New Account Fraud Is Already on Your Books

WRITTEN BY
The fraud numbers that get attention are the ones with a victim who files a report. Account takeover. Stolen credentials. A real person who calls the bank and says something is wrong.
New account fraud does not work that way. The person who opens the account does not even exist. No one calls. No one complains. The loss does not surface until the account has been used, the credit has been extended, and the fraudster has disappeared.
According to Javelin Strategy and Research’s 2026 identity fraud study "The Illusion of Progress," traditional fraud losses held steady.
New account fraud surged 31% year-over-year, affecting 5.4 million victims in 2025.
The headline number looked fine. The account-opening layer is where the exposure is accumulating.
Most lenders are measuring the wrong thing. The fraud that is accumulating on their books right now will not show up in this quarter's loss report. It will show up in next year's charge-offs. By then, the accounts are closed and the assets are long gone.
What New Account Fraud Actually Is in 2026
New account fraud is not a new category. What is new is the architecture behind it.
A traditional new account fraud scheme required a stolen identity, a willing fraudster, and enough patience to build a credit history before cashing out. Today’s version is faster, more scalable, and harder to catch. Synthetic identity fraud increased 8x year-over-year, according to LexisNexis Risk Solutions’ 2026 Cybercrime Report, derived from analysis of 116 billion transactions. These are not stolen identities. They are constructed ones: real Social Security numbers combined with fabricated names, addresses, and credit histories, built over months or years to pass prime and near-prime credit filters.
Fraudulent accounts that survive onboarding can remain hidden until they ultimately surface as charge-offs. Ghost customers built on synthetic profiles apply for credit across multiple lenders simultaneously. They make payments on time until the credit limit is maxed. Then they stop.
No real victim exists to file a complaint. The account looks legitimate until it is not.
Why the Numbers Are Worse Than They Appear
Sophisticated fraud attacks almost tripled in 2025, rising from 10 percent to 28 percent of all fraud attempts. Sumsub’s analysis found synthetic identities were used in 1 in 5 first-party frauds detected. Those are the schemes that were caught. The ones that were not caught are still on the books.
Misclassification compounds the problem. The 2026 Risk Officer Report from Federal Reserve Financial Services, drawn from a survey of more than 400 risk professionals at financial institutions, confirms the direction: fraud attempts and losses are rising across the board, with account takeover and impersonation schemes leading the volume. More critically, what appears to be first-party fraud at account opening frequently masks synthetic identity exposure. Teams classify it, close the case, and move on. The hybrid scheme underneath stays undetected.
Javelin’s 2026 Fraud Management Trends report identifies three defining fraud patterns for the year: rapidly evolving mule activity, the need to distinguish agentic commerce bots from malicious automation, and the surge in phantom hacker schemes. All three converge at the account-opening layer, where the verification window for intervention is shortest.
What Is Getting Through Onboarding
Two categories of fraud are opening accounts at scale right now, and most verification stacks were not built to stop either of them.
The first is synthetic identity. The profile passes document verification because the documents are real-looking. It passes credit checks because the SSN has a thin but clean file. It passes behavioral checks because the application was completed by a human or a script that mimics human behavior perfectly. Each individual check returns a pass. No individual check had the full picture.
The second is agentic bot traffic. LexisNexis Risk Solutions found that agentic bot traffic rose 450 percent between January and December 2025. Malicious bots now mimic genuine human cursor movements and behavioral signals with high plausibility, fooling the behavioral fraud detection tools that most fintechs and digital lenders rely on for non-document signals, often because those tools were the fastest to deploy, not because they were built for this threat.
The same architectural problem that makes video injection attacks difficult to catch at the liveness layer applies here. The attack is designed to satisfy each check in isolation. No single gate sees the full picture, because no single gate was built to.
Why Most Lenders Don’t Know It Yet
The detection gap is structural, not operational. Most verification stacks were designed around a threat model built on human behavior. A real person applying for credit makes mistakes, shows hesitation, takes time on difficult questions, and leaves behavioral traces that fraud rules were trained to catch.
Synthetic identities and agentic bots do not make those mistakes. The session runs cleanly. The application is completed correctly. The documents look right. And because no real victim exists to flag the account, nothing triggers a review.
The World Economic Forum’s analysis of identity fraud in the age of AI notes that payment method fraud now surpasses ID document fraud in frequency, which signals that criminals have moved past account creation to exploit what happens after an account is opened. The account opening was the easy part. Most stacks still think it is the hard part.
The lag between fraud commission and fraud detection in new account schemes is measured in months, not days. Javelin’s data shows consumers spent an average of 10.4 hours resolving identity fraud issues in 2025, up from 9.5 hours in 2023, reflecting schemes that blur typology boundaries and require more investigation time to untangle. For lenders, that resolution time is preceded by a period of apparent normalcy that can last an entire credit cycle.
The Detection Problem Is a Signal Problem
The accounts getting through are not getting through because verification is absent. Most fintechs and digital lenders are running document checks, credit pulls, and identity confirmation at the point of application. Many stood up those checks fast, through APIs and point solutions, because that was what getting to market required. The problem is that those checks are evaluated in sequence, in isolation, with no shared intelligence between them.
A synthetic identity is built to satisfy each check independently. The document check sees a real-looking ID. The credit check sees a thin but clean file. The behavioral check sees a completed application with no anomalies. Each signal returns a pass. The aggregate picture, if anyone were looking at it, would tell a different story. But no one is looking at the aggregate, because the signals are not generally being aggregated and normalized for a clear, holistic picture.
Regula Forensics’ research on how banks and fintechs will verify in 2026 found that nearly half of respondents now identify orchestrated verification workflows as the most effective counter to emerging fraud. Over 75 percent of banks and fintechs cite insufficient staffing to manage fragmented IDV systems. The detection gap and the staffing gap are the same problem: too many signals, arriving in too many formats, with no infrastructure to translate them into a single decision.
Every signal in the stack (biometric, behavioral, device, document, and credit) needs to flow through a normalization layer that translates disparate provider outputs into a consistent, actionable format before a risk decision is made. That is what allows signals to be corroborated rather than just collected. An AI model cannot reliably score or act on signals that arrive in inconsistent formats from disconnected providers. Normalize the inputs and the decisioning layer has something real to work with. That is the infrastructure layer Grid sits upon, and it is what makes corroboration across providers possible rather than theoretical.
What the Verification Stack Needs to Change
Better document verification is not the answer. Better credit checks are not the answer. The lenders catching synthetic identity fraud are not running better individual checks. They are running checks that talk to each other.
Corroboration across signals is the architectural requirement. Datos Insights’ research on fraud orchestration found that more than 50 percent of financial institutions report experiencing inadequate orchestration of their fraud controls, despite (not because of) their multi-vendor stacks. Adding vendors without a shared infrastructure underneath them makes the fragmentation problem worse, not better.
The practical questions that determine whether a stack is built to catch what is coming through:
Are document signals, behavioral signals, device signals, and credit signals being corroborated against each other, or evaluated in sequence with no shared intelligence?
Is the verification workflow triggered at application only, or does the stack support continuous monitoring after account opening?
When a new account shows early behavioral anomalies post-onboarding, does that trigger a reverification workflow, or does the account continue unreviewed?
Is synthetic identity detection in place, or does the stack rely on credit bureau data alone to flag thin files?
When fraud is detected, is the classification process rigorous enough to distinguish synthetic identity from first-party misrepresentation, or does misclassification bury the real exposure?
The lenders who will absorb this loss cycle are the ones whose stacks were built to answer yes to all of those questions. The ones who will not are running more point checks and calling it a stack. Vendor fragmentation is why fraud goes undetected, and the market is now moving fast toward unified infrastructure as the definitive response.
New account fraud is not a headline event. There is no breach notification. No regulator press release. No moment when the loss becomes visible. It accumulates quietly, in accounts that passed every check, opened by identities that never existed, run by fraudsters who were gone before anyone started looking.
The 31-percent surge Javelin documented is the number that was measurable. The exposure sitting in current books but not yet found is not yet measurable. It will be, when the accounts mature, and the charge-offs arrive.
The question worth asking now: if a synthetic identity opened an account in your portfolio last quarter, what signal would have caught it?
If that answer requires more than one vendor conversation to find, that is the architecture worth examining.
