Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

How Synthetic Identity Fraud is Coming for Machine Identities




Synthetic Identity Fraud: The Emerging Threat to Machine Identities

As the world becomes increasingly dependent on artificial intelligence (AI) and machine learning (ML), a new and sophisticated form of identity fraud is emerging, threatening the security of machine identities. Synthetic identity fraud, also known as fabricated identities, involves creating a new identity that is not based on real-world data but rather on fabricated attributes. This type of fraud is much harder to detect than traditional identity theft, making it a significant concern for organizations that rely on AI and ML systems.



  • Synthetic identity fraud for machine identities involves creating a new, fabricated identity that accumulates permissions and credibility over time without being detected.
  • Fabricated machine identities are difficult to detect because they inherit environment's naming conventions, exist in the correct domain, and carry plausible-looking metadata.
  • The rise of agentic AI is making synthetic identity fraud more timely as AI agents can dynamically acquire credentials and spin up other agents with identities of their own.
  • Strong governance, rotating secrets, enforcing least privilege access, and continuously verifying behavior are essential steps to protect against synthetic identity fraud.
  • Organizations must acknowledge that machine identity security demands a different approach than traditional identity security and use an identity security platform like KeeperPAM to manage ownership, secrets, and privileged access.



  • The threat landscape is constantly evolving, and one emerging threat that has caught the attention of security experts is synthetic identity fraud. This type of fraud involves creating a new identity that is not based on real-world data but rather on fabricated attributes. In this article, we will explore what synthetic identity fraud looks like for machine identities, how it is built, and most importantly, how organizations can defend against it.

    Synthetic identity fraud is often compared to traditional identity theft, where an attacker steals a real person's sensitive information and impersonates them. However, with the rise of AI and ML systems, synthetic identity fraud has taken on a new form. Instead of stealing a real identity, an attacker manufactures a new one by combining several real data points with fabricated ones to create a person who doesn't exist.

    This type of fraud is particularly concerning because it can accumulate permissions and credibility over time before it's ever detected. Since no real victim monitors misuse, a fake identity can silently accumulate benefits without being flagged. This principle has a largely unexplored parallel with non-human identities (NHIs), which are becoming increasingly prevalent in today's AI-powered systems.

    Security teams are spending significant effort to protect NHIs from being stolen. However, the machine-side equivalent of synthetic identity fraud is rarely discussed. This type of fraud involves creating an illegitimate identity that blends real environmental attributes with fake ones so it appears to belong. With enterprises accumulating NHIs faster than they can track them, a fabricated one may slip into the mix with ease if governance is weak and there's no human ownership.

    The mechanics behind synthetic identity fraud for machine identities are similar to those used in traditional human identity theft. An attacker creates a new identity by combining real data points with fabricated ones to create a person who doesn't exist. However, most organizations focus on stolen NHI credentials rather than fabricated identities.

    With fabricated machine identities, an attacker doesn't borrow a real identity but rather creates one that was never supposed to exist. Instead of logging in as a legitimate service account, the attacker registers a new admin-level identity with a similar naming structure, grants it privileges and lets it go unnoticed. Since nothing is hijacked, there's no compromised user to alert and no suspicious behavior to flag.

    The convincing nature of fabricated machine identities lies in their combination of real and invented attributes. A fabricated NHI inherits its environment's naming conventions, exists in the correct domain, carries plausible-looking metadata and requests the kinds of permissions other NHIs already hold. To an administrator skimming a directory of tens of thousands of service accounts, it is simply one more routine workload.

    The lack of attention that synthetic identity fraud gets for machine identities is what makes it so dangerous. Fabricated machine identities can evade detection built to identify stolen ones because the real owner of a stolen identity may notice a login from an unfamiliar place or receive a dark web alert. Meanwhile, a fabricated identity with no owner will not raise any alarms about suspicious behavior, leaked secrets or anything worth noting.

    The rise of agentic AI is making this type of fraud more timely. Until recently, fabricating a machine identity required an attacker to get into a system, create the fake account and assign its privileges manually. However, agentic AI is starting to remove that friction. AI agents already acquire credentials dynamically at runtime, and they are increasingly able to spin up other agents with identities of their own.

    As machine identity creation becomes an automated background activity, the line between a legitimately created identity and a fabricated one begins to blur. This makes it even more challenging for organizations to detect synthetic identity fraud in their systems.

    So, how can organizations defend against synthetic identity fraud? According to security experts, strong governance is key. Assigning ownership of every NHI is crucial to preventing fabricated identities from accumulating permissions and credibility over time.

    Rotating secrets, enforcing least privilege access, and continuously verifying behavior are also essential steps that organizations can take to protect themselves against synthetic identity fraud. Centralized secrets management with automated rotation can sever the paths used by attackers to inject shadow credentials into existing objects, thereby prohibiting fabricated credentials from having a long shelf life.

    Organizations must aim to leave attackers in a position where they're unable to anchor a fabricated identity's authentication. Enforcing least privilege access and Just-in-Time (JIT) access minimize the impact of fabricated identities across environments.

    Continuously verifying behavior is also critical in catching fake identities that were convincing enough to get in. By basing trust on what the identity actually does and what it accesses, organizations can more easily detect synthetic identity fraud in their systems.

    Finally, identifying and addressing the lack of attention paid to machine identity security is crucial. Organizations must acknowledge that machine identity security demands a different approach than traditional identity security, one that involves managing ownership, secrets and privileged access from an identity security platform like KeeperPAM.

    By taking these steps, organizations can eliminate fabricated identity hiding spots and ensure nothing can accumulate. The future of AI-powered systems depends on it.

    Related Information:
  • https://www.ethicalhackingnews.com/articles/How-Synthetic-Identity-Fraud-is-Coming-for-Machine-Identities-ehn.shtml

  • https://thehackernews.com/2026/07/how-synthetic-identity-fraud-is-coming.html


  • Published: Thu Jul 23 08:16:12 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us