📺 Stream EntrepreneurTV for Free 📺

The Government Is Not Immune to Account-Takeover Fraud, and That Could Be Trouble for You and Me Agencies need to develop and implement risk-mitigation strategies to protect their constituents.

By Jonathan McDonald

entrepreneur daily

Opinions expressed by Entrepreneur contributors are their own.

Government agencies (and their customers) aren't immune to cyber-attacks. In fact, they're often a more tempting target with an extensive network of compromised personal data available for sale, or provided by a consumer unaware of a scam. The pandemic only exacerbated an already serious problem with cybersecurity in the public sector. Now, government agencies are faced with scams and fraudulent claims in addition to typical cyber-attacks, and the problem needs real attention.

Account takeover and other threats

One of the most significant threats facing government agencies at all levels during the pandemic is account takeover (ATO). ATO was accompanied, to a lesser degree, by fraudulent account creation, fraudulently filing for benefits or filing under a false identity. The numbers are still being tallied, but costs to U.S. taxpayers from Covid-related fraud totals in the billions.

ATO occurs when a bad actor gains control over a person's benefits account. First, they will gain login details, then change seemingly insignificant PII data on the account slowly. Successful ATOs can unlock a host of benefits for the attacker, who is then free to make fraudulent claims and assume the online identity of the victim.

Gaining access to an account isn't too difficult. Examples of Covid-19 scams abounded over the past year, with scammers calling to "verify benefits," sending phishing text messages or asking people to take part in "Covid-19 surveys." These scams would target personal information that, in some cases, would get the scammers just the info they'd need to execute an ATO.

According to a recent study by TransUnion, government agencies at all levels recognize that ATO is a significant threat to their customers, and that threat has been growing over the past two years. Unfortunately, a corresponding rise in security to combat this threat has not occurred. Mobile devices are one of the most significant vectors for ATO fraud, but government agencies have been slow to respond, which leaves the door to fraudsters wide open.

Beyond ATO, agencies face threats from scammers filing false claims using a real identity or creating a fake identity to make claims. Although neither of these threats are as pressing as ATO, they've cost taxpayers millions. Although noble, the rush to issue benefits to Americans in need created an irresistible opportunity to unscrupulous fraudsters. Some of these were even committed by organized crime rings. There's no question that government agencies need to take steps to improve their security protocols, reduce fraud and ultimately get the funds to the people who need them the most.

Related: Cybersecurity Is No Longer An Option. Your Money Is in Immediate Danger.

Government agencies face implementation barriers

Unfortunately, public sector agencies face different implementation barriers for risk-mitigation strategies than private-sector organizations. Changes often move slowly through bureaucracies, and government agencies are often hampered by more restricted budgets. Furthermore, as in many industries, senior management may have been slow to recognize the risk presented by increasingly sophisticated online attacks. However, there is hope for potential solutions to be simple, effective guards against these problems.

Government employees working to fight against this fraud recognize that it's a problem, and they also recognize solutions are out there. In many cases, some simple security measures would help immensely. Technology has offered several convenient and effective ways to mitigate these threats and help government agencies better protect their constituents and taxpayer resources. Private-sector businesses can also apply these same methods to better combat ATOs.

Two-factor authentication

One of the simplest ways to help mitigate ATO is through enabling two-factor authentication for sign-ins. The simple step of texting or emailing a one-time password could help government agencies add a second layer of identity proofing to online transactions and give constituents additional peace of mind to securing their accounts.

Related: Putting Off Cybersecurity Is Putting You at Much Bigger Risk Than You Realize

Behavioral analytics

Behavioral analytics are also a promising technological solution to a complex problem. Using huge data sets, several identity-verification services can create an online picture of a person's behavioral patterns (including the device profile they typically use). In the event of an ATO, those services can flag behaviors that are out of character for the individual or the device. In the event of questionable behavior, those services can then trigger an online transaction platform to seek additional information from the constituent to authenticate them. This can happen in real-time, with minimal to no friction for the constituent.

These are just a couple of the tools available to government agencies as well as the private sector. Threats like ATO are a real problem, and all reports indicate they will increase in prevalence so government agencies need to develop and implement risk mitigation strategies to protect their constituents. As more and more constituents use mobile devices to access online benefits, it is incumbent upon government agencies to offer higher levels of security.

Jonathan McDonald

EVP & GM, Public Sector at TransUnion

Jonathan McDonald leads TransUnion’s Public Sector business, which provides a suite of mission-critical solutions to help U.S. federal, state and local government agencies manage risk and reduce costs. He has hands-on experience managing large technology programs within various government agencies.

Want to be an Entrepreneur Leadership Network contributor? Apply now to join.

Franchise

McDonald's Introduces a New Dessert Inspired By 'Grandmacore' Trend

McDonald's will launch the "Grandma McFlurry," a limited-time dessert blending syrup, vanilla ice cream and candy pieces, as a tribute to comforting grandmotherly treats — and a nod to a TikTok trend.

Starting a Business

Clinton Sparks Podcast: The Secrets of Entrepreneurship Told by David Meltzer

This podcast is a fun, entertaining and informative show that will teach you how to succeed and achieve your goals with practical advice and actionable steps given through compelling stories and conversations with Clinton and his guests.

Business Culture

Hybrid Work Is Failing Your Employees — Here's Why (and What You Can Do About It)

Business leaders are trying to choose between in-person and remote work. This leads to hybrid, which just isn't effective. Here's why.

Growing a Business

How to Properly Manage the Cash Flow of Your Startup

Ever think financial planning and analysis is just for big businesses? Think again! Startups thrive on solid financial planning, which is key to staying ahead of your competitors.

Productivity

Want to Be More Productive? Here's How Google Executives Structure Their Schedules

These five tactics from inside Google will help you focus and protect your time.

Franchise

The Role and Responsibilities of a Franchisee, Defined

The Yin to the Franchisor's Yang, franchisees are essential to the functionality of the business model.