Identity fraud in fintech concentrates at onboarding, where a remote applicant is accepted in minutes on the strength of a document image and a selfie. Four typologies do most of the damage: synthetic identities, stolen-identity applications, account takeover and money mule recruitment. Each defeats a different control, so each needs a different answer.
Key takeaways
- The FCA fined Monzo 21,091,300 pounds in July 2025 after it onboarded customers on obviously implausible information, including well known London landmarks used as home addresses.
- Starling Bank was fined 28,959,426 pounds in October 2024, having grown from around 43,000 customers in 2017 to 3.6 million in 2023 while its financial crime controls did not keep pace.
- FinCEN issued alert FIN-2024-Alert004 on 13 November 2024 after suspicious activity reports described deepfake identity documents being used to defeat verification.
- A recruited money mule passes every identity check, because the account is opened in their own name with their own genuine documents.
- Australian reporting entities moved to a new initial customer due diligence framework on 31 March 2026, with a transition period for existing customers running to 30 March 2029.
Which identity fraud typologies hit fintech onboarding hardest?
Four patterns account for most of what a fintech fraud team sees, and they fail different controls. A stolen-identity application uses a real person's genuine data, so it clears database checks and is caught only by liveness or device signals. A synthetic identity mixes a real identifier with fabricated attributes, so it fails nothing at all until it defaults.
Account takeover bypasses onboarding entirely by attacking authentication on an account that was verified correctly at the time. Money mule accounts are opened by the real person named on them, which is why identity verification alone will never surface them.
| Typology | What is presented at onboarding | Control that usually catches it |
|---|---|---|
| Stolen identity | Genuine data belonging to a real victim | Liveness detection, device and behavioural signals |
| Synthetic identity | Real identifier plus fabricated attributes | Bureau footprint checks and post-onboarding review |
| Account takeover | Nothing, the account already exists | Authentication controls and session monitoring |
| Money mule | The applicant's own genuine identity | Transaction monitoring and network analysis |
Treating all four as one "identity risk" line in a risk assessment is the mistake that produces a control set with a hole in it. Definitions for the underlying terms sit in our glossary of AML terms.
How does synthetic identity fraud survive a standard KYC check?
It survives because there is no victim to contradict it. The Federal Reserve, which ran a cross-industry focus group specifically to settle a common definition, describes synthetic identity fraud as the use of a combination of personally identifiable information to fabricate a person or entity for financial gain.
The typical construction pairs a genuine identifier with an invented name, address or date of birth. A document check confirms the identifier is real. A database check finds a thin but consistent record. Nothing in the file is reported stolen, because nobody has noticed.
The Federal Reserve's work describes fraudsters then building creditworthiness over time before busting out, buying on credit and disappearing. For a fintech that means the loss arrives long after onboarding closed, and attribution is close to impossible because the identity was never a person. Detection has to come from cross-account linkage and bureau footprint anomalies, not from the onboarding decision itself.
What does account takeover look like in a mobile-first fintech?
Account takeover skips identity verification because the identity was already verified. The attacker acquires credentials through phishing, a data breach or SIM swap, then changes the device binding, the registered phone number or the payee list before moving funds.
The fintech-specific aggravator is instant settlement. In the euro area, new EU rules on instant payments mean money moves within seconds, and from 9 October 2025 payment service providers must offer a verification of payee service that flags a mismatch between the payee name and the IBAN before the payer confirms.
In the United Kingdom, the Payment Systems Regulator's reimbursement requirement caps mandatory reimbursement for authorised push payment scams at 85,000 pounds per claim for payments made on or after 7 October 2024, a level the regulator says covers over 99% of claims. Both sending and receiving firms carry cost, which puts a direct price on weak onboarding at the receiving end.
Why do fintechs end up hosting money mule networks?
Because a mule account is a genuine account. AUSTRAC's guidance, developed with the Fintel Alliance, the Australian Federal Police and the Australian Border Force, was written around criminal networks recruiting international students and temporary residents to receive and forward funds.
The recruit provides their own passport, their own selfie and their own address. Every identity check passes, because every piece of the identity is true. What is false is the purpose of the account, and purpose is not something a document check can test.
That is why AUSTRAC frames the guidance around behavioural and financial indicators rather than identity red flags, and expects firms to combine those indicators with their own transaction monitoring before submitting a suspicious matter report. Fast-growing consumer fintechs are disproportionately targeted because account opening is cheap, remote and quick to repeat across a recruited cohort.
How fast can a fintech onboard without weakening verification?
Speed is not the problem. The problem is when growth in volume is not matched by growth in control capacity, and the FCA has now said so twice in writing.
The regulator recorded that Monzo's customer base grew almost tenfold, from around 600,000 in 2018 to over 5.8 million in 2022, while its financial crime controls failed to keep pace. Starling grew from approximately 43,000 customers in 2017 to 3.6 million in 2023, and the FCA found that measures to tackle financial crime did not keep pace with its growth.
The workable answer is to make depth a function of risk rather than a function of time. A low-risk applicant clears in seconds. An applicant whose device, document or data signals sit outside tolerance moves into a step-up queue that is allowed to take longer. Our identity verification page sets out how that tiering is assembled in practice.
What must a fintech verify, and by when, across major regimes?
The obligation to verify before service is close to universal. What differs is the permitted evidence and the point at which the clock stops.
| Regime | Core rule | Verification timing |
|---|---|---|
| United Kingdom | Money Laundering Regulations 2017, regulation 28 | Before establishing a business relationship or carrying out a transaction |
| European Union | Regulation (EU) 2024/1624, applying from 10 July 2027 | Before the business relationship, with an occasional transaction threshold of EUR 10,000 |
| Australia | AML/CTF Rules and the reformed initial CDD framework | Initial CDD completed before the designated service is provided |
| United States | Customer Identification Program rule, 31 CFR 1020.220 | Within a reasonable time before or after account opening |
Australia is the live one for local firms. Obligations changed on 31 March 2026, splitting due diligence into initial and ongoing CDD, with a three-year window to 30 March 2029 for moving existing customers off the old applicable customer identification procedures.
What is changing now that verification evidence can be generated?
Document images and selfies are no longer scarce. FinCEN issued alert FIN-2024-Alert004 on 13 November 2024 after seeing an increase in suspicious activity reporting describing deepfake media, particularly fraudulent identity documents used to circumvent identity verification and authentication.
The consequence for fintech onboarding is that any single artefact the applicant supplies has become weaker evidence, while signals the applicant does not control have become stronger. Device reputation, injection-attack detection on the camera stream, and independent data sources carry more of the decision than the image does.
Volume gives a sense of the pool fraudsters draw on. The FTC's Consumer Sentinel Network Data Book 2024 records 6.5 million consumer reports received during 2024, sorted into 29 categories of which identity theft is one. Our post on biometric verification versus deepfakes covers the detection side.
Which controls close the gap between onboarding and ongoing monitoring?
The gap is where identity fraud is monetised. An account passes verification, sits quiet, and only later behaves like a mule or a bust-out. Controls that only fire at account opening cannot see any of that.
Four things carry the load. Screening has to continue after onboarding, so sanctions and PEP screening rescreen the book rather than the applicant. Monitoring has to be tuned for mule patterns, including rapid pass-through, third-party deposits and dormancy followed by sudden volume.
Linkage analysis has to run across accounts, since synthetic identities and mule cohorts are visible as clusters long before they are visible individually. For business customers, ownership needs resolving through know your business checks, because a corporate shell is the other way an identity gets borrowed. Fintech-specific obligations are set out on our payments and fintech industry page, and the sector variants of this problem appear in our companion pieces on identity fraud in gaming and identity fraud in real estate.



