Aggravated Identity Theft
| Statute: | 18 U.S.C. § 1028A |
| U.S. Code: | Title 18, Chapter 47 |
| Max Prison: | 2 years mandatory consecutive (5 years for terrorism) |
| Max Fine: | $250,000 |
| Guidelines: | USSG §2B1.6 |
| Base Level: | N/A (mandatory consecutive) |
| Agencies: | FBI, USSS, FTC, SSA-OIG |
| Related: | Wire Fraud, Bank Fraud, False Statements |
Aggravated identity theft is a federal crime under 18 U.S.C. § 1028A. It carries a mandatory minimum consecutive sentence for using someone else's identification during and in relation to certain enumerated felony offenses. Unlike most federal offenses, judges have virtually no discretion in sentencing: they must impose a two-year sentence that runs consecutive to any other sentence the defendant receives.[1]
Congress enacted this statute as part of the Identity Theft Penalty Enhancement Act of 2004, Pub. L. 108-275, 118 Stat. 876, responding to a serious and growing problem. Identity theft was increasingly being used not only as a standalone crime but as an instrument to enable fraud, immigration violations, and a wide range of other federal offenses. The mandatory consecutive requirement substantially increases punishment for defendants who steal identities to commit these crimes.[2] According to the Federal Trade Commission's Consumer Sentinel Network, identity theft complaints have consistently ranked among the top categories of fraud reported to the agency, underscoring the scope of the problem Congress sought to address.[3]
Since its enactment, § 1028A has been shaped by two landmark Supreme Court decisions. In 2009, the Court addressed the knowledge requirement in Flores-Figueroa v. United States, and in 2023, the Court significantly narrowed the statute's reach in Dubin v. United States, holding that the identity use must be "at the crux" of the underlying offense rather than merely incidental to it. Together, these rulings define the boundaries within which prosecutors may charge, and defendants may contest, aggravated identity theft.
Elements of the Offense
To secure a conviction under 18 U.S.C. § 1028A, prosecutors must prove each of the following elements beyond a reasonable doubt.
The first element is that the defendant knowingly transferred, possessed, or used a means of identification of another person. The second is that the defendant did so without lawful authority. The third is that the use occurred during and in relation to an enumerated felony offense listed in the statute. The fourth, established by the Supreme Court in Flores-Figueroa v. United States, is that the defendant knew the identification belonged to an actual living or real person, not a fabricated one.[4]
Means of Identification
The statute reaches a broad range of identifying information. Under 18 U.S.C. § 1028(d)(7), "means of identification" is defined to include name, Social Security number, date of birth, driver's license number, passport number, alien registration number, and any government-issued identification number. It also encompasses unique biometric data such as fingerprints, voice prints, and retina images, as well as unique electronic identification numbers or addresses, routing codes, and telecommunication identifying information or access device credentials. Courts have applied this definition broadly, reflecting Congress's intent to cover the full range of identifying data used in modern fraud schemes.
Knowledge Requirement
The knowledge requirement is one of the most legally significant elements of § 1028A and was the subject of a major Supreme Court ruling. In Flores-Figueroa v. United States (2009), the Court held that the government must prove the defendant knew the means of identification belonged to an actual, real person, not merely that the defendant used some identifying information.[4] A defendant who uses a Social Security number genuinely believed to be fabricated, which happens by coincidence to match a real person's number, does not satisfy this element if the defendant lacked awareness that the number corresponded to an actual individual. The government may rely on circumstantial evidence to establish this knowledge, for example, evidence that the defendant obtained identity information from a known identity theft database or dark web marketplace would tend to show awareness that real persons' data was involved, but the burden remains with the prosecution. This ruling created a meaningful defense avenue that did not exist prior to 2009.
The "At the Crux" Requirement After Dubin
In Dubin v. United States, 599 U.S. 110 (2023), the Supreme Court substantially narrowed the scope of § 1028A, resolving a circuit split over how closely connected the identity use must be to the predicate offense.[5] The Court held that a person uses another's means of identification "during and in relation to" a predicate felony only when the use of that identification is "at the crux" of the underlying offense, meaning the identity is central to the crime itself, not merely a but-for cause or incidental element.
The case arose from a healthcare fraud conviction in which the defendant had overbilled Medicaid by using patient identifying information to submit inflated claims. The government argued this satisfied § 1028A because the patients' Medicaid numbers appeared on the fraudulent claims. The Supreme Court disagreed, holding that where the fraud involves how services are billed, the amount charged, rather than who is being billed, the identity use is not at the crux of the scheme. The decision significantly limited the government's ability to charge § 1028A in healthcare overbilling cases and other fraud contexts where a victim's identity appears in records but is not itself the mechanism of the fraud.[5]
Post-Dubin litigation has continued to develop this standard. Courts have applied the "at the crux" test to distinguish between cases where identity is the instrument of the fraud, such as filing a tax return in someone else's name to steal their refund, and cases where identity appears incidentally, such as routine use of a patient's identification number in a billing context where the fraud lies in the amount charged rather than the identity used. As recently as February 2026, federal courts have continued to apply Dubin to dismiss or narrow § 1028A charges in healthcare overbilling cases, reflecting the ruling's ongoing significance.[6]
Enumerated Predicate Offenses
Aggravated identity theft applies only when the identity theft occurs "during and in relation to" specific felonies enumerated in the statute. The predicate offenses span several categories of federal crime.
In the area of fraud and related crimes, the enumerated offenses include mail fraud (18 U.S.C. § 1341), wire fraud (18 U.S.C. § 1343), bank fraud (18 U.S.C. § 1344), healthcare fraud (18 U.S.C. § 1347), access device fraud (18 U.S.C. § 1029), and computer fraud (18 U.S.C. § 1030). Immigration-related predicate offenses include illegal reentry (8 U.S.C. § 1326), document fraud (18 U.S.C. § 1546), and Social Security fraud (42 U.S.C. § 408). Additional enumerated offenses include theft of public money (18 U.S.C. § 641), false statements (18 U.S.C. § 1001), passport fraud (18 U.S.C. § 1542), and nationality fraud (18 U.S.C. § 1015).[1] If the government cannot prove an enumerated predicate offense, the § 1028A charge cannot stand, regardless of whether identity theft in some form occurred.
Statutory Penalties
| Category | Mandatory Minimum | Maximum Fine | Consecutive Requirement |
|---|---|---|---|
| Standard aggravated identity theft | 2 years | $250,000 | Must run consecutive |
| Terrorism-related identity theft | 5 years | $250,000 | Must run consecutive |
The statute imposes a mandatory two-year term of imprisonment for standard aggravated identity theft, which must run consecutive to, not concurrent with, any sentence imposed for the underlying predicate offense. Courts may not impose probation in lieu of imprisonment, and they may not order the sentence to run concurrently with the predicate offense sentence. Where identity theft is committed in connection with terrorism-related offenses as specified in § 1028A(b)(3), the mandatory consecutive term increases to five years. Each separate instance of using a different person's identification can constitute a separate count, with each additional count carrying its own mandatory two-year term, potentially resulting in substantial aggregate sentences.[1]
The practical effect of the consecutive requirement is considerable. A defendant sentenced to 57 months on wire fraud convictions and 24 months on aggravated identity theft, for example, faces a combined sentence of 81 months, a sentence that has been imposed in real cases prosecuted by the SSA Office of Inspector General and other agencies.[7]
Federal Sentencing Guidelines
Under USSG §2B1.6, aggravated identity theft sentencing follows a straightforward structure. The guideline directs courts to impose the mandatory two-year consecutive sentence required by the statute, with no offense level calculation, no enhancements, and no adjustments. The sentence is fixed by law, and the guidelines do not alter that result.[8]
Relationship to Underlying Offense
The predicate offense is sentenced separately under its own applicable guideline range, and the § 1028A sentence is then imposed to run consecutively. As a practical illustration: a defendant convicted of wire fraud with a guideline range of 24 to 30 months might receive a 27-month sentence on that count. The court then imposes a mandatory 24-month consecutive sentence for the aggravated identity theft count, resulting in a total minimum of 51 months, entirely independent of any additional counts. This stacking structure gives the statute significant leverage in plea negotiations and sentencing outcomes.[8]
Multiple Counts
When a defendant is convicted of multiple counts of aggravated identity theft, the guidelines recognize a distinction based on the circumstances of each count. Multiple counts involving the same victim on the same occasion may run concurrently with one another, while multiple counts involving different victims or different occasions typically run consecutively. Courts retain some discretion with respect to stacking beyond the first mandatory count, though the first count's two-year term remains non-negotiable.
Investigating Agencies
Several federal agencies share responsibility for investigating aggravated identity theft. The Federal Bureau of Investigation (FBI) handles identity theft cases connected to organized fraud, cybercrime, and national security matters. The United States Secret Service (USSS) investigates financial crimes involving identity theft, particularly those targeting financial institutions and government payment systems. The Federal Trade Commission (FTC) serves primarily as a consumer reporting and referral agency, maintaining the Consumer Sentinel Network database that law enforcement uses to track identity theft complaints. The Social Security Administration Office of Inspector General (SSA-OIG) investigates identity theft involving Social Security numbers and benefits fraud, and has brought a substantial number of § 1028A prosecutions in coordination with the Department of Justice.[3]
Common Scenarios
Financial Fraud
Financial fraud is among the most common contexts for § 1028A charges. Defendants in these cases typically use stolen Social Security numbers, names, and dates of birth to open fraudulent credit card accounts, obtain loans, file false tax returns to claim refunds, or access existing bank accounts belonging to the victims. In a representative case prosecuted by the Western District of Washington, a Bremerton couple pleaded guilty to bank fraud and aggravated identity theft after using stolen identity information to fraudulently obtain funds through financial institutions.[9]
Government Benefits Fraud
Stolen identities are frequently used to obtain government benefits to which the defendant is not entitled. Common schemes include filing fraudulent unemployment claims, collecting Social Security benefits under another person's number, billing Medicare or Medicaid for services not rendered or rendered to different patients, and, particularly during the COVID-19 pandemic, obtaining Paycheck Protection Program loans and other federal relief payments using stolen identifying information.
Immigration-Related Identity Theft
A significant volume of § 1028A prosecutions arises in immigration contexts, where defendants use another person's identity documents to work in the United States without authorization, obtain state driver's licenses or identification cards, or reenter the country after deportation. These cases frequently involve Social Security numbers obtained from identity theft networks and used in employment verification systems.
Tax Refund Fraud
Tax refund fraud is a well-documented and damaging application of identity theft. Fraudsters file tax returns in the names of real individuals using stolen Social Security numbers, typically filing before the legitimate taxpayer submits their own return. The fraudster intercepts the refund, often directed to a prepaid debit card, leaving the real taxpayer to deal with the IRS over a return they did not file. Organized rings have operated this scheme at scale, filing thousands of returns using identities stolen from healthcare facilities, employers, and data breach victims.
Notable Cases
PPP and COVID Relief Fraud
COVID-19 relief fraud produced a substantial increase in § 1028A prosecutions. Defendants across the country were charged with filing fraudulent PPP loan applications using stolen identities, submitting unemployment claims with other individuals' personal information, and obtaining multiple relief payments by cycling through stolen identity data. The scale of the fraud and the ease with which relief funds were distributed created fertile ground for identity-based schemes, and the mandatory consecutive sentence made § 1028A a consistent feature of COVID fraud indictments.
Data Breach Cases
Major data breaches have triggered prosecutions in which defendants purchased stolen identity data on dark web marketplaces or directly exploited breached databases to obtain usable identity credentials. These cases illustrate the organized, commercial nature of modern identity theft: stolen data is harvested, sold, and monetized in structured criminal networks. Prosecutors have used § 1028A to significantly increase sentences in these cases, reflecting Congress's intent to punish the downstream use of stolen identities, not merely their acquisition.
Tax Fraud Rings
Organized groups have operated systematic tax fraud schemes by stealing identities from healthcare facilities, employers, and other institutions with access to large volumes of personal data. Using stolen Social Security numbers and biographical information, these rings filed thousands of fraudulent tax returns and received refunds on prepaid debit cards that were difficult to trace. Several large-scale prosecutions have resulted in sentences substantially extended by mandatory consecutive terms under § 1028A.
Wire Fraud and Identity Theft Networks
In a case highlighted by FBI Seattle, two sisters were indicted for wide-ranging wire fraud and identity theft offenses involving a scheme that used stolen identities to perpetrate financial fraud across multiple victims and transactions.[10] Cases of this type, involving multiple victims, multiple counts, and coordinated fraud, illustrate how the mandatory consecutive structure of § 1028A compounds sentences when identity theft is repeated across a scheme.
Conspiracy Arrests by SSA-OIG
In June 2026, four individuals were arrested on charges including conspiracy to commit identity theft, wire fraud, bank fraud, Social Security misuse, aggravated identity theft, and forced labor, a case illustrating how § 1028A is charged alongside a constellation of related offenses when identity theft is embedded in a broader criminal enterprise.<ref name="ssa-oig-conspiracy">["Four Individuals Arrested for Conspiracy to Commit Identity Theft, Wire Fraud, Bank Fraud,
References
- ↑ 1.0 1.1 1.2 18 U.S.C. § 1028A.
- ↑ Identity Theft Penalty Enhancement Act of 2004, Pub. L. 108-275.
- ↑ 3.0 3.1 Federal Trade Commission, Consumer Sentinel Network Data Book (annual), available at ftc.gov.
- ↑ 4.0 4.1 Flores-Figueroa v. United States, 556 U.S. 646 (2009).
- ↑ 5.0 5.1 Dubin v. United States, 599 U.S. 110 (2023).
- ↑ ["Aggravated identity theft sentence enhancement is inappropriate in healthcare fraud case based on overbilling Medicare"], Horvitz & Levy LLP, 2026.
- ↑ ["A federal judge has sentenced an individual to 81 months in prison for aggravated identity theft"], SSA Office of the Inspector General, Facebook, 2025.
- ↑ 8.0 8.1 United States Sentencing Commission, USSG §2B1.6 (2024).
- ↑ ["Bremerton, Washington, couple pleads guilty to bank fraud and aggravated identity theft"], U.S. Department of Justice, 2025.
- ↑ ["Sisters indicted for wide ranging wire fraud and identity theft"], FBI, Federal Bureau of Investigation, Facebook, 2025.