synthetic identities are quietly hijacking BNPL and e-commerce checkouts

Person shopping online with a laptop and credit card, illustrating e-commerce identity verification

Retailers lost an estimated $115 billion to e-commerce fraud in 2024, and the fastest-growing driver isn't a stolen credit card — it's a shopper who was never a real person to begin with. Synthetic identity fraud, where criminals blend real data (a stolen Social Security number, a scraped address) with fabricated details to build a "customer" that passes onboarding checks, is projected to cost the U.S. economy $30–35 billion a year. In 2026, that fraud has found a new favorite target: the buy-now-pay-later checkout button.

Why BNPL and marketplace onboarding are exposed

Buy now, pay later (BNPL) platforms were built for speed — instant credit decisions, minimal friction, no lengthy underwriting. That same speed is what makes them attractive to fraud rings. Unlike a bank opening a mortgage, a BNPL provider or online marketplace typically has seconds to decide whether an applicant is real, and 8.3% of digital account creations were flagged as suspected fraudulent in H1 2025 — a number that keeps climbing as GenAI tools make fake applicants cheaper to manufacture.

Three structural gaps make this possible:

  • Thin-file approval logic. BNPL underwriting leans on identity and behavioral signals rather than deep credit history, so a synthetic profile with a plausible backstory can clear checks that would flag a thinner, but genuine, applicant.
  • Document-only KYC. Many checkout flows still verify identity with a photo ID upload and a selfie match — both of which generative AI can now fabricate convincingly.
  • Fraud-as-a-service tooling. Underground marketplaces sell ready-made synthetic identity kits, complete with fabricated documents and social media histories, lowering the skill bar for would-be fraudsters.

From stolen cards to manufactured customers

Classic identity theft leaves a trail: a real victim eventually notices a fraudulent charge. Synthetic identities don't. Because the underlying "person" doesn't exist, there's no one to report the fraud — the loss often isn't discovered until the account defaults, by which point the fraud ring has moved on to the next merchant.

Generative AI is closing the last verification gap

Selfie-based liveness checks and photo ID uploads were, until recently, a reasonably effective backstop against synthetic applicants. That's changing fast. Fraud operators are now using generative AI across the entire synthetic identity pipeline — producing fabricated ID documents, AI-generated selfies, and even deepfake video for the liveness checks that BNPL and marketplace platforms increasingly rely on. The same underlying technology now costing consumers billions in voice-cloning and deepfake scams is being repurposed to manufacture entire fake customers at checkout scale.

The result is a verification arms race: static, document-based KYC checks are no longer a reliable signal that the person behind an application — or an account — is real.

What retailers and BNPL providers should do now

Fighting synthetic identities requires moving verification beyond documents that AI can now forge convincingly. Effective defenses include:

  • Voice-to-face verification that cross-checks an applicant's voice against their claimed identity without relying on a stored biometric database — closing gaps that photo-only checks miss.
  • Real-time deepfake and injection-attack detection at the point of onboarding, not just at account creation, since synthetic identities are often "aged" through legitimate-looking activity before being used for fraud.
  • Continuous, risk-based re-verification for high-value actions like credit limit increases or large BNPL installment approvals, rather than a single one-time check at signup.
  • Cross-merchant signal sharing to catch synthetic identities that are "grown" across multiple platforms before being cashed out on any single one.

Treat onboarding as the new fraud perimeter

As BNPL and digital-first retail keep growing, the account creation flow — not the payment step — is becoming the primary fraud battleground. Merchants that still treat a photo ID and a selfie as sufficient proof of identity are, in effect, trusting a check that generative AI has already learned to beat.

Corsound AI helps banks, lenders, and consumer platforms stop synthetic identities and deepfake-driven fraud before an account is ever approved. Learn how our identity verification technology protects onboarding flows at corsound.ai/prevent-identity-fraud.

Photo: Negative Space / Pexels

See Corsound AI Voice Intelligence In Action
Thank you.
Your submission has been received.
Oops! Something went wrong while submitting the form.