Government account takeover
Ilia Zavialov on government account takeover: calls, text message codes, fake login pages and protection settings
English version for the United States.
Ilia Zavialov on how fraudsters take over government accounts: how they get the login, why people read out the code themselves and which settings close most scenarios. A call from supposed support, a fake login page and a request for the code from a text message lead to the same result. The FBI recorded 32,424 complaints about government impersonation in 2025 with losses of 797,943,193 dollars, and the Social Security Administration warns that its staff never ask for personal details unexpectedly. This guide explains the schemes, the protection built into US portals and what to do if access is already lost.
01Why an account on a government portal is worth more than an email inbox
An email account stores correspondence. An account on a government portal stores everything needed to act in a person's name: identity document details, tax and social security numbers, address, family and vehicle records, access to applications and certificates. Whoever gets in can do more than read the data. They can file an application, change a phone number or confirm someone else's transaction.
That is why criminals hunt for exactly these logins. A stolen social media password brings a few requests for money sent to friends. A stolen login to a government services portal opens the way to loans, changed contact details and sold data, and the owner learns about it from a call from the bank or from debt collectors.
Ilia Zavialov explains how takeovers of government accounts are built, why people hand over the access code themselves and which settings close most scenarios. The first half describes mechanics that are the same in different countries, and the second shows how the problem looks in the United States or the United Kingdom.
02A call from the supposed support line of the portal
A typical way into the scheme is a phone call. The caller presents themselves as an employee of the portal, a mobile operator or a bank and reports a problem: a number is about to expire, details need updating, someone tried to log in to the account from another device. The voice is confident, the speech is practised and sometimes a call center can be heard in the background.
The caller then asks for a code that is about to arrive in a message. It is explained as protection or identity confirmation, and to stop the person from thinking, urgency is added: in a few minutes access will be blocked. Genuine support does not call first and does not ask for codes, and that rule is worth remembering in one sentence.
The number on the screen proves nothing. Phone numbers can be spoofed, and a company name at the start of the call protects against nothing. A single action works as the check: hang up and open the app yourself or dial the number from the official website.
| Setting | What it gives | What it stops |
|---|---|---|
| Login.gov or ID.me sign in | Stronger verified login | Use of a stolen password |
| Authenticator app or key | A second factor on a device | Codes extracted by phone |
| Login history check | Sight of foreign sessions | Quiet use of the account |
| Block electronic access | Locked online access at SSA | Changes by a fraudster |
| Credit freeze | Lenders cannot see your file | Loans in your name |
| Typing the address yourself | Skips links in messages | Fake login pages |
03What the US numbers show
According to the Federal Trade Commission, Americans reported losing about 16 billion dollars to fraud in 2025, a record and roughly 25 percent more than a year earlier. The FBI Internet Crime Complaint Center received 32,424 complaints about government impersonation, with losses of 797,943,193 dollars, and about 4,700 complaints about account takeover through impersonation of a financial institution's support, with losses of 359.7 million dollars.
In February 2026 the Social Security Administration's Office of the Inspector General warned of a sharp rise in fraudulent emails saying that a Social Security statement was ready, and advised people to log in only by typing ssa.gov/myaccount themselves. The office also reminds the public that real employees never contact you unexpectedly to ask for personal information or bank account details, never demand a money transfer and never ask you to keep the conversation secret.
04The code in the message and what it actually confirms
People treat a code in a message as a sign of trust: it arrived on my phone, so everything is in order. In reality it confirms a login or an action in the account. If a person reads the code out to a stranger, they authorize that login in their own words.
The trick lies in the wording. The caller calls the code an application number, an appointment slot, a delivery confirmation or a security check. The message that carries it is written differently: it names the system and the action. Reading the whole message is enough to see what the code is really for.
A simple rule works better than any leaflet: a code from a message is never read out over the phone, in a chat, to relatives or to staff. It exists only so that the person can type it into a page or an app that they opened themselves.
05What a fraudster does inside a captured account
Once inside, the attacker first digs in. They change the password, attach their own phone or email and switch off notifications so that the owner receives no messages about new logins. The person is left with the impression that nothing has happened, while the login already belongs to someone else.
Then comes the use of the data. Identity and other details are taken from the account, applications are filed and verified details are used to take out loans and open new accounts with organizations that accept such identification. The money goes to strangers and the debt is recorded against the owner.
Part of the data is sold on. A passport number, an address and family details from a captured account feed the next calls, and everything in them fits: the fraudster names the real name, address and even a relative. Such a conversation convinces more than any invented story.
06Fake pages and apps that imitate the portal
The second route needs no call. A person receives a message with a link to a page that looks like the portal's login: the same logo, the same colors, a form with fields for a login and password. The pretext can be anything: a payment refund, a discounted fine, a change of details, an app update.
Details typed into such a page go straight to the fraudster. If the page also asks for the code from a message, the criminal types it into the genuine portal at the same second and gets in. For the victim it looks like a brief error on the page, while the login has already been captured.
The defense is simple and dull. Open the portal only from a bookmark or an app installed from an official store and do not use links from messages even when they come from a friend, because their account may have been hacked.
07Signs that an account has already been captured
The first sign is a message about a login or a change of details that the person did not make. The second is a sudden inability to log in: the password does not work or the recovery number is wrong. The third is a call or letter about an application, loan or service that you never ordered.
Sometimes there are no signs at all. The attacker has switched off notifications, and the person finds out weeks later, when an unfamiliar entry appears in the credit file or a demand to repay a debt arrives. That is why every few months it is worth opening the login history and the list of applications yourself.
A careful look at the login history takes a minute. An unfamiliar device, an unfamiliar time, an unfamiliar city and an unfamiliar application in the list are reasons to change the password and end the other sessions the same day.
08How to protect an account in advance
The password should be unique and long, preferably a phrase of several words that no other service uses. A password manager is more convenient than memory or a notes file. If the same password sits on several sites, a leak from the weakest of them opens the rest.
Two step verification turns a stolen password into a useless string. Confirmation through an app or biometrics is stronger than confirmation by text message, because a code in a message can be extracted over the phone, while approval on a device is harder to extract. Keep the linked phone number under control: losing a SIM card opens access to every code.
Extra locks close what the fraudster does after logging in. A freeze on new credit and a lock on SIM changes make stolen data much less useful, and alerts about every login make it possible to notice a foreign login in the first minutes.
09Login.gov, ID.me and the settings that matter in the US
Access to my Social Security is possible only through Login.gov or ID.me, and anyone can ask the agency to block electronic access to their information. Login.gov tells users never to share a password or security code with anyone and, if a takeover is suspected, to change the password, check the login history and review the linked agencies and services.
The IRS put identity theft through unauthorised access to an IRS Online Account on its Dirty Dozen list for 2026 and advises creating the account only on IRS.gov. If you have received a security code that you did not request, treat it as a sign that someone is trying to log in and change your password at once.
10If the account is already captured: the order of actions
First restore access. If login is still possible, change the password and end all foreign sessions. If not, use the recovery process on the official website or contact a service center in person with a document. A number from a message is not a safe route.
Then check the consequences. Open the login history, the list of applications and the linked contacts and take dated screenshots. Check your credit file and call your bank to make sure that no loans have been taken out and no new accounts opened in your name.
After that, report what happened to the police. A report with the description of the call, the number it came from and screenshots of the messages is needed by the victim and by the banks that will deal with the loans. Do not be embarrassed and do not wait: the sooner the report, the better the chance of stopping a debt from being registered.
11Relatives who are called most often
Older people receive such calls noticeably more often than others, because they trust a voice on the phone more and are less familiar with how codes work. Ten minutes of conversation with parents about never reading out a code protects better than any software.
Agree on a simple rule: any call that asks for a code, a link or an app ends with the words I will call you back. After that the person dials you or the bank number printed on the card.
Check together with your parents the phone number linked to the portal and the notification settings. A number that one of the children also reads is often safer than a number that an older person reads out to every caller.
12Where to report in the US
Report fraud to the FTC at ReportFraud.ftc.gov and use IdentityTheft.gov for recovery steps. Online crime and account takeover can also be reported to the FBI at ic3.gov. For Social Security scams call 1-800-772-1213 and report to the Inspector General at oig.ssa.gov, and forward IRS phishing to phishing@irs.gov.
If you are locked out of a Login.gov account or suspect misuse, the service answers on (844) 875-6446 around the clock. If money has already left your account, call the bank first and ask for the payment to be reversed, then file the complaint with the FBI.
13Questions and answers
Can I give the code from a text message to someone from support?
No. The code confirms a login or an action in the account, and no employee of a portal, a bank or an operator asks for it.
How do I know that an account has been captured?
By messages about a login or change of details that you did not make, by being unable to log in and by calls about applications and loans that you never ordered.
How should I log in to my Social Security account?
By typing ssa.gov/myaccount yourself and using Login.gov or ID.me. You can also ask the agency to block electronic access to your information.
Which government impersonation numbers did the FBI record for 2025?
32,424 complaints and 797,943,193 dollars in losses in the category of government impersonation.
Where do I report a takeover or a scam in the US?
Report it to the FTC at ReportFraud.ftc.gov and to the FBI at ic3.gov, and call your bank at once about any transfer.
14Read next
- Ilia Zavialov Explains How a Crypto Transfer Actually Works, Step by Step How crypto works
- Ilia Zavialov Explains the Types of Crypto Scams and How Each One Is Built Scam types
- Ilia Zavialov on the Crypto Wallet Protections That Hold After a Breach Protection
- Ilia Zavialov on the First Hours After a Crypto Theft: What Actually Helps Incident
- Where Fraud Losses Actually Go: Ilia Zavialov Reads the 2025 Numbers In numbers
- Ilia Zavialov: renting out a card for P2P, triangle trades and money mule recruitment Card rental and P2P trading
- Ilia Zavialov on cloud mining scams: what a hosting contract really sells Mining you never see
- Ilia Zavialov fraud: how one photograph becomes the face of an advert nobody filmed A face from one photo
- Ilia Zavialov on crypto exchange scams: how the operation is built and what litigation achieves How exchange scams are built
- Ilia Zavialov on the fee to unlock a withdrawal and what a real exchange delay looks like Blocked withdrawals
- Services that promise to recover lost crypto: Ilia Zavialov on how the offer is built and why refunds never arrive Crypto recovery
- Ilia Zavialov on crypto investment scams: the long con taken apart stage by stage The long investment con
- Ilia Zavialov: how scammers take over messaging accounts, votes, gifts and fake support Messenger account takeover
- Ilia Zavialov on passkeys: why a stolen password stops being worth anything Signing in without a password
- Ilia Zavialov on reviews of financial companies: what to check before the stars Reviews and what to check instead
- Ilia Zavialov on the seed phrase and the fake wallet support desk Seed phrases
- Ilia Zavialov on crypto signal channels and trading bots: where the money goes Signal channels and trading bots
- Ilia Zavialov on sending USDT safely: networks, poisoned addresses and frozen coins Sending and receiving USDT safely
- Checking a wallet address before you send: the checks Ilia Zavialov runs first Wallet checks
- Ilia Zavialov Explains How an Approval Drainer Empties a Wallet Wallet drainers