Skip to main content
Federal Criminal Penalties for Social Security Email Scams
market dataSource type: independent reporting

Federal Criminal Penalties for Social Security Email Scams

This article consolidates every federal criminal statute applicable to Social Security Administration email impersonation scams, organized by charge type with exact penalty ranges, stacking strategies, and a statute table for quick reference by legal professionals.

Updated

There is no freestanding federal offense called a “Social Security email scam.” In a charging document, the email is usually evidence of the scheme, the impersonation, the credential request, the transmission in interstate commerce, or the step that moved a victim’s identifying information or benefit money. The legal penalties come from the statutes prosecutors can fit to those acts.

That distinction matters because the sentencing exposure in a Social Security Administration email impersonation case rarely stops at one fraud count. Wire fraud can carry the transmission. Aggravated identity theft can add a mandatory consecutive term. SSA-specific provisions apply when the scheme touches benefits, false statements, Social Security numbers, or representative-payee conduct. Other counts—government impersonation, computer fraud, money laundering, or theft of government funds—depend on what happened after the email landed.

Stacked legal statute books and documents with a gavel and email phishing icon

Federal Statute Table for SSA Email Scam Penalties

ChargeStatuteTypical SSA email scam triggerStatutory penalty
Wire fraud18 U.S.C. § 1343Using email or another interstate wire communication to execute a fraud schemeUp to 20 years per count; up to 30 years if the violation affects a financial institution [1]
Aggravated identity theft18 U.S.C. § 1028AKnowingly transferring, possessing, or using another person’s means of identification during and in relation to a listed felonyMandatory 2 years, consecutive to the underlying felony; probation and suspended sentence are barred [2]
False personation of a federal officer or employee18 U.S.C. § 912Pretending to act as SSA, SSA OIG, or another federal official and acting as such or demanding something of valueUp to 3 years [3]
Social Security fraud42 U.S.C. § 408False statements, misuse of Social Security numbers, concealment affecting benefits, or knowing misuse of paymentsGenerally up to 5 years for listed false-statement and misuse offenses; up to 15 years for knowing misuse of benefit payments by certain payees or fiduciaries [4]
SSI fraud under Social Security Act § 163242 U.S.C. § 1383aFalse statements, concealment, conversion, or false evidence in Supplemental Security Income mattersUp to 5 years for general violations; up to 10 years for specified professionals or insiders who submit false evidence [5]
Computer fraud and abuse18 U.S.C. § 1030Unauthorized access to SSA-related accounts, victim accounts, or protected computers after credential capturePenalty depends on subsection and facts; statutory maxima include 1, 5, 10, or 20 years for common access, fraud, damage, and repeat-offense provisions [6]
Money laundering18 U.S.C. § 1956Moving proceeds through accounts, transfers, or transactions designed to promote or conceal the fraudUp to 20 years [7]
Theft of government money or property18 U.S.C. § 641Stealing, converting, or retaining federal benefit fundsUp to 10 years if the value exceeds $1,000; up to 1 year if the value does not exceed $1,000 [8]

The table is the useful starting point, not the end of the analysis. The same set of emails may support several charges if the government can prove distinct statutory elements: a scheme to defraud, use of interstate wires, use of another person’s identifying information, a false claim or statement connected to Social Security benefits, unauthorized account access, and movement of proceeds.

Why the Two-Year Identity Theft Count Changes the Case

The most important penalty number in many SSA phishing fact patterns is not the largest maximum. It is the two-year term in 18 U.S.C. § 1028A. The statute requires a two-year prison term for aggravated identity theft when the defendant knowingly transfers, possesses, or uses another person’s means of identification during and in relation to a listed predicate felony; that term must run consecutively to the punishment for the underlying felony and may not be suspended or replaced with probation [2].

For a penalty memo, that provision changes the floor. A defendant facing a wire fraud count has exposure up to the statutory maximum, with the actual sentence shaped by the Guidelines, loss amount, role, criminal history, plea posture, and other sentencing facts. Add a § 1028A conviction, and the court must impose the identity-theft term consecutive to the sentence on the predicate offense. The two years do not merge into the wire fraud sentence.

In an SSA email scam, the trigger is usually not the email address itself. It is the use of a victim’s name, Social Security number, date of birth, login credentials, benefit information, or other identifying data in relation to another federal felony. A phishing email that merely fails may support attempted or conspiracy theories if charged and proved, but § 1028A becomes most concrete when the record shows possession, transfer, or use of a real person’s identifying information.

Conduct-to-Charge Map

A clean charging analysis usually starts with verbs, not labels. “Social Security email scam” is a public description. The indictment has to describe what the defendant did.

Conduct provedLikely charging consequencePenalty consequence
Sent email messages pretending to be SSA or SSA OIG to induce payment, credentials, or benefit-related actionWire fraud; possibly government impersonationWire fraud supplies the main fraud maximum; impersonation adds a separate federal-officer false-personation count if the elements are met
Used a victim’s Social Security number, name, birth date, account login, or other identifying informationAggravated identity theft if tied to a qualifying predicate felonyMandatory consecutive two-year term becomes the practical sentencing floor
Made false statements or caused false benefit-related submissions to SSA42 U.S.C. § 408 or § 1383a, depending on the program and conductSSA-specific penalties may apply even when general fraud statutes also fit
Captured credentials and accessed online accounts or protected computers without authorizationComputer fraud under 18 U.S.C. § 1030Exposure depends on the precise access, damage, fraud, value, and repeat-offense subsection
Diverted Social Security or SSI paymentsTheft of government funds; SSA-specific benefit misuse provisions; wire fraudBenefit money can support both property-loss counts and program-specific counts
Moved proceeds through bank accounts, transfers, or other transactionsMoney launderingAdds a separate transaction-based maximum when concealment, promotion, or other statutory laundering elements are proved

The charging map also shows why a consumer-facing warning page can be legally incomplete. A warning may correctly say that SSA will not ask for certain information by suspicious email, but a prosecutor still has to decide whether the provable conduct is fraud by wire, identity theft, false personation, benefit fraud, unauthorized access, laundering, theft, or some combination.

Wire Fraud Usually Carries the Email Scheme

Wire fraud is the broad carrier count because the statute reaches schemes to defraud that use wire, radio, or television communication in interstate or foreign commerce. In an email impersonation case, the message itself, the credential submission, a payment instruction, or a later electronic transfer may supply the interstate wire communication. The statutory maximum is up to 20 years per count, rising to up to 30 years if the violation affects a financial institution [1].

The “per count” point deserves attention. A case is not necessarily one email, one count, one maximum. Prosecutors may select particular transmissions as counts, use others as overt acts or scheme evidence, and rely on the same factual course of conduct for loss and victim calculations at sentencing. The statute supplies the ceiling; the indictment and sentencing record determine how much of the scheme is actually in play.

SSA-Specific Fraud Is Narrower Than General Fraud, but It Matters

The SSA-specific statutes are not substitutes for wire fraud. They are program statutes. They matter when the facts touch Social Security numbers, benefit entitlement, representative-payee conduct, Supplemental Security Income, false evidence, concealment, or conversion of payments.

Section 408 covers a set of Social Security fraud offenses, including false statements and concealment connected to rights to payment, misuse of Social Security numbers, and certain misuse of payments. The penalty structure includes up to five years for many listed violations and up to 15 years for specified knowing misuse of benefit payments [4]. SSA’s own administrative guidance separately identifies conduct that may be referred for criminal prosecution, including false statements, concealment, and misuse of benefits, although that guidance is an administrative reference rather than the sentencing statute itself [9].

Section 1383a performs a similar role for Supplemental Security Income. It reaches false statements, concealment, conversion, and false evidence in SSI matters. The general maximum is up to five years, while specified claimant representatives, physicians, translators, current or former SSA employees, and other covered actors face up to 10 years for submitting or causing the submission of false evidence in covered circumstances [5].

That boundary can decide whether the SSA label is legally central or merely part of the disguise. If a defendant sends fake SSA emails to collect gift-card payments, the core federal charge may be wire fraud plus impersonation and identity theft if identifying information is used. If the defendant uses captured information to redirect retirement or SSI payments, file false benefit paperwork, or convert benefit money, the SSA-specific statutes become much more than background.

Impersonation, Access, Laundering, and Government-Funds Counts

False personation under 18 U.S.C. § 912 is a natural fit when the email does more than copy an SSA logo. The statute punishes a person who falsely assumes or pretends to be a federal officer or employee and acts as such, or in that pretended character demands or obtains money, documents, or something of value. The maximum is up to three years [3].

Computer fraud becomes relevant only if the proof moves beyond deception into unauthorized access. Credential capture is often the bridge. If stolen credentials are used to enter a protected computer, victim account, or online benefits environment, § 1030 may supply a separate access-based count. The penalty depends on the subsection charged and aggravating facts such as value, damage, intent, protected-computer status, and prior convictions [6].

Money laundering is also downstream. It is not charged merely because a scam produced proceeds. The government must prove a financial transaction or transfer that fits the laundering statute, such as promotion, concealment, or other listed laundering conduct. When that proof exists, § 1956 carries up to 20 years [7].

Theft of government funds under § 641 is the more direct property count when federal money is stolen, converted, or knowingly retained. In a benefit-diversion case, the object is not just a victim’s personal information; it may be Treasury-paid benefit money. The statute carries up to 10 years if the value exceeds $1,000 and up to one year if the value does not exceed that amount [8].

How Charges Stack in a Typical SSA Email Phishing Case

Consider a hypothetical case. The defendant sends emails that appear to come from SSA, directs recipients to a fake portal, collects names, Social Security numbers, dates of birth, and login credentials, uses those credentials to access accounts, redirects benefit payments, and moves the money through several accounts. No one needs to invent a special “SSA email scam penalty” for that fact pattern.

  • The email transmissions support wire fraud if they were used to execute the scheme.
  • The SSA pose may support government impersonation if the defendant falsely acted as a federal officer or employee or demanded value in that assumed role.
  • The use of real victims’ identifying information may add aggravated identity theft, with the two-year consecutive term.
  • The account access may support computer fraud if it fits a § 1030 subsection.
  • The diverted benefit funds may support SSA-specific fraud and theft of government funds.
  • The movement of proceeds may support money laundering if the transaction evidence satisfies § 1956.

The statutory maxima do not simply add up into the sentence a defendant will receive. Sentencing is governed by the counts of conviction, grouping rules, Guidelines calculations, statutory minimums and maximums, plea terms, restitution, forfeiture, and the court’s analysis under federal sentencing law. But the counts do change the negotiation. A defendant who might otherwise argue over a fraud-guidelines range must still account for a mandatory consecutive § 1028A term if that count remains in the case.

What Current Enforcement Data Does—and Does Not—Show

The volume context is real, but it has to be labeled correctly. In June 2026, the FTC reported that consumers lost about $3.5 billion to imposter scams in 2025, including about $920 million to government impersonation scams [10]. That is not an SSA-email-only sentencing dataset. It is broader consumer-report loss data across imposter scams.

The older-adult figures are also broader than Social Security email phishing. In August 2025, the FTC said reports showed more than a four-fold increase in reported losses by older adults to impersonation scammers [11]. The figure helps explain why elder-targeted impersonation schemes draw enforcement attention, but it does not prove how often a particular SSA email fact pattern produces a particular sentence.

The SSA-specific warning is narrower. In February 2026, SSA OIG warned the public about a surge in fraudulent Social Security Statement emails [12]. That alert is useful for identifying the live fact pattern: an email that borrows SSA branding or a Social Security Statement theme to move the recipient toward a fraudulent link, credential capture, or other requested action. It is not, by itself, a penalty source.

DOJ fraud enforcement releases and SSA OIG sentencing releases show that federal prosecutors continue to bring fraud, identity-theft, and government-program cases, including cases involving Social Security benefits, false statements, identity misuse, and benefit diversion [13][14][15]. They should be used carefully. Those release sets mix many fraud types; they do not isolate email-only SSA phishing as a sentencing category.

Civil Email Penalties Are a Different Track

CAN-SPAM belongs in a different box. Commercial-email enforcement and FTC civil penalty authority may matter in some deceptive-email contexts, but they are not the core criminal penalty structure for SSA impersonation phishing. Folding civil email penalties into a criminal exposure table would make the quick-reference answer worse, not better.

The better comparison for legal research is with other federal imposter and phishing patterns. Evidence questions in phishing cases may overlap with issues discussed in AI phishing detection and admissibility, while elder-targeted impersonation remedies may raise issues closer to grandparent scam legal recourse. Those are adjacent tracks. The criminal penalty question here turns on the federal counts the government can prove.

The Practical Penalty Answer

For Social Security email scam legal penalties, the working answer is a charging map: wire fraud for the electronic fraud scheme; aggravated identity theft when another person’s identifying information is used during a predicate felony; SSA-specific statutes when the facts reach benefits, false statements, Social Security numbers, SSI, or benefit misuse; and add-on counts for impersonation, unauthorized access, laundering, or theft of government money where the proof supports them.

The mandatory consecutive two-year identity-theft term is often the first number to check because it changes the minimum practical exposure. The largest statutory maximum may sit elsewhere—wire fraud, money laundering, or a financial-institution enhancement—but § 1028A changes the sentencing conversation as soon as the identifying-information proof is solid.

Exact exposure still depends on the charged facts, counts of conviction, statutory predicates, loss evidence, Guidelines calculations, and sentencing law. This is a statute-based reference, not legal advice; the point is narrower and more useful than a scam warning: SSA email impersonation can expose a defendant to overlapping federal criminal penalties far beyond any single “email scam” label.

References

  1. 18 U.S. Code § 1343 - Fraud by wire, radio, or television, Cornell Legal Information Institute.
  2. 18 U.S. Code § 1028A - Aggravated identity theft, Cornell Legal Information Institute.
  3. 18 U.S. Code § 912 - Officer or employee of the United States, Cornell Legal Information Institute.
  4. 42 U.S. Code § 408 - Penalties, Cornell Legal Information Institute.
  5. Sec. 1632. Penalties for Fraud, Social Security Administration.
  6. 18 U.S. Code § 1030 - Fraud and related activity in connection with computers, Cornell Legal Information Institute.
  7. 18 U.S. Code § 1956 - Laundering of monetary instruments, Cornell Legal Information Institute.
  8. 18 U.S. Code § 641 - Public money, property or records, Cornell Legal Information Institute.
  9. HA 01130.003 Violations of the Social Security Act or U.S. Criminal Code, Social Security Administration.
  10. FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025, Federal Trade Commission, June 2026.
  11. FTC Data Show More Than Four-Fold Increase in Reports of Impersonation Scammers Stealing Tens, Even Hundreds of Thousands from Older Adults, Federal Trade Commission, August 2025.
  12. SSA Office of the Inspector General Warns Public of Surge in Fraudulent Social Security Statement Emails, Social Security Administration Office of the Inspector General, February 20, 2026.
  13. Week of Fraud: DOJ’s New Fraud Division Announces Numerous Fraud Enforcement Actions and New Measures, U.S. Department of Justice, April 7, 2026.
  14. In One Week, National Fraud Enforcement Division Announces More Arrests, Convictions, and Sentences Representing Over $340 Million, U.S. Department of Justice.
  15. News Releases, Social Security Administration Office of the Inspector General.

Corrections & feedback

Submit corrections, flag outdated information, or provide additional market context. Comments are moderated.

Comments

Join the discussion with an anonymous comment.

Loading comments...
Blogarama - Blog Directory