Identity theft typically involves an attacker stealing a real person's information to impersonate them. Synthetic identity fraud differs by manufacturing a new identity, combining real data points with fabricated ones to create a non-existent person. This makes it harder to detect because no real victim monitors for misuse, allowing the fake identity to accumulate credibility over time.
The principle of synthetic identity fraud has a parallel with Non-Human Identities (NHIs), which are machine-side identities. While security teams focus on protecting NHIs from being stolen, the concept of fabricated NHIs, which were never legitimately provisioned, is rarely discussed. Attackers do not hijack existing service accounts but instead fabricate new ones.
As enterprises accumulate NHIs rapidly, a fabricated one can easily integrate if governance is weak and human ownership is absent. This approach blends real environmental attributes with fake ones, making the fabricated NHI appear legitimate.
For machine identities, an attacker creates an identity that was never supposed to exist, rather than borrowing a real one. This could involve registering a new admin-level identity with a similar naming structure to legitimate accounts and granting it privileges. Since nothing is hijacked, there are no alerts for compromised users or suspicious behavior to flag.
These fabricated NHIs are convincing because they combine real and invented attributes. They inherit naming conventions, exist in the correct domain, carry plausible metadata, and request permissions similar to other NHIs. To an administrator reviewing a large directory of service accounts, such an identity appears as a routine workload, making it an overlooked risk.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Synthetic identity fraud, traditionally understood as creating fake human identities, is now identified as a significant, under-discussed threat to Non-Human Identities (NHIs). Attackers can fabricate new machine identities by blending real and fake attributes, making them difficult to distinguish from legitimate ones. This method bypasses traditional security measures focused on detecting hijacked accounts, posing a challenge for organizations managing a growing number of NHIs.