$0 Identity Theft Prevention After Death — Quick-Start Checklist

Ghosting Identity Theft: How Criminals Exploit the Deceased

What Ghosting Actually Means in Fraud

In cybersecurity and law enforcement circles, "ghosting" doesn't mean ignoring someone's texts. It refers to a specific type of identity theft where a criminal takes over the identity of a deceased person — essentially becoming a ghost of someone who has died. The term exists because the fraud relies on the victim being unable to notice, respond to, or report the crime.

Ghosting is a form of financial fraud in the United States. The mechanics are straightforward: after a person dies, their Social Security number may remain active in credit bureau databases until death records and deceased alerts are processed. During that window, criminals can use the number to open credit cards, apply for loans, file tax returns, or build synthetic identities.

How Criminals Find Their Targets

The sourcing is disturbingly systematic. Fraud networks monitor several publicly available channels:

Obituaries are the primary intelligence source. A typical published obituary includes the deceased's full name, date of birth, city of residence, and often their maiden name or parents' names. That's enough identifying information to purchase a matching Social Security number from dark web marketplaces, where deceased SSNs routinely sell for less than $10.

Probate court filings are public records in most jurisdictions. They list the deceased's assets, the executor's contact information, and the beneficiaries — giving criminals a picture of the estate's value and who to impersonate if needed.

People-search websites (Spokeo, Whitepages, BeenVerified, and similar aggregators) continue to display the deceased person's data — addresses, phone numbers, known associates, and estimated ages — often for months after the death. These profiles remain harvestable until someone actively submits an opt-out request.

The Two Attack Patterns

Direct takeover is the faster approach. The criminal uses the deceased's actual identity — their real name, real SSN, real address — to apply for credit, redirect mail, or file a tax return. This type of ghosting produces immediate results but also leaves an obvious trail, because the activity is tied to a person who institutions will eventually learn has died.

Synthetic identity construction is subtler. The criminal takes only the SSN and pairs it with a fabricated name, a fake date of birth, and a drop address. This hybrid identity applies for a small secured credit card, uses it responsibly for six months, then applies for more credit. Over time, the synthetic identity builds a clean credit score. When the limits are high enough, the criminal maxes everything out and disappears. Because the SSN belongs to a deceased person who won't dispute anything, the fraud can run for years before anyone catches it.

The Federal Reserve has estimated that synthetic identity fraud accounts for billions in losses annually, and deceased SSNs are among the most commonly used building blocks.

Free Download

Get the Identity Theft Prevention After Death — Quick-Start Checklist

Everything in this article as a printable checklist — plus action plans and reference guides you can start using today.

Why the System Makes It Easy

The gap that ghosting exploits is structural. When someone dies in the United States, the funeral director reports the death to the Social Security Administration. The SSA adds the death to the Death Master File. Credit bureaus may receive this information later, but transmission is not immediate and synchronization can fail or be delayed.

During that delay, the deceased's credit file is functionally identical to a living person's. There's no automatic freeze, no proactive alert, and no institution reaching out to check on activity. The file sits there, active and unmonitored, waiting to be used.

Credit bureaus may receive death records through shared data, but the update can be delayed or fail. An executor or other authorized representative should send a certified death certificate and proof of authority to each bureau — Equifax, Experian, and TransUnion — and request a deceased alert. Don't assume an automatic update has appeared.

What Executors Can Do to Shut It Down

Preventing ghosting requires closing every channel that criminals use to source information and exploit credentials:

  • Notify all three credit bureaus immediately — don't wait for the Death Master File to update on its own
  • File IRS Form 56 to notify the IRS of your fiduciary relationship and help route tax correspondence to your address
  • Submit opt-out requests to data brokers — removing the deceased's personal information from public search results cuts off a key intelligence source
  • Write a privacy-conscious obituary — include enough information for the community to identify the deceased without publishing exact birth dates, maiden names, or other data points that facilitate fraud
  • Secure physical mail — redirect or hold USPS delivery so financial documents and pre-approved credit offers don't accumulate at an empty address

The Identity Theft Prevention After Death toolkit provides a structured timeline for all of these actions, with pre-drafted letters for credit bureaus and creditors, a data broker opt-out directory, and communication scripts for the conversations nobody prepares you for.

Get Your Free Identity Theft Prevention After Death — Quick-Start Checklist

Download the Identity Theft Prevention After Death — Quick-Start Checklist — a printable guide with checklists, scripts, and action plans you can start using today.

Learn More →