What happened
In May 2020 the Nigerian fraud group known as Scattered Canary filed thousands of fraudulent unemployment claims against Washington State's Employment Security Department during the pandemic claims surge. The group used personal data stolen in earlier breaches to impersonate real workers, and routed benefit payments to out-of-state accounts controlled by money mules. Reported losses ran to hundreds of millions of dollars before the state froze payments.
How the deception worked
The ring assembled identity packages from earlier consumer data breaches, giving them the Social Security numbers, dates of birth and addresses of real Washington workers. They registered claims using disposable email services and Gmail address variations so that a single controlled inbox could receive correspondence for many claimants, and they targeted the enhanced $600 weekly federal supplement, which raised the payout per fraudulent claim. Benefit payments were then directed to out-of-state bank accounts held by recruited mules. The pretext succeeded because the agency, overwhelmed by unprecedented claim volume, had relaxed verification to speed payments.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
Identity proofing and cross-matching against employer wage records must not be suspended under surge conditions; duplicate-contact and out-of-state-payee detection would have surfaced the ring early.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.