Identity Not Proven at Login.gov

I haven’t gotten around to sharing this, but it’s significant.

“Marisol Cruz Cain, director of GAO’s Information Technology and Cybersecurity branch, told members of the House Committee on Oversight and Government Reform’s Subcommittee on Government Operations that in May 2025, the General Services Administration (GSA) ‘issued a contract modification for Login.gov that indicated the program’s Anti-Fraud Team determined that fraudulent accounts passed the identity proofing services and that the sophistication of the attempts would increase exponentially in the future.’”

This despite the fact that Login.gov had been certified for IAL2 compliance.

The lesson learned, which extends well beyond Login.gov: just because something has a checkbox indicating standards certification doesn’t necessarily mean that it truly conforms with the standard…every time.

Leave a Comment