NearSeal

2026-09-09

Your financial aid office wants your tax transcript and your SSN. What should you actually encrypt?

The U.S. Department of Education announced in 2025 that nearly 150,000 identities it now considers suspect have turned up across current FAFSA applications. One district, Foothill-De Anza Community College District, held 10,000 of its 26,000 applications for fraud investigation. College of Southern Nevada wrote off $7.4 million after a single semester of fraudulent enrollments. The department's response, described in its own press release, is a new identity-validation process: every first-time federal aid applicant must now show an unexpired, government-issued photo ID, in person or over live video, to someone at their school, starting as a temporary measure in summer 2025 and made permanent nationwide that fall.

None of that is about your email. Fraud rings build fake identities mostly from data that leaked somewhere else entirely — old breaches, purchased identity kits, synthetic combinations of real Social Security numbers and invented names. Encrypting the tax transcript you send your own financial aid office does not touch that supply chain, and this post is not going to claim it does. What it changes is narrower and still worth having: whether a real, current, complete set of your own identity documents — the kind that fraud ring is assembled to imitate — sits as plaintext in your inbox, your parent's inbox, and every backup of both, for as long as those accounts exist.

What a financial aid office actually asks you to send

If your FAFSA gets flagged for verification — a routine, non-accusatory step that happens to a large share of applicants every year, not a sign of suspected fraud — the documents a school typically requests are a federal tax return transcript (or proof you used the IRS Data Retrieval Tool), W-2s or 1099s, a signed verification worksheet, and, depending on the school and your situation, a copy of a Social Security card or a government-issued ID. Put together, that is a denser identity kit than almost anything else you will email this year: full legal name, date of birth, address, income, and a Social Security number, cross-referenced against a federal database by design. That density is exactly why it deserves more care than a typical attachment, independent of whether any particular fraud ring is currently active.

The half-measure your school already asks you to do

Most financial aid offices know email is not a great channel, and most also still accept it — NC State's own verification instructions are typical: "You may mail, email or fax documents. If you choose to email, please redact or otherwise obscure sensitive data (SSNs) while ensuring that the student name and ID number remain visible on each page." That is a reasonable ask, and it is also inconsistent across the actual documents in the pile. The IRS redesigned its transcripts back in 2018 specifically to reduce this exposure — an individual transcript today already shows only "last four digits of any SSN: XXX-XX-1234," by default, before you touch it. Your W-2, on the other hand, may or may not be masked the same way: the IRS only permits employers to voluntarily truncate the SSN on the copy they hand employees — some do, many don't, and it's the employer's call, not yours. A Social Security card scan and the school's own verification worksheet have no masked version at all; the whole nine digits, in the clear, is the point of both documents. So "redact the SSN before you email" is good advice for a file where a piece of software already did most of the work, and advice you can't actually follow for the files where it matters most.

Where encrypting the file actually helps

Three situations in this pile are a genuine fit for a file encryptor, and none of them require the financial aid office itself to touch NearSeal.

Your own copy, at rest. Verification tends to repeat — a sibling applies next year, a school asks again, a lender wants the same documents for a private loan. The realistic outcome is that the tax transcript, the W-2s, and the SSN card scan end up sitting together in a "financial aid" folder in Downloads or a synced Drive, in the clear, for years, on however many devices that folder reaches. That folder is the actual long-term liability, not any single email. Encrypt the working set once you're done submitting it for the current cycle — NearSeal does this entirely in your browser, nothing uploaded — and keep the passphrase in a password manager, not in a note next to the file.

Sending the set to a parent or co-signer. A student and a parent are frequently on opposite ends of this paperwork, emailing tax documents back and forth to fill out the same worksheet. That's a real handoff between two people, not a submission into an institutional pipeline, and both sides can run a browser tool. Encrypt the file, then send the passphrase over a separate channel — a text or a phone call, not the same email thread — the same rule any password manager or bank will give you for sharing a secret at all.

An email a school genuinely accepts, if they'll take it encrypted. Some smaller schools and community colleges only take email for this. If yours is one of them, and you'd rather not send an unredacted SSN card in the clear, call the financial aid office first and ask whether they can open a NearSeal-format or age-format attachment — most offices are not set up to decrypt anything, and an encrypted file they can't open just means a resubmission delay. If they say yes, encrypt it, and send the passphrase by phone, not by reply-all in the same thread. One more thing worth doing either way: rename the file to something generic before you encrypt it. NearSeal's container keeps the original filename in its own header (readable, though tamper-evident from the current format version on); "ssn_card_jane_doe.pdf.nearseal" tells anyone who sees it what's inside just as clearly as the unencrypted name would.

Where it doesn't help — and what to use instead

Most schools' actual preferred channel is a document upload inside their own financial aid portal, the same MyPack/Workday-style system NC State and plenty of others use. That system exists specifically to receive these documents, restrict who inside the office can see them, and log that they arrived — an access model an encrypted email attachment can't replicate on its own. If your school gives you a portal, use the portal in plain form, exactly as they built it; don't add NearSeal on top of a channel that's already doing this job. Encryption earns its keep in the two narrower cases above, not as a universal upgrade to every channel a school offers.

And be clear-eyed about the one hard limit: if you encrypt your only copy of a tax transcript during a season when a school is waiting on it, and the passphrase is lost, NearSeal has no recovery path of any kind — no reset link, no support ticket, nothing stored on a server to fall back on, because there is no server. Keep an unencrypted copy in one place you already trust — your own tax software account, the IRS's own Get Transcript service you can pull from again — before you make the encrypted copy the only one that exists.

The honest version

Encrypting your own tax transcript won't slow down a fraud ring built from someone else's leaked data, and it won't replace the photo-ID check your school now runs on new applicants. What it does is close a smaller, more personal gap: the plaintext copy of your own SSN, income, and identity that would otherwise sit in an inbox or a synced folder for years after the financial aid office stopped needing it. Encrypt the copy you keep. Send the passphrase somewhere else. And put the file back into a portal, not an inbox, whenever your school has actually built one.

Sponsored
← NearSeal

This page shows ads only if you consent.