Also called: UI fraud · unemployment identity theft · pandemic unemployment fraud · claim hijacking · unemployment benefits fraud
Unemployment insurance fraud uses someone else's stolen identity — name, Social Security number, date of birth — to file for unemployment benefits in a state where they never worked or don't live. The real person usually finds out from a 1099-G tax form, an employer's inquiry about a claim, or a rejected application of their own. One Maryland conspiracy stole $3.5 million this way.
What it is
Unemployment insurance fraud uses a real person’s stolen identity — name, Social Security number, date
of birth — to file a claim for unemployment benefits in their name, in a state where they may never have
lived or worked. The real person is not called, not emailed, not asked to click anything. The theft
happens entirely inside a state agency’s claims system, using information about them rather than contact
with them.
There is a second, more targeted version: instead of inventing a new claim, someone with access to the
state’s own systems — an employee, or a contractor like the one in a case on this page — reaches into a
claim that already exists and reroutes it, changing the email address, password or payment method so
a real claimant’s own benefits go somewhere else. Regulators call this claim hijacking or account
takeover.
How it actually works
Stolen identities, gathered or bought
Names, dates of birth and Social Security numbers — harvested from a prior data breach or bought as a
bulk list — are the only raw material this scheme needs. No contact with the real person is required to
get started.
Picking who won’t notice
People currently employed, incarcerated, or otherwise unlikely to be checking for an unemployment
notice make the best targets, because nothing about their day-to-day life changes when a claim is filed
in their name.
Filing the claim
A fraudulent claim is submitted through a state workforce agency’s online portal — sometimes dozens of
claims across several states from a single operation.
Where it could have stopped
State unemployment systems were built and, during the pandemic’s early months, hurriedly expanded to move money out fast during a crisis — verifying every applicant’s identity in real time was a secondary priority, and state systems rarely cross-check claims filed against the same identity in another state.
Built to dodge detection
Anonymous email addresses, VPNs and proxy servers are used specifically to defeat the fraud-detection
systems state agencies built in response to the pandemic-era surge in claim volume.
The payout goes somewhere else
A benefits debit card is mailed, or a direct-deposit account is set up, to an address or account the
fraudster controls — not the real claimant’s own.
Fast cashout
Funds are withdrawn from ATMs or spent quickly once the card or deposit arrives, before a bank or state
agency flags the mismatch between the claimant on file and whoever is actually spending the money.
The real person finds out sideways
A 1099-G tax form for benefits they never received, an employer’s inquiry about a claim filed while
they were still working, or their own genuine application getting rejected as a duplicate.
An unwinding disconnected from the criminal case
Correcting the tax record, disputing the claim with the state agency, and monitoring credit all happen
on the real claimant’s own timeline — regardless of whether, or when, whoever filed the claim is ever
caught.
Why it works
No live victim has to be fooled at all. The strongest version of this scheme needs a name, a date of
birth and a Social Security number — not a phone call, a link, or a moment of persuasion. That removes
the one thing most anti-fraud advice trains people to watch for.
Speed was built in on purpose, and verification came second. State agencies stood up or scaled these
systems to move emergency relief fast during a genuine crisis. The trade-off was fewer real-time checks
on who was actually applying — exactly the gap every case on this page exploited.
The best targets aren’t watching. An employed person has no reason to check an unemployment portal.
An incarcerated person is unlikely to see mail about a claim filed in their name at all. Neither one is
positioned to notice anything until a tax form or an employer’s letter forces the issue.
And insider access changes the scale entirely. A single state contractor’s system credentials, as in
one case on this page, can be used to reach into claims that were never fraudulent to begin with and
reroute the money — a different, harder-to-detect mechanism than inventing a claim from nothing.
Where it comes from
Every case on this page traces back to the same event: the rapid expansion of US unemployment insurance
programs under the CARES Act from 2020, which moved unprecedented sums through state systems that were,
by design, built for speed.
The scale, even disputed, is not small. The Government Accountability Office estimates fraud across
all pandemic unemployment programs at $100 billion to $135 billion between April 2020 and May 2023 — 11
to 15% of everything paid out. The Department of Labor disputes GAO’s methodology as likely to overstate
the true figure, and that estimate covers all forms of UI fraud, not identity theft specifically — but
even a contested range at this scale describes a persistent, structural weakness rather than a handful
of isolated cases.
Both an outside and an inside route exist. Godin and Gulley are the more familiar version: an
outsider with stolen identities, filing fresh claims from a distance, using VPNs and proxy servers to
look like different applicants in different places. Smith’s case shows the other route — a state labour
department’s own contractor providing the access, not to invent claims but to take over ones that
already existed.
Real cases
2026 US Sentenced $575,425
Roosevelt Gulley, 42, of Sacramento, California, was sentenced in June 2026 to four years and six months in federal prison for wire fraud and aggravated identity theft. Over three months in 2020, he collected other people's names, dates of birth and Social Security numbers and used them to submit at least 79 fraudulent unemployment claims to California's Employment Development Department, having the resulting benefit debit cards mailed to addresses he controlled and withdrawing the funds at ATMs.
Read the case file ·
1 source
2026 US Sentenced $3.5m
Kiara Smith, 28, of Prince George's County, Maryland, worked as a contractor for the Maryland Department of Labor and gave her state-issued laptop to co-conspirators, who used it to alter unemployment insurance data — changing email addresses, passwords and payment methods on claims — and to approve fraudulent CARES Act benefits. Sentenced in May 2026 to 42 months in federal prison, Smith was the fifth of at least six people sentenced in the conspiracy, which obtained more than $3.5 million.
Read the case file ·
2 sources
2025 US Sentenced $2.3m
David Godin, of Miami, Florida — who also used the aliases "James St Patrick," "David Wetty" and "Vic Pro" — was sentenced in June 2025 to 78 months in federal prison for wire fraud and aggravated identity theft. From June 2020 through November 2023, he used stolen personal information, anonymous email addresses, virtual private networks and proxy servers to file at least 140 fraudulent unemployment insurance claims against multiple state workforce agencies, obtaining more than $2.3 million.
Read the case file ·
1 source
Red flags
- A Form 1099-G for unemployment benefits you never applied for or received.
- A letter from your employer, or from a state workforce agency, about a claim you didn’t file — especially from a state you’ve never worked in.
- Your own genuine unemployment application gets rejected as a duplicate.
- Unexpected unemployment-related mail or a benefits debit card you never requested.
- A password reset or email-change confirmation for an unemployment account you don’t recall setting up — a possible sign of claim hijacking on an account you didn’t even know existed.
If it’s happening to you
- Report it to the state unemployment agency named on the notice or form, even if you’ve never lived
or worked in that state — every state maintains a fraud-reporting line for exactly this.
- Report it to the US Department of Labor’s Office of Inspector General and, for fraud tied to
pandemic-era relief programmes, to the National Center for Disaster Fraud.
- File your taxes based on the income you actually received, not what an incorrect 1099-G says —
don’t wait for a corrected form to arrive before filing.
- Check your credit report at AnnualCreditReport.com and consider a credit freeze, since the same
stolen information used to file a claim can be reused elsewhere.
- If you’re currently employed, ask your employer to confirm they haven’t received any other
unemployment-related inquiries about you — a second sign of the same identity being reused.
- Report it at ReportFraud.ftc.gov and to the FBI’s Internet Crime Complaint Center at ic3.gov. See
where to report for other countries.
Where the money goes
The claim itself is worthless until it becomes cash, which is the point where every case on this page
converges: a state agency issues a prepaid benefits debit card or a direct deposit, sent to an address or
account the fraudster — not the real claimant — controls.
From there the pattern is fast and physical rather than layered: funds are withdrawn from ATMs or spent
directly on the debit card within days of it arriving, before a bank or the issuing agency flags the
mismatch. Multiplying that across dozens or hundreds of claims, as in the largest cases on this page, is
what turns a single stolen identity’s weekly benefit amount into a six- or seven-figure scheme.
By the numbers
No published dataset breaks this scheme out as its own category yet, so there is no chart to show.
The data page explains which agency categories exist and why some schemes are
invisible in official statistics.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.