Witnesses at a US House oversight hearing told lawmakers that the federal government’s approach to verifying identity is outmatched by fraud rings using artificial intelligence, and that agencies need standing authority to adopt new defenses faster than their procurement cycles allow.
The Subcommittee on Government Operations heard testimony on emerging fraud threats, focusing on how digital identity verification can protect taxpayer-funded programs. Jordan Burris, head of public sector at identity firm Socure, testified that the government still treats matching a name, date of birth, and Social Security number against authoritative records as proof of identity, an approach he said “is no longer sufficient.” He described one fraud ring that “created nearly 25,000 synthetic identities and launched more than 35,000 attacks in just 30 days,” arguing the adversary has changed while the federal identity model has not.
David Maimon, head of fraud insights at SentiLink, testified that fraud against government programs has become “a durable, specialized criminal infrastructure” that migrated from pandemic relief into programs including SNAP, Medicare, Medicaid, and tax refunds. Criminals, he said, combine stolen identities with AI-generated faces and deepfake video to defeat liveness checks “using nothing more exotic than face swapping software available to anyone.”
Marisol Cruz Cain of the Government Accountability Office pointed to Login.gov, the General Services Administration’s sign-in service, as a specific gap. She testified that GAO’s 2024 and 2025 reviews found the system did not meet Identity Assurance Level 2, the federal standard for remote identity proofing, because it never included a physical or biometric comparison linking a user to a real identity. To its credit, she added, GSA has since implemented three of GAO’s four recommendations and completed a remote identity proofing pilot bringing the system into line with the NIST IAL2 standard.
The witnesses’ prescription centered on speed and incentives. Maimon urged that agencies get “standing authority to test and deploy technologies to meet the current threats, not just at the next scheduled audit,” while Burris called on Congress to reward stopping fraud “before taxpayer dollars ever leave the Treasury” and to treat identity verification as infrastructure resourced to evolve rather than “built once, certified once and left in place for a decade.”
IAL2, the standard at the center of the Login.gov critique, increasingly shapes commercial offerings too, including Socure’s recent launch of a live-agent Remote Verifier, a line rooted in the company’s 163 million dollar Login.gov call order.
Whether Congress grants the standing authority the witnesses sought, the hearing sharpened a claim the industry has pressed for years: verifying who is asking, before benefits flow, is cheaper than clawing money back afterward.
Sources: House Committee on Oversight and Government Reform
–
By the ID Tech Editorial Team





Follow Us