NearSeal

2026-10-01

The FTC logged nearly 65,000 rental scams asking for your SSN and pay stubs. A real landlord asks for the same thing.

Apply for an apartment and you hand over the same packet almost everywhere: a filled-out application with your Social Security number, a copy of a government ID, and proof of income — usually a few recent pay stubs or a bank statement screenshot. The FTC's own Data Spotlight, published Dec. 22, 2025, is built around an uncomfortable fact: that packet is also exactly what a fake landlord asks for. Here's what encrypting it before you send it actually changes, and the one honest case where that doesn't help at all.

Nearly 65,000 reports, and the documents are the point

The FTC counted "nearly 65,000 rental scams" reported from January 2020 through June 2025, with "about $65 million in losses" and a median reported loss of $1,000. About half of people reporting a scam in the year ending June 2025 said it started with a fake ad on Facebook, another 16% on Craigslist; renters age 18 to 29 were three times more likely than other adults to report losing money, accounting for 46% of reported losses in that group. The agency is specific about what gets collected along the way, separately from any money wired for a deposit: scammers "collect personal information from consumers such as their Social Security number, a picture of your driver's license, paystubs, and other personal details." That's not a side effect of the scam — a stolen identity is a second payout on top of whatever rent deposit never existed.

The problem: a real landlord asks for the identical packet

Nothing about an SSN, a driver's license photo, and a pay stub is unusual to request before renting an apartment — screening applicants this way is routine and, in most states, legal. That's exactly what makes the FTC's finding uncomfortable rather than just informative: the request itself carries no signal. A genuine property manager's application form and a scammer's copy-pasted Craigslist listing ask for the same four things, worded almost the same way. You can't tell which one you're in by reading the ask.

One application packet, two possible destinations SSN + ID photo + pay stubs / bank statement the same four items, either way Fake landlord (scam listing) ~65,000 reports, ~$65M lost since 2020 (FTC) The attacker IS the recipient — they hold the passphrase too → encryption fixes nothing here Real landlord / property manager ~70% of rental properties, individually owned (HUD/Census) Often a personal inbox, no IT department or retention policy → encrypting the packet helps here The ask looks identical from outside FTC's own advice: "Until you've agreed to rent a place, a landlord doesn't need your Social Security number, credit score or other sensitive information." Verify the listing and the person first — encryption decides nothing here.
The same packet reaches two very different recipients, and nothing in the request itself tells you which one you're sending it to.

What makes the legitimate half of this different from a bank

Set the scam branch aside for a moment and assume the listing is real. Per HUD and the Census Bureau's 2021 Rental Housing Finance Survey, "about 70 percent of rental properties, representing 38 percent of all rental units, are owned by individual investors" — and for properties with four or fewer units, that figure is also about 70%, representing 15.9 million properties. That matters for exactly one reason: a mortgage lender or a hospital portal has a security team, a retention schedule, and a breach-notification obligation written into law. An individual landlord renting out a unit or two usually has none of that. Your SSN, ID photo, and pay stub most likely land in an ordinary personal inbox, sitting there indefinitely, forwarded to a spouse or a property-management friend, or still on an old laptop years after you moved out — not because anyone involved is careless by nature, but because nothing requires them to treat it any differently from a dinner reservation.

What encrypting the packet actually fixes

NearSeal runs entirely in your browser — the pay stub, ID photo, or bank statement screenshot you're sending never uploads anywhere to get encrypted. It's sealed on your own device with AES-256-GCM and a passphrase-derived key (PBKDF2-SHA256 at 220 iterations) before it goes anywhere. For the legitimate-landlord branch above, that removes the plaintext copy from the two places you actually control: the file sitting in your own Downloads folder or Sent mail, and the attachment as it crosses the wire into an inbox with no particular security guarantees behind it. For the passphrase to do any good once it arrives, it has to travel by a separate channel from the file — a text or a phone call to the landlord you've already met or verified, not a reply in the same email thread.

The one honest case where that trick doesn't work

Every other document NearSeal has written about — a file for your lawyer, your accountant, a new client — shares one assumption: the recipient is who they say they are, and the risk is someone else intercepting the file in transit or finding it sitting on a server afterward. Sending a passphrase over a second channel defeats exactly that kind of eavesdropper. A rental scam breaks that assumption at the root: the person on the other end of the phone call is the scammer. They set up the fake listing precisely to collect your SSN and ID, so handing them an encrypted file and then calling them with the passphrase accomplishes nothing — you've simply handed over the same plaintext, one extra step later. Encryption authenticates nothing about who you're sending to; it only protects a file from everyone except whoever holds the passphrase, and in a scam, that's already the attacker. The FTC's own advice is the actual defense here, not a cryptographic one: "Until you've agreed to rent a place, a landlord doesn't need your Social Security number, credit score or other sensitive information" — plus checking whether the listed address turns up elsewhere at a different price or under different contact details, a pattern the agency flags as a clear tell. Verify the listing and the person first. Encrypt only once you've done that, for the legitimate half of the trip that's left over.

Two more honest limits, regardless of which branch you're on

NearSeal's default container keeps the original filename in a plaintext header field — bound into the authenticated data so it can't be silently swapped, but still readable without the passphrase. Encrypting a file literally named "jane_smith_ssn_paystub.pdf" tells anyone who intercepts it exactly what's inside before they've cracked anything; rename it to something unremarkable first, or use the opt-in age-encryption.org format, which carries no filename field at all. And there is no passphrase recovery of any kind — if you forget the passphrase before the landlord has had a chance to open the file, the encrypted copy is permanently unreadable, including to you.

Where NearSeal fits

The FTC's numbers describe a scam that collects the same income and ID documents a legitimate rental application needs, and no amount of encryption changes who's on the other end of that specific transaction — only verifying the listing and the landlord does. What's left once you've done that verification is a real, ordinary gap: close to 70% of the time, the inbox your SSN and pay stub are headed into belongs to one person with no security team behind them at all. That's the gap NearSeal closes — not the scam, and not what happens after a legitimate landlord has already opened the file, but the plaintext copy that otherwise sits on your device and in transit the whole way there.

Sponsored
← NearSeal

This page shows ads only if you consent.