Login.gov authentication graphic showing the federal government’s two-year migration deadline

Feds Make Login.gov Mandatory: Fraud Gaps Persist

Login.gov is becoming the federal front door for taxes, benefits and public services, even as GSA works to close fraud gaps and fix longstanding technical problems.

The White House made it official this week that Login.gov is now the required authentication tool for signing into federal websites. That includes anyone accessing their IRS tax information, renewing a passport or applying for benefits.

On Monday a two-year countdown started per the Office of Management and Budget’s (OMB) Memorandum M-26-18. The move to Login.gov is mandated for federal websites, except for businesses, people acting on someone else’s behalf, and Defense Department or national-security systems.

Agencies have one year to deploy Login.gov on sites tied to OMB-designated “High Impact Service Providers,” and two years for all remaining covered public-facing services.

As the rollout begins, feds are still patching security holes and will need to address usability issues.   

And the system isn’t just been beaten by fraudsters — it’s also tripping up legitimate users. The Government Accountability Office, congress’ independent, nonpartisan investigative and auditing arm, reported enrollment tests failed lock out fraudsters. They also reported account-creation failure rates as high as 30 to 40%.

Why the Switch to Login.gov?

The OMB cites cost as the driving force behind the move to Login.gov. It cites a GAO budget cost of $209 million spent on commercial identity-verification vendors between fiscal 2020 and 2023. It estimates the move to Login.gov will cost taxpayers $32.5 million to manage 190 million users, per GAO’s July 2025 report.

The OMB cited the savings by consolidating multiple private vendors such as ID.me and CLEAR into one streamlined offering. Those commercial alternatives such as ID.me and CLEAR aren’t going away anytime soon, but the memo does direct agencies to phase them out once Login.gov can serve the same population.

One unstated motive comes from OMB director Russ Vought and a memo where he says the move to one government-run platform will be a security fix as much as a cost-saver. Agencies, he wrote, have “deployed a range of different solutions and taken inconsistent approaches” to managing digital identity. This scattered, agency-by-agency approach is an identity security liability as much as an inefficiency.

How the identity layers work

The underlying tech of Login.gov mirrors commercial fraud tools used by banks and retailers. Vendors like BioCatch, ThreatMetrix and Fingerprint already sell similar “persistent” device recognition tools in nearly identical terms.

Similarly, Login.gov’s authentication layer starts with a password plus a second factor that includes either an authenticator app, security key, or one-time code. Enrollment will also include a generated 16-character personal key – a one-time-use recovery code you save (print/downloaded/write down) for account recovery.

Identity proofing at IAL2 (the NIST-defined tier required for benefits and tax services, not fully available until 2024 ) will add a document-and-selfie layer. Users upload a state ID and take a live photo. Next, Login.gov pays LexisNexis Risk Solutions, a data-broker and fraud-verification firm, to authenticate the document and validate personal data, and checks the ID against state DMV records via American Association of Motor Vehicle Administrators’  Driver’s License Data Verification service.

An additional layer uses device fingerprinting, which is a way to identify a specific phone or computer by its unique mix of technical traits, rather than by name or login. This is an attempt to flag criminals that get rejected once and try to regain access to Login.gov under a new identity.

The draft requirements also ask vendors to detect AI agents built on ChatGPT, Claude and Gemini attempting to act on a user’s behalf, and to let Login.gov allow, block or rate-limit them accordingly.

Login.gov’s safeguards have already been bypassed

Privacy advocates have pushed back on this underlying technique for years. The Electronic Frontier Foundation’s Panopticlick research found more than 8 in 10 browsers in its sample were uniquely identifiable through their configurations (aka fingerprinting). The group has long criticized it as a tracking method users is harder for users to detect or control than cookies.

GAO cybersecurity director Marisol Cruz Cain testified before a House subcommittee  that suspected fraudulent accounts had successfully passed Login.gov’s IAL2 identity-proofing workflow, with the platform’s Anti-Fraud Team subsequently finding fraudulent indicators.

That finding triggered a GSA contract amendment in May 2025 calling for an additional verification layer, with GSA’s own assessment warning that attack sophistication would “increase exponentially.”

Neither GAO nor GSA has disclosed how the checks were beaten. A successful bypass, GAO noted, enables classic identity theft: redirecting a Social Security beneficiary’s direct deposit, filing a fraudulent tax return, or opening credit accounts in someone else’s name.

The gap sits on top of problems GAO flagged as far back as October 2024, when nine federal agencies separately reported technical issues with Login.gov – including account-creation failure rates of 30–40% and confusing multi-factor setup.

Remote IAL2 identity proofing, the tier now required for tax and benefits access, wasn’t independently certified until that same month, and GSA didn’t complete its remote identity-proofing pilot until March 2025.

As of GAO’s July 2026 testimony, GSA had created a roadmap and Partner Advisory Group but still had not demonstrated that the specific technical problems agencies flagged nearly two years earlier were resolved or established mutually agreed timelines for addressing them.

Total
0
Shares
Previous Article
Cybernetic cat and rabbit facing off on a circuit board representing PollCat and NodeRabbit malware.

Two New RATs, One Very Bad Coding Interview

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading