FinCEN expands student aid fraud crackdown beyond identity verification

The U.S. Treasury Department is expanding its campaign against federal student aid fraud beyond applicant identity verification, asking banks and other financial institutions to identify the accounts, devices and payment networks used to receive and launder fraudulent aid.
A recent alert from the Financial Crimes Enforcement Network (FinCEN), prepared with the Education Department’s Office of Inspector General and the FBI, marks a shift from preventing fraud at the application stage to detecting it after money has entered the financial system.
FinCEN is now focusing on what happens after fraudulent refunds reach bank accounts and begin moving through peer-to-peer payment services, wire transfers, shell companies, money services businesses and digital asset exchanges.
“Every dollar stolen from Federal student aid is a dollar taken from taxpayers and deserving students,” Treasury Secretary Scott Bessent said in the department’s announcement.
Federal Student Aid distributes more than $120 billion annually in grants, work study funds and low interest loans to approximately 13 million students.
The money initially goes to the institution where a student is enrolled. After tuition and fees are deducted, any remaining balance is refunded to the student for education and living expenses. Those refunds are the primary target for fraud rings.
FinCEN says fraud rings often target institutions with open admissions and online programs. Some create “ghost students” by using personal information stolen from real people, including minors, to submit enrollment and FAFSA applications.
Fraudsters may also use AI and other tools to create documents that combine stolen data with fabricated details, producing synthetic identities capable of passing basic verification checks.
AI-powered chatbots or paid accomplices can then complete assignments and maintain the appearance that the supposed student remains enrolled long enough to qualify for the full aid refund.
Identity theft victims may not learn about the fraud until they apply for aid themselves or discover federal student loans issued in their names.
Other operations rely on “straw students,” people who knowingly provide their personal information in exchange for part of the refund.
FinCEN also describes schemes involving corrupt college employees who recruit straw applicants, facilitate their enrollment, complete coursework or manipulate academic records to preserve their eligibility.
The alert points to one North Carolina operation in which a woman organized approximately 80 straw students and fraudulently sought more than $5 million in aid from multiple community colleges.
Investigators found personal information, coursework, Federal Student Aid credentials and bank account details in her home.
Student aid refunds may be deposited by colleges or by payment intermediaries hired to process disbursements.
According to Bank Secrecy Act data cited by FinCEN, automated clearinghouse records may include the word “refund,” a college’s name or abbreviation and sometimes the name of the intended student.
That information can expose discrepancies when the receiving account has no apparent connection to the named student.
FinCEN says money mules may receive refunds intended for multiple unrelated people and then move the proceeds to other accounts, send them abroad or convert them into digital assets.
Domestic shell companies may receive the money directly or accept transfers from mule accounts before purchasing real estate or moving the proceeds overseas.
Fraud rings shift to one-to-one accounts
More sophisticated rings are using what law enforcement calls a “one-to-one” model. Instead of sending several refunds to one account, criminal brokers create separate accounts under false identities, with each account receiving the refund associated with a single fraudulent applicant.
The broker keeps a percentage before forwarding the remainder through peer-to-peer payments, wires or digital assets.
FinCEN’s warning signs include accounts funded only by student aid refunds, business accounts receiving refunds intended for unrelated individuals and rapid transfers following a disbursement.
Financial institutions are also told to look for multiple refund receiving accounts accessed from the same device or out-of-state or international IP address.
The agency cautions that no single indicator proves fraud. Institutions are expected to consider a customer’s normal activity, account profile and the presence of multiple related warning signs.
The alert follows increasingly aggressive identity controls at the application stage. In 2025, selected first-time applicants were required to present valid government-issued photo identification to an authorized college employee, either in person or during a live video conference.
On April 26, Federal Student Aid began screening every FAFSA in real time. Applicants assessed as high risk can be required to show government identification and complete an automated live camera check on a mobile device.
Those unable to complete the process can seek in-person verification through a college financial aid office.
The Department of Education subsequently said about 300,000 previously submitted applications for the 2026–27 award year had been selected for heightened identity verification based on fraud risk indicators. Selection did not establish that an application was fraudulent.
The FinCEN alert does not create another identity verification requirement or mandate biometric checks by financial institutions.
Instead, it adds a downstream layer to the government’s fraud strategy, using transaction, account, device and network intelligence already available to financial institutions to identify fraudulent aid that escaped identity verification at the FAFSA and enrollment stages.
Article Topics
AI fraud | continuous verification | financial crime | FinCEN | fraud prevention | identity verification | students | United States





Comments