1. Home
  2. Death Verification
  3. Deceased Identity Fraud
Fraud intelligence

Deceased identity fraud: how ghosting works and how to stop it

A deceased person's identity is the perfect fraud instrument. It has a real Social Security number, a clean credit history and, critically, no living owner to notice, report or dispute anything. This is what fraudsters do with it, and why the control that stops them is speed rather than sophistication.

Anatomy of the attack

The 90-day window, day by day

Deceased identity fraud is not opportunistic. It is scheduled around a data lag that fraudsters understand better than most institutions do.

Timeline showing deceased records available in about seven days with Verify Deceased versus 30 to 90 days with the Social Security Death Master File, with the difference shaded as the open fraud window
The shaded band is the period where a deceased identity still clears conventional checks because the federal file has not published yet.
Day 0

Date of death

The death occurs. Nothing in any commercial dataset has changed yet, and the identity remains fully valid to every automated check.

Days 1 to 14

The exploitation window opens

Obituaries and public notices make the death discoverable to fraudsters long before it reaches screening data. Applications begin.

Days 15 to 45

Accounts perform, then bust out

New credit lines behave normally to avoid early detection, then are drawn down in full. Benefit and payroll payments continue uninterrupted.

Days 30 to 90

Federal files finally publish

The Death Master File reflects the death. By this point the loss is already booked and recovery odds have collapsed.

Every control in this sequence fires too late except one: screening the identity against a deceased index that is measured in days rather than months.

Attack patterns

Six ways a deceased identity gets monetized

Credit applications in a decedent's name

Cards and personal loans opened weeks after death, before any national file reflects the event. The account performs briefly, then busts out.

Employment and I-9 identity theft

A deceased person's SSN is used to pass onboarding and payroll checks, exposing the employer to penalties and remediation costs.

Continued benefit and pension payments

Retirement, annuity and public benefit payments keep flowing to an account controlled by someone else, creating a growing clawback liability.

Fraudulent insurance and tax claims

Claims and refunds filed against a decedent's identity, often detected only after the payout has already cleared.

Synthetic identity seeding

A real deceased SSN is blended with a fabricated name and date of birth to build a synthetic profile that looks clean to legacy checks.

Account takeover during estate limbo

In the weeks between death and probate, dormant accounts are drained while no one is actively monitoring the relationship.

The control

Detection is not prevention

Screening against a file that lags by one to three months tells you a loss already happened. Screening against a file refreshed daily tells you not to take the risk in the first place. The mechanism is identical; only the timing differs, and timing is the entire control.

  • Verify at the point of decision, not in a monthly retrospective batch
  • Re-screen existing portfolios continuously, because deaths occur after onboarding
  • Treat a decedent SSN paired with mismatched identity data as a synthetic-fraud signal
  • Keep a timestamped evidence trail for every verification you action
See how the API fits your flow
Detection30 to 90 days

The loss is booked. You are now running a recovery process with poor odds.

  • Charge-off already recognised
  • Funds withdrawn and dispersed
  • Investigation cost incurred
Prevention~7 days

The application is declined and the payment is held. There is nothing to recover.

  • No account opened
  • No disbursement released
  • No investigation required
FAQ

Deceased identity fraud, explained

Frequently asked questions

What is deceased identity fraud?

Deceased identity fraud, often called ghosting, is the use of a dead person's identity to obtain credit, employment, benefits, insurance payouts or medical services. It is attractive to fraudsters because the victim cannot detect it, cannot report it and cannot dispute it, so the fraud frequently runs unchallenged until an institution absorbs the loss.

Why is the period right after death the highest risk?

Because the identity still appears completely valid. Credit files remain active, the Social Security number is not yet flagged in most commercial datasets, and the family is focused on grieving rather than monitoring accounts. Federal death files typically take one to three months to publish the death, so every automated check an institution runs during that window returns a clean result.

How is this different from synthetic identity fraud?

They overlap heavily. Synthetic identities are frequently constructed around a real Social Security number belonging to a deceased person, combined with a fabricated name and date of birth. Because the SSN is genuine, the profile survives basic validation. Checking the SSN against a current deceased index exposes the contradiction that conventional identity verification misses.

What are the warning signs institutions should watch for?

Common patterns include a credit application from an identity with a long, clean history but no recent activity; a sudden change of address or contact details shortly before an application; new accounts opened in quick succession across institutions; and applications where the SSN issue date is inconsistent with the stated date of birth. Any of these paired with a deceased-index match is a strong signal.

How can organizations actually prevent it rather than detect it late?

Prevention requires deceased data that is current enough to matter. Screening against a file that lags by one to three months is detection after the fact, not prevention. Screening at the point of decision against an index refreshed daily, and re-screening existing portfolios on a schedule, moves the control from recovery to prevention.

Which sectors are targeted most heavily?

Credit issuers and lenders see the highest volume because credit is the fastest way to convert a stolen identity into cash. Government benefit programmes, pension and retirement plans, insurance carriers and healthcare payers all carry substantial exposure, and employers are increasingly targeted because a deceased SSN can pass standard onboarding checks.

Stop screening against last quarter's data

See how a seven-day deceased index changes your fraud numbers. Sandbox credentials are issued before any commercial commitment.