'Ghosting': How to Stop Identity Theft of a Deceased Family Member
"Ghosting" is a form of identity theft in which someone steals a deceased person's identity to open credit cards, file fraudulent tax returns, or apply for loans in their name. An estimated 2.5 million deceased Americans have their identities used fraudulently every year, according to a widely cited ID Analytics study. The crime exploits a specific, predictable gap: the delay between when someone dies and when that death is fully recorded across credit bureaus and data broker databases.
This guide explains exactly how ghosting works, why obituaries make it worse, and the specific, time-sensitive steps a family needs to take — starting within 48 hours — to close that gap before it can be exploited.
How Ghosting Actually Works
When someone dies, their death is not instantly visible everywhere their personal information exists. The Social Security Administration eventually adds the death to its Death Master File, which credit bureaus and other institutions use to flag an account holder as deceased — but there is a real-world delay in that process, sometimes weeks, during which a deceased person's Social Security number, date of birth, and address still function normally in credit and lending systems.
Identity thieves specifically target this window. They monitor public obituaries and death notices — which frequently include a full name, date of birth, home address, family members' names, and other identifying detail — and use that information to apply for credit cards, personal loans, or lines of credit in the deceased person's name before the accounts are frozen and before credit bureaus have processed the death.
Because the fraud happens in a deceased person's name rather than a living victim's, it is often not discovered for months, sometimes longer than a year, until a collections notice, a denied loan application in the estate's name, or a routine credit check surfaces the fraudulent accounts. By then, the debt has accumulated, and untangling it from a closed estate is significantly harder than catching it early would have been.
The core risk factor: obituaries. A detailed, well-meaning obituary — full name, date of birth, address, family members' names, pet names, memberships, hobbies — hands identity thieves nearly everything they need to convincingly impersonate the deceased in a credit or loan application. This is the single most preventable risk factor in the entire ghosting problem.
Write a Safer Obituary
Before addressing what to do after a death has already been publicized, it's worth noting for future reference: an obituary does not need to include a full date of birth, a home address, or a mother's maiden name to honor someone's memory. Omit or generalize this specific identifying detail — "survived by his wife of 40 years" rather than naming her explicitly alongside a home address, "born in the spring of 1948" rather than an exact date — while still writing a warm, complete tribute. This single change meaningfully reduces the raw material available to identity thieves monitoring obituary listings.
The First 48 Hours: What to Do Immediately
Obtain multiple certified copies of the death certificate. Order at least 10–12 certified copies from the start. Nearly every step below requires submitting an original certified copy, and reordering later adds delay at exactly the moments speed matters most.
Notify the three major credit bureaus. Contact Equifax, Experian, and TransUnion directly and request that a "deceased alert" be placed on the person's credit file. This is the single most effective step for stopping new-account fraud, and it should happen within the first 48 hours if at all possible — not after the funeral, not after probate begins.
Freeze the deceased's credit, and freeze a surviving spouse's credit too. A credit freeze prevents new accounts from being opened using the associated Social Security number without an additional PIN or password. If there is a surviving spouse, freeze their credit as well — thieves sometimes target a surviving spouse's identity in the confusion immediately following a death, when financial oversight is often at its lowest.
Notify the Social Security Administration. If a funeral home is handling arrangements, they often report the death to Social Security automatically — but confirm this rather than assuming it happened. Families can also request limited access to a deceased person's Social Security data through SSA.gov, which reduces the pool of parties who can use that information to enrich a data broker profile.
The First 90 Days: Closing the Wider Gap
Send the death certificate to the IRS. This is a distinct, separate notification from the Social Security Administration and needs to be sent directly to prevent tax refund fraud — one of the most common forms of ghosting.
Contact every financial institution directly. Notify credit card companies, banks, brokerage firms, and lenders — particularly mortgage companies — of the death, providing a certified death certificate to each. Do not assume that notifying one institution or one credit bureau covers the others.
Opt out of prescreened credit and insurance offers. Visit OptOutPrescreen.com to stop the deceased's name from being included on lists used by creditors and insurers for unsolicited offers. This is a five-minute step that closes off one of the more common ways sensitive marketing mail — an easy target for mailbox theft — continues arriving at an empty or infrequently checked address.
Register with the Direct Marketing Association's Mail Preference Service. This further reduces unsolicited commercial mail addressed to the deceased for up to five years, reducing the volume of mail that could otherwise sit unattended in a mailbox containing personally identifying information.
Data Broker Removal: The Ongoing Part of the Process
Beyond credit bureaus and financial institutions, a deceased person's personal information continues to exist across dozens of consumer data broker sites — the same companies that compile and sell personal information for background checks, marketing, and people-search services. These profiles do not automatically disappear at death, and they are a meaningful part of what identity thieves draw on when constructing a convincing fraudulent application.
There is currently no single federal process for removing a deceased person's data from every broker — coverage depends on which state the person lived in and which brokers are registered there. California is currently the most advanced: the state's Delete Act launched a Data Registration and Opt-out Platform (DROP) in January 2026, allowing family members to submit a single request that removes a deceased relative's information from every California-registered data broker at once, rather than filing dozens of individual removal requests. Visit deleteact.cppa.ca.gov to submit a request if the deceased lived in California. For more on California's broader digital estate laws, see our California digital estate planning guide.
Outside California, families generally need to contact major data brokers individually — this is genuinely tedious, but skipping it leaves a meaningful amount of exploitable personal information publicly searchable indefinitely. Processing times for these requests range from a few days to several weeks, and because brokers periodically re-scrape public records, a removed listing can occasionally reappear months later, so a single pass is not always sufficient for a full resolution.
Public Records: The Part You Usually Can't Remove
Property records, voter registrations, court filings, and other government documents remain permanently searchable online after death in most jurisdictions, and these public records continue feeding new data into broker databases in an ongoing cycle regardless of how many individual opt-out requests are filed. This is a structural limitation of the current system rather than something a family can meaningfully work around — awareness of it mainly matters because it explains why data broker removal is not a one-time task, and why ongoing credit monitoring for the estate remains worthwhile for at least the first year after a death.
Social Media and Online Account Exposure
Without intervention, social media profiles remain publicly visible after death, and in some cases continue receiving spam, tags, or unsolicited messages from bots that treat an inactive but unclosed profile as an active target. This compounds the ghosting risk, since a visible, un-memorialized social profile can itself be a source of identifying detail. Memorializing or closing accounts on major platforms closes this exposure — see our guides to Facebook, Instagram, TikTok, and X, and our complete digital estate checklist for a full account-by-account walkthrough.
If Fraud Has Already Happened
If a family discovers evidence of ghosting already in progress — a collection notice, an unfamiliar bill, or something unusual appearing on a credit report pulled for the estate — report it to local police in the deceased's jurisdiction, and notify every relevant financial institution immediately with documentation of both the death and the fraudulent activity. Families should also pull the deceased's credit reports directly (available for free at AnnualCreditReport.com) as part of estate administration, specifically looking for accounts opened after the date of death.
A Practical Checklist for Executors
Order 10–12 certified death certificates immediately. Notify all three credit bureaus and request a deceased alert within 48 hours. Freeze both the deceased's and any surviving spouse's credit. Confirm Social Security notification. Send a death certificate to the IRS separately. Notify every bank, credit card company, brokerage firm, and lender directly. Opt out of prescreened offers at OptOutPrescreen.com. Submit a California DROP request if applicable, or begin individual data broker removal requests otherwise. Memorialize or close social media and online accounts using our complete digital estate checklist. Pull the deceased's credit reports at the six-month and twelve-month marks to confirm no fraudulent activity has appeared.
Frequently Asked Questions
What is ghosting in identity theft?
Ghosting is a form of identity theft in which a criminal steals a deceased person's identity — their name, Social Security number, and other personal details — to open credit cards, apply for loans, or file fraudulent tax returns in that person's name. An estimated 2.5 million deceased Americans have their identities used fraudulently every year.
How do identity thieves find out someone has died?
Identity thieves commonly monitor public obituaries and death notices, which frequently include a full name, date of birth, home address, and family members' names — exactly the information needed to convincingly impersonate the deceased in a credit or loan application. Writing an obituary that omits specific identifying details like a full birth date or home address significantly reduces this risk.
How quickly should a family notify credit bureaus after a death?
As quickly as possible, ideally within 48 hours. Contact Equifax, Experian, and TransUnion directly to request a deceased alert on the credit file, and freeze the deceased's credit. If there is a surviving spouse, freeze their credit as well, since spouses are sometimes targeted during the period immediately following a death when financial oversight is lowest.
What is California's DROP platform for removing a deceased person's data?
California's Data Registration and Opt-out Platform (DROP), launched in January 2026 under the state's Delete Act, lets family members submit a single request to remove a deceased relative's information from every California-registered data broker at once, rather than filing separate removal requests with each one. It is available at deleteact.cppa.ca.gov and currently applies only to California-registered data brokers.
What should I do if I discover fraud has already happened to a deceased relative's identity?
Report it to local police in the deceased's jurisdiction, notify every relevant financial institution with documentation of both the death and the fraudulent activity, and pull the deceased's credit reports directly at AnnualCreditReport.com to identify any accounts opened after the date of death. Estates should continue checking credit reports periodically for at least a year after death, since ghosting fraud is often not discovered for months.
Protect Your Digital Estate — Free Checklist
Our free 30-item checklist covers every account your family needs to manage after you pass.
Get Free ChecklistNeed Professional Legal Advice?
An estate planning attorney can ensure your digital assets are legally protected and your executor has the proper authority to act.
Find an Attorney via LegalZoom