What happened in the Normandale ghost-student case?
The full case record on one page: the sourced timeline, the primary documents quoted verbatim, and the institution's own statements, answered. Every event below is traceable to a document.
On November 5, 2024, someone used a stolen Social Security number and a lookalike email to enroll a fabricated student at Normandale Community College, and a federal loan was originated in the victim's name in January 2025. The victim learned of it roughly fifteen months later, when a 90-day delinquency reached his credit report. The servicer removed the credit harm in late May 2026, and as of this update (Aug. 25, 2026) the U.S. Department of Education has discharged the loan. Minnesota State has withheld the records showing how the fraud was committed, citing Minn. Stat. § 13.37. The system that publicly announced a "tiger team" and "zero tolerance for any fraud" produced, for the victim who engaged it directly in writing: no reply from its security office, no root-cause analysis, no correction, and no apology. Its first on-record response to the case came through KSTP 5 Investigates on Aug. 24, 2026.
Is the fraudulent loan discharged, and what is still open?
Yes. As of this update (Aug. 25, 2026), the U.S. Department of Education has discharged the loan under the False Certification (Identity Theft) discharge. The servicer had removed the fraudulent tradeline from the victim's credit reports in late May 2026, but that is not a discharge; the federal discharge was still pending as of July 2026 and is now granted.
Three things are still open and three are closed. Each line carries the date a document in the record last confirmed it; none of it is updated on a schedule, and a line changes only when a document changes it. Servicer acknowledgment, tradeline removal, and a federal discharge are three different events — see how a fraudulent federal student loan gets discharged.
| State | Item | Where it stands | Last confirmed |
|---|---|---|---|
| Open | Minn. Stat. § 13.072 advisory-opinion challenge | Filed with the Commissioner of Administration over the withholding of application timestamps, originating IP addresses, and audit logs under Minn. Stat. § 13.37. | July 2026 |
| Open | Root-cause analysis | Requested in writing on May 8, 2026. None has been provided to the victim. Normandale's first on-record statement about its response — extra staff, technology and training — came through KSTP 5 Investigates on Aug. 24, 2026 and does not address how this application passed intake. | Aug. 24, 2026 |
| Open | Funds disbursed to the actor | Not recovered. | July 2026 |
| Closed | Federal False Certification (Identity Theft) discharge | Discharged by the U.S. Department of Education. The loan no longer exists in the victim's name; the date on the discharge notice is not published here. | Aug. 25, 2026 (this update) |
| Closed | Credit-reporting harm | Servicer Aidvantage (Maximus) accepted the identity-theft claim and removed the fraudulent tradeline from all three credit reports. | Late May 2026 |
| Closed | Identity verification with the college | Normandale established a live-video appointment with government-ID review and processed the victim's ID Theft Appeal. | May 13–14, 2026 |
Timeline
-
Nov 5, 2024
A fraudulent application is submitted to Normandale Community College through Minnesota State's Universal Application system under the victim's name (with a casing anomaly in the surname), using the victim's real Social Security number, a spoofed lookalike email — the victim's own name with a letter replaced by a zero — a Mankato, MN address the victim has never lived at, a claimed 2013 graduation from Bagley High School (never attended), claimed 2018–2019 attendance at Anthem College in Phoenix — a for-profit chain that shut down in 2014 — and a claimed foster-youth status. The system processes the application "Y-Successful."Source: Minnesota State Universal Application Data record (produced July 2026)
-
Nov 25, 2024
Placement testing on the fraudulent record is completed at approximately 2:54 AM. A vendor's automated confirmation email, later preserved in the records production, captured a datacenter-range originating IP address for this activity — proof that such origination metadata exists in produced records. The raw address is redacted here.Source: Placement-test vendor automated email, in the Minnesota State records production (July 2026)
-
Jan 27, 2025
A federal student loan is originated in the victim's name based on the fraudulent enrollment. The victim receives no notice from any party.Source: Loan servicer records; victim correspondence of May 8, 2026
-
2025
The actor makes small payments, then places the loan in deferment — a documented ghost-student technique that delays detection. No credit bureau activity reaches the victim, whose credit was frozen at all three bureaus and monitored throughout; the Direct loan type documented here generally originates without the consumer credit check a freeze would block. Direct PLUS loans are different: Federal Student Aid performs a credit check, and applicants with a security freeze must lift it before applying.Source: Victim correspondence of May 13, 2026
-
May 22, 2025
After one term at a 0.0 GPA, Normandale mails the fabricated record an Academic and Financial Aid Warning Notification stating "Your GPA is 0.0" and "Your completion rate is 0.0%," and adding: "We believe you can do this, and we are here to help you succeed." The letter is addressed to a person who does not exist.Source: Normandale Academic and Financial Aid Warning Notification, May 22, 2025 (in records production)
-
Apr–May 2026
The loan reaches 90+ days delinquent and the delinquency is furnished to Experian. This is the first moment the victim could have learned the loan existed — roughly fifteen months after origination.Source: Credit report; victim correspondence
-
Early May 2026
The victim files an FTC Identity Theft Report and police reports (report numbers withheld); sends FCRA § 605B block requests to all three bureaus by certified mail; opens a fraud claim with servicer Aidvantage; files a False Certification (Identity Theft) Discharge application; and reports the case to the ED Office of Inspector General.Source: Victim records
-
May 8, 2026
The victim sends a Root Cause Analysis request — application timestamps, originating IP addresses, full audit logs, submission details — to Normandale President Pakou Yang, copying Minnesota State's Chief Information Security Officer and the Office of the General Counsel, and requests identity verification via live video. No root-cause analysis is provided. On first contact, Normandale cannot locate any student record under the victim's name — the record is findable only by SSN, confirming the identifying information had been altered.Source: Email of May 8, 2026, to President Pakou Yang (cc CISO and Office of the General Counsel)
-
May 12, 2026
Assistant General Counsel Daniel G. McCabe takes the victim's call and ends it. In an internal email the same day (3:42 PM), later produced to the victim, McCabe writes: "I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility." The same email states that the data the victim seeks "is largely security information defined by Minn. Stat. 13.37" and that "We also do not offer members of the public the opportunity to audit our cybersecurity."Source: Internal email of May 12, 2026, produced in records response
-
May 13, 2026
In a separate internal email (11:50 AM), later produced to the victim, Assistant General Counsel Daniel G. McCabe writes: "It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one." The victim's own emails in the same production had stated the avenues he would pursue — an ED Office of Inspector General report, a Minnesota Government Data Practices Act request, and contact with the press.Source: Internal email of May 13, 2026, produced in records response
-
May 13–14, 2026
Normandale convenes its President, Registrar, and IT on the case; establishes an identity-verification path (live video appointment with government ID review) and processes the victim's ID Theft Appeal.Source: Emails of May 13–14, 2026
-
Late May 2026
Servicer Aidvantage (Maximus) acknowledges the fraud claim and removes the tradeline from the victim's credit reports. Working with Aidvantage was the fastest and cleanest part of the whole ordeal — the private party with the fewest transparency obligations — while the public institution was still withholding records. The federal False Certification (Identity Theft) discharge was still pending with the U.S. Department of Education as of July 2026; it was later granted (see the Aug. 25, 2026 entry). Funds disbursed to the actor were never recovered. Total the victim paid: $0 — but only after weeks of full-time-job-level effort.Source: Servicer communications
-
July 2026
Minnesota State responds to the victim's Minnesota Government Data Practices Act request: it produces the application record — revealing every red flag above — but withholds all origination metadata (timestamps, IP addresses, audit logs), citing Minn. Stat. § 13.37 "security information." The victim of the fraud is denied the data showing how the fraud was committed. The victim files an advisory-opinion challenge under Minn. Stat. § 13.072 with the Commissioner of Administration, where it is now pending.Source: MGDPA response; advisory opinion request
-
Aug. 24, 2026
KSTP 5 Investigates (Eric Rasmussen) publishes "Fake website calls out reality of 'ghost student' problem at Minnesota colleges" — the first on-record response from Normandale or Minnesota State to this case, and the report that identified the victim by name (see about me). The report states the loan was about $9,000 and quotes the victim: "My credit dropped 168 points overnight." Administrators with Normandale and the Minnesota State system "were unaware of [the victim's] website until 5 INVESTIGATES contacted them." Dara Hagen, Normandale's vice president of Student Affairs: "Since then, we've had about 29,000 fraudulent or potentially fraudulent applications that we've processed," and "We were seeing probably 42% of our applications or so being fraudulent, and now we're down to about 31%" — a figure the college says represents applications flagged for further review before any aid was disbursed. On the 0.0 GPA letter, Hagen: "We do have students who end up stopping out that are real students," and "And so, at some point there will be outreach." The college says it has committed extra staff, technology and training. Minnesota State says it flagged 2,696 fraudulent or potentially fraudulent financial aid applications in 2025–26, down from more than 7,700 the prior year; its Chief Information Security Officer, Craig Munson, says attackers changed tactics "several times" and that the system is in "constant improvement mode." The Legislature approved $3 million in one-time funding for an automated identity verification system; the system says the money has started flowing and a pilot vendor could be announced "in the coming weeks." Full quotations are in the institution's on-record response below; the author's own account is on Why This Site Exists.Source: KSTP 5 Investigates, Aug. 24, 2026, "Fake website calls out reality of 'ghost student' problem at Minnesota colleges." Bracketed text stands in for the name as it appeared in the report.
-
By Aug. 25, 2026
As of this update (Aug. 25, 2026), the U.S. Department of Education has discharged the loan under the False Certification (Identity Theft) discharge applied for in early May 2026. This closes the federal item that was still pending in July 2026: the loan no longer exists in the victim's name. The date on the discharge notice is not published here. Servicer acknowledgment, tradeline removal, and discharge were three separate events, and the whole path took under four months from the early-May 2026 application — it is set out for other victims on how a fraudulent federal student loan gets discharged.Source: Department of Education discharge, confirmed by the victim for this update (Aug. 25, 2026)
Attribution note
Evidence gathered during remediation — an IP address produced to the victim in correspondence — indicates the actor likely operated from outside the United States, possibly the Netherlands. This is presented as an investigative lead, not an established fact. Whatever the actor's location, the mechanics are documented: the fraud required only two inputs — a stolen SSN and a lookalike email address.
That correspondence also matters for the records fight above: the institution sent the victim an originating IP address during remediation, before Minnesota State took the position — in the May 12, 2026 counsel email and the July 2026 records response — that originating IP addresses are "security information" under Minn. Stat. § 13.37 that cannot be disclosed to him. The same category of data was disclosable when the institution volunteered it, and classified once the victim formally asked — see What Went Wrong. If you are facing something similar, start with What To Do.
What do the primary documents say?
The underlying files are not published, and there is no plan to publish them. The produced records are dense with personal data: the victim's identifiers, plus addresses and numbers that may belong to uninvolved third parties. This site will not gamble on a redaction being complete. Instead, this page names each document, dates it, states what it shows, and quotes its load-bearing passages verbatim, heat and all, including material unflattering to the victim's side of the exchange. "[the victim]" marks a visible redaction. Anyone named who believes a quotation is inaccurate or missing context can say so via corrections. The standards this policy comes from are set out on who runs this site, and why.
Source index
- Minnesota State Universal Application Data record (produced July 2026) — the fraudulent application of November 5, 2024, processed "Y-Successful"; red flags detailed on What Went Wrong.
- Academic and Financial Aid Warning Notification (May 22, 2025) — the encouragement letter mailed to the fabricated record.
- Correspondence with Normandale leadership (May 8–14, 2026) — the report, the "no record under his name" response, the live-video verification setup.
- Minnesota State Office of General Counsel internal emails (May 12–13, 2026) — source of the verbatim quotes below.
- Minnesota Government Data Practices Act response (July 2026) — produces the application record; withholds origination metadata under Minn. Stat. § 13.37.
- Servicer and remediation records — supporting the timeline above.
- KSTP 5 Investigates report (Aug. 24, 2026) — "Fake website calls out reality of 'ghost student' problem at Minnesota colleges", Eric Rasmussen; the public source for the institution's on-record statements, the $9,000 loan amount, the 168-point credit drop, and the 2025–26 Minnesota State figures. Quoted verbatim in the on-record response below.
Each source is held by the victim in full; none is posted — they carry the victim's identifiers and date of birth, third-party addresses, the fraudster's phone number, and raw originating-IP material.
The encouragement letter (May 22, 2025)
Mailed to the fabricated record after a semester recorded as 0.0 GPA and 0.0% completion (see timeline), closing:
"We believe you can do this, and we are here to help you succeed."Normandale Community College, Academic and Financial Aid Warning Notification, May 22, 2025
The Office of General Counsel emails (May 12–13, 2026)
Internal emails by Daniel G. McCabe, Assistant General Counsel, Minnesota State, produced in the Data Practices Act response. Nothing is trimmed inside a quotation. The production also contains the victim's own May 8 and May 12 emails, so any recipient can compare what he actually wrote against how it was characterized.
"I think we can provide [the victim] the data we would typically provide a student asking for their financial aid data. We don't have to consider the threat actor the data subject."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production). Bracketed text stands in for the name as it appeared in the report.
"However, the data he is specifically asking for is largely security information defined by Minn. Stat. 13.37 (application timestamps, originating IP addresses, full audit logs, exact dates and times of submission). We also do not offer members of the public the opportunity to audit our cybersecurity."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production)
"I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email, May 12, 2026, 3:42 PM (in DPA production). Bracketed text stands in for the name as it appeared in the report.
"It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one."Daniel G. McCabe, Assistant General Counsel, Minnesota State — internal email to Susan Ant, May 13, 2026, 11:50 AM (in DPA production). Bracketed text stands in for the name as it appeared in the report.
The financial-aid correspondence — Susan Ant (May 12, 2026)
In the same production, Susan Ant, Director of Financial Aid and Scholarships at Normandale, apologized to the victim and coordinated the identity-verification process. The failure documented on this site is institutional and legal, not hers — she is one of the people this site thanks.
"I'm sorry that this has happened to you."Susan Ant, Director of Financial Aid and Scholarships, Normandale — email, May 12, 2026 (in production)
"Again, I am sorry that this has happened to you and hope we can work together to resolve this as much as possible."Susan Ant, Director of Financial Aid and Scholarships, Normandale — email, May 12, 2026 (in production)
A "tiger team" on television. Silence for the victim who engaged it directly.
Minnesota State's Chief Information Security Officer, Craig Munson, publicly described a dedicated "tiger team" and "zero tolerance for any fraud" (KSTP 5 Investigates, Sept. 15, 2025), and the Legislature created an enrollment-fraud working group. On May 8, 2026, the victim engaged the security office directly: a written root-cause request to Normandale President Pakou Yang, copying the CISO. What those announced defenses produced for the actual victim, per the produced record and as of publication: no reply from the security office, no root-cause analysis, no correction, and no apology. The institution's first on-record response to this case came through KSTP 5 Investigates on Aug. 24, 2026 — quoted in full below.
The facts above are documented; the conclusion that follows is the author's opinion, drawn from them. A system that announces its defenses on television and then, when the actual victim engages it directly and in writing, produces nothing — no reply, no analysis, no correction, no apology — has answered the only question that matters. In the author's view, that response makes it very clear the announced structures were not built for the people the fraud actually happens to, and that when directly engaged, the system simply does not care.
Each block pairs a real, sourced quotation — reproduced verbatim, from public statements to KSTP 5 Investigates and from the produced emails above — with a response that is clearly labeled opinion: fair comment on public officials' documented conduct on a matter of public concern. No invented words are placed in any real person's mouth.
"We've put together, I like to call it, a 'tiger team,'"
— Craig Munson, Chief Information Security Officer, Minnesota State, to KSTP 5 Investigates, Sept. 15, 2025
We are defended by a dedicated tiger team. Its win-loss record is available by Data Practices Act request and will be produced in part — with the wins redacted and the losses withheld pending a private retreat. The produced record of this case contains the tiger team's complete documented contribution to it, reproduced here in full: .
"What I can say is, in the circles that I'm in, there is zero tolerance for any fraud,"
— Craig Munson to KSTP 5 Investigates, Sept. 15, 2025
In this case it matured into zero tolerance for records requests about the fraud, for phone calls about the fraud, and for the person the fraud actually happened to.
"However, the data he is specifically asking for is largely security information defined by Minn. Stat. 13.37 (application timestamps, originating IP addresses, full audit logs, exact dates and times of submission). We also do not offer members of the public the opportunity to audit our cybersecurity."
— McCabe internal email, May 12, 2026 (verbatim; attributed in full above)
Correct. In this case that opportunity was reserved for the applicant of November 5, 2024, who completed the audit in a single submission, at 2:54 in the morning, and passed.
"I did abruptly end my brief conversation with [the victim]. I informed him that the College was working on the issue, and he responded with hostility."
— McCabe internal email, May 12, 2026 (verbatim; the original names the victim, redacted here)
The institution's own records characterize two people: a stranger who fabricated a person and took out a federal loan in someone else's name (filed as a "student"), and the actual human being who called to report it (filed as "hostility").
"It's worth monitoring from my standpoint because [the victim] has threatened litigation. But I don't need to get into the weeds on this one."
— McCabe internal email, May 13, 2026 (verbatim; the original names the victim, redacted here)
The production shows what the victim actually said he would do: an OIG report, a records request, and a call to a reporter — all three happened; none is a lawsuit. The weeds, it turns out, were load-bearing.
Source reporting: KSTP 5 Investigates (kstp.com) — Eric Rasmussen / 5 Investigates, "Ghost students target Minnesota colleges," Sept. 15, 2025; and "Fake website calls out reality of 'ghost student' problem at Minnesota colleges", Aug. 24, 2026. The McCabe quotations are verbatim from the produced emails in the documents section above.
What did the institution say on the record on Aug. 24, 2026?
Asked about this case by KSTP 5 Investigates, Normandale and Minnesota State responded on the record for the first time — through the reporter, not to the victim. Every quotation below is verbatim from KSTP 5 Investigates, Aug. 24, 2026, "Fake website calls out reality of 'ghost student' problem at Minnesota colleges." Bracketed text redacts the victim's name, which the report publishes and this site now carries on about me.
Normandale — Dara Hagen, vice president of Student Affairs
"Since then, we've had about 29,000 fraudulent or potentially fraudulent applications that we've processed. We were seeing probably 42% of our applications or so being fraudulent, and now we're down to about 31%."Dara Hagen, vice president of Student Affairs, Normandale Community College, to KSTP 5 Investigates, Aug. 24, 2026. The college says the figure represents applications flagged for further review before any student aid was disbursed.
"I think certainly folks are going to tell a story through their perspective and their experience and we're going to do the same. I go back to us being people-centered and really wanting to be a partner in that process as much as we can. At times, we're frustrated too that we can't do more."Dara Hagen to KSTP 5 Investigates, Aug. 24, 2026
"We do have students who end up stopping out that are real students. And so, at some point there will be outreach."Dara Hagen to KSTP 5 Investigates, Aug. 24, 2026 — on the 0.0 GPA warning letter; the report adds that administrators insist a 0.0 GPA does not always mean a ghost student.
The report also states: administrators with Normandale and the Minnesota State system "were unaware of [the victim's] website until 5 INVESTIGATES contacted them"; the college "has committed additional resources to combat enrollment fraud, including extra staff, technology and training"; and the victim's "imposter was still able to access federal student aid before the fraud was discovered."
Minnesota State — Craig Munson, Chief Information Security Officer
"We are in this constant improvement mode where, 'how can we get better?'"Craig Munson, Chief Information Security Officer, Minnesota State, to KSTP 5 Investigates, Aug. 24, 2026 — after saying attackers have changed their tactics "several times" since the system's Sept. 2025 statements.
"We want to make sure that the information that's on that student enrollment application matches who they say they are in real life."Craig Munson to KSTP 5 Investigates, Aug. 24, 2026 — on the automated identity verification system funded by $3 million in one-time legislative money; the system says the money has started flowing and a pilot vendor could be announced "in the coming weeks."
The report also states that Minnesota State — Normandale and 32 other colleges and universities — flagged 2,696 fraudulent or potentially fraudulent financial aid applications during the 2025–26 academic year, down from more than 7,700 the previous school year. Those figures, with the Sept. 15, 2025 numbers they supersede, are set out on the Minnesota State figures.
The quotations above are the record; what follows is the author's opinion, drawn from it. In the author's view, a 31% flagged rate after two years of announced defenses is not a solved problem, and a partnership that begins when a reporter calls — with no reply to the victim's own written request of May 8, 2026 — is not the "people-centered" process described. The reduction from 42% to 31%, and from more than 7,700 to 2,696, is real and is credited here as such; the author's view is that it measures how many applications are still getting through, not how many people are being protected. Nothing here asserts what any official knew or intended.
"I go back to us being people-centered and really wanting to be a partner in that process as much as we can. At times, we're frustrated too that we can't do more."
— Dara Hagen, vice president of Student Affairs, Normandale, to KSTP 5 Investigates, Aug. 24, 2026
The partnership, per the same report, began the day a television station called. The victim's own written request of May 8, 2026 remains, per the produced record, unanswered on the point it asked about.
"We do have students who end up stopping out that are real students. And so, at some point there will be outreach."
— Dara Hagen to KSTP 5 Investigates, Aug. 24, 2026
There was. It reached the ghost on May 22, 2025, in writing, with warmth. The real person it was built from heard from a credit bureau, eleven months later.
Next: how a fraudulent application got approved itemises the eleven documented failures behind this sequence; what ghost student fraud is and how big it has become places the case in the national and Minnesota State numbers; where the law fails student identity theft victims explains why almost none of it produces a remedy. If this is happening to you, go to what to do about a student loan you never took out.
- Fraudulent application submitted November 5, 2024; processed "Y-Successful."
- Federal loan originated January 27, 2025; first discoverable by the victim April–May 2026.
- Tradeline removed late May 2026; loan discharged by the U.S. Department of Education, confirmed Aug. 25, 2026.
- July 2026: records response withholds timestamps, IP addresses, and audit logs under Minn. Stat. § 13.37.
- Aug. 24, 2026: KSTP 5 Investigates reports the loan was about $9,000, the victim's credit dropped 168 points, Normandale's flagged share fell from about 42% to about 31%, and Minnesota State flagged 2,696 applications in 2025–26.
The page question and the status question above appear verbatim in this page's FAQPage structured data, and every timeline event appears item-for-item in its ItemList structured data — what you read is what machines read. Quotations are verbatim; commentary is labeled opinion. Independent site; not legal advice.