Unemployment insurance fraud

Also called: UI fraud · unemployment identity theft · pandemic unemployment fraud · claim hijacking · unemployment benefits fraud

Unemployment insurance fraud uses someone else's stolen identity — name, Social Security number, date of birth — to file for unemployment benefits in a state where they never worked or don't live. The real person usually finds out from a 1099-G tax form, an employer's inquiry about a claim, or a rejected application of their own. One Maryland conspiracy stole $3.5 million this way.

Key facts

Category
Identity theft
First documented
2020
Typical loss
$500k–$3500k USD, per victim
Main channels
state unemployment insurance web portals, stolen personally identifiable information from data breaches, insider access to state agency systems
Who is targeted
Anyone whose name, Social Security number and date of birth appear in a prior data breach — which is most of the adult population at this point; People currently employed, who have no reason to be watching for an unemployment notice at all; Incarcerated people, whose identities are used precisely because they are unlikely to see mail or check a claim status themselves; Anyone whose real claim is processed by a state system that a corrupted insider — a contractor or employee with account access — can also reach
Documented origins
United States
Main targets
United States
Case files
3 documented cases
Last reviewed
2026-09-11
Anatomy of unemployment insurance fraudAnatomy of unemployment insurance fraud. No call, no link — a stolen identity files the claim, and a benefits card goes somewhere else. 1. Stolen identities, gathered or bought: Names, dates of birth and Social Security numbers, harvested from a data breach or bought as a bulk list — no contact with the real person is required to get started. 2. Picking who won't notice: People currently employed, incarcerated, or otherwise unlikely to be watching for an unemployment notice make the best targets. 3. Filing the claim: A fraudulent claim is submitted through a state agency's online portal, sometimes dozens across several states from one operation. 4. Built to dodge detection: Anonymous email addresses, VPNs and proxy servers defeat the fraud-detection systems agencies built in response to the pandemic-era claim surge. 5. The payout goes somewhere else: A benefits debit card is mailed, or a direct-deposit account is set up, to an address or account the fraudster controls. 6. Fast cashout: Funds are withdrawn at ATMs or spent quickly once the card or deposit arrives, before a mismatch is flagged. 7. The real person finds out sideways: A 1099-G tax form for benefits never received, an employer's inquiry, or their own genuine claim rejected as a duplicate. 8. An unwinding disconnected from the criminal case: Correcting tax records, disputing the claim with the state agency, and credit monitoring all happen on the real claimant's own timeline. The diagram marks stage 3 as the point where the scheme can still be stopped: State systems were built to move pandemic relief fast, with real-time identity verification as a secondary priority, and rarely cross-check claims filed against the same identity in another state.Anatomy of unemployment insurance fraudNo call, no link — a stolen identity files the claim, and a benefits card goes somewhere else.1Stolen identities,gathered or boughtNames, dates of birth andSocial Security numbers,harvested from a databreach or bought as a bulklist — no contact with thereal person is required toget started.Days to weeks2Picking who won'tnoticePeople currently employed,incarcerated, or otherwiseunlikely to be watching foran unemployment notice makethe best targets.Days3Filing the claimA fraudulent claim issubmitted through a stateagency's online portal,sometimes dozens acrossseveral states from oneoperation.Minutes per claim4Built to dodgedetectionAnonymous email addresses,VPNs and proxy serversdefeat the fraud-detectionsystems agencies built inresponse to thepandemic-era claim surge.Ongoing5The payout goessomewhere elseA benefits debit card ismailed, or a direct-depositaccount is set up, to anaddress or account thefraudster controls.Days6Fast cashoutFunds are withdrawn at ATMsor spent quickly once thecard or deposit arrives,before a mismatch isflagged.Hours to days7The real person findsout sidewaysA 1099-G tax form forbenefits never received, anemployer's inquiry, ortheir own genuine claimrejected as a duplicate.Months later8An unwindingdisconnected from thecriminal caseCorrecting tax records,disputing the claim withthe state agency, andcredit monitoring allhappen on the realclaimant's own timeline.MonthsWhere it can still be stopped — stage 3State systems were built to move pandemic relief fast, with real-time identity verification as a secondary priority, and rarely cross-check claims filedagainst the same identity in another state.Stages from the US Department of Labor's unemployment identity fraud guidance and three sentenced unemployment insurance fraud prosecutions documented on this site's case pages.howscamswork.com
The stages of the scheme, in order, with the point where it can still be stopped.

What it is

Unemployment insurance fraud uses a real person’s stolen identity — name, Social Security number, date of birth — to file a claim for unemployment benefits in their name, in a state where they may never have lived or worked. The real person is not called, not emailed, not asked to click anything. The theft happens entirely inside a state agency’s claims system, using information about them rather than contact with them.

There is a second, more targeted version: instead of inventing a new claim, someone with access to the state’s own systems — an employee, or a contractor like the one in a case on this page — reaches into a claim that already exists and reroutes it, changing the email address, password or payment method so a real claimant’s own benefits go somewhere else. Regulators call this claim hijacking or account takeover.

How it actually works

  1. Stolen identities, gathered or bought

    Names, dates of birth and Social Security numbers — harvested from a prior data breach or bought as a bulk list — are the only raw material this scheme needs. No contact with the real person is required to get started.

  2. Picking who won’t notice

    People currently employed, incarcerated, or otherwise unlikely to be checking for an unemployment notice make the best targets, because nothing about their day-to-day life changes when a claim is filed in their name.

  3. Filing the claim

    A fraudulent claim is submitted through a state workforce agency’s online portal — sometimes dozens of claims across several states from a single operation.

    Where it could have stopped

    State unemployment systems were built and, during the pandemic’s early months, hurriedly expanded to move money out fast during a crisis — verifying every applicant’s identity in real time was a secondary priority, and state systems rarely cross-check claims filed against the same identity in another state.

  4. Built to dodge detection

    Anonymous email addresses, VPNs and proxy servers are used specifically to defeat the fraud-detection systems state agencies built in response to the pandemic-era surge in claim volume.

  5. The payout goes somewhere else

    A benefits debit card is mailed, or a direct-deposit account is set up, to an address or account the fraudster controls — not the real claimant’s own.

  6. Fast cashout

    Funds are withdrawn from ATMs or spent quickly once the card or deposit arrives, before a bank or state agency flags the mismatch between the claimant on file and whoever is actually spending the money.

  7. The real person finds out sideways

    A 1099-G tax form for benefits they never received, an employer’s inquiry about a claim filed while they were still working, or their own genuine application getting rejected as a duplicate.

  8. An unwinding disconnected from the criminal case

    Correcting the tax record, disputing the claim with the state agency, and monitoring credit all happen on the real claimant’s own timeline — regardless of whether, or when, whoever filed the claim is ever caught.

Why it works

No live victim has to be fooled at all. The strongest version of this scheme needs a name, a date of birth and a Social Security number — not a phone call, a link, or a moment of persuasion. That removes the one thing most anti-fraud advice trains people to watch for.

Speed was built in on purpose, and verification came second. State agencies stood up or scaled these systems to move emergency relief fast during a genuine crisis. The trade-off was fewer real-time checks on who was actually applying — exactly the gap every case on this page exploited.

The best targets aren’t watching. An employed person has no reason to check an unemployment portal. An incarcerated person is unlikely to see mail about a claim filed in their name at all. Neither one is positioned to notice anything until a tax form or an employer’s letter forces the issue.

And insider access changes the scale entirely. A single state contractor’s system credentials, as in one case on this page, can be used to reach into claims that were never fraudulent to begin with and reroute the money — a different, harder-to-detect mechanism than inventing a claim from nothing.

Where it comes from

Every case on this page traces back to the same event: the rapid expansion of US unemployment insurance programs under the CARES Act from 2020, which moved unprecedented sums through state systems that were, by design, built for speed.

The scale, even disputed, is not small. The Government Accountability Office estimates fraud across all pandemic unemployment programs at $100 billion to $135 billion between April 2020 and May 2023 — 11 to 15% of everything paid out. The Department of Labor disputes GAO’s methodology as likely to overstate the true figure, and that estimate covers all forms of UI fraud, not identity theft specifically — but even a contested range at this scale describes a persistent, structural weakness rather than a handful of isolated cases.

Both an outside and an inside route exist. Godin and Gulley are the more familiar version: an outsider with stolen identities, filing fresh claims from a distance, using VPNs and proxy servers to look like different applicants in different places. Smith’s case shows the other route — a state labour department’s own contractor providing the access, not to invent claims but to take over ones that already existed.

Real cases

79 fraudulent claims, debit cards by mail, and an ATM withdrawal trail

2026 US Sentenced $575,425

Roosevelt Gulley, 42, of Sacramento, California, was sentenced in June 2026 to four years and six months in federal prison for wire fraud and aggravated identity theft. Over three months in 2020, he collected other people's names, dates of birth and Social Security numbers and used them to submit at least 79 fraudulent unemployment claims to California's Employment Development Department, having the resulting benefit debit cards mailed to addresses he controlled and withdrawing the funds at ATMs.

Read the case file · 1 source

A state labour department's own laptop, used to hijack $3.5 million in claims

2026 US Sentenced $3.5m

Kiara Smith, 28, of Prince George's County, Maryland, worked as a contractor for the Maryland Department of Labor and gave her state-issued laptop to co-conspirators, who used it to alter unemployment insurance data — changing email addresses, passwords and payment methods on claims — and to approve fraudulent CARES Act benefits. Sentenced in May 2026 to 42 months in federal prison, Smith was the fifth of at least six people sentenced in the conspiracy, which obtained more than $3.5 million.

Read the case file · 2 sources

Stolen identities, VPNs and proxy servers, and $2.3 million in unemployment claims

2025 US Sentenced $2.3m

David Godin, of Miami, Florida — who also used the aliases "James St Patrick," "David Wetty" and "Vic Pro" — was sentenced in June 2025 to 78 months in federal prison for wire fraud and aggravated identity theft. From June 2020 through November 2023, he used stolen personal information, anonymous email addresses, virtual private networks and proxy servers to file at least 140 fraudulent unemployment insurance claims against multiple state workforce agencies, obtaining more than $2.3 million.

Read the case file · 1 source

Red flags

  • A Form 1099-G for unemployment benefits you never applied for or received.
  • A letter from your employer, or from a state workforce agency, about a claim you didn’t file — especially from a state you’ve never worked in.
  • Your own genuine unemployment application gets rejected as a duplicate.
  • Unexpected unemployment-related mail or a benefits debit card you never requested.
  • A password reset or email-change confirmation for an unemployment account you don’t recall setting up — a possible sign of claim hijacking on an account you didn’t even know existed.

If it’s happening to you

  1. Report it to the state unemployment agency named on the notice or form, even if you’ve never lived or worked in that state — every state maintains a fraud-reporting line for exactly this.
  2. Report it to the US Department of Labor’s Office of Inspector General and, for fraud tied to pandemic-era relief programmes, to the National Center for Disaster Fraud.
  3. File your taxes based on the income you actually received, not what an incorrect 1099-G says — don’t wait for a corrected form to arrive before filing.
  4. Check your credit report at AnnualCreditReport.com and consider a credit freeze, since the same stolen information used to file a claim can be reused elsewhere.
  5. If you’re currently employed, ask your employer to confirm they haven’t received any other unemployment-related inquiries about you — a second sign of the same identity being reused.
  6. Report it at ReportFraud.ftc.gov and to the FBI’s Internet Crime Complaint Center at ic3.gov. See where to report for other countries.

Where the money goes

The claim itself is worthless until it becomes cash, which is the point where every case on this page converges: a state agency issues a prepaid benefits debit card or a direct deposit, sent to an address or account the fraudster — not the real claimant — controls.

From there the pattern is fast and physical rather than layered: funds are withdrawn from ATMs or spent directly on the debit card within days of it arriving, before a bank or the issuing agency flags the mismatch. Multiplying that across dozens or hundreds of claims, as in the largest cases on this page, is what turns a single stolen identity’s weekly benefit amount into a six- or seven-figure scheme.

The other half of this story

Our sibling site Clean on Paper explains how benefit-card cash gets moved on from there — the same account-and-card cash-out pattern documented on this site’s own money mule recruitment page.

By the numbers

No published dataset breaks this scheme out as its own category yet, so there is no chart to show. The data page explains which agency categories exist and why some schemes are invisible in official statistics.

Sources

Every factual claim above traces to one of these. Statistics are reported losses; see methodology for what that does and does not measure.

  1. Miami man sentenced to federal prison for $2.3 million COVID-19 unemployment insurance benefits fraud scheme. US Internal Revenue Service, Criminal Investigation. Accessed 2026-09-11. Supports: The Godin case: the multi-state VPN/proxy-server method, the 140-plus fraudulent claims, and the $2.3 million total.
  2. Sacramento Man Sentenced for Covid-Related Unemployment Insurance Fraud Scheme. California Statewide Law Enforcement Association, reproducing the US Attorney's Office for the Eastern District of California press release. Accessed 2026-09-11. Supports: The Gulley case: the stolen personal information, the 79 fraudulent applications, the debit-card-to-controlled-address method, and the ATM cashout.
  3. Prince George's County woman sentenced to prison for unemployment insurance fraud. Yahoo News, syndicating DC News Now and US Attorney's Office for the District of Maryland reporting. Accessed 2026-09-11. Supports: The Smith case: the state labour department contractor role, the laptop access given to co-conspirators, and the altered claims data.
  4. Maryland Woman Gets 3.5 Years for $3.5 Million COVID Unemployment Fraud Scheme. Townhall. Accessed 2026-09-11. Supports: The Smith case: the sentence and financial penalties, and the four co-conspirators' individual sentences.
  5. Report Unemployment Identity Fraud. US Department of Labor. Accessed 2026-09-11. Supports: The definition of claim hijacking/account takeover, the four ways victims typically discover the fraud, and the recommended steps for reporting it and correcting tax records.
  6. Unemployment Insurance: Estimated Amount of Fraud During Pandemic Likely Between $100 Billion and $135 Billion. US Government Accountability Office. Accessed 2026-09-11. Supports: The $100–135 billion fraud estimate, the April 2020–May 2023 period it covers, the 11–15% share of total benefits paid, and the Department of Labor's dispute that the estimate is likely overstated.

Common questions

How would I even know if someone filed an unemployment claim in my name?

Usually sideways, not directly. The Department of Labor names four ways this surfaces: a 1099-G tax form for benefits you never received; an employer's inquiry about a claim filed in your name while you were still working there; unexpected unemployment mail from a state you've never worked in; or your own genuine application getting rejected as a duplicate.

I'm currently employed. Am I still a target?

You may be a preferred one. Someone with a job has no reason to be checking an unemployment portal, which means a fraudulent claim in their name can run for weeks before an employer inquiry or a tax form surfaces it. Every case on this page involved identities used without the real person doing anything to invite it.

What is 'claim hijacking,' and how is it different from a fake new claim?

A new fraudulent claim is invented from a stolen identity that never filed for benefits at all. Claim hijacking — also called account takeover — instead targets a claim that already exists, changing its email address, password or payment method so a legitimate claimant's own benefits get rerouted. One case on this page involved a state labour department contractor giving co-conspirators the system access to do exactly that.

Do I owe tax on benefits I never actually received?

No — but the IRS will not automatically know that. The Department of Labor's guidance is to report only the income you actually received when filing, without waiting for a corrected 1099-G, and to report the fraud to the state agency that issued the incorrect form so the record gets fixed on their end too.

Is pandemic-era unemployment fraud really as large as the headlines say?

The GAO's own estimate — $100 billion to $135 billion in fraud across all pandemic unemployment programs from April 2020 to May 2023 — is disputed by the Department of Labor, which called the methodology likely to overstate the true figure, while GAO has defended its approach. That estimate also covers all forms of UI fraud, not identity theft alone. Treat it as a contested upper bound, not a settled count.

Where a hijacked or fabricated claim turns into cashWhere a hijacked or fabricated claim turns into cash. The identity is stolen once. The payout has to be redirected every time. Where a hijacked or fabricated claim turns into cashThe identity is stolen once. The payout has to be redirected every time.A stolen name, SocialSecurity number anddate of birthThe stolen identityfiles a new claim, ortakes over an existingone by changing itsemail, password orpayment methodA fraudulent claimfiled, or an existingclaim hijackedThe state agencyissues a benefitsdebit card or sets upa direct deposit,addressed to thefraudster rather thanthe real claimantA benefits debit cardor direct deposit,sent to an address thefraudster controlsFunds are withdrawn atATMs or spentdirectly, usuallywithin days of thecard or depositarrivingCash withdrawn at ATMsor spentReversibilityA recall is realistically possible only at the first hop, and only in the first hours. After the money is converted it becomes an investigation, not a refund.How benefit-card cash gets moved on from there — Clean on Paper, our sibling sitehttps://cleanonpaper.site/techniques/money-mules/A recall is realistically possible only before the card or deposit is touched — a state agency can sometimes freeze or claw back a payment flagged early, which is why the gap between a scheme's intended and actual take can be large. Once cash is out, it is an investigation, not a refund.howscamswork.com
Where the money goes after it leaves, and where it becomes hard to recover.

Report it

Reporting is what produces the enforcement data on this page. Find the right agency and phone number for your country on the report page. If money moved in the last few hours, call your bank first.