Socure Report Finds Disaster Relief Efforts Were Plagued by Fraud After Texas Floods
By Dominic Sow · 17 December 2025

As federal policymakers explore faster, more decentralized approaches to disaster relief, new research from Socure reveals that these programs are deeply vulnerable to fraud, and that bad actors possess the scale and sophistication to exploit existing weaknesses, as well as those introduced by proposed reforms.
Socure, the AI-first platform for global identity and risk decisioning, today released new research uncovering how organized domestic and international fraud rings rapidly mobilized to exploit victims and relief programs following the catastrophic July 2025 floods in Central Texas.
The report, titled “Exploiting Disaster: Identity Fraud Spikes After Texas Floods,” provides an in-depth look at how criminal networks, including those with ties to China, Morocco, and other countries, weaponized pre-built “identity farms” and proxy networks to target disaster assistance funds intended for survivors.
As disaster relief programs increasingly prioritize speed through faster approvals, consolidated payouts, and broader state-level administration, these findings underscore the growing need for identity certainty and proactive fraud controls across the entire disaster-aid ecosystem, including federal agencies, state governments, financial institutions, and payment platforms.
“This research shows that fraudsters don't wait for recovery efforts to begin—they activate immediately,” said Mike Cook, Head of Fraud Insights at Socure. “Sophisticated fraud rings lie in wait with pre-built fake identities, ready to exploit moments of crisis – waiting for an early weather report, for example – ready to hit. As a former Texas flood survivor myself, I hope this research helps agencies and organizations better protect relief funds when speed and accuracy matter most.”
Socure’s analysis examined activity before and after the July 4 Kerr County floods and identified a repeatable, fast-moving fraud playbook:
- Fraudsters were ready to launch campaigns in lockstep with news coverage. Attacks surged within hours of the floods and again immediately after Federal Emergency Management Agency (FEMA) and Small Business Administration (SBA) relief announcements, demonstrating how criminals time attacks around public communications.
- Disaster relief programs were top targets. Nearly 29% of observed fraud attempts aimed to steal government assistance, followed by money-movement and credit card attacks.
- Local actors struck first; global networks scaled fast. Domestic fraud dominated early, but international attacks rose within days, including activity traced to OFAC-sanctioned regions.
- China-linked identity farms drove scale. Approximately 30% of international fraud originated from long-running Chinese identity farms generating synthetic and stolen identities for years.
- Residents faced elevated risk. Post-flood, Kerr County residents were 3.5× more likely to be targeted for identity fraud than before the disaster.
Companies in this story: Socure
People in this story: Mike Cook, Rivka Gewirtz Little