[House Hearing, 119 Congress]
[From the U.S. Government Publishing Office]


                       EMERGING FRAUD THREATS AND
                      THE EVOLVING FRAUD LANDSCAPE
=======================================================================

                                HEARING

                               BEFORE THE

                        SUBCOMMITTEE ON GOVERNMENT 
                                OPERATIONS

                                 OF THE

                        COMMITTEE ON OVERSIGHT AND 
                            GOVERNMENT REFORM

                     U.S. HOUSE OF REPRESENTATIVES

                    ONE HUNDRED NINETEENTH CONGRESS

                             SECOND SESSION

                               __________

                             JULY 15, 2026

                               __________

                           Serial No. 119-70

                               __________

Printed for the use of the Committee on Oversight and Government Reform

[GRAPHIC NOT AVAILABLE IN TIFF FORMAT]

    Available on: govinfo.gov, oversight.house.gov or docs.house.gov
    
                               __________

                   U.S. GOVERNMENT PUBLISHING OFFICE
64-225 PDF                 WASHINGTON : 2026
=======================================================================
    
              COMMITTEE ON OVERSIGHT AND GOVERNMENT REFORM

                    JAMES COMER, Kentucky, Chairman

Jim Jordan, Ohio                     Robert Garcia, California, Ranking 
Mike Turner, Ohio                        Minority Member
Paul Gosar, Arizona                  Eleanor Holmes Norton, District of 
Virginia Foxx, North Carolina            Columbia
Glenn Grothman, Wisconsin            Stephen F. Lynch, Massachusetts
Michael Cloud, Texas                 Raja Krishnamoorthi, Illinois
Gary Palmer, Alabama                 Ro Khanna, California
Clay Higgins, Louisiana              Kweisi Mfume, Maryland
Pete Sessions, Texas                 Shontel Brown, Ohio
Andy Biggs, Arizona                  Melanie Stansbury, New Mexico
Nancy Mace, South Carolina           Maxwell Frost, Florida
Pat Fallon, Texas                    Greg Casar, Texas
Byron Donalds, Florida               Jasmine Crockett, Texas
Scott Perry, Pennsylvania            Emily Randall, Washington
William Timmons, South Carolina      Suhas Subramanyam, Virginia
Tim Burchett, Tennessee              Yassamin Ansari, Arizona
Lauren Boebert, Colorado             Wesley Bell, Missouri
Anna Paulina Luna, Florida           Lateefah Simon, California
Nick Langworthy, New York            Dave Min, California
Eric Burlison, Missouri              James Walkinshaw, Virginia
Elijah Crane, Arizona                Christian Menefee, Texas
Brian Jack, Georgia                  Ayanna Pressley, Massachusetts
John McGuire, Virginia               Rashida Tlaib, Michigan
Brandon Gill, Texas
Richard McCormick, Georgia

                                 ------                                

                       Mark Marin, Staff Director
                   James Rust, Deputy Staff Director
                     Ryan Giachetti, Chief Counsel
           Jennifer Kamara, Director of Strategic Initiatives
                         Hannah Cathey, Counsel
                      Bill Womack, Senior Advisor
         Mallory Cogar, Director of Operations and Chief Clerk

                      Contact Number: 202-225-5074

                Robert Edmonson, Minority Staff Director
                      Contact Number: 202-225-5051
                                 ------                                

                 Subcommittee on Government Operations

                     Pete Sessions, Texas, Chairman

Virginia Foxx, North Carolina        Kweisi Mfume, Maryland, Ranking 
Gary Palmer, Alabama                     Member
Tim Burchett, Tennessee              Eleanor Holmes Norton, District of 
Brian Jack, Georgia                      Columbia
Brandon Gill, Texas                  Maxwell Frost, Florida
                                     Emily Randall, Washington
                         
                        C  O  N  T  E  N  T  S

                              ----------                              

                           OPENING STATEMENTS

                                                                   Page

Hon. Pete Sessions, U.S. Representative, Chairman................     1

Hon. Kweisi Mfume, U.S. Representative, Ranking Member...........     3

                               WITNESSES

Mr. Jordan Burris, Vice President and Head of Public Sector 
  Strategy, Socure
Oral Statement...................................................     7

Ms. Marisol Cruz Cain, Director, Information Technology and 
  Cybersecurity, U.S. Government Accountability Office
Oral Statement...................................................     9

Mr. David Maimon, Head of Fraud Insights, SentiLink
Oral Statement...................................................    10

Mr. Jay Stanley (Minority Witness), Senior Policy Analyst, 
  American Civil Liberties Union
Oral Statement...................................................    12

Written opening statements and bios are available on the U.S. 
  House of Representatives Document Repository at: 
  docs.house.gov.

                           INDEX OF DOCUMENTS

  * Statement for the Record, Better Identify Coalition; 
  submitted by Rep. Sessions.

  * Statement for the Record, Defense Credit Union Council; 
  submitted by Rep. Sessions.

  * Article, Wired, ``A DOGE Affiliate Is Now in Charge of the US 
  Government ID Platform''; submitted by Rep. Randall.

  * Article, New York Times, ``DOGE Put Critical Social Security 
  Data at Risk''; submitted by Rep. Randall.

  * Article, Washington Post, ``Musk's DOGE Agents Access 
  Sensitive Personnel Data Alarming Security Officials''; 
  submitted by Rep. Randall.

  * Article, NPR, ``Trump Admin Admits Even More Ways DOGE 
  Accessed Sensitive Personal Data''; submitted by Rep. Randall.

The documents listed above are available at: docs.house.gov.

                          ADDITIONAL DOCUMENTS

  * Questions for the Record: Mr. Jordan Burris; submitted by 
  Rep. Sessions.

  * Questions for the Record: Ms. Marisol Cruz Cain; submitted by 
  Rep. Sessions.

  * Questions for the Record: Ms. Marisol Cruz Cain; submitted by 
  Rep. Walkinshaw.

  * Questions for the Record: Mr. David Maimon; submitted by Rep. 
  Sessions.

  * Questions for the Record: Mr. Jay Stanley; submitted by Rep. 
  Frost.

  * Questions for the Record: Mr. Jay Stanley; submitted by Rep. 
  Walkinshaw.

These documents were submitted after the hearing, and may be 
  available upon request.


 
                       EMERGING FRAUD THREATS AND
                      THE EVOLVING FRAUD LANDSCAPE

                              ----------                              


                        WEDNESDAY, JULY 15, 2026

                     U.S. House of Representatives

              Committee on Oversight and Government Reform

                 Subcommittee on Government Operations

                                                   Washington, D.C.

    The Subcommittee met, pursuant to notice, at 2:03 p.m., 
Room 2154, Rayburn House Office Building, Hon. Pete Sessions, 
[Chairman of the Subcommittee] presiding.
    Present: Representatives Sessions, Foxx, Palmer, Jack, 
Mfume, Norton, Frost, and Randall.
    Also present: Representative Walkinshaw.

          OPENING STATEMENT OF CHAIRMAN PETE SESSIONS

                   REPRESENTATIVE FROM TEXAS

    Mr. Sessions. Good afternoon, and welcome to today's 
hearing on emerging threats and the evolving fraud landscape 
here in the United States of America. Over the years, the 
Government Operations Subcommittee, on a bipartisan basis, has 
held several hearings addressing the issue of fraud, addressing 
the things that the U.S. Government faces, as well as the 
American people. And each time we have been talking about 
fraud, how to identify it and how to prevent it. In our 
discussions, we have highlighted the importance of government 
agencies focusing on preventing fraud before it happens. And, 
as we have heard countless times before, once the money has 
gone out the door, it is hard to get back.
    This remains a very important issue in this Subcommittee, 
to both the young Ranking Member and myself in this 
Subcommittee, is very important. But one critical element 
missing from our many conversations is what sort of fraud are 
we trying to prevent? How does it really work? What really are 
we doing about it? And where do we need to focus our attention 
to make sure that we are going to address this properly?
    In our past discussions, we have referenced the fraudsters 
in a dark room stealing Aunt Sally's Social Security number. We 
have highlighted the risk posed by foreign actors applying to 
multiple disaster relief programs. We have discussed elaborate 
fraud rings that exploit loopholes in benefit programs in order 
to receive payment for services that they should not have 
received, but perhaps got the money.
    But fraud threats are changing, and they are rapidly 
advancing. Identifying fraud threats specifically are booming 
as fraudulent actors become smarter and gain access to tools 
intended to make our life easier and their life easier through 
AI. This gives them more power. It is up to us to catch up. It 
is up to us to find it and to find a way that we are going to 
corner the market on our side of the agenda.
    Government programs rely on identity verification to 
confirm that the individual applying for benefits and services 
are who they say they are. However, we have seen over the years 
the platforms used for these verifications have failed to meet 
the expectations.
    In March 2023, this Subcommittee held a hearing focused on 
Login.gov. And the troubling findings from the General Services 
Administration's Inspector General report that was released 
that month told us point-blank we have a problem. In short, GSA 
misled government clients about the extent to which Login.gov 
met certain technical standards and expressly what they said it 
would do. These standards were the backbone of what was needed 
to ensure that an identity verification platform could prevent 
fraud, protect the taxpayer, and give the government the 
necessary information that it would need to know who they were 
speaking to and what that person might be eligible for, for 
benefits.
    Over the years, many changes have been made to Login.gov, 
and Federal agencies have explored other public- and private-
sector solutions for digital identification verification. As we 
are moving to a more digital environment where individuals may 
no longer be asked to present a physical ID card, we need to 
better understand what threats there are and what the fraud 
landscape looks like.
    Today's fraud landscape looks different than the one that 
existed when we started this investigation, and it is rapidly 
evolving even today. Fraudsters from literally anywhere in the 
world can now create hundreds or thousands of synthetic 
identities and apply for many different government benefit 
programs simultaneously. It is no longer they could; they are. 
Bad actors are able to develop the use of deep fakes, mimicking 
the likeness of an individual to circumvent the safeguards that 
have been put in place to protect the taxpayer.
    Bad actors have made it their business to exploit 
vulnerabilities in government programs. It is necessary that we 
understand that they have been successful, and we need to make 
sure we are developing the tools that actually allow us to see 
the fraud before it occurs, not when it is out the door. 
Identity verification has long been a one-time check at the 
beginning of an application process, but considering the rapid 
evolution of identity fraud, we should start thinking about 
validating and constantly validating identity as it moves 
forward.
    Fraud should not be considered the cost of doing business 
because it means that someone is not getting the benefit that 
they were eligible for. And if there is one overriding 
principle that this Subcommittee, all of our Members agree on, 
it is that the people who we have intended the benefits to go 
to, they should be the ones that get it. And any diminishment 
of that is considered a failure on our part also.
    In January of this year, I introduced bipartisan 
legislation to combat identity fraud and theft. The Stop 
Identity Fraud and Identity Theft Act aims to strengthen the 
Nation's digital identity verification infrastructure and 
protect individuals, businesses, and government programs from 
rising identity fraud and theft. I am hoping that this 
legislation is a step in the right direction. And after meeting 
with our panel members, I will tell you it is a step because we 
are going to learn more today in this rapidly evolving 
landscape that we call fraud, along with the verification 
systems that are available today.
    We have a great panel of witnesses who can shed light on 
new identity fraud threats plaguing our systems, how the fraud 
landscape is evolving, and what the government should be doing 
and is doing to keep up with that. I look forward to a fruitful 
discussion.
    And I want to personally thank our Ranking Member, Mr. 
Mfume, for his continued support. Those of you who are new to 
this Subcommittee will learn that both Mr. Mfume and I insist 
on making sure that we work well together, that we listen to 
each other, that we listen to all of our Members and allow them 
to fully participate, adding thoughts and ideas, but perhaps 
more importantly, to show up and listen and learn about the 
landscape that is directly in front of us.
    Mr. Mfume is a very dear friend of mine. He is a man who 
has a distinguished service, not just to the U.S. Congress, but 
to the United States of America and to his district. And you 
will soon learn, those of you who are here, that we have many 
distinguished Members of this Subcommittee who are here because 
they believe in not only doing their job, but also helping us 
curb the appetite that fraudsters have to take advantage of our 
citizens.
    With that said, I would like to now ask the gentleman if he 
would engage us with any opening statement he would like to 
make. The distinguished gentleman is recognized.

        OPENING STATEMENT OF RANKING MEMBER KWEISI MFUME

                  REPRESENTATIVE FROM MARYLAND

    Mr. Mfume. I want to thank you, Mr. Chairman, for your kind 
and clearly overly gracious set of remarks, for your 
friendship, for your stewardship of this Committee [sic], and 
for the ability for us on both sides of the aisle to really 
delve into detail on various issues, but none more important 
than this issue of fraud.
    I know I speak for all of my colleagues on my side of the 
aisle when I say we welcome this hearing, as we did the 
previous one. We look forward to finding answers, quite 
frankly, and finding a way to get out of the situation that we 
are in with respect to the level and the significance of fraud 
within our government.
    So, we are here today to talk about fraud, particularly 
emerging threats and solutions related to digital identity 
verification. Social Security numbers and paper cards made 
sense 90 years ago, long before the current age of computers 
and digital technology. Programs have matured, scammers have 
adopted them and found a way to get around them, and so the 
government must also, I think, adapt its service delivery and 
technology to prevent fraud and to better serve the American 
people.
    That adaptation was exactly what the Federal Government had 
in mind many years ago when it came up with the idea and then 
later became the reality of something called Login.gov, which 
we are all familiar with, a single secure sign-in that works 
across agencies. Before Login.gov, each agency maintained its 
own identity verification. Good luck with that one. It was not 
just a headache for our constituents, it was also a costly 
overlap in functions and a critical cyber vulnerability.
    While the GSA may have stumbled out of the gate with the 
initial release, we finally reached a point, I think, where 
agencies across all levels of government have a safe, secure, 
and verified gateway to government services that improves the 
customer service and helps our constituents across the services 
and the resources that their taxes pay for.
    The turnaround in this program serves as an important 
example of bipartisan congressional oversight. Where once 
accusations of false promises dogged that program, Login.gov 
can now effectively serve the American people. We first 
learned, however, of the issues with Login.gov when the General 
Services Administration Inspector General published a report 
finding that several individuals at GSA had misled its agency 
customers that the system could do higher levels of identity 
verification than GSA itself. Those sort of things created 
problems.
    Three years ago, we had a hearing exploring the issue and 
sent further follow-up letters, as the Chairman indicated, and 
briefings to ensure that GSA fixed the system that provided the 
service that they promised their agency clients. A year after 
our hearing, GSA announced it had fully implemented the 
National Institute of Standards and Technology's standard and 
had rolled it out to their agencies and to their partners. 
Today, Login.gov has over 100 million users across more than 50 
agencies and 500 applications across Federal, state, and local 
government.
    Now, that does not mean that the work to ensure digital 
identity verification across the entire Federal Government is 
finished. I look forward, like many of you, to hearing from our 
witnesses today about how we can effectively implement the next 
generation of Login.gov and identity management. However, we 
must carefully consider the difficulties and the pitfalls of 
the new technologies and not just assume that they do not have 
any.
    Innovations like digital ID can better combat fraud and 
electronically safeguard identity, much more so than a 9-digit 
number on a piece of paper. Digital ID sounds great. I would 
not need to carry around a plastic license, just a smartphone 
if I am the average American citizen with cutting-edge 
technology to safeguard my personal information. The problem 
is, however, that that very phone provides a new vector of 
attack, and any computer is vulnerable to a cyber attack, as we 
know, regardless of its level of sophistication.
    Digital ID can also limit access for people who have 
trouble using technology and even for people who cannot afford 
a smartphone. Sometimes, people just break their phones and 
cannot take time out of their busy day to immediately go and 
get a new one, so I do not think we can afford to lock people 
out of government or private services because they cannot 
access or afford a smartphone. Anytime the government can 
revoke access to services, even for benevolent purposes, we 
must find a way to protect against abuse.
    The Trump Administration's DOGE program, the Department of 
Government Efficiency, which many of us thought was the 
Department of Government Evil, used a key Social Security 
Administration identity database to mark thousands of living 
people as dead in order to exert financial hardship. A 
whistleblower recently said that he planned to expand this to 
millions of people. Now, do we really want to move to a system 
where the government can invalidate any ID it wants to just by 
sending an instruction to the phone that is in your pocket?
    I can absolutely think of places where digital ID has valid 
uses for age verification and for fraud prevention, but every 
place that an American taps their phone to access services 
cannot be a ``bread crumb to the track'' or ``bread crumb 
follow the track'' process in their daily lives.
    So, I am excited to have those of you who are here to 
discuss the new technologies to prevent fraud against the 
American taxpayer. We must also ensure that we keep an eye on 
the horizon to prevent any sort of mass surveillance and 
government surveillance that can literally decide if, in fact, 
we are considered live or dead.
    So, I want to thank the Chairman again for keeping his 
commitment on this issue, for Members on both sides of the 
aisle that continue to plow through this. It has been a couple 
of years now. We are going to continue to do what we have to do 
until we cannot do it anymore. And I appreciate the opportunity 
to have all of you here and hear what you have to say on the 
record.
    And Mr. Chairman, I yield back to you.
    Mr. Sessions. The gentleman yields back his time. Thank you 
very much.
    I would like to ask unanimous consent, if I can, to allow 
the distinguished gentleman, who has a meeting that he has to 
attend, to very quickly give some brief remarks.
    I would like to yield time now to the distinguished 
gentleman, Chairman Gary Palmer. Chairman Palmer, you are 
recognized.
    Mr. Palmer. Thank you, Mr. Chairman. Thank you for holding 
this hearing, and I would like to thank the Ranking Member for 
the bipartisanship that we have seen throughout this process in 
trying to address the fraud and also other issues related to 
improper payments.
    This is an extremely important issue. I just came out of a 
meeting with Dr. Phillip Swagel, the Director of the 
Congressional Budget Office, and we estimate just the initial 
investigations into fraud that will have about $168 billion in 
savings. I want to make certain that people understand this is 
not just about the money. So much of this fraud mismanagement 
occurs in programs that are designed to help people who need 
help. And when we are losing that much money, we are being 
defrauded of that much money, those are funds that are not 
available for people who are truly in need. So, this is a huge 
issue for us, and it is not limited to domestic fraud. What we 
saw during the COVID pandemic, the programs at the Federal 
level were being defrauded by a massive network of foreign 
actors.
    But we also have other issues, aside from the fraud. I 
think, one of the things that we found is that there is a 
tremendous need to modernize Federal data systems, bring them 
into the 21st century because a lot of the issues that we have 
with improper payments are directly related to antiquated data 
systems.
    So, Mr. Chairman, I really hate that I am not going to be 
able to participate in this hearing. I think it is extremely 
important and would have benefited greatly from hearing the 
questions to our witnesses and their answers.
    With that, Mr. Chairman, again, thank you for the privilege 
of being able to address the issue. I yield back.
    Mr. Sessions. The gentleman yields back his time. Thank you 
very much.
    Without objection, Congressman Walkinshaw of Virginia is 
waived onto the Subcommittee for the purpose of questioning the 
witnesses at today's Subcommittee hearing.
    I now would like to move to welcome our witnesses who have 
taken their time today to be with us, and I am very delighted 
to say that I think that you will find and the Members will 
find their input very valuable to exactly the same things that 
the Chairman was talking about, and that is that we need to 
understand what is out there today. It is easy for us to think 
that we understand a lot, and we are going to learn a lot 
today.
    So, I am pleased to welcome our witnesses. Mr. Jordan 
Burris is Vice President and the Head of Public Sector at 
Socure, where he partners with government leaders to develop 
and implement private-sector solutions for identity 
verification and fraud risk management.
    Next, we have Marisol Cruz Cain, who is Director of 
Information Technology and Cybersecurity at the GAO. The 
Government Accounting [sic] Office has experts that provide not 
only expert testimony, but have an idea of the day-to-day 
activities that move across the government. She oversees 
Federal cybersecurity and privacy work. Her portfolio includes 
emerging technologies, the National Cybersecurity Strategy, and 
agency efforts to protect privacy, sensitive data, and critical 
computing infrastructure.
    Next, we have David Maimon, and he is the Head of Fraud 
Insights at SentiLink, a company that combines technology and 
expertise to stop identity fraud at the application stage. He 
is also a professor in the Department of Criminal Justice and 
Criminology at Georgia State University, where he directs the 
evidence-based Cybersecurity Research Group.
    Last, Mr. Jay Stanley is a senior policy analyst at the 
American Civil Liberties Union. His work focuses on technology-
related privacy and civil liberties issues and that future and 
how it impacts public policy.
    Thank you to each of you for joining us. I would now ask 
that each of you rise in pursuant to Committee Rule 9(g). The 
witnesses will each, as they stand, to take the--you can all 
stand please--to take the oath to the witnesses, and I would 
ask that you please raise your right hand.
    I will read this and then let you affirm or choose as you 
would do.
    Do you solemnly swear or affirm that the testimony that you 
are about to give is the truth, the whole truth, and nothing 
but the truth, so help you, God? That is a question.
    Mr. Burris. I do.
    Ms. Cruz Cain. I do.
    Mr. Maimon. I do.
    Mr. Stanley. I do.
    Mr. Sessions. Please let the record reflect that the 
witnesses have answered in the affirmative. Thank you very 
much. You may all take your seat.
    I have had an opportunity to speak with each of you, 
hopefully, except Mr. Stanley. Mr. Stanley, I want you to know 
that I have advised the other witnesses here that we appreciate 
you being here as we do them, that I run the Committee [sic] 
hearings differently. I would like for you to be able to finish 
your sentence. I would like for you to be able to complete your 
thought. I would like for you to be able to thoughtfully 
respond and provide this Subcommittee with the things which you 
have come professionally to do to us.
    At 5 minutes, I am not going to bang the gavel. You are 
here. You are a professional. We need to hear from you, and I 
try and give that same type of leverage to each of our Members. 
So, I am delighted. But with that said, if you do not take 
advantage of it, I will not either. We have an idea that we are 
trying to move our business and allow our Members an 
opportunity to come and do their business also.
    So, we will now move forward with the feedback from our 
witnesses, and we will first move to the distinguished 
gentleman, Mr. Burris. Mr. Burris, you are recognized for 5 
minutes.

                 STATEMENT OF MR. JORDAN BURRIS

       VICE PRESIDENT AND HEAD OF PUBLIC SECTOR STRATEGY

                             SOCURE

    Mr. Burris. Chairman Sessions, Ranking Member Mfume, and 
Members of the Subcommittee, thank you for your leadership on 
this critical topic and for the opportunity to be back here to 
be part of the conversation.
    For the last 15 years, I have worked on one question from 
inside and outside the government. How do we know with 
confidence that the person on the other side of a digital 
transaction is who they claim to be? Today, that question has 
become far more difficult to answer. And here is the blunt 
truth. The way the Federal Government verifies identity was 
designed for a threat that no longer exists. Every day, 
however, we defend that old model as though it still does and 
give fraud networks another opportunity to steal taxpayer 
dollars and undermine public trust.
    GAO estimates Federal fraud losses at as high as $521 
billion every year. Further, the pandemic exposed just how far 
our identity infrastructure has fallen behind. Those losses 
were a warning. Today, the gap has widened dramatically, and by 
the time we update the next set of estimates, it will be double 
or triple the size.
    My name is Jordan Burris, and I lead the public sector 
business at Socure. Socure was founded on a simple premise. In 
a digital world, proving who someone is should be accurate, 
fast, and fair. Today, our AI native identity and fraud 
intelligence platform helps more than 3,000 organizations 
globally, including over 150 public sector organizations, make 
trusted identity decisions. That broad view allows us to see 
how fraud evolves across the economy and increasingly targets 
the government.
    Before joining Socure, I served as Chief of Staff in the 
White House Office of the Federal Chief Information Officer, 
helping shape Federal identity policy through the COVID 
response and the government's transition to zero trust after 
SolarWinds. Working inside the government and in the private 
sector has shown me just how rapidly this threat has evolved.
    Some of the identity industry have begun calling this 
moment World War Fraud, and I understand why. We are no longer 
confronting isolated fraudsters. We are facing organized, 
increasingly sophisticated, transnational fraud rings using AI 
at industrial scale. One fraud ring we profiled created nearly 
25,000 synthetic identities and launched more than 35,000 
attacks in just 30 days.
    The adversary has changed. Our Federal identity model, 
however, has not, and yet many in the government believe it 
will hold up to today or even tomorrow's fraud threat. For 
decades, the government has treated matching a name, date of 
birth, and Social Security number validated against government 
authoritative records as proof of identity. That approach is no 
longer sufficient. Further, fraud does not stop at enrollment, 
and identity verification cannot either. It must become a 
continuous discipline that evaluates risk throughout the 
lifecycle of an account.
    From where I sit, identity should be considered critical 
infrastructure. Nearly every interaction Americans have with 
their government--benefits, tax administration, disaster 
relief, veteran services, and healthcare--depends on getting 
this decision right. Done correctly, better security means 
better access. It makes it easier to say yes to legitimate 
Americans and no to industrialized fraud rings.
    This year, Socure supported the Department of Education in 
deploying real-time risk-based identity screening in the Free 
Application for Federal Student Aid (FAFSA) process, protecting 
more than $1 billion in taxpayer funds, while allowing over 92 
percent of legitimate applicants to pass automatically. That is 
the model the government should continue pursuing. Prevention 
before payment, risk-based rather than one-size-fits-all, 
continuous rather than point-in-time, and outcomes rather than 
checklists.
    To make this the Federal model, I would leave the Committee 
with five recommendations. First, measure outcomes, not 
compliance, requiring systems to prove that they can stop the 
changing fraud threat.
    Second, make continuous identity verification the standard 
across the lifecycle of an account.
    Third, expand secure data sharing where we know it works, 
through trusted resources like Do Not Pay and other cross-
government solutions.
    Fourth, reward fraud prevention instead of recovery, where 
agencies are incentivized to stop fraud before taxpayer dollars 
ever leave the Treasury.
    And finally, treat identity verification as dynamic 
infrastructure that must be resourced to evolve continuously, 
not built once, certified once, and left in place for a decade.
    To be clear, Congress does not need to prescribe a specific 
technology, but Congress can establish a new expectation. The 
technology exists, and the evidence is clear. Now, our policies 
and practices must catch up to the threat, so Americans can 
trust their government in the AI era.
    Thank you, and I look forward to your questions.
    Mr. Sessions. Mr. Burris, thank you very much.
    We now move to the gentlewoman, Ms. Cain. Ms. Cain, you are 
recognized for 5 minutes.

               STATEMENT OF MS. MARISOL CRUZ CAIN

                            DIRECTOR

            INFORMATION TECHNOLOGY AND CYBERSECURITY

             U.S. GOVERNMENT ACCOUNTABILITY OFFICE

    Ms. Cruz Cain. Chairman Sessions, Ranking Member Mfume, and 
Members of the Subcommittee, thank you for inviting GAO to 
contribute to this important discussion on identity-related 
fraud threats and Federal efforts to improve identity 
verification processes.
    As you know, Federal agencies use personally identifiable 
information to verify the identity of individuals who access 
accounts on government websites. An increase in sophisticated 
cyber-attacks has led to a greater risk of that Personally 
identifiable information (PII) being stolen and used to commit 
different types of fraud. Malicious actors can then use that 
information to fraudulently receive government benefits, commit 
tax- or wage-related fraud, or create new credit cards or take 
over people's accounts. These attacks can harm individuals, 
result in financial loss, or damage the reputation of Federal 
agencies and financial institutions.
    Because of this, GAO has long emphasized the urgent need 
for the Federal Government to improve its ability to protect 
against these cyber-attacks. Today, I will focus on issues 
related to identity-related fraud threats. I will also discuss 
the recent actions that GSA has taken to improve Login.gov's 
identity verification services and alignment with Federal 
guidelines.
    Fraud has been a longstanding issue within the Federal 
Government. One particular type is identity-related fraud, 
which can include thieves opening new accounts in someone 
else's name or stealing PII to obtain government benefits. For 
example, we have reported that hundreds of billions of dollars 
were lost to the--in the pandemic to potentially fraudulent 
payments.
    The harms caused by breaches of PII or identity theft can 
extend beyond tangible financial loss to include lost time, 
such as when those victims spend months or years even working 
to restore their identities. Additionally, there can be 
reputational harm or emotional distress.
    To address these issues, GSA developed Login.gov as a means 
to verify users' identities who want to create an account to 
access Federal websites. Accordingly, GSA has a significant 
responsibility for protecting users' PII that they collect 
during that process. In 2024 and 2025, we reported on 
Login.gov's process for identity verification, its misalignment 
with Federal guidelines for identity verification, and fraud 
prevention measures.
    In our reports, we identified several weaknesses in GSA's 
implementation of Login.gov, including that the system did not 
meet the requirements to verify a person at the ILA-2 level, 
and that was because the system never included a physical or 
biometric comparison to link a user to a specific real-life 
identity. As a result, we recommended that GSA take four 
actions to ensure that the PII is better protected and to 
lessen the risk of identity theft. To its credit, GSA has fully 
implemented three of those actions. Most importantly, they have 
completed their remote identity proofing pilot, ensuring that 
the system is compliant with National Institute of Standards 
and Technology (NIST)'s ILA-2 standards. However, GSA has not 
taken important steps to collaborate with agencies to address 
Login.gov's technical challenges.
    GSA has developed a roadmap that outlines planned and 
ongoing efforts to improve its system functionality. However, 
this action alone does not fully address all of the technical 
challenges that we identified in our report. For instance, 
agencies reported that they lacked visibility into 
authentications, that the system had a high failure rate, and 
also, it lacked fraud controls. GSA's roadmap did not contain 
efforts directly aimed at addressing these challenges. It is 
important for GSA to work with agencies to solve these issues, 
as doing so will help ensure that Login.gov delivers the 
functionality agencies need to effectively verify users' 
identities while also combating fraud threats.
    In summary, identity-related fraud threats are pervasive 
and likely to continue to escalate. Protecting individuals' PII 
is critical, as the harms can be significant. GSA has taken 
several actions to improve Login.gov, but needs to continue to 
address fraud and technical challenges.
    This concludes my remarks, and I look forward to answering 
any questions you may have. Thank you.
    Mr. Sessions. Ms. Cruz, thank you very much.
    Dr. Maimon, you are now recognized.

                 STATEMENT OF MR. DAVID MAIMON

                     HEAD OF FRAUD INSIGHTS

                           SENTILINK

    Mr. Maimon. Chairman Sessions, Ranking Member Mfume, and 
Members of the Subcommittee, thank you so much for the 
opportunity to testify today.
    I serve as Head of Fraud Insight at SentiLink and as a 
professor of criminal justice and criminology at Georgia State 
University. For nearly two decades, I have studied cybercrime 
by going where it happens, into darknet markets, telegram 
channels, and encrypted platforms where fraudsters buy, sell, 
and teach each other how to steal from government programs. I 
also go into the field myself, to the mail drops, virtual 
offices, and shell addresses these operations use to look 
legitimate. My testimony today is based on that firsthand work.
    The central lesson from my research is this: Fraud against 
government programs is no longer a series of isolated schemes. 
It is a durable, specialized criminal infrastructure, and it 
moves. The pandemic did not create this infrastructure, but it 
supercharged it. Criminals learned how to acquire stolen and 
synthetic identities, stand up shell companies, open bank 
accounts, and recruit money mules at scale. When pandemic 
relief programs ended, none of that capacity disappeared. It 
simply migrated.
    Today, my team is tracking that same infrastructure inside 
Supplemental Nutrition Assistance Program (SNAP), Medicare, 
Medicaid, Federal student aid, tax refunds, and Small Business 
Administration (SBA)-backed loans. A few examples illustrate 
how. We are watching criminals combine stolen identities with 
AI-generated faces and deepfake video to defeat liveness checks 
at digital banks and tax preparers using nothing more exotic 
than face swapping software available to anyone. We are 
watching an Electronic Benefits Transfer (EBT) fraud market 
where one criminal steals card data, a separate paid service 
verifies the balance before the card is even used, and the 
third actor cashes it out. And my own field investigation of a 
Florida durable medical equipment company, whose office I found 
abandoned in Delray Beach, is now tied to a Department of 
Justice case alleging $3.76 billion in fraudulent Medicare and 
Medicaid claims.
    Different programs, different agencies, same playbook--the 
same stolen identity, the same shell company, the same bank 
account, reused across systems that rarely talk to each other. 
Debt fragmentation is the vulnerability. Criminals exploit the 
seams between agencies precisely because our defenses are built 
program by program, while their infrastructure is built to move 
across all of them.
    Given my time today, I want to leave the Subcommittee with 
four priorities. First, replace self-attestation with verified 
data wherever the risk is high. Too many programs still take 
applicants at their word on income, identity, or eligibility. 
That was the single biggest vulnerability exploited during the 
pandemic, and it remains one today.
    Second, expand real-time cross-agency data matching. The 
same identity that files a fraudulent tax return can apply for 
a SNAP benefit the same week. Agencies that only compare notes 
and periodic bet runs weeks after the money is gone cannot see 
that pattern. They need to see it before disbursement, not 
after.
    Third, strengthen prepayment screening and move toward 
risk-based disbursement. Built on the model of Treasury's Do 
Not Pay system, but expand its authority and its reach so that 
suspicious payments are held before they leave the government, 
rather than chased afterward through recovery audits that 
criminals have already outrun.
    Fourth, give agencies the flexibility to adopt smarter 
tools and keep it current. Much of today's verification 
infrastructure and the policies behind them were built for an 
earlier threat. And procurement and rulemaking cycles that take 
years cannot keep pace with fraud tactics that shift in months 
or less. Agencies need standing authority to test and deploy 
technologies to meet the current threats, not just at the next 
scheduled audit. None of this requires slowing down help for 
legitimate applicants. It requires distinguishing them from 
fraud earlier, using signals criminals cannot easily fabricate.
    The Federal Government already has some of the tools it 
needs, what is missing is the authority, the coordination, and 
the sustained investment to use those tools before the money 
moves, not after. Every dollar we protect from organized fraud 
is a dollar that stays available for the people Congress 
intended to help.
    Thank you, and I look forward to your questions.
    Mr. Sessions. Dr. Maimon, thank you very much.
    Mr. Stanley, welcome. We are delighted that you are with 
us. The gentleman is recognized.

        STATEMENT OF MR. JAY STANLEY (MINORITY WITNESS)

                     SENIOR POLICY ANALYST

                 AMERICAN CIVIL LIBERTIES UNION

    Mr. Stanley. Thank you so much. Chairman Sessions, Ranking 
Member Mfume, and Members of the Subcommittee, thank you for 
inviting me to testify today, and thank you for your attention 
to the subject of digital identification, which I do not think 
has received the attention it deserves.
    I hope to leave you with three overarching points today. 
First, a digital ID system would be a disaster for individual 
liberties if it is not done right. If any such system is to 
become standardized, it must be built with great care and 
awareness of big potential downsides. We have to ensure America 
does not become a checkpoint society and that digital IDs do 
not become virtual ankle monitors, something that tracks us, 
but we cannot turn off or escape.
    Second, the digital ID system that is most likely to become 
dominant, mobile driver's licenses or MDLs issued by the 
states, is not being done right. Driver's licenses are already 
in most Americans' wallets and are by far the most likely form 
of digital ID to become standard. Login.gov itself is moving 
toward relying on them.
    Third, there are much better alternatives if we just do it 
right.
    So, let me start by explaining my first two points, that 
digital IDs have the potential to be a disaster if they are not 
done right, and that they are not being done right today. One 
big problem is that once this infrastructure is built, we start 
getting identity requests from every direction. Want to enter a 
7-Eleven? Scan your ID. Want to buy a cup of coffee, park your 
car? Tap here, please. Want to watch a video, log into social 
media, look at a news site, shopping site? Click here to send 
us your driver's license.
    There is already far too much tracking that takes place 
online, and polls show Americans are very uncomfortable with 
it. But there has been a steady pushback, and that tracking has 
been getting harder for companies in some ways. A digital ID 
could lock it down and make it inescapable. You cannot just run 
to the Department of Motor Vehicles (DMV) and get a new 
identity the way you can get a new username and password.
    Those pushing MDLs in the states have done nothing to 
counter this easily predictable side effect. We may create a 
digital ID to solve government fraud or identity theft or other 
problems, but there is a horde of others waiting in the shadows 
who will instantly pounce on this infrastructure to use it for 
their own purposes once it is created. The result will be a 
checkpoint society of constant ID proofing. With a digital ID 
that will be really easy. Just tap, click, or scan.
    And a digital ID system, if not built carefully, could send 
a report back to the government every time you show your ID, a 
record of every beer purchase, bank, and doctor's office visit, 
and online, every website you visit. This is called ``phone 
home.'' This capability was built into the MDL standard as an 
option.
    There is also the issue of accessibility. If digital IDs 
become mandatory, either legally or as a practical matter, that 
would harm the surprisingly large number of people who do not 
have a smartphone, about one in ten people in the United States 
according to studies, including over 1/5 of people over age 65. 
Some may lack the resources to afford one; others, the 
technological literacy to use them. That is why offline options 
for doing business are vital to protect. If we do not make sure 
that digital IDs are an empowering option for people rather 
than an imprisoning requirement, then people without 
smartphones will be shut out of many necessary functions of 
life and often benefits that they sorely need. So, these are 
easily foreseeable, predictable consequences of a digital ID.
    But that brings me to my third point. If a digital ID is to 
be created, there are alternative paths that would prevent many 
of these harms. In terms of alternatives, I have two quick 
points to make before I stop.
    First, the field of privacy-enhancing cryptography is 
advancing fast and already can do amazing things that allow us 
to have our cake and eat it too when it comes to privacy and 
security. One example is privacy-enhancing technology called 
zero-knowledge proofs. Using that kind of tech, digital IDs can 
let me prove I am over 21 without sharing my date of birth or 
my identity. And it can do that in a way that if I prove my age 
multiple times to the same seller, they do not even know that I 
am the same person. That is the kind of thing that is needed to 
stop IDs from being this kind of ankle bracelet tracker.
    But that kind of technology is useless if we do not bother 
to build it in, and it has not been built into the MDL 
standard. If a system can reduce fraud and provide other 
benefits without enabling tracking, why would we build one that 
does enable tracking? There are other key protections we can 
build. On our website, we have outlined 12 key protections that 
we think are necessary in a digital ID system. There is more 
about that in my written testimony.
    And then, second, there are some states that are moving in 
the right direction here. Some, like New Jersey and Illinois, 
have put some important protections in place into their digital 
ID-enabling legislation. And the State of Utah is the most 
notable. It has set out a separate path, which they call State 
Endorsed Digital Identity, or SEDI, that is emerging as a far 
more privacy-protective alternative to the MDLs that many 
states have adopted. Some other states are starting to work 
with Utah to join in that effort and build that alternative 
path.
    The bottom line is if we build a digital ID system, it must 
be done right. We urge Congress to ensure that it is. American 
freedom is the top priority.
    Thank you very much, and I look forward to your questions.
    Mr. Sessions. Mr. Stanley, thank you very much. I 
appreciate each of the witnesses being here.
    I would like to move first to the distinguished gentleman, 
Mr. Jack, for his questions. The gentleman is recognized.
    Mr. Jack. Thank you very much, Mr. Chairman.
    And I appreciate your testimony this morning, Mr. Burris. 
My first question is for you. The public increasingly relies on 
the internet to access government services, and I am just 
curious, from your perspective, what fraud threats might my 
constituents be facing that they are not even aware of yet?
    Mr. Burris. Representative, thank you for the question. 
When it comes to the fraud threats and the way that they are 
evolving across the landscape, every single interaction, every 
single time that an individual is engaging both with their 
government and in their commercial life, there is the chance, 
the opportunity, that an adversary could be attempting to pose 
as them, could be attempting to enroll in an account. We see 
this across financial services where we work. We see this 
across various aspects of the gig economy where we work, and 
then, of course, with government organizations.
    The reality here is that all of the information, all the 
PII that exists for many folks within this room has been stolen 
by the adversary, and they are using that to attempt to become 
them, and therefore, that they can access what would be either 
their bank accounts and help move money all across the economy.
    Mr. Jack. You know, I have heard folks mention anecdotally 
that now with artificial intelligence, people are trying to 
impersonate, you know, a loved one by virtue of maybe their 
voice or their mannerisms, what have you, and using some of 
that information that may have been stolen. Have you seen that, 
and could you elaborate on that for us?
    Mr. Burris. Yes, absolutely. We are in a, what I would 
consider, a national crisis from where I have said, I have 
highlighted and our team has highlighted--Socure--for a number 
of years now that the moment that we are in is unlike any other 
in the sense that AI is being used as an accelerator for what 
attacks that typically would take weeks to occur. And further, 
it is also becoming more cost-effective for the adversary to 
launch those attacks. So, these attacks could be everything 
from launching deepfakes, things where we have seen an 8,000 
percent increase year over year.
    This can also be in terms of the velocity by which attacks 
are happening. This means the speed by which they are 
occurring. And in these instances, these moments, we are seeing 
things that--where attacks used to take weeks in order to be 
conducted, they have been broken down to under 48 hours. And 
this would mean that an adversary has launched an attack where 
they have stolen my information or yours, or even worse, 
fabricated an identity, attempted to open an account and/or 
move money, take over an account that may have existed because 
they went through a call center and were pretending to be you 
using your voice or something that was cloned, an image of 
yours, a biometric, et cetera, and they have used all these 
patterns. And if, like, for, say, they were blocked in some 
way, shape, or form, they then just adapt and iterate, and the 
cycle continues all over again.
    Mr. Jack. Thank you very much.
    Dr. Maimon, do I understand, are you a professor at Georgia 
State University? So, I wanted to acknowledge, first and 
foremost, both my mother and father went to Georgia State 
University. I represent many people who have degrees from 
Georgia State University, and I also host Panthers in the 
district from time to time, so bringing students up here.
    So, I am curious, to build off that last question, you 
obviously understand, you know, criminology, you are a 
professor of it. Help us understand, are most of these threats 
coming from inside our country, or are we starting to see 
foreign adversaries exploit some of this data to, you know, 
fraudulently impact some of our constituents?
    Mr. Maimon. Thank you so much for the question, really 
appreciate it. A lot is coming from abroad. We have a lot going 
on internally as well. It really depends on the type of fraud 
we are looking at. In the context of the type of fraud you just 
mentioned, with folks engaging in online romance fraud, we are 
seeing a lot coming from places like South Asia. A lot is 
moving right now to Africa. In some of the online fraud markets 
that I infiltrate, I spend a lot of time sort of trying to 
infiltrate Yahoo Boys channels, as well as Sakawa Boys 
channels, where I actually see them using those deepfakes to 
swap faces while engaging with some of the victims here in the 
United States.
    It is heartbreaking to see the level of conversations that 
these guys are able to get with those targets, and it is also 
heartbreaking to see the different modus operandi and different 
types of buckets that those criminals are engaging. I can tell 
you that, as of this morning, we are seeing more and more Yahoo 
Boys and Sakawa Boys targeting our 401(k)s, victims' 401(k)s. 
So, you know, we are seeing them convincing targets to borrow 
against the 401(k)s, as well as hand over control completely on 
the 401(k) accounts. So, this is what we are up against. We are 
seeing those deepfakes being used to swap faces, lure targets 
to give away access to the 401(k) accounts, and then, 
unfortunately, victims funnel the money to bank accounts that 
the criminals create, along with the targets, and then the 
money leaves the country.
    So, it depends on the type of fraud. The type of fraud that 
you are referring to definitely comes more from abroad.
    Mr. Jack. I appreciate all of your testimony today, and, 
Mr. Chairman, I am grateful you convened this hearing. I have 
learned a lot already in just this interchange, so thank you 
very much. Mr. Chairman, I yield the remainder of my time.
    Mr. Sessions. The gentleman yields back his time. Thank you 
very much.
    The distinguished gentleman, Mr. Mfume, you are now 
recognized.
    Mr. Mfume. Thank you, Mr. Chairman.
    Mr. Burris, I want to start with you because something you 
said struck me, and it might be the basis of why we are here 
and why we want to come back this way again, and that was that 
you said, if I am paraphrasing you correctly, that we are 
spending years and millions of dollars preparing for a threat 
that does not continue to exist. Can you expand on that, 
please?
    Mr. Burris. Absolutely. And in particular, the part of my 
testimony that I was highlighting was the fact that much of how 
the Federal Government has thought about its standards for how 
to prevent or protect digital identity--and to be very clear, 
digital identity is the makeup of how we present ourselves in 
cyberspace, right? Much of how the government has designed that 
standard today effectively was worked about a decade ago. And 
so, if we are looking at today's fraud threat, how it has 
evolved, how the adversary moves, it no longer can keep pace 
with what we are seeing today.
    So much so one of the efforts that, you know, our company 
led was, as we were engaging with NIST as part of their most 
recent update to the standard, was highlighting that fraud 
should become an underpinning of part of what we evaluate in 
digital identity and when it is established. Not because we 
want it to be harder for people to prove who they are, but 
because the alternative is that we are leaving a floodgate open 
for nation-states to launch their attacks. And from where we 
see it today, you know, there are over 7,500 fraud rings that 
are operating in their own different ways to attempt to attack 
what would be government services or even the commercial 
sector.
    Mr. Mfume. And Mr. Burris, as artificial intelligence 
advances at an alarming rate, what does the government, and in 
particular, what does Login.gov need to do to stay ahead of 
those scammers and to be able to identify them as we move 
forward?
    Mr. Burris. It all starts with admitting that there is a 
problem, so we are going to begin there and say that this is a 
crisis moment for where we are in. I think it is important that 
we understand that, as the Federal Government, we need to 
basically embrace and understand that we need to use AI to 
fight AI at this point. The adversary does not care about how 
anything is constructed, they do not care about our norms, they 
do not care about rules and regulations, they do not care about 
the ages of those who they are engaging with or their political 
affiliation. What they are attempting to do is to take money 
and resources to disrupt what would be the status, the norms, 
that we hold dear. And what we need to do is engage 
aggressively to basically put in place the types of controls 
and measures, many of which have been adopted in other sectors 
for years, in order to help prevent against this threat.
    For Login.gov in particular, I would say, and, you know, 
full disclosure, again, we are one of the vendors that are now 
have been added in order to power what Login.gov is doing. They 
are taking this threat absolutely seriously. In this day and 
age, another fraud team has engaged diligently to understand 
what needs to evolve with the program.
    Mr. Mfume. And Ms. Cruz Cain, you mentioned at some point 
in your testimony, I am trying to get back to it here, where 
GSA implemented four or five recommendations. What was the 
fifth recommendation? Is that still standing?
    Ms. Cruz Cain. We made four. They implemented three. And 
the last one was the agencies, the 24 Chief Financial Officers 
(CFO) Act agencies that we talked to, had technical challenges 
with Login.gov. So, as users, they were not necessarily able to 
use with ease, and they had some issues with the platform, such 
as they would like to know when the users are verified and 
authenticated, why they were not. So, if they fail, the person 
just says, hey, I failed. They have no way of knowing why they 
failed, how they can remedy that, so then you just do not have 
access to your government account so you cannot get your 
benefit. You have no recourse of knowing how that happens. So, 
either you just have to try again, or you have to go to the 
post office. That was one of the issues.
    Another issue is, at the time, they had a high failure 
rate, so they were just getting problems of even logging into 
the system or being able to use it. And at that time, they were 
not having such strong fraud controls. And again, to their 
credit, they have been taking the issue very seriously and 
partnering with new technologies and new companies to enhance 
their fraud controls. But they need to partner with the users 
to make sure that they are also helping them with the issues 
that they are having with Login.gov because if the users cannot 
use it--the technologies can be great, but if your users are 
still having issues using the system, you are going to lose 
that user base.
    Mr. Mfume. Thank you very much. Just one other quick 
question. Mr. Stanley, I appreciated your description of a 
digital ankle bracelet or ankle monitor, and you referenced 
driver IDs. Are they the most vulnerable?
    Mr. Stanley. I think that, in many ways, cryptographically 
secured----
    Mr. Mfume. Driver's licenses.
    Mr. Stanley [continuing]. Digital driver's licenses----
    Mr. Mfume. Are they less vulnerable?
    Mr. Stanley [continuing]. Are less vulnerable, probably, 
than many other techniques for validating identity. Mr. Burris 
talked about use AI to fight AI. There are many technologists 
who say that that is a losing battle, and that you will never--
it will always be a constant arms race because any AI that can 
be used to identify who is real versus who is not, that same AI 
can be used to fake somebody who is not real. And so that is 
why a lot of people in the technology world are turning to 
cryptographically secured tokens or identities so that, 
basically, the DMV or other issuer takes the data in your 
driver's license, digitally signs it with encryption, with a 
secret key, and then publishes a public key, and a verifier can 
look at the public key, and if it matches, it could only have 
been signed by the DMV and not a single bit could have been 
changed.
    And that is cryptography. And so, somebody can prove that 
the thing they have in their phone, the file they have in their 
phone, was issued by the DMV and signed by the DMV. And that is 
one of the reasons why we think that digital driver's licenses 
are poised to move to the forefront in online verification and 
why we worry about all the side effects of that kind of a 
system that I talked about.
    Mr. Mfume. Thank you. Thank you very much.
    I yield back, Mr. Chairman.
    Mr. Sessions. The gentleman yields back his time.
    Ms. Norton, you are now recognized.
    Ms. Norton. Thank you.
    Digital identification and modernized technology systems 
can help verify identities and reduce fraudulent claims, but 
they should not come at the expense or access to vital social 
safety net programs. Mr. Stanley, as more Federal, state, and 
local governments adopt digital identification systems, who 
risks getting left behind?
    Mr. Stanley. Yes, so exclusion is a big potential side 
effect of this kind of a system, and we will need to ensure 
that a digital identity is not mandatory, and we will need to 
pay the costs of ensuring that there are other options, lest we 
dial up the security dial too high and leave a lot of people 
who have genuine needs and are genuinely qualified for benefits 
being locked out.
    We know, in addition to what I said, about 20 percent of 
people over age 65 and ten percent of Americans not having 
smartphones. Studies have found that people with disabilities 
are 20 percent less likely to have smartphones. People with 
incomes under $30,000 a year, 25 percent do not have 
smartphones. Thirty percent of rural Americans lack fixed 
broadband and good internet access, and many people with low 
incomes are on limited data plans.
    And so, basically, we need to ensure that we never assume. 
And a lot of these things will improve over time. Some of these 
studies are a few years old and probably are out of date 
already, but we are never going to get to the point and we 
should never make policy based on an assumption of 100 percent 
adoption of technology because there will always be people who 
cannot or will not or simply do not want to and should have the 
freedom not to use all these advanced technological systems. 
So, I hope that answers your question, Congresswoman Norton.
    Ms. Norton. Mr. Stanley, which populations are most likely 
not own smartphones?
    Mr. Stanley. Sorry, the populations most likely not to own 
smartphones?
    Ms. Norton. Yes.
    Mr. Stanley. Yes, it is again, older Americans and low-
income Americans, disabled Americans. Low-income Americans, of 
course, are disproportionately people of color, and so I think 
those are the populations that would be most affected. People 
who are--often already face a lot of marginalization in life 
may find themselves further locked out of paths toward fully 
living in our society.
    Ms. Norton. Well, Mr. Stanley, given the increased adoption 
of digital identification, are people without smartphones at 
risk of reduced access to government services?
    Mr. Stanley. Well, yes. What we see is that something--a 
technology like a digital ID tends to move over time from being 
an option that empowers people, to being expected, to becoming 
normalized, and then people who do not have it end up as freaks 
and edge cases that just are not accounted for by the systems 
that run our governments, our benefits, and many private-sector 
goods as well. And so, because often it is expensive to 
maintain offline, real-world options for people, but it is 
important that a digital identity system do remain an option. 
There are post offices in every town in America where people 
can do things in person. There are other offline ways of doing 
things, and we need to make a conscious policy decision to 
protect those ways, those alternatives, to protect American 
freedom and to protect people who are vulnerable and need the 
benefits that they are qualified for.
    Ms. Norton. Even for those who do own smartphones, a lost, 
stolen, damaged, or nonfunctioning device could temporarily 
prevent them from accessing the programs they rely on. While we 
should embrace new technology to minimize fraud, we must ensure 
all Americans have access to programs.
    I yield back.
    Mr. Sessions. The gentlewoman yields back her time. Thank 
you very much.
    I now recognize myself for a UC, unanimous consent request. 
I would like to enter into the record two letters that have 
been provided to the Committee, both Mr. Mfume and myself. The 
first is a letter from the Better Identity Coalition. They 
highlight how digital identity credentials like mobile driver's 
licenses and investments in digital identity infrastructure 
could help address this emerging fraud threat that we are 
talking about.
    Second, the second letter is from the Defense Credit Union 
Council. It reinforces how critical it is to protect the 
Nation's military and veteran communities against scammers who 
specifically look to exploit vulnerabilities created by their 
life in the military and to take advantage of that. So, without 
objection, so ordered.
    Thank you very much.
    It is intuitively obvious to each of us that my side, the 
Republican side, the Majority side, does not have many Members 
here. We are in the middle of receiving a briefing on the 
conflict in the Middle East at this time by the Administration, 
and so I have chosen not to cancel this hearing but rather to 
stay myself, and so I may take the place of some of my Members, 
so I would yield myself my time right now.
    Mr. Stanley, thank you for being here. Mr. Stanley, I would 
like to ask a question that really came to me today, and I find 
very interesting, not only your comments, that I find common 
sense and I find myself--I would have to struggle with myself 
to disagree with you. But it brought up one issue, and that is 
we generally see fraud as an overwhelming factor that we need 
to defeat, that when fraud is involved--and fraud could be 
something that then becomes tangible where it has been 
established, necessarily established as opposed to questioned 
to establish whether it is fraud.
    Where fraud is involved, are there limitations on behalf of 
the government to satisfy the requirement of protecting 
themselves? And the for-instance I would like to give is, at an 
airport that I go to every week called Reagan Airport, there is 
a sign from the government that says if you are in this area, 
you are subject completely to search and seizure. In other 
words, we can do, by and large within some balance, what we 
want to do, to ask you, to demand you to comply with our orders 
and those things. Is there a point at which we should be 
careful once we know fraud is involved? And I can give you 
probably several instances, but I want to ask that question to 
you.
    Mr. Stanley. Mr. Chairman, I am not sure I totally 
understand the question. My apologies.
    Mr. Sessions. Okay. So, I will try and help it out. When we 
think that we have established the standard of fraud by a 
government agency, and they then are saying, we are dealing 
with fraud, is there a limit to how far they can go within 
reason but to establish something? For instance, could they 
pick up the phone and call a bank, ``know your customer,'' and 
a bank would have an idea that they are involved.
    And we are trying to move a lot of these issues to 
professionals in law enforcement and professional otherwise. 
Could they call a bank and say, can you please tell me, I have 
got a customer that lives at 1515 Smith Avenue, and this is 
their name, and they tell me they are 68 years old, and they 
told me that they do this, and this, and this. Is that okay? 
Because they have established fraud, and they are trying to 
then run it down. What are the limits? What is the expectation 
that you have?
    Because you have mentioned civil liberties a few times, and 
I respect that, but we are talking about fraud, and we are 
talking about how would you expect the government--are there 
parameters? The government can only go so far? Are we going to 
give the criminals that upper hand? So, that is the question, 
sir.
    Mr. Stanley. Okay. Yes. So, if you are talking about 
investigating fraud that you have evidence it has already 
happened, I think that it would become a criminal investigation 
like any other, and that has been--that is subject to the 
Constitution, the limits of the Constitution, you know, 
presumption of innocence, and the Fourth Amendment to the 
Constitution prohibiting unreasonable searches and seizures, 
and other provisions of the Constitution that have been well 
litigated over the years. So, I would think that a professional 
law enforcement officer would know what those limits are in 
many ways. And whether----
    Mr. Sessions. Have you had a chance, Mr. Stanley, to look 
at the piece of legislation that was passed by this Committee a 
few weeks ago that is waiting for floor arrival that would take 
these options and move them to the Inspector General (IG) in 
the Treasury Department in a specialized unit that are law 
enforcement-type people? Have you looked at that?
    Mr. Stanley. I confess that I have not. I would be happy to 
and get back to the Committee with our views on it.
    Mr. Sessions. If you could do that, I am interested in your 
feedback because we are trying to say that we believe once a 
standard of fraud has been established, that there needs to be 
specialized, sure, but the ability that investigators have to 
go and vet this, we just have to find a way. Is it truthful? 
How widespread is this? And how are we going to handle this?
    Okay. I am going to ask you another question. Got 5 seconds 
left, but we are kind of being a little careful. We are not as 
tight on this. The second one is, is there a limitation on 
someone if they are presently on Social Security, they have 
taken out a loan, SBA, something where they are in the 
government system and we find some instances where there might 
be questions that arise? And I know once again, you are very 
careful, and I agree with that, within the law, within the Bill 
of Rights, within the Constitution, within all the things that 
we could establish. Is it fair game to go back and run people 
back through if they think there is something that might be 
amiss through this organization, even though a person has been 
on government benefits? Because, you see, we think that a lot 
of people that presently are receiving government benefits 
might not be exactly as we thought they were. Is that fair 
game?
    Mr. Stanley. I think it is with some cautions. I think if a 
government agency sees signs of fraud, there is no reason why 
it should not----
    Mr. Sessions. Right, that has to be established.
    Mr. Stanley. There are cautions, especially if you are 
looking at, for example, using AI algorithms in order to do 
that, that may have been trained on sets of preexisting data 
that contain biases. There was a man--there was an NBC report, 
which I could share with the Committee about it, who paid his 
credit card off every month in full, and he got a letter from 
his credit card and they said we are reducing your credit 
limit. And he said, why, I pay off in full? They said because 
we have found that the other store--other customers at some of 
the stores you shop at have been bad credit. And I think that 
that strikes most people as just unfair and guilt by 
association.
    Mr. Sessions. That would be a smell test.
    Mr. Stanley. But I think that a lot of AI algorithms do 
basically the same thing in a hidden way.
    Mr. Sessions. How about if AI discovered that there are 74 
people at your home address that receive benefits because AI 
discovered it, and we think that you might be one of them, and 
we would like to do some sort of a review about this? Is that 
fair game?
    Mr. Stanley. I think that there are good uses of AI and 
that flagging that kind of anomaly, as long as there is human 
review, might make sense. But, for example--for examples like 
that, there are other examples where we see, unfortunately, 
government agencies not building in the checks and balances, 
the due process, and using AI not only to figure out who it 
thinks is suspicion, but then to take actions against people 
that they have trouble, you know, getting due process and 
fighting back. We have seen, for example, in states, people 
losing their disability benefits based on algorithms.
    Mr. Sessions. Okay. So, let me give you that. It would then 
at some point require human intervention to review data to then 
make some decision as opposed to a computer automatically 
assuming something.
    Mr. Stanley. I think that is right. The only other caveat I 
would add is that some of the fraud prevention techniques are 
based on gathering an enormous amount of intrusive data about 
individuals.
    Mr. Sessions. We spoke about this, but you had indicated 
earlier, without human intervention, that meant that someone 
else, a computer or an AI modeling, decided they could send you 
a letter and cutoff your benefits. I am saying that we could 
use these to then go to a human who is trained, who does have 
this professional experience, who would be able to apply it, 
and then would be able to use some rational basis. Okay. So, 
you would agree with that?
    Mr. Stanley. Yes, but what I am saying is that, for 
example, there are industries that use unethical apps on 
people's smartphones to track their location without their 
knowledge or permission. I am sure that many people in this 
room are being tracked by these companies without knowing, and 
that some of that data can be fed into these algorithms for 
deciding who is suspicious and a lot of other very privacy-
invading data. So, if the algorithm you are talking about is 
based on that kind of very intrusive privacy-invading data 
sources, we would have a problem with that.
    Mr. Sessions. Okay. Well, I could bring up lots of 
examples. I am not going to. I want to thank you. I think this 
is an important question. That is why you are here today.
    We would now like to move to the distinguished gentleman 
from Florida, Mr. Frost. Mr. Frost, I yield back my time. We 
now move to you. The gentleman is recognized.
    Mr. Frost. Yes, thank you so much.
    You know, part of my concern as it relates to digital ID 
becoming mandatory is the risk of widespread data collection 
and exposing millions of Americans to harm, which is already an 
issue that this country seeped into many different ways, social 
media, online, and different things like that. Mr. Stanley, how 
could digital ID systems become a barrier for Americans trying 
to access services, benefits, or programs?
    Mr. Stanley. That could happen if, first of all, you are 
unable to get a digital identity system because you do not have 
a smartphone. There are also a lot of Americans who do not have 
access to--who do not have, currently have, any kind of 
driver's license or non-driver ID from DMVs, who--there are 
people whose birth certificates were burned in a fire in 
Tennessee in 1955 and do not have access to them.
    It is a messy world out there, and I think that digital IDs 
seek to impose a sort of neatness and bureaucratic, you know, 
regimentation on it, on all of us. And so, in making policy, we 
have to make sure that people who do not have access to those 
things are not left out. So, you cannot get--there are people 
who cannot get a driver's license. There are people who, maybe 
they have a driver's license, but they will not be able to get 
a digital driver's license because of the things that we talked 
about in terms of not having access to the technology or the 
technological literacy to use it. There was one study that 
found that a very large proportion of people over 65, you know, 
were not able to install an app on a smartphone.
    There could be situations where people's IDs are abusively 
revoked. You know, we have seen, there has been mentioned that 
the Trump Administration put some people in the Social Security 
dead file. We also saw in California, a Democratic candidate 
for Governor proposed that Federal agents who wear masks should 
have their driver's licenses stripped from them. And whatever 
you think of mask-wearing by Federal agents, which is a 
controversial issue, that is using an identity infrastructure 
for political purposes, which is something that we may see in 
the future left, right, or center, and so that could be a 
threat. And we have called for protections against people 
having their IDs yanked by abusive governors or the like. So, 
those are some of the ways in which people could find that they 
are left out of a digital identity infrastructure.
    Mr. Frost. Part of my concern, too, is when we look at this 
Administration, we know they have empowered big tech companies 
like Palantir to create databases of Americans' personal data 
for government use. We know that during the, you know, DOGE 
era, similar things were done during that as well. This data 
collection could make it easier for private companies to abuse 
our data. I know some proponents will say, well, you know, this 
is mainly for government use, but we know it is not only for 
government use. And that is part of my concern with this. There 
is just so much collaboration between private companies, data 
sharing.
    How should we legislate on balancing the convenience and 
the real dangers of digital ID? Which also will lead to losing 
anonymity online, which is something else I am concerned about 
as well.
    Mr. Stanley. Yes, we have a piece on our site that outlines 
12 protections that we call for that we think state 
legislatures should enact that govern any, you know, mobile 
driver's license or digital ID that is created in their state. 
I will not go through them all, but they include such things as 
protecting people against incessant demands from every 
corridor. If you want to do business with us or come in our 
candy store, you have to tap your ID and give us your driver's 
license to get in.
    Mr. Frost. Yes, this is part of my concern, too, that 
making it easier to prove who you are will lead to more 
services, companies asking you to do so for every service that 
is not expected of you right now.
    Mr. Stanley. Yes, it is an excellent point because one of 
the things that, you know, if you are a website and it is 
really, really hard to prove your identity online, you have to 
take a photo of your ID, you have to send it in, you have to 
get a video, you have to do proof of liveness, all this stuff. 
You are not going to ask your visitors, your users to do that 
unless you really need to, so that imposes a limit. But by 
getting rid of all the friction of proving who you are online, 
you get a pop-up like the privacy pop-ups we get today, click 
here to send us your digital ID. It will not only become easier 
for me to share my digital ID, that means that it makes it much 
easier for them to ask me to or demand that I do so.
    And that is one of the big things we have--and that is one 
of the protections that policymakers can make, which is to say, 
these are super IDs, they are cryptographically locked down, 
DMV vetted, everything like that. This is, you know, and that 
you should not be forced to use a super ID to prove your 
identity unless it is legally required, we have called for, 
maybe in certain other specific situations.
    But people are going to need protection against this 
absolute, you know, waterfall of demands that we can easily 
anticipate are going to happen once this is created. And then 
other protections like privacy protections to make sure that 
the wallet holders do not, are not spying on everybody, and 
that, you know, that these cryptographical things that I talked 
about are built in to protect privacy so that, you know, you 
can prove things about yourself without having to, you know, 
create a lifelong relationship with somebody by identifying 
yourself to them.
    Mr. Frost. How can we--and I know we are over, if you can 
indulge me, Mr. Chair. My last question is how can digital ID 
lead to complete loss of anonymity online?
    Mr. Stanley. Yes, so, I mean, the websites are going to 
want everybody to identify themselves all the time. They are 
going to want to do it because their ads will be worth more if 
they know who you are, and they can plug in you--the data they 
have about you to other data they get. They are going to want 
to do it to make sure that you are of age so they can market to 
you under Children's Online Privacy Protection Rule (COPPA), 
which is, you know, you cannot market to people under 13. 
Identity verification, which has become a big controversial 
issue. And bots, a lot of sites are having problems with AI 
impersonating humans, and they are going to want to know that 
you are a human for various reasons, and so there is going to 
be a lot of pressure for a lot of websites to start demanding 
this----
    Mr. Frost. Yes.
    Mr. Stanley [continuing]. All the time.
    Mr. Frost. And part of the concern, right, is the fact that 
this information can be weaponized against consumers, working 
people, who are looking to purchase things online and have that 
information leveraged against them when they are making 
decisions on what they want to buy and how much those items 
cost, correct?
    Mr. Stanley. Yes, surveillance pricing, where stores get a 
bunch of data about their customers, and then they charge you 
based on what they know about you and how much they think you 
will pay and whether you are desperate and so forth. That has 
become a very controversial issue, and states, you know, 
regulation of surveillance pricing has been attracting support 
in the state legislatures from both left and right. And digital 
IDs will make that much easier because if you know they are 
going to charge--if the store is going to charge you more--
like, let us say that the airline happens to know that you have 
just lost a close loved one and you have to fly, they can up 
your price.
    Mr. Frost. Yes.
    Mr. Stanley. And so, you are going to want to see what the 
price is without them knowing who you are, right? But they are 
going to want to know who you are, and there will be this arms 
race. And a digital ID would sort of end that arms race----
    Mr. Frost. Yes.
    Mr. Stanley [continuing]. And you cannot escape them 
knowing who you are----
    Mr. Frost. Yes.
    Mr. Stanley [continuing]. If it is done badly.
    Mr. Frost. Yes, I appreciate it. Thank you for indulging 
me, Mr. Chair. I just think, you know, I am not a Luddite, and 
I just think these conversations are important because it shows 
how much care and intentionality needs to be put into this.
    Oftentimes, we are very excited about something, we move 
quickly on it without thinking the next 10, 20 years into the 
future, and then it is an emergency for another generation to 
handle. I think we have to have these conversations now and 
legislate accordingly.
    Thank you. I yield back.
    Mr. Sessions. The gentleman yields back his time. Thank you 
very much.
    The gentlewoman from Washington is now recognized.
    Ms. Randall. Thank you so much, Mr. Chair, and thank you to 
our panelists for joining us.
    You know, Login.gov gives every American a one-stop portal 
so they can use a single username and password to log in across 
a variety of Federal programs. Sounds like a benefit and a, you 
know, customer service improvement. This is a portal that state 
and local governments can use as well, and it saves taxpayers 
time and money and generally makes life easier.
    Mr. Burris, can you briefly describe how Login.gov has 
leveraged Socure's technology to help reduce identity fraud for 
government programs?
    Mr. Burris. Absolutely. And I think a lot of this comes 
down to trust and basically leveraging what would be considered 
next-generation technologies to try to help balance. A lot of 
the conversation I have heard are around access and speed and 
confirming that the right people ultimately can access these 
services.
    So Login.gov conducted a competitive procurement where they 
evaluated our technology against that of 17 others at the time, 
and they incorporated different components of our solutions, 
everything from solutions that we have around document 
verification, so confirming that it is a legitimate government-
issued ID, and/or what would be facial biometric comparisons, 
so the idea is comparing it and confirming that it is actually 
the right person on the other end of the screen. They also 
incorporated what would be additional fraud models to their 
stack, things that they are incorporating such as identifying 
and understanding what is happening with the device a person 
may be using because it is all too often that the adversary 
would do something such as take a jailbroken device that is 
overseas and attempt to say that they are operating within New 
York or D.C. for that instance, also doing comparisons with 
things like the phone or the address of individuals using their 
email.
    And then some of the flagship offerings that we have 
related to helping to paint a picture or prediction of whether 
or not it is someone who is engaging in what would be a pattern 
that is associated with identity theft and/or synthetic 
identity. And far too often, what we see in the industry is 
that kind of weaknesses in these technologies have led to this 
unfortunate conversation about folks who have been left out and 
forced down alternative paths. It has always been my belief 
that if someone is choosing to engage with a digital service in 
government, they should be able to do so, and the technology 
should adapt to meet them where they are. So, the addition of 
Socure's tools have enabled Login.gov to take strides toward 
being able to address that and make their service more 
accessible while simultaneously combating fraud.
    Ms. Randall. Thank you so much. It is really great news 
that we are innovating in this way to provide access that the 
people want and to smooth some of these barriers to accessing 
services. But, like you have mentioned and based on other 
testimony that we have heard today, we know that scammers and 
identity thieves are constantly trying to find new ways to 
evade ID verification, and that means that Login.gov has to 
remain alert and prepared to fight new forms of fraud. We have 
to keep innovating.
    Ms. Cruz Cain, in GAO's assessment, will there ever be a 
day when Login.gov will be finished and no longer need to adapt 
to face new fraud tactics?
    Ms. Cruz Cain. I do not think so. I think criminals are 
working every day, 24 hours a day, to get better at what they 
do, and largely in the Federal Government, we are reactive. So, 
Login.gov procured the tools because they are being reactive to 
what has been happening within their tools. So, I think largely 
Federal systems are reactive to what is going on and rather 
than being proactive.
    Ms. Randall. Yes. So, would it be safe to say that 
competent and technically capable leadership of the Login.gov 
program is critical to effectively sustain fraud prevention?
    Ms. Cruz Cain. Yes.
    Ms. Randall. And is it critical that leadership has 
experience in effectively managing and protecting sensitive 
data programs?
    Ms. Cruz Cain. Yes.
    Ms. Randall. Would it be very concerning to you, Ms. Cruz 
Cain, if leadership at Login.gov came from an organization that 
had, say, an extensive history of mismanaging private data and 
endangering the privacy and financial security of the American 
people?
    Ms. Cruz Cain. Without, I mean, knowing a little bit more 
about the situation, it would be hard to opine, but we like to 
look at facts and situations. But, I mean, just like I told 
you, we would really need to have experience with technology, 
leadership with good technology, and knowledge of how to 
implement technology.
    Ms. Randall. Absolutely. But if someone who had previously 
been proven to mismanage private data and endanger privacy and 
financial security was moved into leadership, that would be 
concerning?
    Ms. Cruz Cain. Yes, if it was proven.
    Ms. Randall. Yes. Mr. Chairman, I would like to ask 
unanimous consent to submit these following articles to the 
record. ``DOGE Put Critical Social Security Data at Risk'' from 
The New York Times. From NPR, ``The Trump Administration Admits 
Even More Ways DOGE Accessed Sensitive Personal Data.'' 
Washington Post and Wired, similar subject matter.
    Mr. Sessions. Without objection.
    Ms. Randall. And just in my remaining time, I would like to 
say what these articles say, that President Trump took one of 
the DOGE bros who oversaw the looting of the Federal 
Government's data and endangered the privacy of every American 
and put him in charge of identity verification and login 
systems for every American. And based on our previous line of 
questioning, that does not sound like a way to safeguard the 
American people's information.
    And I yield back.
    Mr. Sessions. The gentlewoman yields back her time.
    We would now like to move to the second round. With your 
understanding, we are doing that, sir.
    Dr. Maimon, you and I spent some time yesterday. Maybe it 
was today. Days run together. But you most expressly indicated 
that you have not only great knowledge, but work on a day-to-
day basis with many people who are criminals and who are 
attempting to be fraudsters at our systems. And I did not have 
a chance--you did not really delve into this area very much, 
but I think Mr. Mfume and I need to hear this about not only 
that it exists, that they are very active, that they are on the 
dark web or open web, that they target certain people and that 
they learn areas that are vulnerable, and that they openly talk 
about it. It is no longer behind anybody's back anymore. Do you 
mind taking the time that you need to express the things that 
we need to understand about the attack that is against us and 
our agencies?
    Mr. Maimon. With pleasure, Mr. Chairman. As you mentioned, 
Mr. Chairman, I spent my time, my days infiltrating darknet 
platforms, Telegram groups, trying to understand what 
fraudsters put out there and how they bypass a lot of the 
security solutions that we deploy on financial institutions as 
well as on the government side. Oftentimes, what we find in 
those platforms are tutorials, which will walk you through how 
to bypass many of the security solutions that we have out 
there. The tutorials sometimes will be offered for free, other 
times you will pay for them, amounts ranging from $150 to $250, 
specific guidelines with respect to how to bypass and obtain 
SBA loans, FAFSA aid. We are seeing, as of earlier this 
morning, people talking about how to get targets' 401(k) 
accounts, which I think is a major issue to our country, and we 
simply see that on scale. We see that, as I mentioned earlier, 
on darknet and Telegram, but also more and more on Facebook, on 
Twitter, on Instagram.
    A lot of what we see also on--is available on the internet, 
on the clearnet, websites that the criminal put together and 
simply offer fake driver licenses for sale. This is the reality 
that we are dealing with, organized crime groups with very 
detailed supply chains, which will have our identities offered 
for sale. They will have services which will allow the 
fraudsters to build histories around their identities. They 
will walk you through how to create deepfakes, high-quality 
deepfakes, both images as well as videos. They will teach you 
how to take those videos and images and inject them in the 
cameras of the computers or the smartphone that folks are using 
in order to apply for benefits or apply for SBA loans and then 
secure all those resources that they get from the government.
    So, this is what we are up against. We are seeing that 
happen domestically with a lot of organized crime groups 
operating within the United States, but a lot is happening from 
abroad as well. We are infiltrating Russian crime groups. We 
were able to infiltrate some Chinese crime groups who operate 
the scam compounds in South Asia and are explicit about the 
type of operations and our identity and how, you know, how they 
essentially offer those identities for sale and essentially 
walk you through the list of steps you need to engage in in 
order to target our benefit program. This is what we are up 
against, unfortunately, at this point.
    Mr. Sessions. So, furthering this development that you are 
talking about, I spoke with you about how we had looked at, 
during 2021, 2022, 2023, 2024, numbers of agencies that did not 
have their workers at work. They were not engaging the people 
who were seeking services. They were not able to, even when 
working from home necessarily, did not have a full array of 
opportunities to vet who people were, know your customer, to 
look at things. And so, this huge amount of money that we were 
talking about today in testimony before this Subcommittee, that 
is very consistent with what we have heard GAO say in the past.
    It has found a real home to where this is more than a 
cottage industry. It is people who literally are figuring out 
how to do this. And you said to me, whenever we last spoke this 
morning, you do believe human interaction--and I brought up my 
circumstance of talking to Social Security, how they vetted me, 
how they talked to me about things that I would know about 
myself that probably not a lot of people would understand. Is 
this the kind of fair game that would be used to vet people on 
a regular basis? And how can we cross-get this type of 
information to where if you are at SBA, you may or may not have 
that available to you? If you are at Social Security, you 
probably could ask some detailed questions about working 
history, about doing other things.
    Do we need to expand or develop some way for agencies that 
take a new, perhaps a new, request from a person? It could be 
about--not VA because you could ask about those questions, but 
about someone who is recently unemployed and asking about depth 
of knowledge. How do we really help those agencies make the 
determination even when speaking to a person?
    Mr. Maimon. This is a great question, Mr. Chairman, and I 
agree with your statement. I think, and maybe you can go back 
to my career as sociology in the Ohio State University, first 
class in the degree, we were taught about the difference 
between Gemeinschaft and Gesellschaft, community and society. 
The reason why I am bringing this important distinction is that 
in the past, here in the United States or any other place, when 
you went into the bank or to the IRS and asked for opening a 
new bank account or a loan or getting some governmental 
benefits, the guy sitting across from you knew who you were. He 
knew your family. He knew where you worked. He knew your 
history, so to speak. And so, they were able to assess the risk 
you posed to the organization more effectively.
    Now, you know, we are at this point in a point of a 
society. We have a lot of people living in this great country, 
very difficult to assess, in the same way we assessed in the 
past, folks' history. But fortunately, we do have solutions out 
there which will allow you to taggle the signals, create and 
look at some historical signals around identities.
    So, if the government is willing to sort of use some of 
those solutions to try and assess the historical evidence 
around those individuals who need to be verified, then I think 
we will be in a better place to sort of determine whether 
individuals are who they say they are, or they are completely 
different individuals stealing identities or using synthetic 
identities.
    And in that sense, I just want to refer to the conversation 
we had earlier about the driver's licenses and MDL. One of the 
things that we proved already, you know, during the last ten 
years or so is that pretty much everything could be faked. 
That, I think, will go also to the MDL. I mean, criminals will 
be able to find ways to use this technology to their benefit. 
What they will not be able to fake is the historical evidence.
    And that goes as well to the AI solutions out there, right? 
I mean, AI will be able to give you an amazing picture of a 
person who does not exist, or AI will be able to take my face 
and bring it to life when I am abroad, so to speak, and try and 
authenticate me when I am trying to get unemployment benefits. 
But one thing that AI tools will not be able to do at this 
point is to create the historical signals around me or around 
anyone who is trying to identify themselves.
    And I think that is where the solution lies, being able to 
find solutions which will allow us to look at historical 
evidence around individuals, around their name, date of birth, 
addresses, telephone numbers, and make assessments with respect 
to whether they are who they say they are.
    Mr. Sessions. Ms. Cain, furthering this discussion, I had a 
chance to engage you also yesterday, and part of this was about 
the viewpoint that when there was a failure, meaning a person 
came through Login.gov, provided information, but it was not 
what I would call successful, so there would be a failure, 
then, evidently, it is not unusual for someone, not as a 
challenge, but to ask for authentication of who they are, to go 
to a post office. You had indicated that one of the things 
which you have engaged government agencies on, and perhaps GSA, 
is data and information back about what caused that failure. 
Was it a question we asked? Was it a picture, any number of 
facts and factors?
    Following up on Dr. Maimon, you are the cybersecurity 
person also at GSA, and you are aware of the power of 
technology, the power of these things that could be used to 
fool people, to give false positives, to do things. Do you see 
that in this process that we need to go with new areas that 
would add some more depth to where you did not fail off one or 
two or three, you failed off five different questions because 
you were looking for them? How do we go and ascertain when 
someone falls out, whether that was fraud, whether that was 
someone you were openly challenging, and they see you later, 
and so they never went to the post office, and to where we then 
learn what they did, how they did it, where they asked the 
question, who they were? We could move them to the organization 
we talked about this morning, to Pandemic Response 
Accountability Committee (PRAC).
    Ms. Cruz Cain. I think it is an important question because 
the people who are failing and are legitimately the person that 
they say they are, are going to keep trying because they want 
that government benefit that they are entitled to.
    Mr. Sessions. And they could go to a post office.
    Ms. Cruz Cain. Right, they could go to the post office and 
go take their documents and verify who they are that way, but 
there are also barriers to that. So, if you are in a rural 
area, your post office may be far, you may not have reliable 
transportation there, there may be lots of barriers for you to 
do that, so it might not be that easy. So, a lot of the 
agencies reported to us that they would like to have visibility 
into that authentication and why it failed, so they might be 
able to help that person on the end and say, well, yes, it was 
because the name that you put in was not the name that HUD had 
on, or there was a letter transposed, or your new address was 
never updated in HUD's database.
    And there was a privacy principle called redress. You know, 
you are supposed to be able to get the most updated, or 
whatever information an agency has on you, so you are able to 
correct it if it is wrong. That process can be easy, or GAO has 
reported that process can take very long for you to be able to 
update your information. So, if that takes me months to years 
to get my address updated in a government database, I am going 
to fail for that whole year on every government agency that I 
use Login.gov to try to access, which is going to be a very big 
barrier for me to get any government benefits that I am 
eligible for.
    So, that was something that many agencies brought up for 
us. And giving those agencies that ability to--insight into 
that and to be able to say, hey, this is why you failed, you 
know, here are your options, and again, some of them may not 
even be able to go to a post office and have that secondary 
option available to them, but, you know, you are going to have 
to do that if you want your benefits. That was one thing that 
was really helpful to them because some people would--
fraudsters would probably legitimately stop. If they were not 
able to go somewhere and prove who they said they were, nine 
times out of ten, they are stopped. They will take their other 
synthetic identities and keep trying to get through, but they 
would stop probably with that fraud name and say, okay, look, I 
have got 300 others that I just paid $3 for. I am going to keep 
pushing those.
    So, I think the difference is you really need to think 
about the people who are really who they say they are, who are 
having that false positive, that they are going to keep trying, 
and they need that reason why so that they can go remedy that 
so they can continue to be--not be found ineligible for the 
benefits that they are legally entitled to.
    Mr. Sessions. Okay. Interesting. Thank you.
    Mr. Mfume?
    Mr. Mfume. Thank you, Mr. Chairman. It has been an 
interesting hearing, to say the very least.
    One of the things that I hope comes out of these sort of 
interactions are ideas that would affect and change existing 
law and policy. And I know all of you in your work have come 
across items, matters, and issues that you said, if this were 
only changed or if this could be in place. So, I want to come 
back to that in just a minute, and it will be a quick minute 
too, but I want you give some thought to that because, as 
legislators, that is very important to all of us, no matter 
what side of the aisle we serve on, if we are in fact trying to 
deal with an issue and a problem, and certainly, this is one of 
them.
    I want to, if I might, Dr. Maimon, go back to something you 
said earlier, and then I will come back and we will try to wrap 
this up on this side anyway. I am interested in your work that 
you have been doing tracking Russian and Chinese cyber networks 
and their ability to infiltrate this country, but more 
importantly, their ability to take advantage of the citizens of 
the United States. It sounds like fascinating work, but I am 
sure it is also leading you to some ideas about how we can do 
things better.
    What I really want to know, though, on this matter, the 
evidence that you are coming up with as you track these crime 
syndicates and cyber networks, whether they are Russian or 
Chinese, are you or your organization sharing that information 
with the Director of National Intelligence or sharing it with 
the FBI, or are they about doing what they do in their own 
silo, developing their own intelligence and not doing a 
comparative analysis of both? Could you speak about that for a 
minute?
    Mr. Maimon. Of course. Thank you so much for this question. 
I do what I do in order to make sure that the American public 
is aware of what is going on there, and when I investigate, my 
investigations usually result in publications. I put together 
white papers; I put together news articles and let the public 
know about what I find.
    Oftentimes, we will reach out to law enforcement, and then 
we will simply give it to them, and then they need to make a 
decision with respect to whether they want to pursue an 
investigation or not. I can tell you that in the past, we had a 
very strong relationship, as a professor in Georgia State 
University, with the Department of Homeland Security. What we 
have done back then, that was during the pandemic time, we 
essentially had a monthly meeting with local folks in DHS, and 
we simply talked about what is it that we find out there. What 
is it that the Department of Homeland Security (DHS) did with 
that information? Obviously, I have no idea because, 
oftentimes, what happens is that law enforcement takes this 
information and do their own thing, sort of speaking.
    And so, I can tell you that I am doing my best to make sure 
that everybody is aware of what I find out there, but I have 
limited visibility with respect to the actions folks take once 
I put information out there.
    Mr. Mfume. Well, if I could be the devil's advocate, if I 
am the Director of National Intelligence or the head of the 
FBI, I might say, well, he has never given that information to 
us. So, do you forward that to them? Are you in contact? Is 
there a liaison that shares the information so they can match 
it up with their own intelligence?
    Mr. Maimon. So, in the past, what I was doing is 
essentially having a monthly meeting with the Department of 
Homeland Security. That was during COVID time. We had a very 
strong relationship at the time, where we essentially 
provided----
    Mr. Mfume. Right, but I am specifically speaking about the 
Director of National Intelligence and the Federal Bureau of 
Investigation.
    Mr. Maimon. Yes, I do not have a relationship with the FBI. 
I do not stay in touch with the FBI. I am more than happy to be 
in touch with them and let them know about what I know.
    Mr. Mfume. Yes, because it seems like you have done an 
extensive amount of work, and I can appreciate white papers and 
editorials and that sort of thing, but everybody does not read, 
and if it is something so pertinent or hot or game-changing, 
those two agencies, more than anyone else, I think, needs to 
know. So, let us pray that they are listening. They obviously 
are. I hope that they would take advantage of the work that you 
have already done just to match it up against their own 
intelligence. This is a very serious issue, as we all agree, 
and the more we can do to be effective, the better.
    And now, I just want to come back to all of you, just very 
briefly, with respect to this notion about policy changes or 
about proposed legislative avenues to address some of the more 
glaring aspects of this, or maybe just to address things that 
right now are not getting any attention. I am going to start 
with you, Mr. Burris, and I will end up with you, Mr. Stanley.
    Mr. Burris. Thank you, Ranking Member, for the opportunity 
to address this item. You know, there were a number of 
recommendations that I provided as part of my testimony as far 
as where we could be pursuing policy levers. I actually will 
lead with one that was not in there, and it is really around 
mindset shift and culture. And if you indulge me for just a 
moment, it shows you the depth of my nerd.
    It goes into--I was thinking actually back to the Avengers 
movie, the last one with Captain America, and how there was 
like the darkest moment where they were basically up against an 
insurmountable threat, basically took all the Avengers coming 
together at the same time out of nowhere in order to try to 
combat what they were seeing or what was about to happen. I 
think that generally, culturally, has to change within the 
Federal Government in the sense that right now, when you are 
talking about who is fighting fraud within an agency, an 
organization, they are doing it siloed. They are doing it 
without sharing intelligence. They are doing it without having 
the types of conversations that need to happen, so much so that 
Federal Emergency Management Agency (FEMA) could be having an 
existential fraud threat, and they are not talking to the SBA. 
They are not talking to Treasury. They are not talking to GSA 
even. And so, there is an opportunity to basically culturally 
shift to say that we all have to get on the same page about 
what we are fighting against and then change that dynamic so 
that way we can actually can take some of these more proactive 
measures that I have outlined in my testimony.
    Mr. Mfume. Thank you very much. I appreciate that. I did 
not see the movie, but I appreciate your context. But I am 
talking now about policy more so than mindset. Mindset is going 
to take a while, but if we can implement minor or major policy 
changes, that will make a difference right now.
    Ms. Cruz Cain?
    Ms. Cruz Cain. I will go for a big one, but I think we do 
need to revamp the Federal Privacy Act. So, the Privacy Act 
goes back to 1974. GAO has plugged many times in its reports 
that that was created way before policy and technology has 
updated, and we need to revisit that. But I also think that 
there is a great need for a consumer privacy law as well that 
starts at the Federal level but also allows states to have some 
input into it because of, right now, there is no Federal 
consumer privacy law, and it is a sort of framework of 
mismatched state laws, local laws, and, you know, there is 
nothing really governing at a higher level of what needs to be 
done.
    Mr. Mfume. Thank you.
    And Dr. Maimon, I appreciate the extensive nature of your 
written remarks. I tried to get through all 20 pages. I do not 
know if I did or not, but thank you very much for that.
    Mr. Maimon. Thank you so much. I think in terms of policy--
and I really appreciate this question because I sit at Georgia 
State University in the School of Policy. One of the things 
that I would strongly recommend is an evidence-based approach. 
I think, you know, we are in a point in time where science has 
advanced dramatically. We have evidence-based medicine, 
evidence-based policing, all essentially suggest that in order 
to make decisions with respect to policy or the implementation 
and tools, what we need to do is essentially test what works 
and what does not.
    Unfortunately, we do not have that in the context of fraud. 
So, I think if we are thinking about policies and policy 
changes, the first thing we need to sort of have in mind is a 
different state of mind, and that is of evidence-based, what 
works and what does not in the context of fraud prevention.
    In the context of the government operation, we are in a 
very difficult position, I would say, because, to be honest, we 
do not really know how much fraud we have. We have reports on 
improper payments, but we do not know how much fraud we have on 
the government side. We hear numbers and very large numbers, so 
it is definitely an issue, but we need to be able to quantify 
how much fraud we have. And then after we quantify that number, 
we need to try and assess how to reduce that number to the 
minimum possible in order to make sure the taxpayers get their 
money's worth in terms of benefits, in terms of programs that 
they should have access to.
    So, I think if we need to sort of have something in mind 
when we think about a policy change, then it is definitely an 
evidence-based approach to fighting fraud.
    Mr. Stanley. [Off mic.]
    Mr. Mfume. Mr. Stanley, could you turn your mic on, please?
    Mr. Stanley. I am so sorry about that. I would agree with 
Ms. Cruz Cain that strengthening the Privacy Act of 1974 is 
sorely needed, as well as overarching consumer privacy 
legislation. I believe that the United States is the only 
advanced industrial Organization for Economic Co-operation and 
Development (OECD) nation that does not have an overarching 
privacy law that sets baseline expectations for both 
individuals and businesses about what is fair and what is not 
in terms of how people's information is treated.
    And then, as I have been arguing, I think that we need to 
set standards for digital driver's licenses in the states and 
other digital IDs that put in place both requirements for how 
they are built technically. They should have certain encryption 
capabilities that protect privacy while still allowing for 
people to authenticate themselves. And there should be an 
envelope of legal protections around them to make sure that 
they remain optional and not mandatory, for example, and to 
limit overuse. And so those would be the top things that I 
think the Congress should consider.
    Mr. Mfume. Thank you very much. I want to thank all of you.
    Mr. Chairman, you may recall this idea of revamping the 
Federal Privacy Act continues to come up. The last hearing we 
did like this, that same thing came up. So, I want to commit 
myself, and I am sure, you know, you and I will get together on 
this and figure out how, in fact, we might be able to move 
forward with some joint legislation that at least starts to 
move the ball regarding the Federal Privacy Act. It has been a 
long time since 1972. The world has changed, and the least we 
can do, I think, is to try to find a way to protect the privacy 
of Americans by updating the Federal policy that we have. And I 
want to commit myself to working with you in that regard. I 
yield back.
    Mr. Sessions. The gentleman yields back his time. Was that 
your closing statement also?
    Mr. Mfume. Yes.
    Mr. Sessions. The gentleman did make a closing statement.
    I, too, want to join in with my dear friend, Mr. Mfume, and 
thank each of you for being here. This issue is not going to go 
away. The question is, are we serious enough to continue the 
search to look for these things? And I think all four of you 
have proven to us today that there is not just much ground to 
go, but there is much to learn.
    And I think both Mr. Mfume and I need to provide some, 
perhaps, guidance back to inspectors general, their attention 
to this, to help GAO to reinforce the things that they are 
after, to have the GSA follow-up. I find myself in a position 
where I do not want to say that they are not paying attention. 
I think they are trying to do a number of things that are 
important. But Mr. Mfume and I find ourselves on this end of 
the trying to save the taxpayer, trying to understand that the 
people, whether it is one of my sons or it is one of his 
constituents, that need government benefits and government 
services to work properly, to be legally bound to recognize 
these things, but that we will bleed ourselves out. We can 
bleed ourselves out by people who are outside the system, 
causing us to completely miss the mark.
    So, we are going to stay after this. We are going to make 
sure that we approach every single angle and challenge 
government to do that. We have, by and large, decided we do 
understand the PRAC. We do understand the importance of data. 
We do understand the need to make sure that it survives in 
perpetuity, yes, probably for a lot longer, that we give it the 
authority and the responsibility to evolve itself, to meet the 
emerging and new threats, and to provide information back.
    But, I want to thank you for your insistence that we will 
continue to work together, and I want to thank each of you.
    So, with that said, without objection, all Members have 
five legislative days within which to submit materials and 
additional written questions for the witnesses, which would be 
forwarded to the witnesses.
    If there is no such further business, without objection, 
the Subcommittee stands adjourned.
    [Whereupon, at 3:58 p.m., the Subcommittee was adjourned.]

                            [all]