Identity management

Identity Fraud in Higher Education: Ghost Students, FAFSA Fraud, and How to Stop Them

Christine Owen

Field CTO

Young man in headphones studying on a laptop at a kitchen counter, illustrating identity fraud in higher education risks for online learners.

Colleges and universities are losing millions to applicants who don't exist. Pandemic-era remote enrollment and generative AI let fraud rings apply at machine speed, collect financial aid, and disappear. Layered identity proofing and passwordless authentication close the gaps that let them in.

Identity fraud in higher education has outgrown its reputation as an IT problem. Fraud rings now target colleges at scale, using AI-generated identities to enroll, collect financial aid, and vanish. Every fake student drains money, consumes a seat, and puts an institution's federal funding at risk.

The schemes are accelerating and the conditions that created them are still in place, but the gaps most institutions are leaving open are fixable.

Types of identity fraud in higher education

Identity fraud isn’t just one scheme. Many institutions face several at once, and they often chain together:

Ghost students and synthetic identities

Criminals use stolen identities, or assemble synthetic ones from fragments of real data, to apply for admission. Online programs with low-friction enrollment are the usual target. The aid disbursement is the payout, and by the time an empty seat raises questions, the money and the identity behind it are both gone.

FAFSA and refund fraud

Two paths lead to the same place. Financial aid fraud begins with a fabricated applicant filing for FAFSA aid that was never earned. Refund fraud begins with a real, enrolled student whose account is quietly taken over so the refund lands in someone else's bank. Both run through approved disbursement systems, which is why the transaction looks routine until the money is already gone.

Student email compromise and account takeover

A compromised student inbox is rarely the goal itself. It's the credential that unlocks everything else. An attacker holding a working student account can authorize password resets across connected systems, change where a refund gets deposited, and send requests to financial aid staff from an address those staff have no reason to question.

These accounts are easy to reach because students reuse passwords and sign in from personal devices no one on campus manages. They also stay compromised, because nothing flags the takeover for weeks.

Re-admit fraud

Impersonating a former student sidesteps most admissions scrutiny. Returning applicants face lighter vetting, and loans get issued in the real person's name. This is student identity theft with a delayed fuse; the victim often learns about it years later, when a credit application turns up debt they never took on.

Credential and diploma fraud

Fraudsters issue counterfeit diplomas bearing a real university's name, or use stolen identities to pull official transcripts. The damage lands on the institution's reputation and on every employer relying on it.

Business email compromise and vendor impersonation

This attack targets the people who move money rather than the systems that hold it. A convincing email arrives from what appears to be a trusted internal authority or an established supplier, asking that a payment be released quickly or that banking details on file be updated.

Decentralized procurement gives attackers plenty of approval paths to test, and the pressure of grant cycles and fiscal deadlines supplies a believable reason to skip the usual verification step.

Student data and research IP theft

One compromised account can expose student records, research data, and university intellectual property. It also supplies the personal details that make the next round of impersonation more convincing.

How widespread is identity fraud in higher education?

Measuring higher education identity fraud is difficult, since incidents against institutions and individuals often go unreported. The figures that do surface are alarming enough.

In 2024 alone, California community colleges received 1.2 million fraudulent applications, resulting in losses of $13 million. One college reported receiving 50 fake applications in 2 seconds, highlighting the speed of today’s scams. Some colleges have discovered that 1 in 3 applicants is actually a ghost student.

Before 2020, identity fraud cost higher education under $10 million a year. By 2023, the figure passed $100 million, a tenfold increase.

Those figures represent detected fraud, which makes them a floor rather than a ceiling. The more useful question is what changed between 2020 and 2023 to bend the curve that sharply.

How generative AI is reshaping higher education fraud

Free tools now complete applications, write admissions essays, fabricate identities, and imitate real people convincingly. What once took effort and some craft now takes a prompt.

That shift changes fraud in two ways at once:

  1. Volume goes up, because one operator can submit thousands of applications instead of dozens

  2. Detection gets harder, because the gap between a fabricated applicant and a real one has narrowed to almost nothing

Deepfaked video and forged government IDs now clear the kind of manual review most institutions still rely on. Training staff to spot fakes stopped being a viable defense the moment the fakes got better than human eyes could detect.

Remote enrollment created the opening

When campuses closed, schools moved instruction online and loosened enrollment procedures to match. Applying from anywhere, with minimal vetting, became normal.

Most of those changes stayed. Online and remote programs are now central to enrollment strategy, which means the conditions that made large-scale application fraud possible are permanent features of the system rather than emergency measures waiting to be rolled back.

Why colleges and universities are a preferred target

Higher education offers an unusual combination of high payout and low resistance:

  • Enrolled students qualify for substantial loans and aid, so a single working identity is worth thousands

  • Admissions and disbursement run on trusted, automated workflows that assume the applicant is who they claim to be

  • Stolen funds move through layered accounts quickly, making recovery and prosecution unlikely

  • Breached student data, as in the Canvas/Instructure breach, hands attackers the details they need to impersonate students and pressure staff

Why standard controls don't catch identity fraud

Most higher education cybersecurity is built to detect intrusion: an unauthorized login, an unpatched system, a suspicious connection. Identity fraud triggers none of it.

The applications arrive through the admissions portal, the emails come from real, authenticated accounts, and the disbursements follow approved processes. Nothing is technically breached, because the attacker isn't breaking in. They're being let in, through a front door that never confirmed who they were. Detection has to happen at the identity layer or else it doesn't happen at all.

What the Department of Education requires for identity proofing

The scale of ghost student fraud prompted the Department of Education to mandate real-time identity proofing for first-time FAFSA applicants and anyone flagged as high risk. Applicants present a government ID, typically a driver's license or passport, either in person or on a live video call with an authorized party. Schools retain a copy of the verified ID.

Some states have gone further. California applies the requirement to all applicants, new and returning. But in many states and at many schools, applications still carry no identity proofing at all.

Identity proofing at enrollment isn't enough

A one-time ID check verifies a person at a single moment, then extends trust to every interaction that follows.

That leaves the highest-value moments unprotected. Refund fraud, account takeover, and re-admit fraud all happen after the FAFSA is filed.

The federal process also has a ceiling of its own. A staff member reviewing a document on a live video call is poorly positioned to catch a competent deepfake or a well-made forgery. The requirement sets a floor for who gets checked, not a standard for how well the check holds.

The check is worth doing, but it’s not sufficient on its own.

Preventing identity fraud in higher education

Effective student identity verification treats identity as something the institution establishes once and confirms continuously, rather than a box checked at admission.

The five controls below build on each other: proofing creates the trusted record, the verified digital identity carries that record into every system a student touches, and step-up verification protects the moments where money and access change hands.

They can be deployed in stages, but the sequence matters, since nothing downstream is stronger than the proofing underneath it.

None of this is reserved for large, well-resourced universities. Community colleges absorb the heaviest share of application fraud and have the least margin to absorb the losses, and these controls are within reach at that scale.

Proof identity with more than a document check

Digital identity verification pairs government-ID checking with liveness detection and biometric matching, which together catch the deepfakes, forged IDs, and synthetic identities that manual review misses. That is a stronger standard than what the Department of Education currently requires, where the outcome depends on one person's read of a document held up to a camera.

Issue a verified digital identity

Students use it to access aid, register for classes, update payment details, or reach the help desk. Student ID numbers and course rosters no longer work as proof, as the Canvas/Instructure breach showed.

Replace passwords with biometric, phishing-resistant authentication

This removes the credential attackers want most and shuts down student email compromise at the source. It also cuts login times and password resets, and one authentication carries across every system a student touches, so the stronger control arrives as less friction rather than more.

Give students a digital identity wallet

A digital identity wallet holds the verified identity and any credentials tied to it, so a student proves who they are without an institution re-collecting documents each time. Students choose what gets shared and with whom, which means the data travels with them rather than accumulating in systems that later get breached.

Apply step-up verification where risk concentrates

Account recovery, banking and refund changes, and aid modifications warrant stronger assurance, including for returning students and alumni regaining access. The principle is proportionality; routine actions stay frictionless, and assurance rises only where the consequence of a wrong answer does.

If this seems like a lot, consider the alternatives: identity fraud gets worse, schools face significant financial and operational consequences, and students lose trust in their institutions.

Identity fraud is now an enrollment problem

What used to sit with IT now runs straight through admissions and financial aid. Federal identity proofing rules set the floor, and the institutions treating that floor as the finish line are the ones still exposed.

Colleges and universities are already managing declining enrollment and financial strain. Identity fraud deepens both, adds Title IV compliance exposure, and erodes the trust students place in their institution.

Higher education identity verification has moved well past the annual password reset. Strong identity proofing, passwordless authentication, and digital identity wallets reduce fraud risk across the entire student lifecycle.

1Kosmos builds identity solutions purpose-made for higher education. See how we help institutions verify identities, protect high-risk interactions, and secure access from application through alumni status.

About the author

Christine Owen

Field CTO

Christine is a former attorney who transitioned to Identity and Access Management (IAM) over a decade ago. As the Field CTO at 1Kosmos, Christine works on strategy and supports clients through identity verification and digital identity wallets. Prior to 1Kosmos, she spent 10 years as a consultant for IAM and Zero Trust in the public sector.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

The latest in identity security.

Enter our orbit.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.

Transform how you verify and authenticate

Secure onboarding, eliminate passwords, and stop fraud on one platform. Schedule a demo and see it in action.