“Sometimes the identity is completely synthetic. More often, the criminal is using a real person’s stolen information, which can make the applicant look legitimate during a basic records check,” he says.
AI is amplifying the challenge.
“Generative AI is lowering the costs as well as the skill barriers for creating fake identities,” he says. “It used to be hours and hours of work to create a fake ID. With AI, you get it via a simple text prompt, and AI bots can mass-submit college applications for financial aid.”
The Financial Implications of Ghost Students
The problem is real. More than 800 people attended the first Higher Education Fraud Summit in July 2026 to talk about solutions with federal student aid staff, inspectors general, representatives from higher education institutions and vendor partners.
The event was convened by the U.S. Department of Education and featured Undersecretary of Education Nicholas Kent; Colin McDonald, assistant attorney general for the National Fraud Enforcement Division at the Department of Justice; and Scott Brady, executive director of the White House Task Force to Eliminate Fraud.
Investigations by the Office of Inspector General have yielded more than $35 million in restitution, settlements, fines, savings, recoveries and forfeitures over the past 12 months.
- Implemented in April, the new Free Application for Federal Student Aid (FAFSA) identity verification screening system rejected fraudulent applications for about $2 billion in federal student aid funds.
- Also in April, a Florida woman — who dubbed herself a “student loan default guru” and ran a website with the same name — pleaded guilty to engineering a $5 million federal student loan forgiveness fraud racket.
- In May, a Michigan man pleaded guilty to running a fraud ring that involved the identities of more than 1,200 people and more than 100 schools in 24 states. The man targeted more than $16 million in federal student aid in the decade-long scheme.
- In June, the bipartisan-supported No Aid for Ghost Students Act of 2026 (H.R. 7892) to stop financial aid fraud passed in the House of Representatives. The bill requires the Department of Education to use a real-time identity fraud detection system to screen every FAFSA form starting Oct. 1, 2026.
DISCOVER: Higher ed IT can use risk assessments and other tools to detect ghost students.
“If you look at the successful investigations over the past five years, there’s been about $350 million in ghost student schemes that have been thwarted,” says Kayne McGladrey, a cybersecurity risk adviser and senior member of IEEE, a nonprofit professional organization that champions technical innovation.
Why Traditional Enrollment Systems Miss AI-Generated Identities
For most schools, traditional enrollment systems aren’t up to the challenge. “The fundamental problem is that many enrollment systems were designed to validate information, not prove identity,” Powell says.
“They ask whether the name, Social Security number, address and date of birth appear valid. But valid data does not necessarily mean the person submitting it is the rightful owner,” he says. “When criminals use stolen identity information, every individual data element may pass verification.”
In legacy systems, “gathering and maintaining identification can be hard and time-consuming,” says Mathew Woodyard, director of Okta Threat Intelligence. Older systems typically don’t have built-in identity verification capabilities, “and that makes them more vulnerable.”
LEARN MORE: University IT leaders share their zero-trust journeys.
The Layered Identity Architecture That Stops Ghost Student Fraud
A layered approach to identity can help put the brakes on FAFSA fraud. “No single control is going to solve this. You need layers that reinforce one another,” Powell says. He describes the approach as follows:
- Layer 1: Identity Proofing. “Confirm that the person exists, that the documents are legitimate, and that the applicant is the rightful owner of those documents.”
- Layer 2: Account Security. “Bind the verified identity to a protected account, use strong authentication and watch for account recovery or contact information changes that could indicate takeover.”
- Layer 3: Behavioral Trust. “Continue evaluating the session, device, network, academic engagement and financial activity. Identity verification should not end when the application is approved.”
Biometrics and real-time AI can help here.
“Biometric liveness detection, behavioral analytics and cross-referencing telemetry are all essential defenses,” McGladrey says.
Liveness detection would catch a synthetic face on a video call. AI-informed telemetry could sound an alarm if dozens or hundreds of applications are coming from the same device or IP address.
With these tools in place, “a scammer can’t win just by faking something really well,” he says.
