HomeBlogDetecting Synthetic & Stolen Identity Orders
Tutorial2026-07-227 min read

Detecting Synthetic & Stolen Identity Orders

Synthetic and stolen-identity orders look clean on the surface but fall apart under scrutiny. Learn the mismatch signals, the checks that expose fabricated identities, and when to route an order to manual review.

Detecting Synthetic & Stolen Identity Orders

The hardest fraud to catch is the fraud that looks legitimate. A stolen-card order often arrives looking like a perfect customer: real name, valid address, a card that authorizes cleanly. A synthetic-identity order looks even better, because the identity was engineered specifically to pass. The chargeback shows up weeks later, after you've shipped, and by then the loss is yours to eat.

These two threats are related but distinct. Stolen identity means a fraudster is using a real person's genuine details—card, name, address—without permission. Synthetic identity means the identity itself is fabricated: a plausible but non-existent person assembled from a mix of real and invented data, sometimes aged for months to build fake credibility. Both aim for the same outcome: a clean-looking order that turns into a chargeback or a shipment to a fraudster.

Why these orders slip through

Basic fraud filters check whether the card authorizes and whether the address exists. Sophisticated fraud passes both. The card authorizes because it's real and stolen. The address exists because it's a reshipper or a controlled drop. AVS matches because the fraudster has the real billing details. Surface-level checks were built for a cruder era of fraud; today's operators design around them.

Catching this class of fraud means looking past whether the data is *valid* and asking whether it's *coherent*—do all the pieces of this identity actually belong together and behave like a real person?

The mismatch signals that expose fraud

Fabricated and stolen identities leak inconsistencies. No single one is conclusive, but clusters are.

Signals.

  • Geographic incoherence. Billing address in one country, IP in another, shipping to a third—especially when the IP is a VPN or proxy masking the real location.
  • Name-and-data mismatch. A card name that doesn't match the account name, or an email that has no relationship to either (xk92free@ on an order for "Robert Miller").
  • Reshipper and freight-forwarder addresses. Shipping to known package-forwarding hubs, especially for high-value, resellable goods.
  • Thin or fabricated history. Synthetic identities often have no digital footprint—an email with no age, a phone that doesn't tie to the name, an address newly associated with the identity.
  • Velocity across identities. Multiple "different" customers sharing a device fingerprint, IP, or shipping address—one operator behind many faces.
  • High-value, express-shipped, first-time orders. Fraud favors goods that are easy to resell and fast to move before the chargeback lands.
  • Anonymizing networks. Orders routed through VPNs, proxies, or Tor to hide the buyer's true origin.

Real customers occasionally trip one of these—someone genuinely shipping a gift abroad, say. Fraud trips several at once.

Coherence checks that go deeper

Move your verification from "is this valid" to "does this hold together."

  • Billing–shipping–IP triangulation. Map all three locations. Wide, unexplained spread—particularly with a masked IP—is a strong flag.
  • Email and phone age and linkage. Check whether the email and phone plausibly belong to the named person and whether they've existed long enough to be real. Freshly-minted contact details on a high-value order deserve scrutiny.
  • Address reputation. Screen shipping addresses against known reshipper and freight-forwarder databases.
  • Cross-order linkage. Look for the same device, IP, or address behind multiple distinct-looking orders. Synthetic-identity rings reuse infrastructure even when they vary the names.
  • Network origin. Determine whether the order came through a VPN, proxy, Tor, or datacenter connection—legitimate buyers rarely do, fraudsters routinely do.

When to route to manual review

You don't want to hand-review every order—that doesn't scale and it delays honest customers. The goal is a risk score that lets clean orders through automatically and pulls only genuinely suspicious ones aside.

Best control. Define clear triggers that send an order to manual review instead of auto-fulfilling it:

  • Order value above a threshold *and* any mismatch signal present.
  • Shipping to a reshipper or freight-forwarder address.
  • IP masked by a VPN, proxy, or Tor node.
  • Two or more coherence signals firing together.
  • A device or address already linked to a prior chargeback.

For flagged orders, a short manual pass—verifying details, sometimes a quick confirmation contact with the customer—resolves most cases fast. Honest customers verify easily; fraudsters go quiet.

Where automated scoring carries the load

Doing all of this manually on every order is impossible, and rigid rules are brittle—fraudsters learn them and route around them. What works is scoring that weighs many signals together and adapts.

Shieldy — Fraud Filter is built for this. At checkout it evaluates IP reputation, country, VPN/proxy/Tor use, and behavioral signals, and combines them through AI fraud scoring into a single risk judgment. Rather than depending on any one rule, it looks at the whole shape of an order—so a synthetic identity that passes AVS still gets flagged when its IP, geography, and behavior don't cohere. Orders that clear the score fulfill normally; risky ones get held or blocked at checkout before you ship.

A sensible baseline:

  • Block or challenge orders from anonymizing networks and high-risk countries you don't serve.
  • Auto-flag high-value first-time orders with geographic mismatches for manual review.
  • Let coherent, residential-origin orders through untouched.

Used alongside your own coherence checks and review triggers, it turns an unmanageable manual problem into a handful of exceptions a person can actually look at.

The payoff of catching it early

Every synthetic or stolen-identity order you stop before shipping is a chargeback you never receive, a product you keep, and a processor dispute you avoid. The difference between a store that eats identity fraud and one that doesn't isn't luck—it's a habit of asking whether an order's details actually belong together, backed by scoring that does the heavy lifting.

Start by adding coherence checks to your review process and defining hard triggers for manual review. Then let automated scoring filter the obvious risk at checkout so your team only touches the genuine edge cases. If you'd like that scoring in place, explore Shieldy's plans—it starts free, and the first blocked chargeback usually pays for the year.

Protect your Shopify store today

Install Shieldy free — block fraud, bots, and VPNs in under 5 minutes.

Install on Shopify — Free