Discovering your name, credentials, or institutional affiliation attached to a paper you never wrote, never saw, and never approved is a distinct and increasingly documented form of research misconduct — not a hypothetical edge case. It happens to real researchers, has been documented repeatedly by Retraction Watch and university research-integrity offices, and appears to be accelerating as generative AI lowers the cost of producing a plausible-looking manuscript at scale. This guide covers what authorship identity theft actually is, the mechanisms behind it (including where AI tools fit in), and the concrete, sequenced steps to take if it happens to you.
What counts as authorship identity theft
Authorship identity theft is the use of a real person’s name, credentials, and/or institutional affiliation on a manuscript, without that person’s knowledge or consent, to lend the paper false credibility. It is distinct from several adjacent, better-known authorship problems that CASRAI covers elsewhere:
- It is not honorary/guest authorship — where a real contributor knowingly consents to be listed despite not meeting authorship criteria. Identity theft involves no consent at any point.
- It is not ghost authorship — where an uncredited writer does real work behind a byline that omits them. Identity theft runs the opposite direction: a byline is added, not omitted, and the named person did no work at all.
- It is not simple name-collision — two genuine researchers who happen to share a common name, sometimes in the same field, can be confused in citation records or bibliographic databases without any bad-faith actor being involved. This is a real, separate data-quality problem (part of why persistent identifiers like ORCID exist), but it is not fraud.
- It overlaps with, but is broader than, journal hijacking and paper mills — see CASRAI’s Hijacked Journal and Peer Review Fraud entries. A hijacked or predatory venue is often the *setting* in which authorship theft happens, but the theft itself is the specific act of misappropriating a real identity.
The common thread across documented cases: the named person has no relationship to the manuscript’s content, submission, or review process, and typically finds out only after the paper is already public — often by accident, while checking their own Google Scholar profile or being contacted by a colleague.
How it actually happens
Several mechanisms recur across documented cases, and they are not mutually exclusive — a single fraudulent paper often combines more than one:
Fabricated or reused affiliation and contact details
A submitter lists a real researcher’s name and institutional affiliation, sometimes pairing it with a look-alike or spoofed email address so that editorial correspondence never reaches the actual person. The University of Antwerp’s research-integrity guidance describes this pattern directly, noting that affected researchers typically “discover their names listed as authors on articles they never contributed to, published in obscure journals” — frequently ones that sit outside major indexing services, which lets the fraudulent work circulate with little scrutiny.
Sold authorship slots
Paper mills and informal brokers sell byline positions on manuscripts — sometimes on legitimately researched work stolen from its real author, sometimes on wholly fabricated papers — to buyers seeking a fast publication credit. CASRAI covered a documented instance of this directly: see Stolen Study, Sold as Authorship Slots on Telegram, where an economics researcher’s own study was stolen and resold with substitute authors, discovered only when her original submission was rejected as too similar to the “new” paper already in print.
Direct impersonation of a named individual
In the most acute version, a specific real person’s identity is used without any of their own work involved at all — their name simply attached to someone else’s manuscript to borrow their institutional credibility. CASRAI documented one such case in detail: see Walsh Medical Media Demanded EUR499 to Retract a Paper Falsely Attributed to an Impersonated Author. A separate, independently reported case followed a similar shape: psychologist Maryam Farhang discovered her name and affiliation listed as an author on an unrelated paper about autism diagnosis technologies in the Journal of Research in Allied Life Sciences, work she had never contributed to and whose subject matter did not match her own research focus at all. The journal removed the article and an associate editor described it as a “misunderstanding,” but the paper remained visible on ResearchGate and an affiliated university site after the retraction (Retraction Watch, February 2026).
Where AI tools change the picture
Generative AI does not create a new category of fraud here — impersonation and sold authorship predate large language models by years — but several documented and widely discussed dynamics plausibly lower the barrier and raise the volume:
- Manuscript generation at scale. LLMs can produce a fluent, structurally plausible paper — introduction, methods, discussion, references — in minutes, reducing the labor cost of producing something a low-scrutiny or hijacked journal will accept. Paper-mill output has already been documented rising sharply in life-science literature over the past decade; the specific incremental effect of generative AI on that trend is real and actively discussed but not yet precisely quantified in the literature CASRAI could verify, and this guide will not assign it a specific statistic.
- Fabricated reference lists and boilerplate. AI-generated manuscripts frequently include placeholder or incomplete citations — a pattern noted in the Farhang case above — which is one practical tell when reviewing a suspicious paper that carries your name.
- Cheaper mass-produced correspondence. Spoofed or look-alike emails, fabricated co-author “consent,” and templated cover letters are all easier to generate credibly and at volume than they were even a few years ago, which matters directly for how paper mills recruit or fabricate author lists.
Editorial and integrity bodies have responded accordingly: COPE’s guidance library has been actively expanding to address paper-mill fraud specifically, including tighter language on re-reviewing potentially innocent co-authors swept into a batch retraction rather than treating every listed name as equally culpable — directly relevant if your name turns up on a fraudulent paper alongside others you don’t recognize either.
What to do if your name appears on a paper you didn’t write
The sequence below follows the pattern recommended by university research-integrity offices and consistent with how the documented cases above were actually resolved.
1. Document everything before you contact anyone
Save a PDF or full screenshot of the article as it currently appears, including the full author list, affiliations, and any acknowledgments. Record the journal name, publisher, DOI, submission and publication dates, and the corresponding author’s listed contact details — that information tends to disappear or change once a publisher is alerted to a problem, so capture it first.
2. Search beyond the journal itself
A retraction or removal notice on the journal’s own site does not mean the paper is gone. Check Google Scholar, ResearchGate, Scopus, OpenAlex, and Web of Science for copies or indexed records under your name — all of these can continue surfacing a “removed” paper independently of the publisher, as happened in the Farhang case above, where the article stayed visible on ResearchGate and an affiliated university page after the journal itself took it down.
3. Contact your institution’s research integrity office
Most universities have a designated office or research integrity officer for exactly this situation. Reporting internally, not just to the journal, matters for two reasons: it creates an institutional record protecting you if the fraudulent paper surfaces later (in a tenure review, grant application cross-check, or plagiarism-detection sweep), and your institution may have established channels or legal counsel that carry more weight with a publisher than an individual complaint.
4. Contact the journal and publisher directly, in writing
Request an explanation, a correction or retraction, and written confirmation once it’s issued. State plainly that you did not author, review, submit, or consent to the paper. If the publisher is a COPE member, its process should follow COPE’s retraction guidance, which recognizes fabricated authorship as valid retraction grounds distinct from the underlying data or findings being flawed. Be aware, per the documented case above, that some publishers respond slowly, minimize the incident as a “misunderstanding,” or — as in the Walsh Medical Media case — attempt to charge a fee before acting; neither response changes that you are entitled to a correction or retraction, and persistence in writing, with your institution copied, is often what moves a stalled case forward.
5. Request removal from third-party indexes and repositories separately
A journal-side retraction does not automatically propagate to ResearchGate, institutional repositories, Scopus, or citation managers. Each typically has its own takedown or correction-request process and needs to be contacted separately with your documentation from step 1.
6. Consider a public or professional statement, deliberately
Some affected researchers have posted about the incident on professional networks once they had documentation and had already engaged their institution — this can help pre-empt a colleague or hiring committee independently discovering the fraudulent paper and questioning it out of context. This is a judgment call best made after steps 1-4 are underway, not instead of them.
Reducing your exposure going forward
No individual measure fully prevents identity theft in authorship — the fraud happens on the submitting side, outside a victim’s control — but several practices make misuse easier to catch quickly and easier to contest credibly once caught:
- Maintain and monitor an ORCID iD. Because ORCID records are updated by the researcher (or by a trusted party the researcher explicitly authorizes), a fraudulent paper is far less likely to appear correctly linked to your genuine ORCID record — and checking your own record periodically is a fast way to notice something you didn’t add.
- Set up name-alert monitoring. A basic search alert on your name plus institutional affiliation catches new indexed mentions, including in venues you’d otherwise never encounter.
- Use CRediT contributor statements consistently on your own genuine papers. A clear, specific pattern of documented contribution on your real work makes an anomalous, undocumented byline stand out faster to anyone reviewing your publication record — see CASRAI’s CRediT & Authorship Attribution overview and the individual CRediT role pages for how contributor statements are structured.
- Know the difference between a dispute and theft when something looks wrong. If a colleague added you to a paper without proper discussion, that may be an authorship dispute to resolve directly — see CASRAI’s guide on when an authorship dispute crosses into research misconduct. If you have no relationship to the paper or its authors at all, you’re dealing with the identity-theft scenario this guide covers, and the response is different: contact the journal and your institution immediately rather than trying to negotiate with a co-author.
Frequently asked questions
Is this the same as plagiarism?
No. Plagiarism is presenting someone else’s work or words as your own. Authorship identity theft is the reverse: someone else’s (often fabricated or stolen) work is presented under your name, without your knowledge. The Vijayalakshmi S / RV University case is a useful illustration of how the two can even collide — the original researcher whose study was stolen and resold was, in one documented instance, later accused of plagiarizing the very paper built from her own stolen work.
Can this affect my career even after the paper is retracted?
Potentially, yes — indexed copies can persist on repositories and citation databases after a journal-side retraction (see step 2 above), and a retraction notice itself, even when it correctly states the paper wasn’t yours, can still surface in automated screening tools used by funders, hiring committees, or plagiarism-detection software unless you have documentation ready to explain it. This is the practical reason to keep your own written record of the incident and its resolution, not just rely on the retraction notice existing somewhere online.
What if the journal won’t respond or refuses to retract?
Escalate in writing through your institution, which may have more leverage than an individual, and consider notifying the journal’s professional membership body (COPE membership, if applicable) or the platform hosting a persistent copy (ResearchGate, an institutional repository) directly, since publisher inaction doesn’t prevent a hosting platform from acting on a well-documented takedown request.
Does having an ORCID iD prevent this from happening?
No — ORCID cannot stop someone from submitting a fraudulent paper under your name to a journal that doesn’t verify authorship claims. What it does is give you an authoritative, self-controlled record of your genuine publications, which makes a fraudulent addition easier for you (or anyone checking) to spot as inconsistent with your real record.
Authorship identity theft sits at the intersection of research integrity, publishing ethics, and persistent-identifier infrastructure — see CASRAI’s broader CRediT & Authorship Attribution pillar for related material on contributor roles, authorship criteria, and dispute resolution.







