in

Pandemic Benefit Fraud: How Stolen Identities Exploited Emergency Payment Systems

What the misuse of prison inmates’ identities reveals about unemployment fraud, mule accounts and the control failures behind rapid government disbursement

Stolen identities of prison inmates
The Prison Identity Loophole: Pandemic Benefit Fraud and Control Failures

The exploitation of incarcerated people’s identities during the COVID-19 pandemic illustrates how quickly stolen personal information can be converted into government payments when emergency disbursement programmes operate under intense pressure.

In May 2023, Brooke Stewart of St. Joseph, Missouri, pleaded guilty to stealing federal funds after using identity information belonging to five state or federal prison inmates to facilitate fraudulent unemployment claims. She also obtained benefits using her own identity and that of another person. The scheme generated at least $139,663 in Coronavirus Aid, Relief, and Economic Security Act unemployment benefits between May 2020 and June 2021.

None of the incarcerated individuals whose identities were used received the fraudulent payments. In October 2023, Stewart was sentenced to two years and six months in federal prison and ordered to repay the full $139,663.

The case was relatively small compared with the largest pandemic-relief prosecutions. Its importance lies in what it reveals about the wider operating model: stolen identities, fragmented government data, remotely submitted claims and financial accounts capable of receiving funds without a sufficiently strong connection to the person named as the claimant.

For financial crime teams, the lesson extends beyond unemployment insurance. Any emergency programme that prioritises rapid access to funds can become a target for identity theft, account misuse, organised fraud and laundering unless identity, eligibility and payment-recipient controls operate as one connected system.

Key Takeaways

  • Pandemic Relief Programs Created Significant Fraud Opportunities
  • Stolen Identities Were Used to Submit Fraudulent Benefit Claims
  • Incarcerated Individuals Can Be Targeted for Identity-Based Fraud
  • Identity Theft Can Enable Large-Scale Government Benefits Fraud
  • Criminals Exploit Eligibility Gaps and Weak Verification Controls
  • Fraudulent Claims Can Be Distributed Across Multiple Identities
  • Government Programs Are Vulnerable During Rapid Emergency Deployment
  • Identity Owners May Be Completely Unaware of the Fraud
  • Public-Sector Fraud Can Generate Significant Financial Losses
  • COVID-19 Fraud Demonstrates the Importance of Cross-Agency Data Matching
  • Benefit Fraud and Identity Fraud Are Closely Connected
  • Post-Payment Investigation Remains Critical to Recovering Public Funds

Listen the podcast

Watch the video

Why the case matters now

Pandemic unemployment fraud was not limited to isolated opportunists. It became one of the largest identity-enabled fraud events in recent US history.

The Government Accountability Office estimated that fraudulent unemployment insurance payments made between April 2020 and May 2023 were likely between $100 billion and $135 billion. The wider pandemic-relief environment affected at least 19 federal programmes, including unemployment insurance, the Paycheck Protection Program and Economic Injury Disaster Loans.

By the end of 2024, at least 2,532 defendants had been found guilty of offences involving pandemic-relief programmes. Nearly half of convicted defendants faced conspiracy charges, reflecting the involvement of organised groups as well as individual offenders.

Department of Labor investigations had resulted, by January 2025, in more than 2,075 people being charged with unemployment insurance fraud-related crimes, more than 1,550 convictions and over $1.1 billion in investigative monetary outcomes. Authorities continued receiving new complaints and pursuing cases years after the temporary programmes ended.

The long enforcement tail demonstrates that emergency fraud does not end when the programme closes. Investigations, asset recovery, identity remediation, overpayment reconciliation and prosecutions can continue for a decade or more.

How the Stewart scheme worked

Stewart used personal information belonging to five incarcerated individuals to support false unemployment claims. Because those people were in prison, they were not eligible for the Missouri and enhanced federal unemployment benefits claimed in their names.

The claims created an artificial identity journey. The named claimant was a real person with a valid identity, but the contact information, application activity and destination of the funds were controlled by someone else.

This distinguishes the scheme from wholly synthetic identity fraud. The identities were not fabricated by combining fictional and genuine attributes. They belonged to identifiable people whose information was used without their participation.

The payments were therefore associated with authentic names and Social Security numbers, reducing the likelihood that basic identity-format checks would identify the fraud. The decisive inconsistency was between the claimant’s recorded incarceration status and the claim that the individual was available for and affected by unemployment.

Stewart’s conduct also did not begin in an otherwise clean criminal history. She was on supervision following a 2019 state conviction for trafficking in stolen identities when she committed the federal offence. That background reinforces a broader point: emergency programmes can be targeted by offenders who already possess experience, data or relationships relevant to identity crime.

Why incarcerated identities became attractive targets

Incarcerated individuals represent a distinctive identity-fraud risk because their personal information remains valid while their ability to detect, challenge and correct misuse may be constrained.

A prisoner may have limited access to financial statements, credit-monitoring services, government correspondence and digital accounts. Suspicious tax or benefit documents may be sent to a previous address or remain undiscovered until long after the fraudulent payment has been made.

The identity can therefore appear administratively credible while the genuine person is unable to participate in ordinary verification or complaint processes.

Incarceration information is also held in systems separate from those administering employment and benefit programmes. Unless state workforce agencies have timely access to accurate prisoner data and perform effective cross-matches, a claim may progress without identifying that the named applicant is incarcerated.

A June 2026 Department of Labor Office of Inspector General audit demonstrated that this weakness remained material. The OIG had previously identified approximately $267.3 million in potentially fraudulent pandemic unemployment payments associated with federal prisoners’ Social Security numbers.

The audit found weaknesses in federal oversight of state investigations and inconsistent access to the Social Security Administration’s Prisoner Update Processing System. It concluded that additional fraudulent payments involving prisoners’ identities were likely to have gone undetected.

The risk must nevertheless be assessed carefully. A payment associated with an incarcerated person may involve identity theft, collusion, coercion or direct participation. In Stewart’s case, the named prisoners received none of the money. Investigators should therefore avoid assuming that the identity holder benefited merely because their details appeared on the claim.

Why emergency benefit fraud scaled so efficiently

The first reason was speed. Governments needed to deliver assistance rapidly to unprecedented numbers of unemployed people. Controls designed for ordinary volumes had to process large populations, including self-employed workers and other claimants who did not fit traditional unemployment-insurance records.

The second reason was fragmented administration. State agencies operated different systems, procedures and fraud controls. A criminal could submit claims in several jurisdictions, exploiting delays in multistate data matching and inconsistent verification standards.

The third reason was remote access. Claims could be submitted using online forms, webmail accounts, mobile numbers and remotely controlled devices. An offender did not need to appear physically before the paying agency.

The fourth reason was abundant stolen identity information. Data breaches, phishing, previous fraud and illicit markets gave criminals access to names, Social Security numbers, dates of birth and addresses. Once obtained, the same identity package could be tested against several programmes.

The fifth reason was flexible disbursement infrastructure. Benefits could be paid into deposit accounts or through prepaid-card programmes. Fraudsters could direct several claimants’ payments towards accounts, addresses or devices under common control and then withdraw or transfer the money rapidly.

Finally, the same networks could target several relief programmes. An identity used for unemployment fraud might also be tested against business loans, tax credits or other government assistance. Separate agencies could therefore approve apparently unrelated applications connected to the same criminal actor.

How government fraud becomes a financial-sector problem

The predicate offence occurs when a fraudulent claim is submitted to the government. The proceeds, however, enter the regulated financial system.

Banks, fintechs, prepaid-card providers and peer-to-peer payment services may receive, hold and move the stolen funds. Their controls can therefore identify fraud that was not detected during the application process.

FinCEN identified several important patterns during the pandemic. These included accounts receiving unemployment payments from states in which the customer did not live or work, payments issued in the names of people other than the account holder and multiple claimants’ benefits entering one account.

Other indicators included newly opened or previously inactive accounts suddenly receiving numerous government payments, followed by rapid cash withdrawal, prepaid-card purchases, peer-to-peer transfers or movement to out-of-state and overseas accounts.

Digital evidence was equally important. Multiple applications could share the same email address, device, IP address, telephone number or bank account. Login locations might be inconsistent with the claimant’s residence or the state issuing the payment.

No single indicator proves fraud. A customer may legitimately move state, receive payments relating to a prior employer or help manage finances for another person. The stronger cases emerge when several inconsistencies form a coherent network.

Why conventional controls missed the activity

Government agencies and financial institutions observed different parts of the scheme.

The workforce agency saw a claimant’s identity, employment history, eligibility declarations and contact information. The bank saw the customer account, incoming government payment and subsequent transactions. A prison authority held the information showing that the named person was incarcerated.

Unless those records were compared, each participant lacked the evidence needed to identify the full fraud.

Identity verification was also frequently treated as confirmation of eligibility. Verifying that a Social Security number and name belong to a real person does not establish that the person submitted the application, is entitled to the benefit or controls the receiving account.

Payment controls faced a similar limitation. A deposit from a government agency may appear lower risk than a transfer from an unknown individual. During an emergency, unusually large volumes of legitimate public payments can make suspicious activity less visible.

Criminals benefited from this fragmentation. They did not need to defeat every control. They needed to find one route through the application process and one financial destination that remained operational long enough to receive and remove the funds.

What an evidence-led investigation looks like

The investigation should begin by reconstructing the complete claim-to-cash timeline. Analysts need to identify when the application was created, which identity information was used, what device and contact data were supplied, where the funds were sent and how they were subsequently withdrawn or transferred.

Eligibility evidence should be tested against independent records. For incarcerated claimants, this includes the dates and location of imprisonment. For other cases, relevant information may include employment, earnings, death records, residence and claims submitted in other states.

Investigators should then establish who controlled the payment destination. Account ownership alone may not reveal effective control. Shared devices, online-banking logins, card use, cash withdrawals, phone numbers and transfer beneficiaries may connect the account to the person who filed the false claim.

The review should extend beyond the initially identified payment. Related claims may share an email address, IP address, physical address, employer, bank account or withdrawal location. Network analysis can reveal that an apparently small case is one component of a larger organised scheme.

Evidence should also distinguish the identity-theft victim from the beneficiary. People whose identities were used may require correction of government and tax records even where they suffered no direct account loss.

What a resilient control stack looks like

The first layer is identity and eligibility separation. Programmes should verify not only that an identity exists, but that the person controls the application and meets the relevant eligibility conditions.

The second layer is pre-payment data matching. Claims should be compared, where legally authorised, against prisoner, death, employment, multistate-claim and government-payment records before funds are released. High-risk matches should trigger review rather than automatic rejection where the data may be incomplete.

The third layer is recipient-account verification. The relationship between the claimant and payment destination should be established. Payments to unrelated accounts, repeated changes of destination and one account receiving benefits for several people require enhanced scrutiny.

The fourth layer is shared network intelligence. Agencies should analyse common emails, phones, IP addresses, devices, employers, physical addresses and bank accounts across applications. The objective is to identify organised infrastructure rather than assess every claim independently.

The fifth layer is financial-institution monitoring. Banks and payment providers should connect government-payment information with customer identity, account age, expected activity and downstream movement. Rapid withdrawal should be evaluated alongside recipient mismatch and linked-payment evidence.

The sixth layer is rapid interdiction. Public agencies and financial institutions need procedures for freezing, recalling and returning suspected fraudulent payments before they are withdrawn. Preserving the associated device and account evidence is essential for prosecution and recovery.

Finally, emergency programmes need fraud-risk governance before the crisis begins. Identity services, data-sharing agreements, investigation protocols and payment-recovery channels should be designed in advance rather than assembled after losses become systemic.


Pandemic Benefit Fraud
How Stolen Identities Exploited Emergency Payment Systems

What this means for financial crime leaders

The Stewart case demonstrates how a comparatively simple identity-theft scheme can exploit gaps between public-benefit administration, incarceration data and financial accounts.

The principal lesson is not that emergency payments should be delayed until every risk is eliminated. During a crisis, excessive friction can prevent legitimate claimants from receiving essential support. The objective is to combine rapid access with controls focused on the highest-risk inconsistencies.

Financial crime leaders should ask whether their institutions can identify multiple government payments linked to unrelated identities, whether public-sector fraud intelligence reaches receiving institutions quickly and whether suspected proceeds can be restricted before they leave the account.

They should also recognise that stolen-identity victims may include people with limited ability to detect misuse, including prisoners, deceased individuals, children and people without regular access to financial services.

Pandemic unemployment fraud became industrialised because criminals connected identity data, remote applications and payment infrastructure faster than government and financial institutions connected their controls.

The strongest response to the next emergency will be built before funds begin to move: integrated identity assurance, real-time eligibility checks, network analytics, recipient-account verification and rapid public-private information sharing capable of distinguishing genuine need from organised exploitation.

What Financial Institutions Should Consider

  • Strengthen Identity Verification for Government Benefit Payments
  • Detect Multiple Benefit Payments Linked to Shared Accounts
  • Monitor Unusual Government Payment Activity
  • Identify Accounts Receiving Funds for Multiple Unrelated Individuals
  • Apply Device and Network Intelligence to Benefit-Related Transactions
  • Detect Rapid Movement of Government Funds After Receipt
  • Monitor Cash Withdrawals Following Benefit Payments
  • Strengthen Mule Account Detection
  • Identify Identity and Account Mismatches
  • Incorporate Public-Sector Fraud Typologies Into Transaction Monitoring
  • Improve Information Sharing With Government Agencies
  • Use Cross-Customer Analytics to Detect Coordinated Fraud
  • Apply Retrospective Reviews to High-Risk Pandemic-Era Payments
  • Strengthen Fraud Controls During Emergency Financial Programs
  • Treat Government Benefits Fraud as Both Fraud and Financial Crime Risk

Download the briefing

Pandemic Benefit Fraud: Systematic Exploitation of Emergency Payment Systems

What do you think?

Leave a Reply

Your email address will not be published. Required fields are marked *

GIPHY App Key not set. Please check settings

One Comment

  1. The exploitation of incarcerated individuals’ identities during the COVID-19 pandemic demonstrates how quickly emergency financial assistance can be converted into criminal proceeds when identity, eligibility and payment controls operate in isolation.

    The underlying weakness was not simply the use of stolen personal information. It was the absence of a sufficiently connected control environment capable of confirming that the claimant controlled the application, met the programme’s eligibility requirements and had a legitimate relationship with the account receiving the funds.

    Pandemic unemployment fraud also showed how public-sector crime becomes a financial-sector risk. Government agencies may approve the claim, but banks, fintechs and prepaid-card providers often receive the first transactional indicators that several identities, states or benefit programmes are connected to the same account, device or withdrawal network.

    Future emergency programmes must therefore balance rapid access to essential support with proportionate, intelligence-led controls. This includes real-time prisoner, death, employment and multistate-claim checks; stronger recipient-account verification; network analysis across applications; and rapid information sharing between public agencies and financial institutions.

    Investigations must also distinguish clearly between identity-theft victims and criminal beneficiaries. Incarcerated people and other vulnerable populations may have limited ability to detect that their identities have been misused and should not be assumed to have participated merely because their information appeared on a fraudulent claim.

    Ultimately, emergency fraud scales when criminals connect stolen identities, remote applications and payment infrastructure faster than institutions connect their data and controls. The strongest defence against the next crisis will be built in advance through integrated identity assurance, pre-payment risk detection and rapid public-private action before fraudulent funds can be dispersed.

Philippine Authorities Crack Down on Massive VAT Fraud Scheme

Ghost Receipts and VAT Fraud: Inside the Philippines’ ₱50 Billion Tax-Evasion Scheme

Navigating Online Dating Scams

Online Dating Scams: How Romance Fraud Turns Emotional Trust into Financial Loss