Join our Newsletter — 33% off our NHI Course

Ghost Fraud

Ghost fraud is the misuse of a deceased person’s identity for financial gain. Criminals may use the person’s records to access accounts, apply for credit, or claim benefits that should have stopped after death. Deepfakes can make this fraud more convincing by adding a believable live face or video presence.

What ghost fraud is really exploiting

Ghost fraud is not just a stolen-identity scheme, it is a posthumous identity abuse pattern. The fraudster relies on the fact that a deceased person’s records can remain active enough in banks, credit systems, government databases, or benefits workflows to support applications, account access, or claims that should have ended at death.

That makes the core problem less about the person and more about the persistence of trust in records. If death is not reflected quickly and consistently across institutions, the identity can continue to function as a usable asset for fraud.

How ghost fraud works in practice

Common abuse paths include opening new accounts, taking over existing accounts, applying for credit, filing insurance or benefit claims, or using the deceased person’s data to pass weak verification checks. The deceased individual’s history often gives the fraudster a useful base of real names, addresses, dates, and family relationships.

Deepfakes can increase the effectiveness of these schemes by adding a convincing live face, voice, or video presence during remote onboarding or support interactions. That matters most where institutions still treat visual presence as a strong trust signal, even when the underlying account evidence is thin.

Why ghost fraud is hard to detect

Ghost fraud often blends into normal onboarding or servicing activity because the underlying data may look legitimate. A person’s prior credit footprint, legacy records, or family-linked information can reduce friction for a criminal if verification is too reliant on static data.

Detection gets harder when organisations do not share death signals reliably, do not reconcile records quickly, or have weak exception handling for unusual post-death activity. The fraud may appear as ordinary account maintenance unless systems are tuned to look for inconsistent identity lifecycle events.

What makes ghost fraud damaging

The harm can include direct financial loss, wrongful benefits payments, fraudulent credit exposure, administrative burden, and distress for surviving relatives who must unwind the damage. It can also erode trust in identity verification processes when an institution fails to notice that a deceased person is still being treated as active.

Because these cases often span financial services, public records, and customer servicing, the damage is not limited to a single account. One compromised post-death identity can be reused across multiple institutions and over a long period if no one closes the loop.

Risk and Threat Considerations

Ghost fraud is a lifecycle-control problem as much as a fraud problem. The main risk is that identity data outlives the person, creating a window where a deceased record can still satisfy weak checks, especially when remote verification relies on stale or partial evidence.

Failure mechanism: Fraud succeeds when death records, account systems, and verification workflows are not reconciled quickly enough, allowing a deceased person’s profile to remain operational for credit, benefit, or account abuse.

Impact: Organisations can issue money, services, or access to an attacker while also creating legal, operational, and reputational fallout for failing to recognise that the identity should no longer be active.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-63, NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Ghost fraud depends on weak proofing and identity assurance for remote verification.
Recommendation — Raise assurance for remote proofing and authentication to reduce misuse of stale identity records.
NIST SP 800-53 Rev 5 IA-8 — Identification and Authentication (Non-Organizational Users) Ghost fraud often targets customer or external identity verification and access.
AU-2 — Event Logging Ghost fraud detection depends on audit trails for unusual post-death account activity.
Recommendation — Apply IA-8 to verify external identities before granting account access or benefits. Log account creation, recovery, and benefit events to spot suspicious identity misuse.
NIST CSF 2.0 ID.AM-01 — Identities and Roles Inventory Ghost fraud is enabled when identity records remain active after death.
Recommendation — Maintain an accurate identity inventory so deceased records can be suppressed quickly.
CIS Controls v8 CIS-6 — Access Control Management Ghost fraud exploits lingering access paths and weak removal of stale identities.
Recommendation — Remove or block stale identity access paths when death or ineligibility is confirmed.

Practitioner Guidance

What to watch for: Organisations should treat ghost fraud as an identity-verification and record-integrity issue, not only a downstream fraud case. Strong controls depend on timely death notification, cross-system suppression of outdated identities, and additional scrutiny when an application or servicing event conflicts with known lifecycle data.

For remote interactions, the key judgement is whether the evidence being used actually proves a live, eligible person, rather than merely a plausible face or a familiar record. That is where FinCEN becomes relevant for fraud monitoring and reporting discipline, while NIST SP 800-63 Digital Identity Guidelines helps frame stronger identity assurance expectations for remote proofing and authentication.

Practitioner takeaway: If death-state data is not treated as a first-class identity control, fraudsters can keep a dead identity economically useful for far longer than most systems expect.