By Dr. Karen Holding-Jordan, former Dean of Records & Registration Continuing Education, Wake Technical Community College
Recently, FinCEN issued a 13-page alert, co-authored with the Department of Education and the FBI, warning financial institutions about organized fraud rings targeting federal student aid. Ghost students. Synthetic identities built with AI. Stolen personal data from real people, including minors, used to enroll fake students and siphon off refund checks.
This isn’t a theoretical risk. The Department of Education blocked more than $1 billion in attempted student aid fraud in 2025. And community colleges bore the brunt.
I’ve spent my career in continuing education. I’ve seen what manual processes look like from the inside. Staff enter registrations by hand. Payment data lives in one system while enrollment records sit in another. Student information is stored in spreadsheets that anyone with shared drive access can open. And here’s what I know: the institutions most exposed to fraud, audit failures, and data breaches aren’t the ones with bad intentions. They’re the ones still running manual processes that make it impossible to verify, track, or secure student records at scale.
The threat is here. It’s targeting your college.
When we talk about ghost students and aid fraud, the conversation usually centers on credit-bearing programs and FAFSA. But if you run a CE operation, don’t look away.
Workforce Pell went live last month. The final rule, published May 19, 2026, extends Pell Grant eligibility to short-term workforce training programs for the first time. Programs between 150 and 599 clock hours, designed for exactly the kind of training CE divisions deliver, now qualify for federal financial aid. That means federal compliance scrutiny follows. Programs must demonstrate a 70% completion rate and a 70% verified job placement rate. States must build systems to monitor outcomes. Institutions must track, report, and prove results.
What happens when a program fails to meet those thresholds? It loses Pell eligibility. And the reporting demands don’t care whether your data lives in a governed system or a folder on someone’s desktop.
Think about that. Can you document every registration, every payment, every completion for a given program right now? Not next week. Right now.
If your answer involves pulling data from three different places and reconciling it manually, you have a problem that Workforce Pell is about to make urgent.
Manual processes aren’t just slow. They’re dangerous.
Education was the most attacked industry globally in 2025, averaging over 4,300 cyberattacks per organization per week according to Check Point Research — a 41% increase year over year. Ransomware gangs claimed credit for 251 attacks on educational institutions that year, and more than 3.96 million educational records were breached, up 27% from 3.11 million in 2024, according to Comparitech’s education ransomware research. The Illuminate Education breach alone exposed personal information for millions of students across California, New York, and Connecticut, resulting in a $5.1 million settlement.
And those are the institutions with dedicated IT security teams and enterprise systems.
Now think about your CE office. If you’re running registration through email, paper forms, or a shared spreadsheet, ask yourself: Who has access to student Social Security numbers? How would you know if someone copied that file? Where is your audit trail?
The honest answer, for too many continuing education programs, is that there isn’t one.
I’m not pointing fingers. I’ve been there. When I arrived at Wake Tech, I inherited the same kind of fragmented processes that most CE leaders know well. Separate systems. Manual workarounds. No single source of truth for who registered, who paid, who completed. The staff did heroic work, but the systems made it impossible to answer basic compliance questions without hours of manual effort.
What changed for us
Wake Tech is North Carolina’s largest community college. Our CE division serves more than 37,000 learners annually, including over 12,000 fee-waived, unduplicated students every academic year. We were in dire need of a system that could handle that volume without the manual processes, inconsistent data, and compliance headaches that were holding us back.
We went live with Enrole in eight weeks. In the first six months, we processed over 4,000 fee-waived CE registrations through the platform, and overall CE enrollment grew 19% year over year. Since then, we’ve processed more than 15,000 fee-waived registrations total.
But the numbers only tell part of the story.
Enrole gave us the modern infrastructure we needed to scale efficiently while delivering a student experience that truly reflects the Wake Tech standard.
The system integrates directly with Ellucian Colleague via Ethos API, so registration data flows to our SIS in real time. No more manual entry. No more reconciling spreadsheets against Colleague records. The system allows for the verification of fee waiver eligibility and supports PIN-based access for employer coordinators, so our workforce partners can enroll their employees without calling our registrar’s office. Automation saves our staff more than three hours per week, and that time goes back into serving students instead of chasing paperwork.
Put another way: we went from a system where registration and student data were disconnected from our institutional systems to one where everything flows together. Registration, payment, communication, completion tracking, SIS integration. One system, one audit trail, real-time data.
Enrole has helped us process thousands of fee-waiver registrations, communicate more effectively with students, and strengthen our support for workforce partners. It’s had a meaningful impact on our operations and the communities we serve.
But it matters even more in the world we’re entering right now. FinCEN, the FBI, and the Department of Education are issuing joint alerts about AI-powered identity fraud targeting higher education. Workforce Pell is demanding verified outcomes and documented compliance. In this environment, your registration system is a security and compliance system whether you designed it that way or not.
Spreadsheets don’t meet SOC 2 Type 2 standards. Paper forms aren’t PCI compliant. Shared drives don’t provide the kind of access controls that protect student data under FERPA. And none of them give you the audit trail you’ll need when someone asks you to prove your program’s completion rate for Workforce Pell eligibility.
The budget conversation you’re already having
I understand the budget conversations. I’ve had them. CE divisions don’t always get the same institutional support as credit-bearing programs, even though we’re increasingly where the growth is. That means every dollar has to justify itself.
So here’s how I’d frame it: what’s the cost of a data breach involving student records? What’s the cost of losing Workforce Pell eligibility because you can’t produce the documentation? What’s the cost of staff spending days reconciling data that should flow automatically?
I gave you our Wake Tech story in detail because I lived it. But we’re not the only CE operation that’s made this shift. At SIUE, the School of Professional Development and Applied Knowledge runs non-credit and professional development programs across a range of disciplines. Their team was building courses and processing registrations through manual workflows similar to what many of us have inherited. After moving to Enrole, they cut course-creation time by 50% or more and halved staff time spent registering students. At Tulsa Tech, consolidating registration, payments, and certificate issuance into one system cut cross-unit coordination meetings from three or four a week down to one, with automated hourly data transfers to Ellucian Colleague. Those aren’t abstract improvements. That’s capacity returned to your team and risk removed from your operation.
The question for CE leaders right now isn’t whether you can afford to modernize your registration system. It’s whether you can afford not to, in a year when federal agencies are actively hunting for fraud, new compliance requirements are taking effect, and the systems you’re using were never designed to protect anyone.
What comes next
If you’re running manual CE registration processes, here’s what I’d encourage. Stop thinking of your registration system as an administrative tool. Start thinking of it as your compliance and security infrastructure. Because that’s what auditors and federal agencies see when they look at it.
Enrole was purpose-built for non-credit and workforce education. It connects your registration data to your SIS, your financial systems, and your LMS in real time. It meets the security standards (SOC 2, PCI, WCAG) that the current environment demands. And it gives you the kind of audit trail that lets you answer compliance questions in minutes, not days.
You already know what the risks are. You’ve read the same FinCEN alert I have. You’ve seen the Workforce Pell requirements. The question is what you do about the system sitting between your students and those risks.
If any of this sounds familiar, the Entrinsik team is ready to have a real conversation about what it takes to get your operation ready for what’s coming.
Sources
-
- S. Department of Education, “U.S. Department of Education Prevents More Than $1 Billion in Federal Student Aid Fraud This Year” (December 11, 2025). (Link)
- FinCEN Alert FIN-2026-Alert004, “Fraud Schemes Targeting Federal Student Aid” (July 24, 2026) (https://www.fincen.gov/news/news-releases/fincen-issues-alert-fraud-schemes-targeting-federal-student-aid)
- Check Point Research, “Back-to-School Sees Cyber Attacks Surge in Education” (August 28, 2025) (https://blog.checkpoint.com/research/cyber-attacks-surge-against-education-sector-ahead-of-back-to-school-season)
- Comparitech, “Education Ransomware Roundup: 2025 stats on attacks, ransoms, and data breaches” (February 5, 2026) (https://www.comparitech.com/news/education-ransomware-roundup-2025-stats-on-attacks-ransoms-and-data-breaches/)
- New York Attorney General, “Attorney General James and Multistate Coalition Secure $5.1 Million from Education Software Company for Failing to Protect Students’ Data” (Illuminate Education settlement, November 6, 2025) (https://ag.ny.gov/press-release/2025/attorney-general-james-and-multistate-coalition-secure-51-million-education)
- GovTech, “Ed-Tech Company Reaches Settlement Over Data Breach” (November 7, 2025) (https://www.govtech.com/education/k-12/ed-tech-company-reaches-settlement-over-data-breach)
- S. Department of Education / Federal Register, “Accountability in Higher Education and Access Through Demand-Driven Workforce Pell” (May 19, 2026). (Link)
- NAWB, “Workforce Pell Final Rule Published—Are You Ready for the July 1 Implementation?” — May 20, 2026 (https://www.nawb.org/workforce-pell-final-rule-published-are-you-ready-for-the-july-1-implementation/)
- GovTech, “Hunting Ghost Students” (California community college losses), November 7, 2025 (https://www.govtech.com/voices/hunting-ghost-students)