News

A Fake Person That Passes Bank Verification Costs $200. Here’s How They’re Built.

synthetic identity dark web

Somewhere on a dark web marketplace right now, you can buy a complete human identity for $200. It doesn’t belong to a real person. No real person was directly robbed to create it. But it has a name, an address, a Social Security number, a face that passes automated camera checks, and a voice that passes phone authentication, and it can open a bank account in about the same amount of time it would take you to.

If that sounds like science fiction, it was, until recently. Synthetic identity fraud has existed as a concept since the early 2000s. But AI has changed the cost and the scale of it so dramatically in 2026 that researchers now call it a “full-scale dark web industry” rather than a specialist criminal technique.

This week, identity protection firm Coveron and threat intelligence platform NordLayer published the most detailed pricing and supply breakdown of this market seen publicly. Here’s what they found, why it matters, and what it means for anyone whose data has ever appeared in a breach.

Quick answer: Coveron and NordLayer Intelligence analyzed over 362,000 dark web forum and Telegram posts and found complete synthetic identities, fake human personas capable of passing automated bank KYC checks, selling for as little as $200. Individual components like deepfake selfies go for $10 to $200. These identities combine real stolen data like Social Security numbers with AI-generated names, deepfake faces, and three-second voice clones. The market for this service has grown eightfold since 2024. McKinsey estimates synthetic identities now account for 10 to 15% of unsecured lending charge-offs in the United States.

What a “Digital Frankenstein” Actually Is

The term is dramatic, but the mechanics are straightforward once you break them down.

A synthetic identity is not a stolen identity. When someone’s real identity is stolen, a criminal impersonates an existing person,ย  uses their real name, their real address, and their real credit history. The victim notices eventually, because activity appears on their real accounts.

A synthetic identity is something different. It’s a person who does not exist, built from a patchwork of real and fabricated data. Typically, it starts with a real piece of identifying information, almost always a Social Security number from a data breach, and attaches it to a made-up name, a made-up address, and an AI-generated face. Add a cloned voice from a three-second audio sample, add a deepfake selfie that passes liveness detection, and you have a complete human being that no real human can report stolen, because no real human was ever attached to it.

synthetic identity dark web

This is why the fraud is so persistent. When a real identity is stolen, the victim can dispute fraudulent accounts and freeze their credit. When a synthetic identity is used for fraud, there is no victim to detect it until the institution that extended credit realizes the person it lent money to simply does not exist.

The raw material for these identities comes from exactly the kinds of breaches we’ve covered throughout 2026. The 153 million driver’s license database exposed through IDScan.net provided names, addresses, physical descriptions, and license numbers, everything needed to make a synthetic identity appear grounded in a specific real state and region. The Bank of Baroda breach exposed full KYC records, including Aadhaar numbers and photographs. Each large breach adds to a growing supply of authentic building blocks that fraudsters use to construct identities that look real because parts of them are.

The Full Price Menu: From $10 to $2,000

Coveron’s research, drawn from 22 queries across 362,000 dark web forum and Telegram channel posts, found a structured market with distinct product tiers. This isn’t an informal grey market. It operates with guaranteed delivery windows, tiered pricing, and, as Coveron’s managing director Tomas Sinicki noted, refund policies.

The cheapest entry point is $10 to $50: a single deepfake image or a basic document scan, enough to bypass one automated identity check on a single platform. This is the product tier most relevant to fraud at scale, low cost, and mass deployed across many targets simultaneously.

A deepfake selfie for use in video identity verification sells for $50 to $200. These aren’t simple photo edits. They’re AI-generated images calibrated to pass liveness detection systems, which are supposed to verify that the person is real and present by checking for blink patterns, micro-movements, and lighting variation. The tools generating these can replicate all of those signals in real time at latency under 50 milliseconds, according to video identification vendor telemetry.

A custom voice clone costs $50 to $300. Three seconds of source audio, pulled from a social media video, a recorded call, a public statement, or a news clip, is enough for current voice synthesis tools to generate unlimited speech in a matching voice. The resulting clone is used to pass phone-based voice authentication or interactive IVR identity checks.

The complete synthetic identity package, Social Security number plus AI-generated name and address plus deepfake selfie plus matching documents, sells for around $200. This is the entry point for opening financial accounts, passing bank onboarding, and accessing cryptocurrency exchanges.

At the premium end sits what researchers call the “digital ghost” package, priced at $500 to $2,000. This is not just a fake identity. It’s an aged fake identity, one that has existed for six months to two years, has verified accounts with real usage history, and comes with a matched device fingerprint. This product is designed for situations where a simple identity isn’t enough because the target platform checks account age, activity, and behavioral consistency. The digital ghost passes those checks because it has been incubating long enough to look legitimate.

Cato Networks separately documented a commercial toolkit called ProKYC, sold at around $629 per year, that bundles synthetic document generation with real-time deepfake video specifically built for financial institution onboarding flows. MIT Technology Review found 22 public Telegram channels offering virtual camera injectors and deepfake generators from around $30. This market is not hidden. Parts of it are openly advertised.

The Three Ways These Bypass KYC

Understanding exactly how fake identities defeat identity verification matters because the defenses depend on knowing which attack vector is being used.

The Three Ways These Bypass KYC

Face-swapping is the most widely used. A fraudster sits in front of a webcam while a real-time AI model replaces their face with the synthetic face from the digital identity being used. The swap runs at under 50 milliseconds latency, which makes it invisible to video-based verification. Passive liveness detection, which checks that the face is genuinely present by looking for blink patterns and micro-movements, gets defeated because the swap engine generates exactly those movements in the synthetic face overlay. Crucially, the document being verified can be genuine (stolen) or synthetic, while the face on screen is entirely generated.

Camera injection goes a step further. Rather than sitting in front of a webcam at all, a camera injection module inserts a fully pre-generated or synthesized video feed directly into the computer’s operating system at the camera driver level. The verification application receives what looks like a webcam signal, but it’s entirely fake, a generated stream with no real person behind it. The application sees a person. There is none.

Voice cloning attacks phone-based and IVR authentication. A three-second clip of a target’s voice, or any voice that matches the demographic characteristics needed, feeds a synthesis engine that can then generate that voice saying anything in real time. For synthetic identity fraud, this doesn’t even need to match a real person’s voice. It just needs to sound natural and consistent across verification calls.

Group-IB documented 8,065 biometric injection attempts against a single financial institution’s digital loan onboarding system between January and August 2025 alone. That’s one institution. The attacks are happening at industrial scale.

The Credit-Building Phase Nobody Talks About

Most coverage of synthetic identity fraud treats it as an account opening problem. Open a fake account, commit fraud, disappear. But that’s not how the most damaging synthetic identity schemes work.

The more sophisticated approach involves an incubation phase. A synthetic identity opens accounts and uses them responsibly for months, small purchases, on-time payments, modest credit limit increases. The identity builds a credit history that looks entirely legitimate to automated scoring systems because it is, by the system’s metrics, legitimate. Then comes what fraud researchers call the “bust out”: the identity applies for maximum available credit across multiple lenders simultaneously, maxes every account in a short window, and vanishes. No real person is looking for the fraud, because no real person was attached to the identity.

McKinsey estimates that synthetic identities now account for 10 to 15% of charge-offs in unsecured lending in the United States. A charge-off is when a lender writes off a debt as uncollectable. Most of that 10 to 15% is written off as credit loss, not fraud, because the lender has no real person to pursue, and the detection systems didn’t flag the identity as fake while it was performing well.

The institutions absorbing these losses are credit card issuers, buy-now-pay-later providers, personal loan platforms, and neobanks, the same financial infrastructure that processes legitimate consumer transactions every day. The losses eventually flow back into higher interest rates, tighter lending criteria, and reduced credit access for real people.

How Fast This Market Has Grown

The scale of growth is one of the most striking elements of Coveron’s research.

In Q1 2024, there were roughly 40 dark web posts per month discussing deepfakes in the context of identity fraud. By Q2 2026, that number had risen to 307 per month, an eightfold increase in two years. The growth wasn’t gradual. It was flat through 2025 and then jumped sharply in 2026, when monthly averages hit 255 posts.

NordLayer’s separate data confirms the shape of that curve. In the first five months of 2026 alone, discussions about deepfake-as-a-service on monitored channels already exceeded the full-year total for 2025 by 39%. If the pace holds, the 2026 total will be roughly 3.3 times the 2025 level.

A dark digital landscape where small glowing seeds of deepfake technology

In the past year alone, Coveron identified 10,463 posts offering complete identity data bundled with deepfake selfies and ready-to-use documentation, and a further 7,845 posts advertising what the market calls “raw KYC bypass kits”, Social Security numbers combined with matching driver’s license images and deepfake selfies.

This is a market that grew because the tools to build it became cheap and the raw material to feed it became abundant. The raw material is data from breaches, and 2026 has been a significant year for breaches. As we covered in our piece on what the underground market for stolen credit cards looks like, criminal markets self-organize around cost efficiency. When breach data became cheap and AI image tools became accessible, the synthetic identity market expanded to fill the opportunity.

Your Social Security Number Is the Foundation

Here’s the uncomfortable element that most coverage of this story glosses over: a synthetic identity still needs a real Social Security number.

It doesn’t need your Social Security number specifically. It needs any real SSN that hasn’t already been heavily used to build a credit profile. This is why the synthetic identity market disproportionately targets certain demographics, children, elderly people, new immigrants, and people who have historically had limited credit access, whose SSNs are less likely to have extensive credit histories attached, making them easier to “clean” and build a fake profile around.

Your SSN from a data breach doesn’t just expose you to identity theft in the traditional sense. It can become the backbone of a synthetic identity that frauds financial institutions in a name you’ve never heard of, attached to a face you’ve never seen. You may never know. The bust-out damage appears on the lender’s books, not yours. But the SSN at the root of it is yours.

This is why we have consistently emphasized, across our coverage of the Substack breach and the Greenberg Traurig law firm incident,that Social Security number exposure is categorically more serious than email or password exposure.ย  A password can be changed. An SSN cannot.

Businesses Can No Longer Trust What They See on Screen

The implications for any company that verifies identities remotely are significant.

A single-factor identity check, upload a photo of your ID, has been obsolete for some time. A video selfie check is now also being defeated systematically. Even multi-step biometric verification that includes liveness detection is being beaten by camera injection and real-time face-swap at scale.

The practical implication for risk teams is uncomfortable: the assumption that “passing KYC” is equivalent to “this is a real person” is no longer safe. That assumption needs to be replaced with a layered model that combines document verification, behavioral analysis, device fingerprint history, and out-of-band verification where stakes are high.

In Europe, the emerging answer is the eIDAS 2.0 European Digital Identity Wallet, which is being rolled out through 2026 and 2027. It promises portable, cryptographically verified identity that doesn’t rely on document scanning or biometric video checks, reducing the attack surface for synthetic identity creation significantly. In the US, there is no equivalent national framework in force yet.

For individuals, the practical connection runs through data exposure. As we covered in our guide to what to do when your data is on the dark web, the most effective defensive steps remain credit freezes and active monitoringnot because they prevent synthetic identities from being built, but because they limit what can be done with a real SSN when it’s combined with fake credentials.

What You Can Actually Do

The honest answer is that individuals have limited ability to prevent synthetic identities from being created using their leaked data. Once an SSN is in circulation in breach databases, it’s there. What individuals can do is make it harder to use and faster to detect.

Freeze your credit at all three bureaus. Equifax, Experian, and TransUnion each allow a free security freeze. A freeze doesn’t prevent someone from using your SSN as the foundation of a synthetic identity, but it prevents that identity from opening new credit accounts with your SSN successfully. It’s the most effective single step available to consumers.

Set up credit monitoring with real-time alerts. New inquiries on your credit file, new account openings, or address changes are signals that your SSN may be in use. Catching these early limits the window for a bust-out scheme to build credit before you notice.

Check your Social Security statement annually. The Social Security Administration’s online portal lets you see earnings attributed to your SSN. An SSN being used by a synthetic identity for employment-based fraud will show up here as earnings you didn’t receive.

Be cautious of unsolicited identity verification requests. A message asking you to verify your identity for a service you didn’t initiate, particularly one that asks for a selfie, a voice recording, or a document scan, may be an attempt to capture your biometric data for use in a synthetic identity package. Go directly to official channels rather than responding to inbound requests.

For businesses doing ,ย KYC: single-factor or single-check approaches need urgent review. Layering document verification with behavioral signals, device history, and challenge-based verification is the direction the industry is movingand the data in this report suggests it needs to move faster.

Frequently Asked Questions

What is a synthetic identity?

A fake human identity that combines real stolen data, usually a Social Security number, with AI-generated names, addresses, deepfake photos, and cloned voices. It doesn’t represent any real person, but it’s designed to pass automated identity verification.

How much does one cost on the dark web?

Between $10 for a single deepfake image to bypass one check, and $200 for a complete identity package. Premium aged identities with credit histories sell for $500 to $2,000. Commercial toolkits for generating these at scale sell for around $629 per year.

How do synthetic identities beat KYC checks?

Through face-swapping (real-time AI overlay that passes liveness detection), camera injection (feeding a generated video stream to verification apps), and voice cloning (synthesising matching speech from a three-second audio sample).

Why are they hard to detect?

Because sophisticated schemes incubate the identity for months, building legitimate-looking credit behavior before executing a bust-out. Automated systems see consistent, normal usage until it’s too late.

What can I do to protect my SSN?

Freeze your credit at all three bureaus. Set up monitoring alerts for new inquiries and account openings. Check your Social Security earnings statement annually for unexplained employment records.

Written by Muhammad Anas

Contributing writer at DarkWebDecoded.com covering dark web security, scam alerts, and privacy tools.

๐Ÿ“‹ Latest Articles

View all →
Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here's How They Did It.
News

Seven Chinese AI Labs Stole 190 Million Claude Exchanges. Here’s How They Did It.

Between May and July 2026, accounts linked to Alibaba’s AI division generated more than three million conversations with…

Sep 14, 2026
11 min read
Greenberg Traurig Data Breach
News

Greenberg Traurig Data Breach: One Law Firm Hit. Six in Three Weeks. Here’s the Real Story.

Greenberg Traurig confirmed a data breach to Vermont’s Attorney General on September 8, 2026. A ransomware group called…

Sep 12, 2026
10 min read
Operation Alice dark web
News

Operation Alice: One Person Was Running 373,000 Dark Web Sites. Every Customer Is Now a Suspect.

Between March 9 and March 19, 2026, law enforcement agencies from 23 countries quietly dismantled one of the…

Sep 10, 2026
10 min read
Bank of Baroda Data Breach
News

Bank of Baroda Data Breach: Why TripleX Released 1TB for Free And Why That’s the Whole Story

When a ransomware group steals data, the usual move is to demand payment. Hand over the money, or…

Sep 10, 2026
10 min read
Infostealer logs illustration showing a glowing ZIP archive leaking stolen passwords, browser cookies, credit cards, and crypto wallet data from a laptop
Guides

Infostealer Logs – The Breach That Rarely Gets Reported

Infostealer logs: In the first half of 2025, over 1.8 billion credentials containing saved passwords, usernames, phone numbers,…

Sep 10, 2026
12 min read
Wireframe chat marketplace stamped "SEIZED" beside frozen crypto wallets, illustrating the Xinbi Guarantee takedown and $52.8M freeze.
News

Xinbi Guarantee Seized – Inside the $24B Telegram Scam Marketplace

If you ask the average person where the largest criminal marketplaces on the internet are located, they’ll say…

Sep 10, 2026
10 min read
0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted