Login.gov Cleared These Accounts as Verified Under Federal Standards. GSA’s Own Anti-Fraud Team Later Found Them Fraudulent.
Login.gov is the federal government’s shared identity-verification service — the system more than 20 agencies now lean on to confirm that whoever is applying for a tax refund, a Social Security benefit, or an unemployment claim online is who they claim to be. It runs on a specific technical bar: NIST’s Identity Assurance Level 2 (IAL2), designed to catch a stolen identity before an account is ever approved. On July 15, 2026, GAO Director Marisol Cruz Cain told the House Oversight Committee’s Subcommittee on Government Operations something that undercuts that bar directly: accounts that had already passed Login.gov’s own IAL2 verification were later investigated and found fraudulent anyway.
The finding surfaced almost by accident — buried in a May 2025 sole-source contract modification GSA filed to justify awarding Login.gov’s identity-proofing vendor more money without competitive bidding. In its own words, quoted in GAO’s testimony, GSA disclosed that its Login.gov Anti-Fraud Team had been investigating “suspected fraudulent accounts” that had already cleared the government’s identity-proofing workflow, and that without an added layer of verification, “the sophistication of these attempts would increase exponentially.”
GAO-26-109261 is a testimony, not a freestanding new audit — it synthesizes and updates two earlier full-length GAO reports on Login.gov. Of the four recommendations those reports produced, three are now implemented. The fourth — actually agreeing on a timeline to fix the technical complaints agencies keep filing — is still open.
- $187 million — GSA's 2021 technology-modernization allocation that built Login.gov into the government's shared identity-verification system — GAO-26-109261
- 3 of 4 — GAO recommendations on Login.gov GSA has now implemented; the fourth — agreed timeframes to fix agencies' technical complaints — remains open — GAO-26-109261
- 12 of 21 — agencies using Login.gov that reported challenges tied to noncompliance with NIST's IAL2 identity-proofing guidelines — GAO-25-106640
- 9 of 21 — agencies reporting no real visibility into their own authentication data, high failure rates, or missing fraud controls — GAO-25-106640
- July 15, 2026 — date GAO Director Marisol Cruz Cain testified on Login.gov's fraud and technical failures before the House Oversight Subcommittee on Government Operations — GAO-26-109261
GSA folded $187 million in technology-modernization funding into Login.gov in 2021, betting that one shared identity layer could replace the patchwork of logins each agency built on its own. Instead of the IRS, the Social Security Administration, and the Department of Veterans Affairs each separately vetting whether an online applicant is real and not a stolen identity, they could all lean on a single service built to the same NIST IAL2 standard. More than 20 agencies eventually signed on.
That is the program Cruz Cain testified about on July 15, before a subcommittee chaired by Rep. Pete Sessions (R-TX), with Rep. Kweisi Mfume (D-MD) as ranking member. She was not alone in the room: Jordan Burris of the identity-verification firm Socure, David Maimon of SentiLink and Georgia State University, and the ACLU’s Jay Stanley all testified the same day — Stanley specifically warning lawmakers against letting any federal identity-verification system harden into what he called “a de facto national identity card.”
The verification failure at the center of Cruz Cain’s testimony did not come from a leak or an inspector general referral — it came from GSA’s own procurement file. In a May 2025 sole-source contract modification filed under FAR 8.4, GSA disclosed that its Login.gov Anti-Fraud Team had investigated accounts suspected of fraud that had already cleared IAL2 identity-proofing — the government’s own bar for concluding a person is who they claim to be. GSA did not soften the stakes: without another verification layer, the agency wrote, “the sophistication of these attempts would increase exponentially,” leaving “the Login.gov platform…at greater risk for fraud attacks.”
“The sophistication of these attempts would increase exponentially.”
GSA, Limited Sources Justification (FAR 8.4), sam.gov — quoted in GAO-26-109261
GAO groups the threats GSA is racing to stay ahead of into four categories: new-account fraud built on stolen Social Security numbers and driver’s license data; existing-account takeover, where a legitimate account is hijacked after the fact; synthetic identity fraud, which stitches real and fabricated information into an identity that maps to no single victim; and government-benefits fraud, where the target is not the login itself but the payment behind it.
The benefits-fraud category is where the abstraction becomes a check that does not arrive. The Social Security Administration has reported cases of beneficiaries’ information being “used to fraudulently redirect the beneficiary’s direct deposit benefits” — meaning a Login.gov-verified account can be the mechanism that reroutes someone else’s monthly payment before the real beneficiary notices. That is the sharp end of what an IAL2-cleared-then-fraudulent account can do: not a hypothetical access risk, but someone else’s rent check.
Beyond fraud, GAO’s underlying October 2024 review surveyed the 21 agencies then using Login.gov and found the rollout rougher than the pitch suggests. Twelve of the 21 reported challenges tied to noncompliance with NIST’s IAL2 guidelines — the exact standard the system is supposed to guarantee. Nine reported no real visibility into their own authentication data, on top of high failure rates and missing fraud controls. Eight cited problems with Login.gov’s pricing structure. None of that is exotic; it is the ordinary friction of a shared federal utility — but it means the “20-plus agencies standardized on one system” pitch understates how many of them are still filing complaints about it.
Of the four recommendations GAO issued from its 2024 and 2025 reports, GSA has closed three: it completed a remote identity-proofing pilot by March 2025, documented lessons learned from that pilot by June 2025, and began the annual backup-integrity testing GAO wanted, verified as underway by GAO this July. The fourth is still open: establishing agreed-upon timeframes with partner agencies for actually resolving the technical complaints those 21 agencies filed. GSA published a roadmap in December 2024 and stood up a “Partner Advisory Group” to work the issue — but GAO’s flat assessment is that neither “fully demonstrate[s]” the underlying problems are resolved.
The testimony lands as Login.gov gets new management under a GSA leadership team installed to cut costs, not just secure logins. GSA Administrator Edward C. Forst — a Trump nominee and former Cushman & Wakefield and Goldman Sachs executive, confirmed and sworn in this past December — now oversees a program whose day-to-day direction changed hands again in April 2026, when Greg Hogan took over as Login.gov’s program director. Hogan previously served as chief information officer at the Office of Personnel Management, installed there on President Trump’s second day in office as part of the DOGE-era wave of appointments, and passed through the White House’s “National Design Studio” before landing at Login.gov.
Marisol Cruz Cain — GAO Director, Information Technology and Cybersecurity; delivered the July 15, 2026 testimony synthesizing GAO’s Login.gov findings.
GSA Administrator Edward C. Forst — Trump administration appointee; confirmed and sworn in December 2025.
Login.gov Program Director Greg Hogan — took over the program in April 2026; a DOGE-era appointee previously installed as OPM's CIO.
Rep. Pete Sessions (R-TX) — chairs the House Oversight Subcommittee on Government Operations that heard the testimony.
Rep. Kweisi Mfume (D-MD) — the subcommittee’s ranking member.
Rep. Marjorie Taylor Greene (R-GA) — chairs House Oversight’s separate DOGE subcommittee, which held a related hearing on federal payment fraud.
The efficiency framing runs through how administration allies talk about the program. A GSA official aligned with DOGE efforts told Nextgov/FCW in March 2025 that Login.gov is “a critical part of Government-wide efforts to promote efficiency and fight fraud.” The House Oversight Committee’s separate DOGE subcommittee, chaired by Rep. Marjorie Taylor Greene (R-GA), has pushed the argument further in its own hearings on federal payment fraud — including one where LexisNexis Risk Solutions CEO Haywood Talcove testified that better identity verification could save the government “$1 trillion a year.” Neither GAO nor NBC News’s own reporting on that hearing could find support for the figure; NBC reported the claim “lacks supporting evidence.” The accounts that beat Login.gov’s own verification are documented in the government’s own contract file. The trillion-dollar savings number is not.
A federal identity-verification system built around one promise — that IAL2 proofing means the person behind an account is real — has itself disclosed, in its own contract paperwork, that accounts clearing that exact bar were later found fraudulent. Three of GAO’s four recommendations on Login.gov are done; the fourth, actually agreeing on when agencies’ technical complaints get fixed, is not. Login.gov now has new leadership installed to make government more efficient, and administration allies are happy to cite it as proof efficiency and fraud-fighting can coexist. What they have not done is match GAO’s rigor: the accounts-passed-then-flagged-fraudulent finding traces to GSA’s own procurement file. The trillion-dollar savings claim floated in a companion hearing does not trace to anything at all.



