← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Synthetic Identity Fraud Emerges as Threat to Machine Identities

New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Synthetic identity fraud creates new, fake identities, not stolen ones.
  • This concept applies to Non-Human Identities (NHIs) in enterprise environments.
  • Fabricated NHIs are hard to detect as they mimic legitimate accounts.
  • Attackers create new admin-level NHIs rather than hijacking existing ones.

Understanding Synthetic Identity Fraud

Identity theft typically involves an attacker stealing a real person's information to impersonate them. Synthetic identity fraud differs by manufacturing a new identity, combining real data points with fabricated ones to create a non-existent person. This makes it harder to detect because no real victim monitors for misuse, allowing the fake identity to accumulate credibility over time.

Synthetic Fraud for Machine Identities

The principle of synthetic identity fraud has a parallel with Non-Human Identities (NHIs), which are machine-side identities. While security teams focus on protecting NHIs from being stolen, the concept of fabricated NHIs, which were never legitimately provisioned, is rarely discussed. Attackers do not hijack existing service accounts but instead fabricate new ones.

As enterprises accumulate NHIs rapidly, a fabricated one can easily integrate if governance is weak and human ownership is absent. This approach blends real environmental attributes with fake ones, making the fabricated NHI appear legitimate.

How Fabricated Machine Identities Operate

For machine identities, an attacker creates an identity that was never supposed to exist, rather than borrowing a real one. This could involve registering a new admin-level identity with a similar naming structure to legitimate accounts and granting it privileges. Since nothing is hijacked, there are no alerts for compromised users or suspicious behavior to flag.

These fabricated NHIs are convincing because they combine real and invented attributes. They inherit naming conventions, exist in the correct domain, carry plausible metadata, and request permissions similar to other NHIs. To an administrator reviewing a large directory of service accounts, such an identity appears as a routine workload, making it an overlooked risk.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~39 min · 35 stories · Jul 22

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Synthetic identity fraud, traditionally understood as creating fake human identities, is now identified as a significant, under-discussed threat to Non-Human Identities (NHIs). Attackers can fabricate new machine identities by blending real and fake attributes, making them difficult to distinguish from legitimate ones. This method bypasses traditional security measures focused on detecting hijacked accounts, posing a challenge for organizations managing a growing number of NHIs.