What happened in the Normandale ghost-student case?
The full case record on one page: the sourced timeline, the primary documents quoted verbatim, and the institution's own statements, answered. Every event below is traceable to a document.
On November 5, 2024, someone used a stolen Social Security number and a lookalike email to enroll a fabricated student at Normandale Community College, and a federal loan was originated in the victim's name in January 2025. The victim learned of it roughly fifteen months later, when a 90-day delinquency reached his credit report. The servicer removed the credit harm, but the federal discharge remains pending as of July 2026, and Minnesota State has withheld the records showing how the fraud was committed, citing Minn. Stat. § 13.37. The system that publicly announced a "tiger team" and "zero tolerance for any fraud" produced, for the victim who engaged it directly in writing: no reply from its security office, no root-cause analysis, no correction, and no apology.
Timeline
-
Nov 5, 2024
A fraudulent application is submitted to Normandale Community College through Minnesota State's Universal Application system under the victim's name (with a casing anomaly in the surname), using the victim's real Social Security number, a spoofed lookalike email — the victim's own name with a letter replaced by a zero — a Mankato, MN address the victim has never lived at, a claimed 2013 graduation from Bagley High School (never attended), claimed 2018–2019 attendance at Anthem College in Phoenix — a for-profit chain that shut down in 2014 — and a claimed foster-youth status. The system processes the application "Y-Successful."Source: Minnesota State Universal Application Data record (produced July 2026)
-
Nov 25, 2024
Placement testing on the fraudulent record is completed at approximately 2:54 AM. A vendor's automated confirmation email, later preserved in the records production, captured a datacenter-range originating IP address for this activity — proof that such origination metadata exists in produced records. The raw address is redacted here.Source: Placement-test vendor automated email, in the Minnesota State records production (July 2026)
-
Jan 27, 2025
A federal student loan is originated in the victim's name based on the fraudulent enrollment. The victim receives no notice from any party.Source: Loan servicer records; victim correspondence of May 8, 2026
-
2025
The actor makes small payments, then places the loan in deferment — a documented ghost-student technique that delays detection. No credit bureau activity reaches the victim, whose credit was frozen at all three bureaus and monitored throughout; the Direct loan type documented here generally originates without the consumer credit check a freeze would block. Direct PLUS loans are different: Federal Student Aid performs a credit check, and applicants with a security freeze must lift it before applying.Source: Victim correspondence of May 13, 2026
-
May 22, 2025
After one term at a 0.0 GPA, Normandale mails the fabricated record an Academic and Financial Aid Warning Notification stating "Your GPA is 0.0" and "Your completion rate is 0.0%," and adding: "We believe you can do this, and we are here to help you succeed." The letter is addressed to a person who does not exist.Source: Normandale Academic and Financial Aid Warning Notification, May 22, 2025 (in records production)
-
Apr–May 2026
The loan reaches 90+ days delinquent and the delinquency is furnished to Experian. This is the first moment the victim could have learned the loan existed — roughly fifteen months after origination.Source: Credit report; victim correspondence
-
Early May 2026
The victim files an FTC Identity Theft Report and police reports (report numbers withheld); sends FCRA § 605B block requests to all three bureaus by certified mail; opens a fraud claim with servicer Aidvantage; files a False Certification (Identity Theft) Discharge application; and reports the case to the ED Office of Inspector General.Source: Victim records
-
May 8, 2026
The victim sends a Root Cause Analysis request — application timestamps, originating IP addresses, full audit logs, submission details — to Normandale President Pakou Yang, copying Minnesota State's Chief Information Security Officer and the Office of the General Counsel, and requests identity verification via live video. No root-cause analysis is provided. On first contact, Normandale cannot locate any student record under the victim's name — the record is findable only by SSN, confirming the identifying information had been altered.Source: Email of May 8, 2026, to President Pakou Yang (cc CISO and Office of the General Counsel)
-
May 12, 2026
Assistant General Counsel Daniel G. McCabe takes the victim's call and ends it. In an internal email the same day (3:42 PM), later produced to the victim, McCabe writes: "I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility." The same email states that the data the victim seeks "is largely security information defined by Minn. Stat. 13.37" and that "We also do not offer members of the public the opportunity to audit our cybersecurity."Source: Internal email of May 12, 2026, produced in records response
-
May 13, 2026
In a separate internal email (11:50 AM), later produced to the victim, Assistant General Counsel Daniel G. McCabe writes: "It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one." The victim's own emails in the same production had stated the avenues he would pursue — an ED Office of Inspector General report, a Minnesota Government Data Practices Act request, and contact with the press.Source: Internal email of May 13, 2026, produced in records response
-
May 13–14, 2026
Normandale convenes its President, Registrar, and IT on the case; establishes an identity-verification path (live video appointment with government ID review) and processes the victim's ID Theft Appeal.Source: Emails of May 13–14, 2026
-
Late May 2026
Servicer Aidvantage (Maximus) acknowledges the fraud claim and removes the tradeline from the victim's credit reports. Working with Aidvantage was the fastest and cleanest part of the whole ordeal — the private party with the fewest transparency obligations — while the public institution was still withholding records. The federal False Certification (Identity Theft) discharge remains pending with the U.S. Department of Education as of July 2026 — the loan itself has not yet been discharged. Funds disbursed to the actor were never recovered. Total the victim paid: $0 — but only after weeks of full-time-job-level effort.Source: Servicer communications
-
July 2026
Minnesota State responds to the victim's Minnesota Government Data Practices Act request: it produces the application record — revealing every red flag above — but withholds all origination metadata (timestamps, IP addresses, audit logs), citing Minn. Stat. § 13.37 "security information." The victim of the fraud is denied the data showing how the fraud was committed. The victim files an advisory-opinion challenge under Minn. Stat. § 13.072 with the Commissioner of Administration, where it is now pending.Source: MGDPA response; advisory opinion request
Attribution note
Evidence gathered during remediation — an IP address produced to the victim in correspondence — indicates the actor likely operated from outside the United States, possibly the Netherlands. This is presented as an investigative lead, not an established fact. Whatever the actor's location, the mechanics are documented: the fraud required only two inputs — a stolen SSN and a lookalike email address.
That correspondence also matters for the records fight above: the institution sent the victim an originating IP address during remediation, before Minnesota State took the position — in the May 12, 2026 counsel email and the July 2026 records response — that originating IP addresses are "security information" under Minn. Stat. § 13.37 that cannot be disclosed to him. The same category of data was disclosable when the institution volunteered it, and classified once the victim formally asked — see What Went Wrong. If you are facing something similar, start with What To Do.
The documents
The underlying files are not published, and there is no plan to publish them. The produced records are dense with personal data: the victim's identifiers, plus addresses and numbers that may belong to uninvolved third parties. This site will not gamble on a redaction being complete. Instead, this page names each document, dates it, states what it shows, and quotes its load-bearing passages verbatim, heat and all, including material unflattering to the victim's side of the exchange. "[the victim]" marks a visible redaction. Anyone named who believes a quotation is inaccurate or missing context can say so via corrections.
Source index
- Minnesota State Universal Application Data record (produced July 2026) — the fraudulent application of November 5, 2024, processed "Y-Successful"; red flags detailed on What Went Wrong.
- Academic and Financial Aid Warning Notification (May 22, 2025) — the encouragement letter mailed to the fabricated record.
- Correspondence with Normandale leadership (May 8–14, 2026) — the report, the "no record under his name" response, the live-video verification setup.
- Minnesota State Office of General Counsel internal emails (May 12–13, 2026) — source of the verbatim quotes below.
- Minnesota Government Data Practices Act response (July 2026) — produces the application record; withholds origination metadata under Minn. Stat. § 13.37.
- Servicer and remediation records — supporting the timeline above.
Each source is held by the victim in full; none is posted — they carry the victim's identifiers and date of birth, third-party addresses, the fraudster's phone number, and raw originating-IP material.
The encouragement letter (May 22, 2025)
Mailed to the fabricated record after a semester recorded as 0.0 GPA and 0.0% completion (see timeline), closing:
"We believe you can do this, and we are here to help you succeed."Normandale Community College, Academic and Financial Aid Warning Notification, May 22, 2025
The Office of General Counsel emails (May 12–13, 2026)
Internal emails by Daniel G. McCabe, Assistant General Counsel, Minnesota State, produced in the Data Practices Act response. Nothing is trimmed inside a quotation. The production also contains the victim's own May 8 and May 12 emails, so any recipient can compare what he actually wrote against how it was characterized.
"I think we can provide [the victim] the data we would typically provide a student asking for their financial aid data. We don't have to consider the threat actor the data subject."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production). Bracketed text redacts the victim's name.
"However, the data he is specifically asking for is largely security information defined by Minn. Stat. 13.37 (application timestamps, originating IP addresses, full audit logs, exact dates and times of submission). We also do not offer members of the public the opportunity to audit our cybersecurity."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production)
"I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production). Bracketed text redacts the victim's name.
"It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email to Susan Ant, May 13, 2026, 11:50 AM (in DPA production). Bracketed text redacts the victim's name.
The financial-aid correspondence — Susan Ant (May 12, 2026)
In the same production, Susan Ant, Director of Financial Aid and Scholarships at Normandale, apologized to the victim and coordinated the identity-verification process. The failure documented on this site is institutional and legal, not hers — she is one of the people this site thanks.
"I'm sorry that this has happened to you."Susan Ant, Director of Financial Aid and Scholarships, Normandale — email, May 12, 2026 (in production)
"Again, I am sorry that this has happened to you and hope we can work together to resolve this as much as possible."Susan Ant, Director of Financial Aid and Scholarships, Normandale — email, May 12, 2026 (in production)
A "tiger team" on television. Silence for the victim who engaged it directly.
Minnesota State's Chief Information Security Officer, Craig Munson, publicly described a dedicated "tiger team" and "zero tolerance for any fraud" (KSTP 5 Investigates, Sept. 15, 2025), and the Legislature created an enrollment-fraud working group. On May 8, 2026, the victim engaged the security office directly: a written root-cause request to Normandale President Pakou Yang, copying the CISO. What those announced defenses produced for the actual victim, per the produced record and as of publication: no reply from the security office, no root-cause analysis, no correction, and no apology.
The facts above are documented; the conclusion that follows is the author's opinion, drawn from them. A system that announces its defenses on television and then, when the actual victim engages it directly and in writing, produces nothing — no reply, no analysis, no correction, no apology — has answered the only question that matters. In the author's view, that response makes it very clear the announced structures were not built for the people the fraud actually happens to, and that when directly engaged, the system simply does not care.
Each block pairs a real, sourced quotation — reproduced verbatim, from public statements to KSTP 5 Investigates and from the produced emails above — with a response that is clearly labeled opinion: fair comment on public officials' documented conduct on a matter of public concern. No invented words are placed in any real person's mouth.
"We've put together, I like to call it, a 'tiger team,'"
— Craig Munson, Chief Information Security Officer, Minnesota State, to KSTP 5 Investigates, Sept. 15, 2025
We are defended by a dedicated tiger team. Its win-loss record is available by Data Practices Act request and will be produced in part — with the wins redacted and the losses withheld pending a private retreat. The produced record of this case contains the tiger team's complete documented contribution to it, reproduced here in full: .
"What I can say is, in the circles that I'm in, there is zero tolerance for any fraud,"
— Craig Munson to KSTP 5 Investigates, Sept. 15, 2025
In this case it matured into zero tolerance for records requests about the fraud, for phone calls about the fraud, and for the person the fraud actually happened to.
"However, the data he is specifically asking for is largely security information defined by Minn. Stat. 13.37 (application timestamps, originating IP addresses, full audit logs, exact dates and times of submission). We also do not offer members of the public the opportunity to audit our cybersecurity."
— McCabe internal email, May 12, 2026 (verbatim; attributed in full above)
Correct. In this case that opportunity was reserved for the applicant of November 5, 2024, who completed the audit in a single submission, at 2:54 in the morning, and passed.
"I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility."
— McCabe internal email, May 12, 2026 (verbatim; the original names the victim, redacted here)
The institution's own records characterize two people: a stranger who fabricated a person and took out a federal loan in someone else's name (filed as a "student"), and the actual human being who called to report it (filed as "hostility").
"It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one."
— McCabe internal email, May 13, 2026 (verbatim; the original names the victim, redacted here)
The production shows what the victim actually said he would do: an OIG report, a records request, and a call to a reporter — all three happened; none is a lawsuit. The weeds, it turns out, were load-bearing.
Source reporting: KSTP 5 Investigates (kstp.com) — Eric Rasmussen / 5 Investigates, "Ghost students target Minnesota colleges," Sept. 15, 2025. The McCabe quotations are verbatim from the produced emails in the documents section above.
- Fraudulent application submitted November 5, 2024; processed "Y-Successful."
- Federal loan originated January 27, 2025; first discoverable by the victim April–May 2026.
- Tradeline removed late May 2026; federal discharge pending as of July 2026.
- July 2026: records response withholds timestamps, IP addresses, and audit logs under Minn. Stat. § 13.37.
Every timeline event above appears item-for-item in this page's ItemList structured data — what you read is what machines read. Quotations are verbatim; commentary is labeled opinion. Independent site; not legal advice.