What is deceased identity theft, and how can you protect a loved one's accounts?

Deceased identity theft, or ghosting, occurs when cybercriminals exploit inactive social profiles, emails, and credentials of deceased individuals; it can be prevented by securing accounts and deploying automated digital dead man's switches to delete or archive sensitive assets before they become vulnerable.

Deceased identity theft is one of the fastest-growing forms of cybercrime. When someone dies, their online accounts become sitting targets. Social media profiles go inactive but remain visible. Email accounts sit unmonitored. Bank notifications pile up in inboxes that no one is checking. Credit card statements arrive electronically to accounts that are still open.

Criminals monitor obituaries, social media death notices, and public probate records to identify recently deceased individuals. They then use publicly available information — full name, date of birth, address, mother's maiden name (often found in obituaries) — to attempt account takeovers, open new credit accounts, file fraudulent tax returns, and even claim Social Security death benefits.

The IRS reported in 2025 that deceased identity theft cases increased 34% year-over-year, with average losses of $15,000 per incident. The emotional toll on grieving families is even worse — discovering that a deceased loved one's identity has been stolen adds financial stress and bureaucratic nightmare to an already devastating time.

Use our Death Audit Checklist to secure your accounts against posthumous exploitation.

How ghosting works: the criminal playbook

Identity thieves targeting the deceased follow a predictable pattern:

Step 1: Target identification Criminals scan obituary websites, funeral home websites, newspaper death notices, and social media memorial posts. These sources typically provide full name, date of birth, city of residence, and family members' names — enough to start identity theft.

Step 2: Account reconnaissance They search for the deceased's email addresses, social media profiles, and online accounts. Inactive accounts are ideal targets because no one is monitoring them for suspicious activity.

Step 3: Account takeover Using the personal information from the obituary, they attempt password resets on email accounts. If the security questions are based on publicly available information (mother's maiden name, city of birth, first pet's name — all potentially found in obituaries or social media), they can reset the password and gain access.

Step 4: Credential cascading Once they have email access, they search for passwords, bank statements, credit card notifications, and account registration emails. One email account can unlock dozens of other accounts.

Step 5: Financial exploitation They open new credit accounts, file fraudulent tax returns for refunds, claim government benefits, or make purchases using stored payment methods on e-commerce accounts.

The entire process can take as little as 48 hours from the publication of an obituary.

The posthumous identity protection checklist

Immediate actions (do these now, before anything happens): • Set up platform-level legacy contacts (Google, Apple, Facebook) to ensure accounts are managed, not abandoned • Remove publicly available security question answers from social media (mother's maiden name, birth city, pet names) • Enable two-factor authentication on all critical accounts • Store all credentials in a ZeroLatch encrypted vault with automated delivery to your executor

Actions for your executor (include in your estate plan): • Notify all three credit bureaus (Equifax, Experian, TransUnion) of the death to place a "deceased alert" on credit files • Close email accounts or set up forwarding to the executor's email • Memorialize or delete social media profiles (don't leave them inactive) • Close unused online shopping accounts (Amazon, eBay) that have payment methods stored • Cancel all subscriptions and recurring payments • Notify banks and credit card companies to close accounts • File a final tax return to prevent fraudulent returns • Notify the Social Security Administration to prevent benefit fraud

Automated protection with ZeroLatch: Configure your dead man's switch to deliver credentials to your executor quickly (7-14 days) so they can: • Access and secure email accounts before criminals do • Change passwords on critical accounts • Close inactive social media profiles • Cancel subscriptions and stored payment methods • Export and delete sensitive data from cloud storage

The faster your executor can access and secure your accounts, the smaller the window of vulnerability for ghosting attacks. Test your account security with our Password Strength Tester.