Identity theft
Also known as: Identity theft · Identity fraud · Stolen identity · ID theft
The unauthorized use of another person's real data to open accounts, obtain credit or commit fraud in their name — where the data is genuine, but the person using it is not its owner.
Legal basis
US FTC — IdentityTheft.gov
In identity theft, the data is legitimate — the name, Social Security number and documents belong to a real person — but whoever presents it is someone else. That is why it passes any check that only validates the data: the SSN is issued, the date of birth matches, the ID is genuine. The victim usually finds out only when the bill arrives for credit they never requested.
It differs from synthetic identity fraud, where the data is fabricated, and from first-party fraud, where the person themselves acts in bad faith. In the US it is a federal crime under 18 U.S.C. § 1028 and is reported through the FTC's IdentityTheft.gov. For a lender, the question stops being "is the data valid?" — in identity theft, it is — and becomes "is the person on the other side really the owner?", which is where biometrics and liveness weigh more than attribute validation.
Frequently asked questions
What is the difference between identity theft and synthetic identity?
In identity theft, the data is real and belongs to a victim, but it is used by someone else without authorization. In synthetic identity fraud, the data is fabricated — a combination that corresponds to no one. In both, validating the data alone is not enough; you have to confirm the person presenting it is the owner.