the true incidence runs far higher.

But there is a deeper issue of lack of regulations around SSN verification, which was made more challenging when the Social Security Administration started randomly issuing SSN’s in 2011. This change in the way SSN’s are issued to citizens made it far harder for financial institutions to verify whether an SSN was “valid” for a given applicant, taking into account the age of the applicant and their location in the country. Synthetic identity fraudsters have taken full advantage of this change in the way SSN’s are issued.

Generative AI has made identity fabrication faster and more convincing. Fraudsters now use it to produce fake supporting documents, fabricated backgrounds, and even synthetic family members, and to generate deepfake media that can defeat the identity checks meant to stop them. This is not a fringe concern. In November 2024, the U.S. Treasury's FinCEN issued an alert warning financial institutions about a rise in fraudulent identity documents created with generative AI being used to circumvent identity verification and authentication, and reminded them of their related suspicious-activity reporting obligations under the Bank Secrecy Act.

4. Red Flags at Onboarding

Well-constructed synthetic or stolen identities can leave very little trace, but in most cases they still leave some. These warning signs at onboarding tend to fall into five categories.

Identity inconsistencies: Mismatches across the applicant's details such as name, SSN, and date of birth, an SSN that was issued after the applicant's stated date of birth, or a single address or phone number tied to multiple identities.

Device and velocity anomalies: Multiple applications from the same device or IP address, a burst of submissions in a short window, and signs of automation, all of which can point to a large-scale fraud operation rather than a single applicant.

Thin or fabricated credit files: A very new and suspiciously clean credit history, a file padded with many authorized-user accounts, or other credit-building activity that looks engineered to be busted out later.

Reused or shared attributes: The same email, phone number, or address appearing across otherwise unrelated applications. Catching this requires linking all applications that share data points, because each one looks legitimate on its own.

Document anomalies: Submissions backed only by templated or AI-generated documents, such as a scanned or photographed front and back of a driver's license, with no original source file, metadata, or other evidence of the document's authentic provenance.

On their own, these signals are weak. They become meaningful when they cluster like an identity mismatch on a device tied to several other applications, or a fabricated-looking document alongside a thin credit file for a first-time applicant. Treating each of these red flags in isolation as if they were simply check boxes is likely to result in false positives that increase the load on reviewers and which will tend to erode trust in the review process. Instead, the red flags should be treated as a correlated set of red flags that indicate the presence of a synthetic identity as opposed to a thin-file customer.

Mceclip3 5

5. How to Detect It

Identity verification at onboarding uses a layered set of methods. It starts with document verification, such as an ID card, then moves to biometric checks like face or iris, and to liveness detection to confirm the user is a real, present person. This stage needs particular attention to injection attacks and attempts that use deepfakes or fabricated media.

Behavioral and device signals are collected at the time of application, not after the account is opened, when it is too late to take action.

Cross-application link analysis catches fraud rings. Accounts that each look clean in isolation but share attributes that, considered together, reveal coordinated fraud. The greatest value of cross-application link analysis is that each synthetic account is created and tested to pass on its own, so the fraud is only visible once the accounts are linked.

Data from a consortium of institutions and from signals shared by institutions fills a gap that no single institution can fill so lenders do not typically have a view of the entire pattern of a synthetic identity created and tested across multiple institutions that the identity interacts with.

A combined risk score brings all of these inputs together into one approve, review, or decline decision at onboarding.

The layers of this stack were carefully ordered. It would be a complete waste of time and money to do cross-application link analysis or use consortium data to look for patterns before doing basic identity verification to find document mismatches. Conversely, relying solely on identity verification without the network view provided by link analysis and shared signals would mean that a synthetic identity would pass all the identity verification checks. The reason for the layered approach is that each layer is able to catch what the preceding layer was not designed to see.

6. The Know Your Customer (KYC) and Know Your Business (KYB) Tie

Application fraud is, by nature, a failure of onboarding, so it cannot be addressed in isolation from a complete Know Your Customer (KYC) and Know Your Business (KYB) program. Fraud prevention and compliance are really looking at the same checks from two angles: one to avoid a fraud loss, the other to meet a regulatory obligation.

Two core parts of the KYC process map directly onto application fraud detection. The first, the Customer Identification Program (CIP), is the minimum identity information a firm collects to verify, as far as is reasonable, the true identity of the person opening an account before the account is opened.

The Customer Due Diligence(CDD) process then assesses the risk of the customer behind the verified identity. Screening and verification of identity as a first-line fraud detection process for third-party and synthetic identity fraud is essentially the CIP and CDD processes done well. A synthetic identity would fail CIP checks that are performed poorly. A fabricated income would fail the CDD process. It is the same set of processes, used by two teams, compliance and fraud, with slightly different vocabulary.

For business onboarding, the same principle applies through KYB. Verifying a company's legitimacy, its structure, and its owners is a core onboarding step, and identifying the Ultimate Beneficial Owner (UBO), the person who ultimately owns or controls the company, is central to it. A UBO can be hidden behind a complex corporate structure, but establishing who it is separates a real business from a fabricated one or a shell entity. Just as a synthetic identity is built to pass as a real person, a fictitious company is built to pass as a real business, opening accounts and moving money under the appearance of genuine economic activity.

Screening and verification is performed in order to prevent application fraud as part of the onboarding workflow before any live fraud monitoring is enabled on an account. Treating screening and verification as a separate secondary control is therefore how application fraud can happen in the first place.

7. How Sanction Scanner Helps

When an account is created and behavioral history is not yet available, Sanction Scanner's FUSION platform supports the onboarding decision by combining customer risk scoring with name screening across sanctions, PEP, and adverse media.

That gives institutions a defensible accept-or-review decision at the point of onboarding. Because Fusion's fraud monitoring runs on the same shared data, the risk picture built at onboarding carries straight through to ongoing monitoring once the account is active. The result is a single, continuous view of the customer rather than two disconnected systems handing off between onboarding and live monitoring.

Mceclip1 7

Sources:

[1] Federal Reserve Bank of Boston. Gen AI Is Ramping Up the Threat of Synthetic Identity Fraud. 2025.

[2] Federal Reserve, FedPayments Improvement. Synthetic Identity Fraud. 2024.

[3] Financial Crimes Enforcement Network. FinCEN Alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions (FIN-2024-Alert004). 2024.

[4] Social Security Administration. Social Security Number Randomization. 2011.

FAQ's Blog Post

Cross-application link analysis matters because each synthetic account is built and tested to pass on its own. Individually, every application looks clean. The fraud only becomes visible once accounts are linked by shared attributes like a common device, email, or address, which is why no single-application check catches a coordinated ring.

Bust-out fraud sits between first-party and third-party fraud. The fraudster opens an account, keeps it in good standing to earn higher credit limits, then maxes out every line and disappears, leaving the balance unpaid. It unfolds slowly, which makes it easy to miss, but it is common enough by volume to watch for.

Application fraud is a failure of onboarding, so it maps directly onto KYC and KYB. Done well, the Customer Identification Program and Customer Due Diligence that satisfy regulators are the same checks that stop third-party and synthetic identity fraud. Fraud and compliance run the same processes from two angles.

Institutions detect application fraud with a layered onboarding stack: Document verification, biometric and liveness checks, behavioral and device signals collected during the application, cross-application link analysis to expose fraud rings, and consortium data shared across institutions. A combined risk score turns all of it into one approve, review, or decline decision.

Application fraud red flags cluster in five areas: Identity inconsistencies like an SSN issued before the applicant's birth date, device and velocity anomalies, thin or suspiciously clean credit files, reused attributes shared across unrelated applications, and templated or AI-generated documents. Any one is weak alone; together they signal a synthetic identity.

Synthetic identity fraud combines real information, such as a stolen or unissued Social Security number, with fabricated details like name and date of birth. Because the identity belongs to no single real person, no one notices the misuse and reports it, so losses get booked as bad debt and the crime stays badly undercounted.

Application fraud is hard to detect because it happens before any pattern exists. A new account has no baseline, so the usual anomaly detection has nothing to compare against. A criminal using a stolen or synthetic identity looks exactly like a genuine new customer, and by the time monitoring would normally step in, the fraud is already done.

Third-party application fraud uses someone else's identity, whether stolen or synthetic, so the core question is whether the applicant is who they claim to be. First-party fraud uses the applicant's own real identity with false information about income or intent to repay. Third-party fraud yields to identity verification; first-party needs behavioral and credit-risk signals.

The difference is which account is targeted. Application fraud creates a fraudulent account from scratch at onboarding, so there is no history to compare against. Account takeover hijacks an account that already exists, so detection can lean on the customer's established behavioral baseline. One is an onboarding problem, the other a monitoring one.

Application fraud, also called new account fraud, is when a criminal opens a new account using a stolen, synthetic, or fake identity. It happens at the very start of onboarding, before any legitimate relationship exists. Because there is no prior activity to compare against, detection depends almost entirely on identity verification and risk scoring.