Search

Search bills, members, committees and pages...

H.Hrg.119

U.S. HouseHouse Government Reform CommitteeJul 15, 2026

Summary

H.Hrg.119 is a hearing titled EMERGING FRAUD THREATS AND THE EVOLVING FRAUD LANDSCAPE, held by the House Government Reform Committee on Jul 15, 2026.


Record

H.Hrg.119 has its transcript on the record.

Transcript

The transcript runs to 2,123 lines and 114,374 characters, as the Government Publishing Office printed it.

house-hearing-64225.txt
1[House Hearing, 119 Congress]2[From the U.S. Government Publishing Office]34                       EMERGING FRAUD THREATS AND5                      THE EVOLVING FRAUD LANDSCAPE6=======================================================================78                                HEARING910                               BEFORE THE1112                        SUBCOMMITTEE ON GOVERNMENT13                                OPERATIONS1415                                 OF THE1617                        COMMITTEE ON OVERSIGHT AND18                            GOVERNMENT REFORM1920                     U.S. HOUSE OF REPRESENTATIVES2122                    ONE HUNDRED NINETEENTH CONGRESS2324                             SECOND SESSION2526                               __________2728                             JULY 15, 20262930                               __________3132                           Serial No. 119-703334                               __________3536Printed for the use of the Committee on Oversight and Government Reform3738[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]3940    Available on: govinfo.gov, oversight.house.gov or docs.house.gov4142                               __________4344                   U.S. GOVERNMENT PUBLISHING OFFICE4564-225 PDF                 WASHINGTON : 202646=======================================================================4748              COMMITTEE ON OVERSIGHT AND GOVERNMENT REFORM4950                    JAMES COMER, Kentucky, Chairman5152Jim Jordan, Ohio                     Robert Garcia, California, Ranking53Mike Turner, Ohio                        Minority Member54Paul Gosar, Arizona                  Eleanor Holmes Norton, District of55Virginia Foxx, North Carolina            Columbia56Glenn Grothman, Wisconsin            Stephen F. Lynch, Massachusetts57Michael Cloud, Texas                 Raja Krishnamoorthi, Illinois58Gary Palmer, Alabama                 Ro Khanna, California59Clay Higgins, Louisiana              Kweisi Mfume, Maryland60Pete Sessions, Texas                 Shontel Brown, Ohio61Andy Biggs, Arizona                  Melanie Stansbury, New Mexico62Nancy Mace, South Carolina           Maxwell Frost, Florida63Pat Fallon, Texas                    Greg Casar, Texas64Byron Donalds, Florida               Jasmine Crockett, Texas65Scott Perry, Pennsylvania            Emily Randall, Washington66William Timmons, South Carolina      Suhas Subramanyam, Virginia67Tim Burchett, Tennessee              Yassamin Ansari, Arizona68Lauren Boebert, Colorado             Wesley Bell, Missouri69Anna Paulina Luna, Florida           Lateefah Simon, California70Nick Langworthy, New York            Dave Min, California71Eric Burlison, Missouri              James Walkinshaw, Virginia72Elijah Crane, Arizona                Christian Menefee, Texas73Brian Jack, Georgia                  Ayanna Pressley, Massachusetts74John McGuire, Virginia               Rashida Tlaib, Michigan75Brandon Gill, Texas76Richard McCormick, Georgia7778                                 ------7980                       Mark Marin, Staff Director81                   James Rust, Deputy Staff Director82                     Ryan Giachetti, Chief Counsel83           Jennifer Kamara, Director of Strategic Initiatives84                         Hannah Cathey, Counsel85                      Bill Womack, Senior Advisor86         Mallory Cogar, Director of Operations and Chief Clerk8788                      Contact Number: 202-225-50748990                Robert Edmonson, Minority Staff Director91                      Contact Number: 202-225-505192                                 ------9394                 Subcommittee on Government Operations9596                     Pete Sessions, Texas, Chairman9798Virginia Foxx, North Carolina        Kweisi Mfume, Maryland, Ranking99Gary Palmer, Alabama                     Member100Tim Burchett, Tennessee              Eleanor Holmes Norton, District of101Brian Jack, Georgia                      Columbia102Brandon Gill, Texas                  Maxwell Frost, Florida103                                     Emily Randall, Washington104105                        C  O  N  T  E  N  T  S106107                              ----------108109                           OPENING STATEMENTS110111                                                                   Page112113Hon. Pete Sessions, U.S. Representative, Chairman................     1114115Hon. Kweisi Mfume, U.S. Representative, Ranking Member...........     3116117                               WITNESSES118119Mr. Jordan Burris, Vice President and Head of Public Sector120  Strategy, Socure121Oral Statement...................................................     7122123Ms. Marisol Cruz Cain, Director, Information Technology and124  Cybersecurity, U.S. Government Accountability Office125Oral Statement...................................................     9126127Mr. David Maimon, Head of Fraud Insights, SentiLink128Oral Statement...................................................    10129130Mr. Jay Stanley (Minority Witness), Senior Policy Analyst,131  American Civil Liberties Union132Oral Statement...................................................    12133134Written opening statements and bios are available on the U.S.135  House of Representatives Document Repository at:136  docs.house.gov.137138                           INDEX OF DOCUMENTS139140  * Statement for the Record, Better Identify Coalition;141  submitted by Rep. Sessions.142143  * Statement for the Record, Defense Credit Union Council;144  submitted by Rep. Sessions.145146  * Article, Wired, ``A DOGE Affiliate Is Now in Charge of the US147  Government ID Platform''; submitted by Rep. Randall.148149  * Article, New York Times, ``DOGE Put Critical Social Security150  Data at Risk''; submitted by Rep. Randall.151152  * Article, Washington Post, ``Musk's DOGE Agents Access153  Sensitive Personnel Data Alarming Security Officials'';154  submitted by Rep. Randall.155156  * Article, NPR, ``Trump Admin Admits Even More Ways DOGE157  Accessed Sensitive Personal Data''; submitted by Rep. Randall.158159The documents listed above are available at: docs.house.gov.160161                          ADDITIONAL DOCUMENTS162163  * Questions for the Record: Mr. Jordan Burris; submitted by164  Rep. Sessions.165166  * Questions for the Record: Ms. Marisol Cruz Cain; submitted by167  Rep. Sessions.168169  * Questions for the Record: Ms. Marisol Cruz Cain; submitted by170  Rep. Walkinshaw.171172  * Questions for the Record: Mr. David Maimon; submitted by Rep.173  Sessions.174175  * Questions for the Record: Mr. Jay Stanley; submitted by Rep.176  Frost.177178  * Questions for the Record: Mr. Jay Stanley; submitted by Rep.179  Walkinshaw.180181These documents were submitted after the hearing, and may be182  available upon request.183184                       EMERGING FRAUD THREATS AND185                      THE EVOLVING FRAUD LANDSCAPE186187                              ----------188189                        WEDNESDAY, JULY 15, 2026190191                     U.S. House of Representatives192193              Committee on Oversight and Government Reform194195                 Subcommittee on Government Operations196197                                                   Washington, D.C.198199    The Subcommittee met, pursuant to notice, at 2:03 p.m.,200Room 2154, Rayburn House Office Building, Hon. Pete Sessions,201[Chairman of the Subcommittee] presiding.202    Present: Representatives Sessions, Foxx, Palmer, Jack,203Mfume, Norton, Frost, and Randall.204    Also present: Representative Walkinshaw.205206          OPENING STATEMENT OF CHAIRMAN PETE SESSIONS207208                   REPRESENTATIVE FROM TEXAS209210    Mr. Sessions. Good afternoon, and welcome to today's211hearing on emerging threats and the evolving fraud landscape212here in the United States of America. Over the years, the213Government Operations Subcommittee, on a bipartisan basis, has214held several hearings addressing the issue of fraud, addressing215the things that the U.S. Government faces, as well as the216American people. And each time we have been talking about217fraud, how to identify it and how to prevent it. In our218discussions, we have highlighted the importance of government219agencies focusing on preventing fraud before it happens. And,220as we have heard countless times before, once the money has221gone out the door, it is hard to get back.222    This remains a very important issue in this Subcommittee,223to both the young Ranking Member and myself in this224Subcommittee, is very important. But one critical element225missing from our many conversations is what sort of fraud are226we trying to prevent? How does it really work? What really are227we doing about it? And where do we need to focus our attention228to make sure that we are going to address this properly?229    In our past discussions, we have referenced the fraudsters230in a dark room stealing Aunt Sally's Social Security number. We231have highlighted the risk posed by foreign actors applying to232multiple disaster relief programs. We have discussed elaborate233fraud rings that exploit loopholes in benefit programs in order234to receive payment for services that they should not have235received, but perhaps got the money.236    But fraud threats are changing, and they are rapidly237advancing. Identifying fraud threats specifically are booming238as fraudulent actors become smarter and gain access to tools239intended to make our life easier and their life easier through240AI. This gives them more power. It is up to us to catch up. It241is up to us to find it and to find a way that we are going to242corner the market on our side of the agenda.243    Government programs rely on identity verification to244confirm that the individual applying for benefits and services245are who they say they are. However, we have seen over the years246the platforms used for these verifications have failed to meet247the expectations.248    In March 2023, this Subcommittee held a hearing focused on249Login.gov. And the troubling findings from the General Services250Administration's Inspector General report that was released251that month told us point-blank we have a problem. In short, GSA252misled government clients about the extent to which Login.gov253met certain technical standards and expressly what they said it254would do. These standards were the backbone of what was needed255to ensure that an identity verification platform could prevent256fraud, protect the taxpayer, and give the government the257necessary information that it would need to know who they were258speaking to and what that person might be eligible for, for259benefits.260    Over the years, many changes have been made to Login.gov,261and Federal agencies have explored other public- and private-262sector solutions for digital identification verification. As we263are moving to a more digital environment where individuals may264no longer be asked to present a physical ID card, we need to265better understand what threats there are and what the fraud266landscape looks like.267    Today's fraud landscape looks different than the one that268existed when we started this investigation, and it is rapidly269evolving even today. Fraudsters from literally anywhere in the270world can now create hundreds or thousands of synthetic271identities and apply for many different government benefit272programs simultaneously. It is no longer they could; they are.273Bad actors are able to develop the use of deep fakes, mimicking274the likeness of an individual to circumvent the safeguards that275have been put in place to protect the taxpayer.276    Bad actors have made it their business to exploit277vulnerabilities in government programs. It is necessary that we278understand that they have been successful, and we need to make279sure we are developing the tools that actually allow us to see280the fraud before it occurs, not when it is out the door.281Identity verification has long been a one-time check at the282beginning of an application process, but considering the rapid283evolution of identity fraud, we should start thinking about284validating and constantly validating identity as it moves285forward.286    Fraud should not be considered the cost of doing business287because it means that someone is not getting the benefit that288they were eligible for. And if there is one overriding289principle that this Subcommittee, all of our Members agree on,290it is that the people who we have intended the benefits to go291to, they should be the ones that get it. And any diminishment292of that is considered a failure on our part also.293    In January of this year, I introduced bipartisan294legislation to combat identity fraud and theft. The Stop295Identity Fraud and Identity Theft Act aims to strengthen the296Nation's digital identity verification infrastructure and297protect individuals, businesses, and government programs from298rising identity fraud and theft. I am hoping that this299legislation is a step in the right direction. And after meeting300with our panel members, I will tell you it is a step because we301are going to learn more today in this rapidly evolving302landscape that we call fraud, along with the verification303systems that are available today.304    We have a great panel of witnesses who can shed light on305new identity fraud threats plaguing our systems, how the fraud306landscape is evolving, and what the government should be doing307and is doing to keep up with that. I look forward to a fruitful308discussion.309    And I want to personally thank our Ranking Member, Mr.310Mfume, for his continued support. Those of you who are new to311this Subcommittee will learn that both Mr. Mfume and I insist312on making sure that we work well together, that we listen to313each other, that we listen to all of our Members and allow them314to fully participate, adding thoughts and ideas, but perhaps315more importantly, to show up and listen and learn about the316landscape that is directly in front of us.317    Mr. Mfume is a very dear friend of mine. He is a man who318has a distinguished service, not just to the U.S. Congress, but319to the United States of America and to his district. And you320will soon learn, those of you who are here, that we have many321distinguished Members of this Subcommittee who are here because322they believe in not only doing their job, but also helping us323curb the appetite that fraudsters have to take advantage of our324citizens.325    With that said, I would like to now ask the gentleman if he326would engage us with any opening statement he would like to327make. The distinguished gentleman is recognized.328329        OPENING STATEMENT OF RANKING MEMBER KWEISI MFUME330331                  REPRESENTATIVE FROM MARYLAND332333    Mr. Mfume. I want to thank you, Mr. Chairman, for your kind334and clearly overly gracious set of remarks, for your335friendship, for your stewardship of this Committee [sic], and336for the ability for us on both sides of the aisle to really337delve into detail on various issues, but none more important338than this issue of fraud.339    I know I speak for all of my colleagues on my side of the340aisle when I say we welcome this hearing, as we did the341previous one. We look forward to finding answers, quite342frankly, and finding a way to get out of the situation that we343are in with respect to the level and the significance of fraud344within our government.345    So, we are here today to talk about fraud, particularly346emerging threats and solutions related to digital identity347verification. Social Security numbers and paper cards made348sense 90 years ago, long before the current age of computers349and digital technology. Programs have matured, scammers have350adopted them and found a way to get around them, and so the351government must also, I think, adapt its service delivery and352technology to prevent fraud and to better serve the American353people.354    That adaptation was exactly what the Federal Government had355in mind many years ago when it came up with the idea and then356later became the reality of something called Login.gov, which357we are all familiar with, a single secure sign-in that works358across agencies. Before Login.gov, each agency maintained its359own identity verification. Good luck with that one. It was not360just a headache for our constituents, it was also a costly361overlap in functions and a critical cyber vulnerability.362    While the GSA may have stumbled out of the gate with the363initial release, we finally reached a point, I think, where364agencies across all levels of government have a safe, secure,365and verified gateway to government services that improves the366customer service and helps our constituents across the services367and the resources that their taxes pay for.368    The turnaround in this program serves as an important369example of bipartisan congressional oversight. Where once370accusations of false promises dogged that program, Login.gov371can now effectively serve the American people. We first372learned, however, of the issues with Login.gov when the General373Services Administration Inspector General published a report374finding that several individuals at GSA had misled its agency375customers that the system could do higher levels of identity376verification than GSA itself. Those sort of things created377problems.378    Three years ago, we had a hearing exploring the issue and379sent further follow-up letters, as the Chairman indicated, and380briefings to ensure that GSA fixed the system that provided the381service that they promised their agency clients. A year after382our hearing, GSA announced it had fully implemented the383National Institute of Standards and Technology's standard and384had rolled it out to their agencies and to their partners.385Today, Login.gov has over 100 million users across more than 50386agencies and 500 applications across Federal, state, and local387government.388    Now, that does not mean that the work to ensure digital389identity verification across the entire Federal Government is390finished. I look forward, like many of you, to hearing from our391witnesses today about how we can effectively implement the next392generation of Login.gov and identity management. However, we393must carefully consider the difficulties and the pitfalls of394the new technologies and not just assume that they do not have395any.396    Innovations like digital ID can better combat fraud and397electronically safeguard identity, much more so than a 9-digit398number on a piece of paper. Digital ID sounds great. I would399not need to carry around a plastic license, just a smartphone400if I am the average American citizen with cutting-edge401technology to safeguard my personal information. The problem402is, however, that that very phone provides a new vector of403attack, and any computer is vulnerable to a cyber attack, as we404know, regardless of its level of sophistication.405    Digital ID can also limit access for people who have406trouble using technology and even for people who cannot afford407a smartphone. Sometimes, people just break their phones and408cannot take time out of their busy day to immediately go and409get a new one, so I do not think we can afford to lock people410out of government or private services because they cannot411access or afford a smartphone. Anytime the government can412revoke access to services, even for benevolent purposes, we413must find a way to protect against abuse.414    The Trump Administration's DOGE program, the Department of415Government Efficiency, which many of us thought was the416Department of Government Evil, used a key Social Security417Administration identity database to mark thousands of living418people as dead in order to exert financial hardship. A419whistleblower recently said that he planned to expand this to420millions of people. Now, do we really want to move to a system421where the government can invalidate any ID it wants to just by422sending an instruction to the phone that is in your pocket?423    I can absolutely think of places where digital ID has valid424uses for age verification and for fraud prevention, but every425place that an American taps their phone to access services426cannot be a ``bread crumb to the track'' or ``bread crumb427follow the track'' process in their daily lives.428    So, I am excited to have those of you who are here to429discuss the new technologies to prevent fraud against the430American taxpayer. We must also ensure that we keep an eye on431the horizon to prevent any sort of mass surveillance and432government surveillance that can literally decide if, in fact,433we are considered live or dead.434    So, I want to thank the Chairman again for keeping his435commitment on this issue, for Members on both sides of the436aisle that continue to plow through this. It has been a couple437of years now. We are going to continue to do what we have to do438until we cannot do it anymore. And I appreciate the opportunity439to have all of you here and hear what you have to say on the440record.441    And Mr. Chairman, I yield back to you.442    Mr. Sessions. The gentleman yields back his time. Thank you443very much.444    I would like to ask unanimous consent, if I can, to allow445the distinguished gentleman, who has a meeting that he has to446attend, to very quickly give some brief remarks.447    I would like to yield time now to the distinguished448gentleman, Chairman Gary Palmer. Chairman Palmer, you are449recognized.450    Mr. Palmer. Thank you, Mr. Chairman. Thank you for holding451this hearing, and I would like to thank the Ranking Member for452the bipartisanship that we have seen throughout this process in453trying to address the fraud and also other issues related to454improper payments.455    This is an extremely important issue. I just came out of a456meeting with Dr. Phillip Swagel, the Director of the457Congressional Budget Office, and we estimate just the initial458investigations into fraud that will have about $168 billion in459savings. I want to make certain that people understand this is460not just about the money. So much of this fraud mismanagement461occurs in programs that are designed to help people who need462help. And when we are losing that much money, we are being463defrauded of that much money, those are funds that are not464available for people who are truly in need. So, this is a huge465issue for us, and it is not limited to domestic fraud. What we466saw during the COVID pandemic, the programs at the Federal467level were being defrauded by a massive network of foreign468actors.469    But we also have other issues, aside from the fraud. I470think, one of the things that we found is that there is a471tremendous need to modernize Federal data systems, bring them472into the 21st century because a lot of the issues that we have473with improper payments are directly related to antiquated data474systems.475    So, Mr. Chairman, I really hate that I am not going to be476able to participate in this hearing. I think it is extremely477important and would have benefited greatly from hearing the478questions to our witnesses and their answers.479    With that, Mr. Chairman, again, thank you for the privilege480of being able to address the issue. I yield back.481    Mr. Sessions. The gentleman yields back his time. Thank you482very much.483    Without objection, Congressman Walkinshaw of Virginia is484waived onto the Subcommittee for the purpose of questioning the485witnesses at today's Subcommittee hearing.486    I now would like to move to welcome our witnesses who have487taken their time today to be with us, and I am very delighted488to say that I think that you will find and the Members will489find their input very valuable to exactly the same things that490the Chairman was talking about, and that is that we need to491understand what is out there today. It is easy for us to think492that we understand a lot, and we are going to learn a lot493today.494    So, I am pleased to welcome our witnesses. Mr. Jordan495Burris is Vice President and the Head of Public Sector at496Socure, where he partners with government leaders to develop497and implement private-sector solutions for identity498verification and fraud risk management.499    Next, we have Marisol Cruz Cain, who is Director of500Information Technology and Cybersecurity at the GAO. The501Government Accounting [sic] Office has experts that provide not502only expert testimony, but have an idea of the day-to-day503activities that move across the government. She oversees504Federal cybersecurity and privacy work. Her portfolio includes505emerging technologies, the National Cybersecurity Strategy, and506agency efforts to protect privacy, sensitive data, and critical507computing infrastructure.508    Next, we have David Maimon, and he is the Head of Fraud509Insights at SentiLink, a company that combines technology and510expertise to stop identity fraud at the application stage. He511is also a professor in the Department of Criminal Justice and512Criminology at Georgia State University, where he directs the513evidence-based Cybersecurity Research Group.514    Last, Mr. Jay Stanley is a senior policy analyst at the515American Civil Liberties Union. His work focuses on technology-516related privacy and civil liberties issues and that future and517how it impacts public policy.518    Thank you to each of you for joining us. I would now ask519that each of you rise in pursuant to Committee Rule 9(g). The520witnesses will each, as they stand, to take the--you can all521stand please--to take the oath to the witnesses, and I would522ask that you please raise your right hand.523    I will read this and then let you affirm or choose as you524would do.525    Do you solemnly swear or affirm that the testimony that you526are about to give is the truth, the whole truth, and nothing527but the truth, so help you, God? That is a question.528    Mr. Burris. I do.529    Ms. Cruz Cain. I do.530    Mr. Maimon. I do.531    Mr. Stanley. I do.532    Mr. Sessions. Please let the record reflect that the533witnesses have answered in the affirmative. Thank you very534much. You may all take your seat.535    I have had an opportunity to speak with each of you,536hopefully, except Mr. Stanley. Mr. Stanley, I want you to know537that I have advised the other witnesses here that we appreciate538you being here as we do them, that I run the Committee [sic]539hearings differently. I would like for you to be able to finish540your sentence. I would like for you to be able to complete your541thought. I would like for you to be able to thoughtfully542respond and provide this Subcommittee with the things which you543have come professionally to do to us.544    At 5 minutes, I am not going to bang the gavel. You are545here. You are a professional. We need to hear from you, and I546try and give that same type of leverage to each of our Members.547So, I am delighted. But with that said, if you do not take548advantage of it, I will not either. We have an idea that we are549trying to move our business and allow our Members an550opportunity to come and do their business also.551    So, we will now move forward with the feedback from our552witnesses, and we will first move to the distinguished553gentleman, Mr. Burris. Mr. Burris, you are recognized for 5554minutes.555556                 STATEMENT OF MR. JORDAN BURRIS557558       VICE PRESIDENT AND HEAD OF PUBLIC SECTOR STRATEGY559560                             SOCURE561562    Mr. Burris. Chairman Sessions, Ranking Member Mfume, and563Members of the Subcommittee, thank you for your leadership on564this critical topic and for the opportunity to be back here to565be part of the conversation.566    For the last 15 years, I have worked on one question from567inside and outside the government. How do we know with568confidence that the person on the other side of a digital569transaction is who they claim to be? Today, that question has570become far more difficult to answer. And here is the blunt571truth. The way the Federal Government verifies identity was572designed for a threat that no longer exists. Every day,573however, we defend that old model as though it still does and574give fraud networks another opportunity to steal taxpayer575dollars and undermine public trust.576    GAO estimates Federal fraud losses at as high as $521577billion every year. Further, the pandemic exposed just how far578our identity infrastructure has fallen behind. Those losses579were a warning. Today, the gap has widened dramatically, and by580the time we update the next set of estimates, it will be double581or triple the size.582    My name is Jordan Burris, and I lead the public sector583business at Socure. Socure was founded on a simple premise. In584a digital world, proving who someone is should be accurate,585fast, and fair. Today, our AI native identity and fraud586intelligence platform helps more than 3,000 organizations587globally, including over 150 public sector organizations, make588trusted identity decisions. That broad view allows us to see589how fraud evolves across the economy and increasingly targets590the government.591    Before joining Socure, I served as Chief of Staff in the592White House Office of the Federal Chief Information Officer,593helping shape Federal identity policy through the COVID594response and the government's transition to zero trust after595SolarWinds. Working inside the government and in the private596sector has shown me just how rapidly this threat has evolved.597    Some of the identity industry have begun calling this598moment World War Fraud, and I understand why. We are no longer599confronting isolated fraudsters. We are facing organized,600increasingly sophisticated, transnational fraud rings using AI601at industrial scale. One fraud ring we profiled created nearly60225,000 synthetic identities and launched more than 35,000603attacks in just 30 days.604    The adversary has changed. Our Federal identity model,605however, has not, and yet many in the government believe it606will hold up to today or even tomorrow's fraud threat. For607decades, the government has treated matching a name, date of608birth, and Social Security number validated against government609authoritative records as proof of identity. That approach is no610longer sufficient. Further, fraud does not stop at enrollment,611and identity verification cannot either. It must become a612continuous discipline that evaluates risk throughout the613lifecycle of an account.614    From where I sit, identity should be considered critical615infrastructure. Nearly every interaction Americans have with616their government--benefits, tax administration, disaster617relief, veteran services, and healthcare--depends on getting618this decision right. Done correctly, better security means619better access. It makes it easier to say yes to legitimate620Americans and no to industrialized fraud rings.621    This year, Socure supported the Department of Education in622deploying real-time risk-based identity screening in the Free623Application for Federal Student Aid (FAFSA) process, protecting624more than $1 billion in taxpayer funds, while allowing over 92625percent of legitimate applicants to pass automatically. That is626the model the government should continue pursuing. Prevention627before payment, risk-based rather than one-size-fits-all,628continuous rather than point-in-time, and outcomes rather than629checklists.630    To make this the Federal model, I would leave the Committee631with five recommendations. First, measure outcomes, not632compliance, requiring systems to prove that they can stop the633changing fraud threat.634    Second, make continuous identity verification the standard635across the lifecycle of an account.636    Third, expand secure data sharing where we know it works,637through trusted resources like Do Not Pay and other cross-638government solutions.639    Fourth, reward fraud prevention instead of recovery, where640agencies are incentivized to stop fraud before taxpayer dollars641ever leave the Treasury.642    And finally, treat identity verification as dynamic643infrastructure that must be resourced to evolve continuously,644not built once, certified once, and left in place for a decade.645    To be clear, Congress does not need to prescribe a specific646technology, but Congress can establish a new expectation. The647technology exists, and the evidence is clear. Now, our policies648and practices must catch up to the threat, so Americans can649trust their government in the AI era.650    Thank you, and I look forward to your questions.651    Mr. Sessions. Mr. Burris, thank you very much.652    We now move to the gentlewoman, Ms. Cain. Ms. Cain, you are653recognized for 5 minutes.654655               STATEMENT OF MS. MARISOL CRUZ CAIN656657                            DIRECTOR658659            INFORMATION TECHNOLOGY AND CYBERSECURITY660661             U.S. GOVERNMENT ACCOUNTABILITY OFFICE662663    Ms. Cruz Cain. Chairman Sessions, Ranking Member Mfume, and664Members of the Subcommittee, thank you for inviting GAO to665contribute to this important discussion on identity-related666fraud threats and Federal efforts to improve identity667verification processes.668    As you know, Federal agencies use personally identifiable669information to verify the identity of individuals who access670accounts on government websites. An increase in sophisticated671cyber-attacks has led to a greater risk of that Personally672identifiable information (PII) being stolen and used to commit673different types of fraud. Malicious actors can then use that674information to fraudulently receive government benefits, commit675tax- or wage-related fraud, or create new credit cards or take676over people's accounts. These attacks can harm individuals,677result in financial loss, or damage the reputation of Federal678agencies and financial institutions.679    Because of this, GAO has long emphasized the urgent need680for the Federal Government to improve its ability to protect681against these cyber-attacks. Today, I will focus on issues682related to identity-related fraud threats. I will also discuss683the recent actions that GSA has taken to improve Login.gov's684identity verification services and alignment with Federal685guidelines.686    Fraud has been a longstanding issue within the Federal687Government. One particular type is identity-related fraud,688which can include thieves opening new accounts in someone689else's name or stealing PII to obtain government benefits. For690example, we have reported that hundreds of billions of dollars691were lost to the--in the pandemic to potentially fraudulent692payments.693    The harms caused by breaches of PII or identity theft can694extend beyond tangible financial loss to include lost time,695such as when those victims spend months or years even working696to restore their identities. Additionally, there can be697reputational harm or emotional distress.698    To address these issues, GSA developed Login.gov as a means699to verify users' identities who want to create an account to700access Federal websites. Accordingly, GSA has a significant701responsibility for protecting users' PII that they collect702during that process. In 2024 and 2025, we reported on703Login.gov's process for identity verification, its misalignment704with Federal guidelines for identity verification, and fraud705prevention measures.706    In our reports, we identified several weaknesses in GSA's707implementation of Login.gov, including that the system did not708meet the requirements to verify a person at the ILA-2 level,709and that was because the system never included a physical or710biometric comparison to link a user to a specific real-life711identity. As a result, we recommended that GSA take four712actions to ensure that the PII is better protected and to713lessen the risk of identity theft. To its credit, GSA has fully714implemented three of those actions. Most importantly, they have715completed their remote identity proofing pilot, ensuring that716the system is compliant with National Institute of Standards717and Technology (NIST)'s ILA-2 standards. However, GSA has not718taken important steps to collaborate with agencies to address719Login.gov's technical challenges.720    GSA has developed a roadmap that outlines planned and721ongoing efforts to improve its system functionality. However,722this action alone does not fully address all of the technical723challenges that we identified in our report. For instance,724agencies reported that they lacked visibility into725authentications, that the system had a high failure rate, and726also, it lacked fraud controls. GSA's roadmap did not contain727efforts directly aimed at addressing these challenges. It is728important for GSA to work with agencies to solve these issues,729as doing so will help ensure that Login.gov delivers the730functionality agencies need to effectively verify users'731identities while also combating fraud threats.732    In summary, identity-related fraud threats are pervasive733and likely to continue to escalate. Protecting individuals' PII734is critical, as the harms can be significant. GSA has taken735several actions to improve Login.gov, but needs to continue to736address fraud and technical challenges.737    This concludes my remarks, and I look forward to answering738any questions you may have. Thank you.739    Mr. Sessions. Ms. Cruz, thank you very much.740    Dr. Maimon, you are now recognized.741742                 STATEMENT OF MR. DAVID MAIMON743744                     HEAD OF FRAUD INSIGHTS745746                           SENTILINK747748    Mr. Maimon. Chairman Sessions, Ranking Member Mfume, and749Members of the Subcommittee, thank you so much for the750opportunity to testify today.751    I serve as Head of Fraud Insight at SentiLink and as a752professor of criminal justice and criminology at Georgia State753University. For nearly two decades, I have studied cybercrime754by going where it happens, into darknet markets, telegram755channels, and encrypted platforms where fraudsters buy, sell,756and teach each other how to steal from government programs. I757also go into the field myself, to the mail drops, virtual758offices, and shell addresses these operations use to look759legitimate. My testimony today is based on that firsthand work.760    The central lesson from my research is this: Fraud against761government programs is no longer a series of isolated schemes.762It is a durable, specialized criminal infrastructure, and it763moves. The pandemic did not create this infrastructure, but it764supercharged it. Criminals learned how to acquire stolen and765synthetic identities, stand up shell companies, open bank766accounts, and recruit money mules at scale. When pandemic767relief programs ended, none of that capacity disappeared. It768simply migrated.769    Today, my team is tracking that same infrastructure inside770Supplemental Nutrition Assistance Program (SNAP), Medicare,771Medicaid, Federal student aid, tax refunds, and Small Business772Administration (SBA)-backed loans. A few examples illustrate773how. We are watching criminals combine stolen identities with774AI-generated faces and deepfake video to defeat liveness checks775at digital banks and tax preparers using nothing more exotic776than face swapping software available to anyone. We are777watching an Electronic Benefits Transfer (EBT) fraud market778where one criminal steals card data, a separate paid service779verifies the balance before the card is even used, and the780third actor cashes it out. And my own field investigation of a781Florida durable medical equipment company, whose office I found782abandoned in Delray Beach, is now tied to a Department of783Justice case alleging $3.76 billion in fraudulent Medicare and784Medicaid claims.785    Different programs, different agencies, same playbook--the786same stolen identity, the same shell company, the same bank787account, reused across systems that rarely talk to each other.788Debt fragmentation is the vulnerability. Criminals exploit the789seams between agencies precisely because our defenses are built790program by program, while their infrastructure is built to move791across all of them.792    Given my time today, I want to leave the Subcommittee with793four priorities. First, replace self-attestation with verified794data wherever the risk is high. Too many programs still take795applicants at their word on income, identity, or eligibility.796That was the single biggest vulnerability exploited during the797pandemic, and it remains one today.798    Second, expand real-time cross-agency data matching. The799same identity that files a fraudulent tax return can apply for800a SNAP benefit the same week. Agencies that only compare notes801and periodic bet runs weeks after the money is gone cannot see802that pattern. They need to see it before disbursement, not803after.804    Third, strengthen prepayment screening and move toward805risk-based disbursement. Built on the model of Treasury's Do806Not Pay system, but expand its authority and its reach so that807suspicious payments are held before they leave the government,808rather than chased afterward through recovery audits that809criminals have already outrun.810    Fourth, give agencies the flexibility to adopt smarter811tools and keep it current. Much of today's verification812infrastructure and the policies behind them were built for an813earlier threat. And procurement and rulemaking cycles that take814years cannot keep pace with fraud tactics that shift in months815or less. Agencies need standing authority to test and deploy816technologies to meet the current threats, not just at the next817scheduled audit. None of this requires slowing down help for818legitimate applicants. It requires distinguishing them from819fraud earlier, using signals criminals cannot easily fabricate.820    The Federal Government already has some of the tools it821needs, what is missing is the authority, the coordination, and822the sustained investment to use those tools before the money823moves, not after. Every dollar we protect from organized fraud824is a dollar that stays available for the people Congress825intended to help.826    Thank you, and I look forward to your questions.827    Mr. Sessions. Dr. Maimon, thank you very much.828    Mr. Stanley, welcome. We are delighted that you are with829us. The gentleman is recognized.830831        STATEMENT OF MR. JAY STANLEY (MINORITY WITNESS)832833                     SENIOR POLICY ANALYST834835                 AMERICAN CIVIL LIBERTIES UNION836837    Mr. Stanley. Thank you so much. Chairman Sessions, Ranking838Member Mfume, and Members of the Subcommittee, thank you for839inviting me to testify today, and thank you for your attention840to the subject of digital identification, which I do not think841has received the attention it deserves.842    I hope to leave you with three overarching points today.843First, a digital ID system would be a disaster for individual844liberties if it is not done right. If any such system is to845become standardized, it must be built with great care and846awareness of big potential downsides. We have to ensure America847does not become a checkpoint society and that digital IDs do848not become virtual ankle monitors, something that tracks us,849but we cannot turn off or escape.850    Second, the digital ID system that is most likely to become851dominant, mobile driver's licenses or MDLs issued by the852states, is not being done right. Driver's licenses are already853in most Americans' wallets and are by far the most likely form854of digital ID to become standard. Login.gov itself is moving855toward relying on them.856    Third, there are much better alternatives if we just do it857right.858    So, let me start by explaining my first two points, that859digital IDs have the potential to be a disaster if they are not860done right, and that they are not being done right today. One861big problem is that once this infrastructure is built, we start862getting identity requests from every direction. Want to enter a8637-Eleven? Scan your ID. Want to buy a cup of coffee, park your864car? Tap here, please. Want to watch a video, log into social865media, look at a news site, shopping site? Click here to send866us your driver's license.867    There is already far too much tracking that takes place868online, and polls show Americans are very uncomfortable with869it. But there has been a steady pushback, and that tracking has870been getting harder for companies in some ways. A digital ID871could lock it down and make it inescapable. You cannot just run872to the Department of Motor Vehicles (DMV) and get a new873identity the way you can get a new username and password.874    Those pushing MDLs in the states have done nothing to875counter this easily predictable side effect. We may create a876digital ID to solve government fraud or identity theft or other877problems, but there is a horde of others waiting in the shadows878who will instantly pounce on this infrastructure to use it for879their own purposes once it is created. The result will be a880checkpoint society of constant ID proofing. With a digital ID881that will be really easy. Just tap, click, or scan.882    And a digital ID system, if not built carefully, could send883a report back to the government every time you show your ID, a884record of every beer purchase, bank, and doctor's office visit,885and online, every website you visit. This is called ``phone886home.'' This capability was built into the MDL standard as an887option.888    There is also the issue of accessibility. If digital IDs889become mandatory, either legally or as a practical matter, that890would harm the surprisingly large number of people who do not891have a smartphone, about one in ten people in the United States892according to studies, including over 1/5 of people over age 65.893Some may lack the resources to afford one; others, the894technological literacy to use them. That is why offline options895for doing business are vital to protect. If we do not make sure896that digital IDs are an empowering option for people rather897than an imprisoning requirement, then people without898smartphones will be shut out of many necessary functions of899life and often benefits that they sorely need. So, these are900easily foreseeable, predictable consequences of a digital ID.901    But that brings me to my third point. If a digital ID is to902be created, there are alternative paths that would prevent many903of these harms. In terms of alternatives, I have two quick904points to make before I stop.905    First, the field of privacy-enhancing cryptography is906advancing fast and already can do amazing things that allow us907to have our cake and eat it too when it comes to privacy and908security. One example is privacy-enhancing technology called909zero-knowledge proofs. Using that kind of tech, digital IDs can910let me prove I am over 21 without sharing my date of birth or911my identity. And it can do that in a way that if I prove my age912multiple times to the same seller, they do not even know that I913am the same person. That is the kind of thing that is needed to914stop IDs from being this kind of ankle bracelet tracker.915    But that kind of technology is useless if we do not bother916to build it in, and it has not been built into the MDL917standard. If a system can reduce fraud and provide other918benefits without enabling tracking, why would we build one that919does enable tracking? There are other key protections we can920build. On our website, we have outlined 12 key protections that921we think are necessary in a digital ID system. There is more922about that in my written testimony.923    And then, second, there are some states that are moving in924the right direction here. Some, like New Jersey and Illinois,925have put some important protections in place into their digital926ID-enabling legislation. And the State of Utah is the most927notable. It has set out a separate path, which they call State928Endorsed Digital Identity, or SEDI, that is emerging as a far929more privacy-protective alternative to the MDLs that many930states have adopted. Some other states are starting to work931with Utah to join in that effort and build that alternative932path.933    The bottom line is if we build a digital ID system, it must934be done right. We urge Congress to ensure that it is. American935freedom is the top priority.936    Thank you very much, and I look forward to your questions.937    Mr. Sessions. Mr. Stanley, thank you very much. I938appreciate each of the witnesses being here.939    I would like to move first to the distinguished gentleman,940Mr. Jack, for his questions. The gentleman is recognized.941    Mr. Jack. Thank you very much, Mr. Chairman.942    And I appreciate your testimony this morning, Mr. Burris.943My first question is for you. The public increasingly relies on944the internet to access government services, and I am just945curious, from your perspective, what fraud threats might my946constituents be facing that they are not even aware of yet?947    Mr. Burris. Representative, thank you for the question.948When it comes to the fraud threats and the way that they are949evolving across the landscape, every single interaction, every950single time that an individual is engaging both with their951government and in their commercial life, there is the chance,952the opportunity, that an adversary could be attempting to pose953as them, could be attempting to enroll in an account. We see954this across financial services where we work. We see this955across various aspects of the gig economy where we work, and956then, of course, with government organizations.957    The reality here is that all of the information, all the958PII that exists for many folks within this room has been stolen959by the adversary, and they are using that to attempt to become960them, and therefore, that they can access what would be either961their bank accounts and help move money all across the economy.962    Mr. Jack. You know, I have heard folks mention anecdotally963that now with artificial intelligence, people are trying to964impersonate, you know, a loved one by virtue of maybe their965voice or their mannerisms, what have you, and using some of966that information that may have been stolen. Have you seen that,967and could you elaborate on that for us?968    Mr. Burris. Yes, absolutely. We are in a, what I would969consider, a national crisis from where I have said, I have970highlighted and our team has highlighted--Socure--for a number971of years now that the moment that we are in is unlike any other972in the sense that AI is being used as an accelerator for what973attacks that typically would take weeks to occur. And further,974it is also becoming more cost-effective for the adversary to975launch those attacks. So, these attacks could be everything976from launching deepfakes, things where we have seen an 8,000977percent increase year over year.978    This can also be in terms of the velocity by which attacks979are happening. This means the speed by which they are980occurring. And in these instances, these moments, we are seeing981things that--where attacks used to take weeks in order to be982conducted, they have been broken down to under 48 hours. And983this would mean that an adversary has launched an attack where984they have stolen my information or yours, or even worse,985fabricated an identity, attempted to open an account and/or986move money, take over an account that may have existed because987they went through a call center and were pretending to be you988using your voice or something that was cloned, an image of989yours, a biometric, et cetera, and they have used all these990patterns. And if, like, for, say, they were blocked in some991way, shape, or form, they then just adapt and iterate, and the992cycle continues all over again.993    Mr. Jack. Thank you very much.994    Dr. Maimon, do I understand, are you a professor at Georgia995State University? So, I wanted to acknowledge, first and996foremost, both my mother and father went to Georgia State997University. I represent many people who have degrees from998Georgia State University, and I also host Panthers in the999district from time to time, so bringing students up here.1000    So, I am curious, to build off that last question, you1001obviously understand, you know, criminology, you are a1002professor of it. Help us understand, are most of these threats1003coming from inside our country, or are we starting to see1004foreign adversaries exploit some of this data to, you know,1005fraudulently impact some of our constituents?1006    Mr. Maimon. Thank you so much for the question, really1007appreciate it. A lot is coming from abroad. We have a lot going1008on internally as well. It really depends on the type of fraud1009we are looking at. In the context of the type of fraud you just1010mentioned, with folks engaging in online romance fraud, we are1011seeing a lot coming from places like South Asia. A lot is1012moving right now to Africa. In some of the online fraud markets1013that I infiltrate, I spend a lot of time sort of trying to1014infiltrate Yahoo Boys channels, as well as Sakawa Boys1015channels, where I actually see them using those deepfakes to1016swap faces while engaging with some of the victims here in the1017United States.1018    It is heartbreaking to see the level of conversations that1019these guys are able to get with those targets, and it is also1020heartbreaking to see the different modus operandi and different1021types of buckets that those criminals are engaging. I can tell1022you that, as of this morning, we are seeing more and more Yahoo1023Boys and Sakawa Boys targeting our 401(k)s, victims' 401(k)s.1024So, you know, we are seeing them convincing targets to borrow1025against the 401(k)s, as well as hand over control completely on1026the 401(k) accounts. So, this is what we are up against. We are1027seeing those deepfakes being used to swap faces, lure targets1028to give away access to the 401(k) accounts, and then,1029unfortunately, victims funnel the money to bank accounts that1030the criminals create, along with the targets, and then the1031money leaves the country.1032    So, it depends on the type of fraud. The type of fraud that1033you are referring to definitely comes more from abroad.1034    Mr. Jack. I appreciate all of your testimony today, and,1035Mr. Chairman, I am grateful you convened this hearing. I have1036learned a lot already in just this interchange, so thank you1037very much. Mr. Chairman, I yield the remainder of my time.1038    Mr. Sessions. The gentleman yields back his time. Thank you1039very much.1040    The distinguished gentleman, Mr. Mfume, you are now1041recognized.1042    Mr. Mfume. Thank you, Mr. Chairman.1043    Mr. Burris, I want to start with you because something you1044said struck me, and it might be the basis of why we are here1045and why we want to come back this way again, and that was that1046you said, if I am paraphrasing you correctly, that we are1047spending years and millions of dollars preparing for a threat1048that does not continue to exist. Can you expand on that,1049please?1050    Mr. Burris. Absolutely. And in particular, the part of my1051testimony that I was highlighting was the fact that much of how1052the Federal Government has thought about its standards for how1053to prevent or protect digital identity--and to be very clear,1054digital identity is the makeup of how we present ourselves in1055cyberspace, right? Much of how the government has designed that1056standard today effectively was worked about a decade ago. And1057so, if we are looking at today's fraud threat, how it has1058evolved, how the adversary moves, it no longer can keep pace1059with what we are seeing today.1060    So much so one of the efforts that, you know, our company1061led was, as we were engaging with NIST as part of their most1062recent update to the standard, was highlighting that fraud1063should become an underpinning of part of what we evaluate in1064digital identity and when it is established. Not because we1065want it to be harder for people to prove who they are, but1066because the alternative is that we are leaving a floodgate open1067for nation-states to launch their attacks. And from where we1068see it today, you know, there are over 7,500 fraud rings that1069are operating in their own different ways to attempt to attack1070what would be government services or even the commercial1071sector.1072    Mr. Mfume. And Mr. Burris, as artificial intelligence1073advances at an alarming rate, what does the government, and in1074particular, what does Login.gov need to do to stay ahead of1075those scammers and to be able to identify them as we move1076forward?1077    Mr. Burris. It all starts with admitting that there is a1078problem, so we are going to begin there and say that this is a1079crisis moment for where we are in. I think it is important that1080we understand that, as the Federal Government, we need to1081basically embrace and understand that we need to use AI to1082fight AI at this point. The adversary does not care about how1083anything is constructed, they do not care about our norms, they1084do not care about rules and regulations, they do not care about1085the ages of those who they are engaging with or their political1086affiliation. What they are attempting to do is to take money1087and resources to disrupt what would be the status, the norms,1088that we hold dear. And what we need to do is engage1089aggressively to basically put in place the types of controls1090and measures, many of which have been adopted in other sectors1091for years, in order to help prevent against this threat.1092    For Login.gov in particular, I would say, and, you know,1093full disclosure, again, we are one of the vendors that are now1094have been added in order to power what Login.gov is doing. They1095are taking this threat absolutely seriously. In this day and1096age, another fraud team has engaged diligently to understand1097what needs to evolve with the program.1098    Mr. Mfume. And Ms. Cruz Cain, you mentioned at some point1099in your testimony, I am trying to get back to it here, where1100GSA implemented four or five recommendations. What was the1101fifth recommendation? Is that still standing?1102    Ms. Cruz Cain. We made four. They implemented three. And1103the last one was the agencies, the 24 Chief Financial Officers1104(CFO) Act agencies that we talked to, had technical challenges1105with Login.gov. So, as users, they were not necessarily able to1106use with ease, and they had some issues with the platform, such1107as they would like to know when the users are verified and1108authenticated, why they were not. So, if they fail, the person1109just says, hey, I failed. They have no way of knowing why they1110failed, how they can remedy that, so then you just do not have1111access to your government account so you cannot get your1112benefit. You have no recourse of knowing how that happens. So,1113either you just have to try again, or you have to go to the1114post office. That was one of the issues.1115    Another issue is, at the time, they had a high failure1116rate, so they were just getting problems of even logging into1117the system or being able to use it. And at that time, they were1118not having such strong fraud controls. And again, to their1119credit, they have been taking the issue very seriously and1120partnering with new technologies and new companies to enhance1121their fraud controls. But they need to partner with the users1122to make sure that they are also helping them with the issues1123that they are having with Login.gov because if the users cannot1124use it--the technologies can be great, but if your users are1125still having issues using the system, you are going to lose1126that user base.1127    Mr. Mfume. Thank you very much. Just one other quick1128question. Mr. Stanley, I appreciated your description of a1129digital ankle bracelet or ankle monitor, and you referenced1130driver IDs. Are they the most vulnerable?1131    Mr. Stanley. I think that, in many ways, cryptographically1132secured----1133    Mr. Mfume. Driver's licenses.1134    Mr. Stanley [continuing]. Digital driver's licenses----1135    Mr. Mfume. Are they less vulnerable?1136    Mr. Stanley [continuing]. Are less vulnerable, probably,1137than many other techniques for validating identity. Mr. Burris1138talked about use AI to fight AI. There are many technologists1139who say that that is a losing battle, and that you will never--1140it will always be a constant arms race because any AI that can1141be used to identify who is real versus who is not, that same AI1142can be used to fake somebody who is not real. And so that is1143why a lot of people in the technology world are turning to1144cryptographically secured tokens or identities so that,1145basically, the DMV or other issuer takes the data in your1146driver's license, digitally signs it with encryption, with a1147secret key, and then publishes a public key, and a verifier can1148look at the public key, and if it matches, it could only have1149been signed by the DMV and not a single bit could have been1150changed.1151    And that is cryptography. And so, somebody can prove that1152the thing they have in their phone, the file they have in their1153phone, was issued by the DMV and signed by the DMV. And that is1154one of the reasons why we think that digital driver's licenses1155are poised to move to the forefront in online verification and1156why we worry about all the side effects of that kind of a1157system that I talked about.1158    Mr. Mfume. Thank you. Thank you very much.1159    I yield back, Mr. Chairman.1160    Mr. Sessions. The gentleman yields back his time.1161    Ms. Norton, you are now recognized.1162    Ms. Norton. Thank you.1163    Digital identification and modernized technology systems1164can help verify identities and reduce fraudulent claims, but1165they should not come at the expense or access to vital social1166safety net programs. Mr. Stanley, as more Federal, state, and1167local governments adopt digital identification systems, who1168risks getting left behind?1169    Mr. Stanley. Yes, so exclusion is a big potential side1170effect of this kind of a system, and we will need to ensure1171that a digital identity is not mandatory, and we will need to1172pay the costs of ensuring that there are other options, lest we1173dial up the security dial too high and leave a lot of people1174who have genuine needs and are genuinely qualified for benefits1175being locked out.1176    We know, in addition to what I said, about 20 percent of1177people over age 65 and ten percent of Americans not having1178smartphones. Studies have found that people with disabilities1179are 20 percent less likely to have smartphones. People with1180incomes under $30,000 a year, 25 percent do not have1181smartphones. Thirty percent of rural Americans lack fixed1182broadband and good internet access, and many people with low1183incomes are on limited data plans.1184    And so, basically, we need to ensure that we never assume.1185And a lot of these things will improve over time. Some of these1186studies are a few years old and probably are out of date1187already, but we are never going to get to the point and we1188should never make policy based on an assumption of 100 percent1189adoption of technology because there will always be people who1190cannot or will not or simply do not want to and should have the1191freedom not to use all these advanced technological systems.1192So, I hope that answers your question, Congresswoman Norton.1193    Ms. Norton. Mr. Stanley, which populations are most likely1194not own smartphones?1195    Mr. Stanley. Sorry, the populations most likely not to own1196smartphones?1197    Ms. Norton. Yes.1198    Mr. Stanley. Yes, it is again, older Americans and low-1199income Americans, disabled Americans. Low-income Americans, of1200course, are disproportionately people of color, and so I think1201those are the populations that would be most affected. People1202who are--often already face a lot of marginalization in life1203may find themselves further locked out of paths toward fully1204living in our society.1205    Ms. Norton. Well, Mr. Stanley, given the increased adoption1206of digital identification, are people without smartphones at1207risk of reduced access to government services?1208    Mr. Stanley. Well, yes. What we see is that something--a1209technology like a digital ID tends to move over time from being1210an option that empowers people, to being expected, to becoming1211normalized, and then people who do not have it end up as freaks1212and edge cases that just are not accounted for by the systems1213that run our governments, our benefits, and many private-sector1214goods as well. And so, because often it is expensive to1215maintain offline, real-world options for people, but it is1216important that a digital identity system do remain an option.1217There are post offices in every town in America where people1218can do things in person. There are other offline ways of doing1219things, and we need to make a conscious policy decision to1220protect those ways, those alternatives, to protect American1221freedom and to protect people who are vulnerable and need the1222benefits that they are qualified for.1223    Ms. Norton. Even for those who do own smartphones, a lost,1224stolen, damaged, or nonfunctioning device could temporarily1225prevent them from accessing the programs they rely on. While we1226should embrace new technology to minimize fraud, we must ensure1227all Americans have access to programs.1228    I yield back.1229    Mr. Sessions. The gentlewoman yields back her time. Thank1230you very much.1231    I now recognize myself for a UC, unanimous consent request.1232I would like to enter into the record two letters that have1233been provided to the Committee, both Mr. Mfume and myself. The1234first is a letter from the Better Identity Coalition. They1235highlight how digital identity credentials like mobile driver's1236licenses and investments in digital identity infrastructure1237could help address this emerging fraud threat that we are1238talking about.1239    Second, the second letter is from the Defense Credit Union1240Council. It reinforces how critical it is to protect the1241Nation's military and veteran communities against scammers who1242specifically look to exploit vulnerabilities created by their1243life in the military and to take advantage of that. So, without1244objection, so ordered.1245    Thank you very much.1246    It is intuitively obvious to each of us that my side, the1247Republican side, the Majority side, does not have many Members1248here. We are in the middle of receiving a briefing on the1249conflict in the Middle East at this time by the Administration,1250and so I have chosen not to cancel this hearing but rather to1251stay myself, and so I may take the place of some of my Members,1252so I would yield myself my time right now.1253    Mr. Stanley, thank you for being here. Mr. Stanley, I would1254like to ask a question that really came to me today, and I find1255very interesting, not only your comments, that I find common1256sense and I find myself--I would have to struggle with myself1257to disagree with you. But it brought up one issue, and that is1258we generally see fraud as an overwhelming factor that we need1259to defeat, that when fraud is involved--and fraud could be1260something that then becomes tangible where it has been1261established, necessarily established as opposed to questioned1262to establish whether it is fraud.1263    Where fraud is involved, are there limitations on behalf of1264the government to satisfy the requirement of protecting1265themselves? And the for-instance I would like to give is, at an1266airport that I go to every week called Reagan Airport, there is1267a sign from the government that says if you are in this area,1268you are subject completely to search and seizure. In other1269words, we can do, by and large within some balance, what we1270want to do, to ask you, to demand you to comply with our orders1271and those things. Is there a point at which we should be1272careful once we know fraud is involved? And I can give you1273probably several instances, but I want to ask that question to1274you.1275    Mr. Stanley. Mr. Chairman, I am not sure I totally1276understand the question. My apologies.1277    Mr. Sessions. Okay. So, I will try and help it out. When we1278think that we have established the standard of fraud by a1279government agency, and they then are saying, we are dealing1280with fraud, is there a limit to how far they can go within1281reason but to establish something? For instance, could they1282pick up the phone and call a bank, ``know your customer,'' and1283a bank would have an idea that they are involved.1284    And we are trying to move a lot of these issues to1285professionals in law enforcement and professional otherwise.1286Could they call a bank and say, can you please tell me, I have1287got a customer that lives at 1515 Smith Avenue, and this is1288their name, and they tell me they are 68 years old, and they1289told me that they do this, and this, and this. Is that okay?1290Because they have established fraud, and they are trying to1291then run it down. What are the limits? What is the expectation1292that you have?1293    Because you have mentioned civil liberties a few times, and1294I respect that, but we are talking about fraud, and we are1295talking about how would you expect the government--are there1296parameters? The government can only go so far? Are we going to1297give the criminals that upper hand? So, that is the question,1298sir.1299    Mr. Stanley. Okay. Yes. So, if you are talking about1300investigating fraud that you have evidence it has already1301happened, I think that it would become a criminal investigation1302like any other, and that has been--that is subject to the1303Constitution, the limits of the Constitution, you know,1304presumption of innocence, and the Fourth Amendment to the1305Constitution prohibiting unreasonable searches and seizures,1306and other provisions of the Constitution that have been well1307litigated over the years. So, I would think that a professional1308law enforcement officer would know what those limits are in1309many ways. And whether----1310    Mr. Sessions. Have you had a chance, Mr. Stanley, to look1311at the piece of legislation that was passed by this Committee a1312few weeks ago that is waiting for floor arrival that would take1313these options and move them to the Inspector General (IG) in1314the Treasury Department in a specialized unit that are law1315enforcement-type people? Have you looked at that?1316    Mr. Stanley. I confess that I have not. I would be happy to1317and get back to the Committee with our views on it.1318    Mr. Sessions. If you could do that, I am interested in your1319feedback because we are trying to say that we believe once a1320standard of fraud has been established, that there needs to be1321specialized, sure, but the ability that investigators have to1322go and vet this, we just have to find a way. Is it truthful?1323How widespread is this? And how are we going to handle this?1324    Okay. I am going to ask you another question. Got 5 seconds1325left, but we are kind of being a little careful. We are not as1326tight on this. The second one is, is there a limitation on1327someone if they are presently on Social Security, they have1328taken out a loan, SBA, something where they are in the1329government system and we find some instances where there might1330be questions that arise? And I know once again, you are very1331careful, and I agree with that, within the law, within the Bill1332of Rights, within the Constitution, within all the things that1333we could establish. Is it fair game to go back and run people1334back through if they think there is something that might be1335amiss through this organization, even though a person has been1336on government benefits? Because, you see, we think that a lot1337of people that presently are receiving government benefits1338might not be exactly as we thought they were. Is that fair1339game?1340    Mr. Stanley. I think it is with some cautions. I think if a1341government agency sees signs of fraud, there is no reason why1342it should not----1343    Mr. Sessions. Right, that has to be established.1344    Mr. Stanley. There are cautions, especially if you are1345looking at, for example, using AI algorithms in order to do1346that, that may have been trained on sets of preexisting data1347that contain biases. There was a man--there was an NBC report,1348which I could share with the Committee about it, who paid his1349credit card off every month in full, and he got a letter from1350his credit card and they said we are reducing your credit1351limit. And he said, why, I pay off in full? They said because1352we have found that the other store--other customers at some of1353the stores you shop at have been bad credit. And I think that1354that strikes most people as just unfair and guilt by1355association.1356    Mr. Sessions. That would be a smell test.1357    Mr. Stanley. But I think that a lot of AI algorithms do1358basically the same thing in a hidden way.1359    Mr. Sessions. How about if AI discovered that there are 741360people at your home address that receive benefits because AI1361discovered it, and we think that you might be one of them, and1362we would like to do some sort of a review about this? Is that1363fair game?1364    Mr. Stanley. I think that there are good uses of AI and1365that flagging that kind of anomaly, as long as there is human1366review, might make sense. But, for example--for examples like1367that, there are other examples where we see, unfortunately,1368government agencies not building in the checks and balances,1369the due process, and using AI not only to figure out who it1370thinks is suspicion, but then to take actions against people1371that they have trouble, you know, getting due process and1372fighting back. We have seen, for example, in states, people1373losing their disability benefits based on algorithms.1374    Mr. Sessions. Okay. So, let me give you that. It would then1375at some point require human intervention to review data to then1376make some decision as opposed to a computer automatically1377assuming something.1378    Mr. Stanley. I think that is right. The only other caveat I1379would add is that some of the fraud prevention techniques are1380based on gathering an enormous amount of intrusive data about1381individuals.1382    Mr. Sessions. We spoke about this, but you had indicated1383earlier, without human intervention, that meant that someone1384else, a computer or an AI modeling, decided they could send you1385a letter and cutoff your benefits. I am saying that we could1386use these to then go to a human who is trained, who does have1387this professional experience, who would be able to apply it,1388and then would be able to use some rational basis. Okay. So,1389you would agree with that?1390    Mr. Stanley. Yes, but what I am saying is that, for1391example, there are industries that use unethical apps on1392people's smartphones to track their location without their1393knowledge or permission. I am sure that many people in this1394room are being tracked by these companies without knowing, and1395that some of that data can be fed into these algorithms for1396deciding who is suspicious and a lot of other very privacy-1397invading data. So, if the algorithm you are talking about is1398based on that kind of very intrusive privacy-invading data1399sources, we would have a problem with that.1400    Mr. Sessions. Okay. Well, I could bring up lots of1401examples. I am not going to. I want to thank you. I think this1402is an important question. That is why you are here today.1403    We would now like to move to the distinguished gentleman1404from Florida, Mr. Frost. Mr. Frost, I yield back my time. We1405now move to you. The gentleman is recognized.1406    Mr. Frost. Yes, thank you so much.1407    You know, part of my concern as it relates to digital ID1408becoming mandatory is the risk of widespread data collection1409and exposing millions of Americans to harm, which is already an1410issue that this country seeped into many different ways, social1411media, online, and different things like that. Mr. Stanley, how1412could digital ID systems become a barrier for Americans trying1413to access services, benefits, or programs?1414    Mr. Stanley. That could happen if, first of all, you are1415unable to get a digital identity system because you do not have1416a smartphone. There are also a lot of Americans who do not have1417access to--who do not have, currently have, any kind of1418driver's license or non-driver ID from DMVs, who--there are1419people whose birth certificates were burned in a fire in1420Tennessee in 1955 and do not have access to them.1421    It is a messy world out there, and I think that digital IDs1422seek to impose a sort of neatness and bureaucratic, you know,1423regimentation on it, on all of us. And so, in making policy, we1424have to make sure that people who do not have access to those1425things are not left out. So, you cannot get--there are people1426who cannot get a driver's license. There are people who, maybe1427they have a driver's license, but they will not be able to get1428a digital driver's license because of the things that we talked1429about in terms of not having access to the technology or the1430technological literacy to use it. There was one study that1431found that a very large proportion of people over 65, you know,1432were not able to install an app on a smartphone.1433    There could be situations where people's IDs are abusively1434revoked. You know, we have seen, there has been mentioned that1435the Trump Administration put some people in the Social Security1436dead file. We also saw in California, a Democratic candidate1437for Governor proposed that Federal agents who wear masks should1438have their driver's licenses stripped from them. And whatever1439you think of mask-wearing by Federal agents, which is a1440controversial issue, that is using an identity infrastructure1441for political purposes, which is something that we may see in1442the future left, right, or center, and so that could be a1443threat. And we have called for protections against people1444having their IDs yanked by abusive governors or the like. So,1445those are some of the ways in which people could find that they1446are left out of a digital identity infrastructure.1447    Mr. Frost. Part of my concern, too, is when we look at this1448Administration, we know they have empowered big tech companies1449like Palantir to create databases of Americans' personal data1450for government use. We know that during the, you know, DOGE1451era, similar things were done during that as well. This data1452collection could make it easier for private companies to abuse1453our data. I know some proponents will say, well, you know, this1454is mainly for government use, but we know it is not only for1455government use. And that is part of my concern with this. There1456is just so much collaboration between private companies, data1457sharing.1458    How should we legislate on balancing the convenience and1459the real dangers of digital ID? Which also will lead to losing1460anonymity online, which is something else I am concerned about1461as well.1462    Mr. Stanley. Yes, we have a piece on our site that outlines146312 protections that we call for that we think state1464legislatures should enact that govern any, you know, mobile1465driver's license or digital ID that is created in their state.1466I will not go through them all, but they include such things as1467protecting people against incessant demands from every1468corridor. If you want to do business with us or come in our1469candy store, you have to tap your ID and give us your driver's1470license to get in.1471    Mr. Frost. Yes, this is part of my concern, too, that1472making it easier to prove who you are will lead to more1473services, companies asking you to do so for every service that1474is not expected of you right now.1475    Mr. Stanley. Yes, it is an excellent point because one of1476the things that, you know, if you are a website and it is1477really, really hard to prove your identity online, you have to1478take a photo of your ID, you have to send it in, you have to1479get a video, you have to do proof of liveness, all this stuff.1480You are not going to ask your visitors, your users to do that1481unless you really need to, so that imposes a limit. But by1482getting rid of all the friction of proving who you are online,1483you get a pop-up like the privacy pop-ups we get today, click1484here to send us your digital ID. It will not only become easier1485for me to share my digital ID, that means that it makes it much1486easier for them to ask me to or demand that I do so.1487    And that is one of the big things we have--and that is one1488of the protections that policymakers can make, which is to say,1489these are super IDs, they are cryptographically locked down,1490DMV vetted, everything like that. This is, you know, and that1491you should not be forced to use a super ID to prove your1492identity unless it is legally required, we have called for,1493maybe in certain other specific situations.1494    But people are going to need protection against this1495absolute, you know, waterfall of demands that we can easily1496anticipate are going to happen once this is created. And then1497other protections like privacy protections to make sure that1498the wallet holders do not, are not spying on everybody, and1499that, you know, that these cryptographical things that I talked1500about are built in to protect privacy so that, you know, you1501can prove things about yourself without having to, you know,1502create a lifelong relationship with somebody by identifying1503yourself to them.1504    Mr. Frost. How can we--and I know we are over, if you can1505indulge me, Mr. Chair. My last question is how can digital ID1506lead to complete loss of anonymity online?1507    Mr. Stanley. Yes, so, I mean, the websites are going to1508want everybody to identify themselves all the time. They are1509going to want to do it because their ads will be worth more if1510they know who you are, and they can plug in you--the data they1511have about you to other data they get. They are going to want1512to do it to make sure that you are of age so they can market to1513you under Children's Online Privacy Protection Rule (COPPA),1514which is, you know, you cannot market to people under 13.1515Identity verification, which has become a big controversial1516issue. And bots, a lot of sites are having problems with AI1517impersonating humans, and they are going to want to know that1518you are a human for various reasons, and so there is going to1519be a lot of pressure for a lot of websites to start demanding1520this----1521    Mr. Frost. Yes.1522    Mr. Stanley [continuing]. All the time.1523    Mr. Frost. And part of the concern, right, is the fact that1524this information can be weaponized against consumers, working1525people, who are looking to purchase things online and have that1526information leveraged against them when they are making1527decisions on what they want to buy and how much those items1528cost, correct?1529    Mr. Stanley. Yes, surveillance pricing, where stores get a1530bunch of data about their customers, and then they charge you1531based on what they know about you and how much they think you1532will pay and whether you are desperate and so forth. That has1533become a very controversial issue, and states, you know,1534regulation of surveillance pricing has been attracting support1535in the state legislatures from both left and right. And digital1536IDs will make that much easier because if you know they are1537going to charge--if the store is going to charge you more--1538like, let us say that the airline happens to know that you have1539just lost a close loved one and you have to fly, they can up1540your price.1541    Mr. Frost. Yes.1542    Mr. Stanley. And so, you are going to want to see what the1543price is without them knowing who you are, right? But they are1544going to want to know who you are, and there will be this arms1545race. And a digital ID would sort of end that arms race----1546    Mr. Frost. Yes.1547    Mr. Stanley [continuing]. And you cannot escape them1548knowing who you are----1549    Mr. Frost. Yes.1550    Mr. Stanley [continuing]. If it is done badly.1551    Mr. Frost. Yes, I appreciate it. Thank you for indulging1552me, Mr. Chair. I just think, you know, I am not a Luddite, and1553I just think these conversations are important because it shows1554how much care and intentionality needs to be put into this.1555    Oftentimes, we are very excited about something, we move1556quickly on it without thinking the next 10, 20 years into the1557future, and then it is an emergency for another generation to1558handle. I think we have to have these conversations now and1559legislate accordingly.1560    Thank you. I yield back.1561    Mr. Sessions. The gentleman yields back his time. Thank you1562very much.1563    The gentlewoman from Washington is now recognized.1564    Ms. Randall. Thank you so much, Mr. Chair, and thank you to1565our panelists for joining us.1566    You know, Login.gov gives every American a one-stop portal1567so they can use a single username and password to log in across1568a variety of Federal programs. Sounds like a benefit and a, you1569know, customer service improvement. This is a portal that state1570and local governments can use as well, and it saves taxpayers1571time and money and generally makes life easier.1572    Mr. Burris, can you briefly describe how Login.gov has1573leveraged Socure's technology to help reduce identity fraud for1574government programs?1575    Mr. Burris. Absolutely. And I think a lot of this comes1576down to trust and basically leveraging what would be considered1577next-generation technologies to try to help balance. A lot of1578the conversation I have heard are around access and speed and1579confirming that the right people ultimately can access these1580services.1581    So Login.gov conducted a competitive procurement where they1582evaluated our technology against that of 17 others at the time,1583and they incorporated different components of our solutions,1584everything from solutions that we have around document1585verification, so confirming that it is a legitimate government-1586issued ID, and/or what would be facial biometric comparisons,1587so the idea is comparing it and confirming that it is actually1588the right person on the other end of the screen. They also1589incorporated what would be additional fraud models to their1590stack, things that they are incorporating such as identifying1591and understanding what is happening with the device a person1592may be using because it is all too often that the adversary1593would do something such as take a jailbroken device that is1594overseas and attempt to say that they are operating within New1595York or D.C. for that instance, also doing comparisons with1596things like the phone or the address of individuals using their1597email.1598    And then some of the flagship offerings that we have1599related to helping to paint a picture or prediction of whether1600or not it is someone who is engaging in what would be a pattern1601that is associated with identity theft and/or synthetic1602identity. And far too often, what we see in the industry is1603that kind of weaknesses in these technologies have led to this1604unfortunate conversation about folks who have been left out and1605forced down alternative paths. It has always been my belief1606that if someone is choosing to engage with a digital service in1607government, they should be able to do so, and the technology1608should adapt to meet them where they are. So, the addition of1609Socure's tools have enabled Login.gov to take strides toward1610being able to address that and make their service more1611accessible while simultaneously combating fraud.1612    Ms. Randall. Thank you so much. It is really great news1613that we are innovating in this way to provide access that the1614people want and to smooth some of these barriers to accessing1615services. But, like you have mentioned and based on other1616testimony that we have heard today, we know that scammers and1617identity thieves are constantly trying to find new ways to1618evade ID verification, and that means that Login.gov has to1619remain alert and prepared to fight new forms of fraud. We have1620to keep innovating.1621    Ms. Cruz Cain, in GAO's assessment, will there ever be a1622day when Login.gov will be finished and no longer need to adapt1623to face new fraud tactics?1624    Ms. Cruz Cain. I do not think so. I think criminals are1625working every day, 24 hours a day, to get better at what they1626do, and largely in the Federal Government, we are reactive. So,1627Login.gov procured the tools because they are being reactive to1628what has been happening within their tools. So, I think largely1629Federal systems are reactive to what is going on and rather1630than being proactive.1631    Ms. Randall. Yes. So, would it be safe to say that1632competent and technically capable leadership of the Login.gov1633program is critical to effectively sustain fraud prevention?1634    Ms. Cruz Cain. Yes.1635    Ms. Randall. And is it critical that leadership has1636experience in effectively managing and protecting sensitive1637data programs?1638    Ms. Cruz Cain. Yes.1639    Ms. Randall. Would it be very concerning to you, Ms. Cruz1640Cain, if leadership at Login.gov came from an organization that1641had, say, an extensive history of mismanaging private data and1642endangering the privacy and financial security of the American1643people?1644    Ms. Cruz Cain. Without, I mean, knowing a little bit more1645about the situation, it would be hard to opine, but we like to1646look at facts and situations. But, I mean, just like I told1647you, we would really need to have experience with technology,1648leadership with good technology, and knowledge of how to1649implement technology.1650    Ms. Randall. Absolutely. But if someone who had previously1651been proven to mismanage private data and endanger privacy and1652financial security was moved into leadership, that would be1653concerning?1654    Ms. Cruz Cain. Yes, if it was proven.1655    Ms. Randall. Yes. Mr. Chairman, I would like to ask1656unanimous consent to submit these following articles to the1657record. ``DOGE Put Critical Social Security Data at Risk'' from1658The New York Times. From NPR, ``The Trump Administration Admits1659Even More Ways DOGE Accessed Sensitive Personal Data.''1660Washington Post and Wired, similar subject matter.1661    Mr. Sessions. Without objection.1662    Ms. Randall. And just in my remaining time, I would like to1663say what these articles say, that President Trump took one of1664the DOGE bros who oversaw the looting of the Federal1665Government's data and endangered the privacy of every American1666and put him in charge of identity verification and login1667systems for every American. And based on our previous line of1668questioning, that does not sound like a way to safeguard the1669American people's information.1670    And I yield back.1671    Mr. Sessions. The gentlewoman yields back her time.1672    We would now like to move to the second round. With your1673understanding, we are doing that, sir.1674    Dr. Maimon, you and I spent some time yesterday. Maybe it1675was today. Days run together. But you most expressly indicated1676that you have not only great knowledge, but work on a day-to-1677day basis with many people who are criminals and who are1678attempting to be fraudsters at our systems. And I did not have1679a chance--you did not really delve into this area very much,1680but I think Mr. Mfume and I need to hear this about not only1681that it exists, that they are very active, that they are on the1682dark web or open web, that they target certain people and that1683they learn areas that are vulnerable, and that they openly talk1684about it. It is no longer behind anybody's back anymore. Do you1685mind taking the time that you need to express the things that1686we need to understand about the attack that is against us and1687our agencies?1688    Mr. Maimon. With pleasure, Mr. Chairman. As you mentioned,1689Mr. Chairman, I spent my time, my days infiltrating darknet1690platforms, Telegram groups, trying to understand what1691fraudsters put out there and how they bypass a lot of the1692security solutions that we deploy on financial institutions as1693well as on the government side. Oftentimes, what we find in1694those platforms are tutorials, which will walk you through how1695to bypass many of the security solutions that we have out1696there. The tutorials sometimes will be offered for free, other1697times you will pay for them, amounts ranging from $150 to $250,1698specific guidelines with respect to how to bypass and obtain1699SBA loans, FAFSA aid. We are seeing, as of earlier this1700morning, people talking about how to get targets' 401(k)1701accounts, which I think is a major issue to our country, and we1702simply see that on scale. We see that, as I mentioned earlier,1703on darknet and Telegram, but also more and more on Facebook, on1704Twitter, on Instagram.1705    A lot of what we see also on--is available on the internet,1706on the clearnet, websites that the criminal put together and1707simply offer fake driver licenses for sale. This is the reality1708that we are dealing with, organized crime groups with very1709detailed supply chains, which will have our identities offered1710for sale. They will have services which will allow the1711fraudsters to build histories around their identities. They1712will walk you through how to create deepfakes, high-quality1713deepfakes, both images as well as videos. They will teach you1714how to take those videos and images and inject them in the1715cameras of the computers or the smartphone that folks are using1716in order to apply for benefits or apply for SBA loans and then1717secure all those resources that they get from the government.1718    So, this is what we are up against. We are seeing that1719happen domestically with a lot of organized crime groups1720operating within the United States, but a lot is happening from1721abroad as well. We are infiltrating Russian crime groups. We1722were able to infiltrate some Chinese crime groups who operate1723the scam compounds in South Asia and are explicit about the1724type of operations and our identity and how, you know, how they1725essentially offer those identities for sale and essentially1726walk you through the list of steps you need to engage in in1727order to target our benefit program. This is what we are up1728against, unfortunately, at this point.1729    Mr. Sessions. So, furthering this development that you are1730talking about, I spoke with you about how we had looked at,1731during 2021, 2022, 2023, 2024, numbers of agencies that did not1732have their workers at work. They were not engaging the people1733who were seeking services. They were not able to, even when1734working from home necessarily, did not have a full array of1735opportunities to vet who people were, know your customer, to1736look at things. And so, this huge amount of money that we were1737talking about today in testimony before this Subcommittee, that1738is very consistent with what we have heard GAO say in the past.1739    It has found a real home to where this is more than a1740cottage industry. It is people who literally are figuring out1741how to do this. And you said to me, whenever we last spoke this1742morning, you do believe human interaction--and I brought up my1743circumstance of talking to Social Security, how they vetted me,1744how they talked to me about things that I would know about1745myself that probably not a lot of people would understand. Is1746this the kind of fair game that would be used to vet people on1747a regular basis? And how can we cross-get this type of1748information to where if you are at SBA, you may or may not have1749that available to you? If you are at Social Security, you1750probably could ask some detailed questions about working1751history, about doing other things.1752    Do we need to expand or develop some way for agencies that1753take a new, perhaps a new, request from a person? It could be1754about--not VA because you could ask about those questions, but1755about someone who is recently unemployed and asking about depth1756of knowledge. How do we really help those agencies make the1757determination even when speaking to a person?1758    Mr. Maimon. This is a great question, Mr. Chairman, and I1759agree with your statement. I think, and maybe you can go back1760to my career as sociology in the Ohio State University, first1761class in the degree, we were taught about the difference1762between Gemeinschaft and Gesellschaft, community and society.1763The reason why I am bringing this important distinction is that1764in the past, here in the United States or any other place, when1765you went into the bank or to the IRS and asked for opening a1766new bank account or a loan or getting some governmental1767benefits, the guy sitting across from you knew who you were. He1768knew your family. He knew where you worked. He knew your1769history, so to speak. And so, they were able to assess the risk1770you posed to the organization more effectively.1771    Now, you know, we are at this point in a point of a1772society. We have a lot of people living in this great country,1773very difficult to assess, in the same way we assessed in the1774past, folks' history. But fortunately, we do have solutions out1775there which will allow you to taggle the signals, create and1776look at some historical signals around identities.1777    So, if the government is willing to sort of use some of1778those solutions to try and assess the historical evidence1779around those individuals who need to be verified, then I think1780we will be in a better place to sort of determine whether1781individuals are who they say they are, or they are completely1782different individuals stealing identities or using synthetic1783identities.1784    And in that sense, I just want to refer to the conversation1785we had earlier about the driver's licenses and MDL. One of the1786things that we proved already, you know, during the last ten1787years or so is that pretty much everything could be faked.1788That, I think, will go also to the MDL. I mean, criminals will1789be able to find ways to use this technology to their benefit.1790What they will not be able to fake is the historical evidence.1791    And that goes as well to the AI solutions out there, right?1792I mean, AI will be able to give you an amazing picture of a1793person who does not exist, or AI will be able to take my face1794and bring it to life when I am abroad, so to speak, and try and1795authenticate me when I am trying to get unemployment benefits.1796But one thing that AI tools will not be able to do at this1797point is to create the historical signals around me or around1798anyone who is trying to identify themselves.1799    And I think that is where the solution lies, being able to1800find solutions which will allow us to look at historical1801evidence around individuals, around their name, date of birth,1802addresses, telephone numbers, and make assessments with respect1803to whether they are who they say they are.1804    Mr. Sessions. Ms. Cain, furthering this discussion, I had a1805chance to engage you also yesterday, and part of this was about1806the viewpoint that when there was a failure, meaning a person1807came through Login.gov, provided information, but it was not1808what I would call successful, so there would be a failure,1809then, evidently, it is not unusual for someone, not as a1810challenge, but to ask for authentication of who they are, to go1811to a post office. You had indicated that one of the things1812which you have engaged government agencies on, and perhaps GSA,1813is data and information back about what caused that failure.1814Was it a question we asked? Was it a picture, any number of1815facts and factors?1816    Following up on Dr. Maimon, you are the cybersecurity1817person also at GSA, and you are aware of the power of1818technology, the power of these things that could be used to1819fool people, to give false positives, to do things. Do you see1820that in this process that we need to go with new areas that1821would add some more depth to where you did not fail off one or1822two or three, you failed off five different questions because1823you were looking for them? How do we go and ascertain when1824someone falls out, whether that was fraud, whether that was1825someone you were openly challenging, and they see you later,1826and so they never went to the post office, and to where we then1827learn what they did, how they did it, where they asked the1828question, who they were? We could move them to the organization1829we talked about this morning, to Pandemic Response1830Accountability Committee (PRAC).1831    Ms. Cruz Cain. I think it is an important question because1832the people who are failing and are legitimately the person that1833they say they are, are going to keep trying because they want1834that government benefit that they are entitled to.1835    Mr. Sessions. And they could go to a post office.1836    Ms. Cruz Cain. Right, they could go to the post office and1837go take their documents and verify who they are that way, but1838there are also barriers to that. So, if you are in a rural1839area, your post office may be far, you may not have reliable1840transportation there, there may be lots of barriers for you to1841do that, so it might not be that easy. So, a lot of the1842agencies reported to us that they would like to have visibility1843into that authentication and why it failed, so they might be1844able to help that person on the end and say, well, yes, it was1845because the name that you put in was not the name that HUD had1846on, or there was a letter transposed, or your new address was1847never updated in HUD's database.1848    And there was a privacy principle called redress. You know,1849you are supposed to be able to get the most updated, or1850whatever information an agency has on you, so you are able to1851correct it if it is wrong. That process can be easy, or GAO has1852reported that process can take very long for you to be able to1853update your information. So, if that takes me months to years1854to get my address updated in a government database, I am going1855to fail for that whole year on every government agency that I1856use Login.gov to try to access, which is going to be a very big1857barrier for me to get any government benefits that I am1858eligible for.1859    So, that was something that many agencies brought up for1860us. And giving those agencies that ability to--insight into1861that and to be able to say, hey, this is why you failed, you1862know, here are your options, and again, some of them may not1863even be able to go to a post office and have that secondary1864option available to them, but, you know, you are going to have1865to do that if you want your benefits. That was one thing that1866was really helpful to them because some people would--1867fraudsters would probably legitimately stop. If they were not1868able to go somewhere and prove who they said they were, nine1869times out of ten, they are stopped. They will take their other1870synthetic identities and keep trying to get through, but they1871would stop probably with that fraud name and say, okay, look, I1872have got 300 others that I just paid $3 for. I am going to keep1873pushing those.1874    So, I think the difference is you really need to think1875about the people who are really who they say they are, who are1876having that false positive, that they are going to keep trying,1877and they need that reason why so that they can go remedy that1878so they can continue to be--not be found ineligible for the1879benefits that they are legally entitled to.1880    Mr. Sessions. Okay. Interesting. Thank you.1881    Mr. Mfume?1882    Mr. Mfume. Thank you, Mr. Chairman. It has been an1883interesting hearing, to say the very least.1884    One of the things that I hope comes out of these sort of1885interactions are ideas that would affect and change existing1886law and policy. And I know all of you in your work have come1887across items, matters, and issues that you said, if this were1888only changed or if this could be in place. So, I want to come1889back to that in just a minute, and it will be a quick minute1890too, but I want you give some thought to that because, as1891legislators, that is very important to all of us, no matter1892what side of the aisle we serve on, if we are in fact trying to1893deal with an issue and a problem, and certainly, this is one of1894them.1895    I want to, if I might, Dr. Maimon, go back to something you1896said earlier, and then I will come back and we will try to wrap1897this up on this side anyway. I am interested in your work that1898you have been doing tracking Russian and Chinese cyber networks1899and their ability to infiltrate this country, but more1900importantly, their ability to take advantage of the citizens of1901the United States. It sounds like fascinating work, but I am1902sure it is also leading you to some ideas about how we can do1903things better.1904    What I really want to know, though, on this matter, the1905evidence that you are coming up with as you track these crime1906syndicates and cyber networks, whether they are Russian or1907Chinese, are you or your organization sharing that information1908with the Director of National Intelligence or sharing it with1909the FBI, or are they about doing what they do in their own1910silo, developing their own intelligence and not doing a1911comparative analysis of both? Could you speak about that for a1912minute?1913    Mr. Maimon. Of course. Thank you so much for this question.1914I do what I do in order to make sure that the American public1915is aware of what is going on there, and when I investigate, my1916investigations usually result in publications. I put together1917white papers; I put together news articles and let the public1918know about what I find.1919    Oftentimes, we will reach out to law enforcement, and then1920we will simply give it to them, and then they need to make a1921decision with respect to whether they want to pursue an1922investigation or not. I can tell you that in the past, we had a1923very strong relationship, as a professor in Georgia State1924University, with the Department of Homeland Security. What we1925have done back then, that was during the pandemic time, we1926essentially had a monthly meeting with local folks in DHS, and1927we simply talked about what is it that we find out there. What1928is it that the Department of Homeland Security (DHS) did with1929that information? Obviously, I have no idea because,1930oftentimes, what happens is that law enforcement takes this1931information and do their own thing, sort of speaking.1932    And so, I can tell you that I am doing my best to make sure1933that everybody is aware of what I find out there, but I have1934limited visibility with respect to the actions folks take once1935I put information out there.1936    Mr. Mfume. Well, if I could be the devil's advocate, if I1937am the Director of National Intelligence or the head of the1938FBI, I might say, well, he has never given that information to1939us. So, do you forward that to them? Are you in contact? Is1940there a liaison that shares the information so they can match1941it up with their own intelligence?1942    Mr. Maimon. So, in the past, what I was doing is1943essentially having a monthly meeting with the Department of1944Homeland Security. That was during COVID time. We had a very1945strong relationship at the time, where we essentially1946provided----1947    Mr. Mfume. Right, but I am specifically speaking about the1948Director of National Intelligence and the Federal Bureau of1949Investigation.1950    Mr. Maimon. Yes, I do not have a relationship with the FBI.1951I do not stay in touch with the FBI. I am more than happy to be1952in touch with them and let them know about what I know.1953    Mr. Mfume. Yes, because it seems like you have done an1954extensive amount of work, and I can appreciate white papers and1955editorials and that sort of thing, but everybody does not read,1956and if it is something so pertinent or hot or game-changing,1957those two agencies, more than anyone else, I think, needs to1958know. So, let us pray that they are listening. They obviously1959are. I hope that they would take advantage of the work that you1960have already done just to match it up against their own1961intelligence. This is a very serious issue, as we all agree,1962and the more we can do to be effective, the better.1963    And now, I just want to come back to all of you, just very1964briefly, with respect to this notion about policy changes or1965about proposed legislative avenues to address some of the more1966glaring aspects of this, or maybe just to address things that1967right now are not getting any attention. I am going to start1968with you, Mr. Burris, and I will end up with you, Mr. Stanley.1969    Mr. Burris. Thank you, Ranking Member, for the opportunity1970to address this item. You know, there were a number of1971recommendations that I provided as part of my testimony as far1972as where we could be pursuing policy levers. I actually will1973lead with one that was not in there, and it is really around1974mindset shift and culture. And if you indulge me for just a1975moment, it shows you the depth of my nerd.1976    It goes into--I was thinking actually back to the Avengers1977movie, the last one with Captain America, and how there was1978like the darkest moment where they were basically up against an1979insurmountable threat, basically took all the Avengers coming1980together at the same time out of nowhere in order to try to1981combat what they were seeing or what was about to happen. I1982think that generally, culturally, has to change within the1983Federal Government in the sense that right now, when you are1984talking about who is fighting fraud within an agency, an1985organization, they are doing it siloed. They are doing it1986without sharing intelligence. They are doing it without having1987the types of conversations that need to happen, so much so that1988Federal Emergency Management Agency (FEMA) could be having an1989existential fraud threat, and they are not talking to the SBA.1990They are not talking to Treasury. They are not talking to GSA1991even. And so, there is an opportunity to basically culturally1992shift to say that we all have to get on the same page about1993what we are fighting against and then change that dynamic so1994that way we can actually can take some of these more proactive1995measures that I have outlined in my testimony.1996    Mr. Mfume. Thank you very much. I appreciate that. I did1997not see the movie, but I appreciate your context. But I am1998talking now about policy more so than mindset. Mindset is going1999to take a while, but if we can implement minor or major policy2000changes, that will make a difference right now.2001    Ms. Cruz Cain?2002    Ms. Cruz Cain. I will go for a big one, but I think we do2003need to revamp the Federal Privacy Act. So, the Privacy Act2004goes back to 1974. GAO has plugged many times in its reports2005that that was created way before policy and technology has2006updated, and we need to revisit that. But I also think that2007there is a great need for a consumer privacy law as well that2008starts at the Federal level but also allows states to have some2009input into it because of, right now, there is no Federal2010consumer privacy law, and it is a sort of framework of2011mismatched state laws, local laws, and, you know, there is2012nothing really governing at a higher level of what needs to be2013done.2014    Mr. Mfume. Thank you.2015    And Dr. Maimon, I appreciate the extensive nature of your2016written remarks. I tried to get through all 20 pages. I do not2017know if I did or not, but thank you very much for that.2018    Mr. Maimon. Thank you so much. I think in terms of policy--2019and I really appreciate this question because I sit at Georgia2020State University in the School of Policy. One of the things2021that I would strongly recommend is an evidence-based approach.2022I think, you know, we are in a point in time where science has2023advanced dramatically. We have evidence-based medicine,2024evidence-based policing, all essentially suggest that in order2025to make decisions with respect to policy or the implementation2026and tools, what we need to do is essentially test what works2027and what does not.2028    Unfortunately, we do not have that in the context of fraud.2029So, I think if we are thinking about policies and policy2030changes, the first thing we need to sort of have in mind is a2031different state of mind, and that is of evidence-based, what2032works and what does not in the context of fraud prevention.2033    In the context of the government operation, we are in a2034very difficult position, I would say, because, to be honest, we2035do not really know how much fraud we have. We have reports on2036improper payments, but we do not know how much fraud we have on2037the government side. We hear numbers and very large numbers, so2038it is definitely an issue, but we need to be able to quantify2039how much fraud we have. And then after we quantify that number,2040we need to try and assess how to reduce that number to the2041minimum possible in order to make sure the taxpayers get their2042money's worth in terms of benefits, in terms of programs that2043they should have access to.2044    So, I think if we need to sort of have something in mind2045when we think about a policy change, then it is definitely an2046evidence-based approach to fighting fraud.2047    Mr. Stanley. [Off mic.]2048    Mr. Mfume. Mr. Stanley, could you turn your mic on, please?2049    Mr. Stanley. I am so sorry about that. I would agree with2050Ms. Cruz Cain that strengthening the Privacy Act of 1974 is2051sorely needed, as well as overarching consumer privacy2052legislation. I believe that the United States is the only2053advanced industrial Organization for Economic Co-operation and2054Development (OECD) nation that does not have an overarching2055privacy law that sets baseline expectations for both2056individuals and businesses about what is fair and what is not2057in terms of how people's information is treated.2058    And then, as I have been arguing, I think that we need to2059set standards for digital driver's licenses in the states and2060other digital IDs that put in place both requirements for how2061they are built technically. They should have certain encryption2062capabilities that protect privacy while still allowing for2063people to authenticate themselves. And there should be an2064envelope of legal protections around them to make sure that2065they remain optional and not mandatory, for example, and to2066limit overuse. And so those would be the top things that I2067think the Congress should consider.2068    Mr. Mfume. Thank you very much. I want to thank all of you.2069    Mr. Chairman, you may recall this idea of revamping the2070Federal Privacy Act continues to come up. The last hearing we2071did like this, that same thing came up. So, I want to commit2072myself, and I am sure, you know, you and I will get together on2073this and figure out how, in fact, we might be able to move2074forward with some joint legislation that at least starts to2075move the ball regarding the Federal Privacy Act. It has been a2076long time since 1972. The world has changed, and the least we2077can do, I think, is to try to find a way to protect the privacy2078of Americans by updating the Federal policy that we have. And I2079want to commit myself to working with you in that regard. I2080yield back.2081    Mr. Sessions. The gentleman yields back his time. Was that2082your closing statement also?2083    Mr. Mfume. Yes.2084    Mr. Sessions. The gentleman did make a closing statement.2085    I, too, want to join in with my dear friend, Mr. Mfume, and2086thank each of you for being here. This issue is not going to go2087away. The question is, are we serious enough to continue the2088search to look for these things? And I think all four of you2089have proven to us today that there is not just much ground to2090go, but there is much to learn.2091    And I think both Mr. Mfume and I need to provide some,2092perhaps, guidance back to inspectors general, their attention2093to this, to help GAO to reinforce the things that they are2094after, to have the GSA follow-up. I find myself in a position2095where I do not want to say that they are not paying attention.2096I think they are trying to do a number of things that are2097important. But Mr. Mfume and I find ourselves on this end of2098the trying to save the taxpayer, trying to understand that the2099people, whether it is one of my sons or it is one of his2100constituents, that need government benefits and government2101services to work properly, to be legally bound to recognize2102these things, but that we will bleed ourselves out. We can2103bleed ourselves out by people who are outside the system,2104causing us to completely miss the mark.2105    So, we are going to stay after this. We are going to make2106sure that we approach every single angle and challenge2107government to do that. We have, by and large, decided we do2108understand the PRAC. We do understand the importance of data.2109We do understand the need to make sure that it survives in2110perpetuity, yes, probably for a lot longer, that we give it the2111authority and the responsibility to evolve itself, to meet the2112emerging and new threats, and to provide information back.2113    But, I want to thank you for your insistence that we will2114continue to work together, and I want to thank each of you.2115    So, with that said, without objection, all Members have2116five legislative days within which to submit materials and2117additional written questions for the witnesses, which would be2118forwarded to the witnesses.2119    If there is no such further business, without objection,2120the Subcommittee stands adjourned.2121    [Whereupon, at 3:58 p.m., the Subcommittee was adjourned.]21222123                            [all]

Source: congress.gov · LC75868