A convincing online identity can be assembled from a name, a photograph, a job history and a handful of profiles, none of which need correspond to a real person. Verifying that someone exists is harder than it looks.
Key takeaways
- A person’s apparent existence online rests on records that are cheap to create and rarely checked against one another, which makes fabricated identities practical.
- Generative tools have lowered the cost of producing plausible faces, biographies, writing samples and supporting profiles that reinforce each other.
- Name collisions complicate matters further, because two people can legitimately share a name while a third profile using it may be invented entirely.
- The harms fall unevenly, affecting recruiters, journalists, lenders, dating-site users and people whose own names are attached to accounts they do not control.
- There is genuine disagreement about whether stronger identity verification improves safety or simply concentrates sensitive personal data in more places.
What does it mean to say a person online does not exist
Most claims that someone exists online are indirect. A profile on a professional network asserts a job history; a company page lists a name; a byline appears above an article; a photograph shows a face. Each of these is a record created by someone, and almost none of them are checked against an authoritative source at the point of creation. When investigators say a person “does not exist”, they usually mean something narrower and more careful: that no independent record can be found which was created by a party with no incentive to lie, and that the records which do exist all trace back to the same origin.
That distinction matters because absence of evidence is weak evidence in either direction. Plenty of real people have almost no digital footprint by choice, by age, or because they live in places where the relevant records are not indexed in English. Equally, a fabricated identity can accumulate an extensive footprint quickly. The practical question is not how much material exists about a person, but whether any of it is independently corroborated — and independence, once profiles start citing and endorsing one another, is precisely what becomes difficult to establish.
Why the subject is drawing attention now
Interest has grown because the effort required to manufacture a plausible person has fallen sharply. Image generation can produce a face that has never belonged to anyone, avoiding the reverse-image searches that used to expose stolen photographs. Text generation can produce a consistent biography, a writing style, correspondence and technical-sounding contributions at a volume no individual fabricator could sustain by hand. Multiple accounts can be created and cross-linked so that each appears to confirm the others.
At the same time, the platforms where professional and social identity is established have not fundamentally changed how they onboard users. Signing up generally requires an email address and sometimes a phone number, both of which are obtainable in quantity. Verification badges, where they exist, often confirm payment or control of an account rather than the identity of a human being behind it.
The result is a widening gap between how confident people feel about someone they have interacted with online and what has actually been checked. Individual cases where an apparently well-documented person turns out to have no verifiable basis tend to circulate widely because they make that gap concrete.
The background a newcomer needs
Fabricated identities are not new. Fraud investigators have long described synthetic identity fraud, in which a fictitious person is assembled — sometimes around a real identifier belonging to someone else — and then given a credit history through small, repaid borrowings until larger sums can be taken. Intelligence and influence operations have used invented personas for far longer than the internet has existed, and pseudonymous authorship has a longer history still, much of it entirely legitimate.
What has changed is scale and coherence. Older fabrications tended to be thin: a single profile, a stolen photograph, an inconsistent biography. Detection often relied on that thinness. Modern fabrications can be broad and internally consistent, spanning several platforms and behaving plausibly over months.
It is also worth separating the categories that get conflated. A pseudonym conceals a real person’s name. An impersonation borrows a real person’s identity. A synthetic identity refers to no one. A name collision is simply two or more real people who happen to share a name — common enough that it regularly produces mistaken conclusions when someone tries to determine whether “the” holder of a name is genuine.
Who is affected and how
Recruiters and hiring managers face candidates whose credentials cannot easily be traced, a problem sharpened by remote hiring where no one meets in person. Employers in regulated sectors carry legal obligations to know who they have engaged, and remote-work fraud schemes have made this a live operational concern rather than a theoretical one.
Journalists and researchers can be fed material by sources who do not exist, or find their own work cited by publications staffed by fabricated bylines. Open-source communities receive contributions from accounts whose provenance is unclear, which matters when the contribution touches security-sensitive code.
Financial institutions absorb losses from synthetic identities that behave like ordinary customers until they do not. Users of dating and social platforms are targeted by long-running confidence schemes that depend on a persona holding up under sustained scrutiny.
A distinct group is affected differently: people whose real names are attached to accounts they never created. They may struggle to prove the negative, find that search results conflate them with a fabrication, and discover that platforms are better equipped to handle impersonation of well-known figures than of ordinary ones.
Where informed people disagree
The sharpest disagreement concerns identity verification. One position holds that platforms should require stronger proof of identity before granting the trappings of credibility, on the grounds that the cost of fabrication is currently far too low. The opposing position holds that mandatory verification builds large repositories of identity documents that become targets in their own right, excludes people without standard documentation, and removes the pseudonymity that protects whistleblowers, abuse survivors and people under repressive governments.
There is also disagreement about detection. Some argue that behavioural and network signals — how accounts are created, connected and used — remain reliable even as generated content improves. Others argue this is an arms race that defenders lose over time, and that effort is better spent on verifying claims rather than detecting fakes.
A third dispute concerns responsibility. Platforms point to the difficulty of verifying billions of accounts; critics point to business models that reward account growth. Whether the burden belongs to platforms, to the institutions relying on their signals, or to individuals remains unsettled.
What this means in practice
The workable principle is corroboration from parties with different incentives. A university registrar, a professional register, a company’s own records, a court filing or a tax authority are records that were created for reasons unconnected to the profile in question. Several social profiles that link to each other are not independent evidence, however numerous.
Practical steps follow from that. Contact institutions directly rather than through details supplied by the person. Treat photographs as weak evidence in both directions, since a generated face will not appear in a reverse-image search. Look for the mundane residue a real working life leaves — colleagues who remember them, older records, small inconsistencies that fabrications smooth over.
Organisations should decide in advance which decisions require verified identity and which do not, and avoid collecting identity documents for decisions that do not warrant them. For individuals, the defensive measure is monitoring: knowing what appears under your own name, and having a record of your genuine accounts.
What to watch next
Three developments are worth following. The first is regulatory: rules on labelling synthetic media and on identity assurance are being developed in several jurisdictions, and their scope will determine how much of this becomes a compliance matter rather than a discretionary one. The second is technical: cryptographic credentials that let someone prove a specific attribute — a qualification, an employment relationship, an age bracket — without disclosing full identity would change the trade-off between verification and privacy, if adoption follows.
The third is institutional. Whether professional networks, code-hosting services and publishers begin to distinguish clearly between “this account is active” and “this person has been verified” will shape how much weight outsiders can reasonably place on their signals. Until then, the sensible default is to treat online presence as an assertion rather than a fact.
Frequently asked questions
How can I tell if an online profile belongs to a real person
Look for corroboration from sources with no connection to the profile itself: institutional registers, employer records contacted directly, published documents predating the account, or people who can independently confirm the relationship. Multiple linked social profiles are not independent evidence. Be aware that a thin footprint is common among real people, so absence of material is suggestive rather than conclusive on its own.
What is synthetic identity fraud
Synthetic identity fraud describes the creation of a fictitious person, often combining fabricated details with real identifiers, in order to obtain credit, services or access. The invented identity is typically built up gradually so that it accumulates a plausible history before being used for larger gains. It differs from ordinary impersonation because there is no single real victim whose identity was copied wholesale.
Does a reverse-image search still detect fake profile photographs
It detects stolen photographs, which remain common, but not generated ones. An image produced by a generative model has no prior existence on the web, so a search returns nothing — a result that can be mistaken for confirmation of authenticity. Image searching is therefore useful for ruling a photograph out, and close to useless for ruling one in.
Why do two profiles with the same name not mean one is fake
Names are not unique identifiers. Common names may be shared by many real people, and identical names appear across unrelated professions and countries. Discovering a second profile with the same name is evidence of a name collision, not of fabrication. Distinguishing the cases requires attaching each profile to distinct verifiable records, such as different employers, institutions or publications.
What should I do if an account is using my name
Document what you find, including copies of the pages, before requesting removal, since evidence often disappears once a platform acts. Use the platform’s impersonation reporting route rather than general abuse reporting. Where the account is being used for fraud, report it to the relevant national fraud or cybercrime body. Consider establishing verifiable presence under your own name so that genuine records are easier to find.
Would mandatory identity verification solve the problem
It would raise the cost of fabrication but introduce different risks. Verification systems require storing or processing identity documents, creating attractive targets for attackers, and they exclude people without standard documentation. They also remove pseudonymity relied upon by people at risk. Most proposals therefore aim at selective assurance for specific high-stakes decisions rather than universal verification of every account.
Sources and further reading
- National cybercrime and fraud reporting bodies, which publish general guidance on identity fraud and impersonation reporting routes.
- Data protection and privacy regulators, for material on identity verification requirements and the risks of document retention.
- Financial-sector supervisory publications, which describe synthetic identity fraud and customer due diligence obligations in general terms.
- Academic and standards work on verifiable credentials and selective disclosure, for the technical alternatives to full identity verification.
Surfaced from the hackernews signal “fabricated online identity”. AI-assisted draft, editorially reviewed.

