Summary
- Jordan Burris (Vice President and Head of Public Sector Strategy, Socure) warned federal identity verification is obsolete against AI-driven fraud rings causing up to $521 billion losses.
- David Maimon (Head of Fraud Insights, SentiLink) described durable criminal infrastructure reusing stolen identities across SNAP, Medicare, student aid, tax refunds and SBA loans.
- Pete Sessions pressed Jay Stanley (Senior Policy Analyst, American Civil Liberties Union) on investigative limits once fraud is established and re-screening current benefit recipients.
- Both sides agreed fraud steals from needy beneficiaries, while privacy and access concerns tempered enthusiasm for mandatory digital identification systems.
- Marisol Cruz Cain (Director / Information Technology and Cybersecurity, US Government Accountability Office) said Login.gov must continuously adapt and improve agency collaboration to combat evolving fraud threats.
Morning digest
Get hearings like this in your inbox
Transcript
Good afternoon and welcome to today's hearing on emerging threats and evolving fraud landscape here in the United States of America. Over the years, the Government Operations Subcommittee on a bipartisan basis has held several hearings addressing the issue of fraud, addressing the the the things that the United States government faces as well as the American people. And each time we have been talking about fraud, how to identify it and how to prevent it. In our discussions we've highlighted the importance of government agencies focusing on preventing fraud before it happens. And as we've heard countless times before, once the money is gone out the door, it's hard to get back. This remains a very important issue and this subcommittee to both the young ranking member and myself in this subcommittee is very important, but one critical element missing from our many conversations is what sort of fraud are we trying to prevent? How does it really work? What really are we doing about it and where do we need to focus our attention to make sure that we are going to address this properly? In our past discussions, we've referenced the fraudsters in our darkroom, stealing our Aunt Sally's social security number. We've highlighted the risk posed posed by foreign actors applying to multiple disaster relief programs. We've discussed elaborate frauderings that exploit loopholes in benefit programs in order to receive payment for services that they should not have received. but perhaps got the money. But fraud threats are changing and they're rapidly advancing. Identifying fraud threats specifically or becoming a fraudstered actor or or booming as fraudulent actors become smarter and gain access to tools intended to make our life easier, and their life easier through AI. This gives them more power. It's up to us to catch up. It's up to have to find it and to find a way that we're gonna corner the market on our side of the agenda. Government programs rely on identify verifi- identity of verification to confirm that the individual planned for benefits to services are who they say they are. However, we've seen over the years the platforms used for this verifications have failed to meet the expectations. In March of twenty twenty-three, this subcommittee held a hearing focused on Login dot gov and the traveling fi- the troubling findings from the General Service Administration's Inspector General report that was released that month told us point blank, we have a problem. In short, GSA misled government clients about the extent to which Login dot gov met certain technical standards and expressly what they said it would do. These standards were the backbone as w- of what was needed to ensure the identity verification platform could prevent fraud, protect the taxpayer, and give the government the necessary, uh, information that it would need to know who they were speaking to and what that person might be eligible for for benefits. Over the years, many changes have been made to login dot gov, and federal agencies have explored other public and private sector solutions for digital identification verification. As we we're moving to a more digital environment where individuals may no longer be asked to present a physical ID card, we need to better understand what threats there are and where what the fraud landscape looks like. Today's fraud landscape landscape looks different than the one that existed when we started this investigation and is rapidly evolving. Even today, fraudsters from literally anywhere in the world can now create hundreds or thousands of synthetic identities and apply for many different government beneficent uh government benefit programs simultaneously. It's not it's not it's no longer they could, they are. Back to adders, bad actors are able to develop the use of deep fakes, mimicking the likeness of an individual, to circumvent the safeguards that have been put in place to protect the taxpayer. Bad actors have made it their business to exploit vulnerabilities in government programs, It is necessary that we understand that they have been successful, and we need to make sure we're developing the tools that actually al- allow us to see the fraud before it occurs, not when it's out the door. Identity verification has long been a one time check at the beginning of an application process, but the considering the rapid eva evolution of identity fraud, validating and constantly validating identity as um as it moves forward. Fraud should not be considered the cost of doing business because it means that someone is not getting the benefit that they were eligible for. And if there is one overriding principle that this subcommittee, all of our members agree on, it is that the people who we have intended the benefits to go to They should be the ones that get it, and any diminishment of that is is is a considered a failure on our part also. In January of this year, I introduced bipartisan legislation to combat identity fraud and theft. The Stop Identity Fraud and and Identity Theft Act aims to strengthen the nation's digital id- identity verification infrastructure and protect individuals, businesses, and government programs from rising identity and fraud and theft. I'm hoping that this legislation is a step in the right direction. And after meeting with our panel members, I will tell you it is a step because we are going to learn more today in this rapidly evolving landscape that we call fraud. along with the verification systems that are available today. We have a great panel of witnesses who can shed light on new identity fraud threats, plaguing our systems, how the fraud landscape is evolving, and the what what the government should be doing and is doing to keep up with that. I look forward to a fruitful discussion and I want to personally thank our ranking ranking member, Mister Nfume, For his continued support, those of you who are new to this uh subcommittee will learn that both m- both Mister Mfume and I insist on making sure that we work well together, that we listen to each other, that we listen to all of our members and allow them to fully participate, adding thoughts and ideas, but perhaps more importantly, to show up and listen and learn about the landscape that is directly in front of us. Mister Nfume is a very dear friend of mine. Uh, he is a man who has a distinguished service service not just to the United States Congress but to United States of America and to his district and uh you will soon learn those of you who are here that we have many distinguished members of this subcommittee who were here because they believe in not only doing their job, but also helping us curb the appetite that fraudsters have to take advantage of our citizens. With that said, uh, I would like to now ask the gentleman if he would engage us with any opening statement he'd like to make. The distinguished gentleman is recognized.
I wanna thank you, Mister Chairman, for your kind and clearly overly gracious set of remarks, um, for your friendship, for your stewardship of this committee, and for the ability, uh, for us on both sides of the aisle to really delve into detail on various issues, but none more important than this issue of fraud. I know I speak for all of my colleagues on my side of the aisle when I say we welcome this hearing as we did the previous one. We look forward to finding answers, quite frankly, and finding a way to get out of the situation that we're in with respect to the level and the significance of fraud within our our government. So we're here today to talk about for our particularly emerging threats and solutions related to digital identity verification. Social security numbers and paper cards made sense ninety years ago, long before the current age of computers and digital technology. Programs have matured, scammers have adopted them and found a way to get around them, and so the government must also, I think, adapt its service delivery and technology to prevent fraud and to better serve the American people. That adaptation was exactly what the federal government had in mind many years ago when it came up with the idea and then later became the reality of something called Login dot Gov which we're all familiar with, a single secure sign-in that works across agencies. Before login dot gov, each agency maintained its own identity verification. Good luck with that one. It wasn't just a headache for our constituents, it was also a costly overlap in functions and a critical cyber vulnerability. While the GSA may have stumbled out of the gate with the initial release, we finally reached a point, I think, where agencies across all levels of government have a safe, secure and verified gateway to government services that improves the customer service and helps our constituents across the services and the resources that their taxes pay for. The turn-around in this program serves as an important example of bipartisan congressional oversight, where once accusations of false promises dogged that program. Login.gov can now effectively serve the American people. We first learned, however, of the issues with Login.gov when the General Services Administration Inspector General published a report finding that several individuals at GSA had misled its agency customers that the system could do higher levels of identity verification than GSA itself. Um, those sort of things created problems. Three years ago we had a hearing exploring the issue and sent further follow-up letters as the chairman indicated and briefings to ensure that GSA fixed the system that provided the service that they promised their agency clients. A year after our hearing, GSA announced it had fully implemented the National Institute of Standard in Technology's standard and had rolled it out to their agencies and to their partners. Today, Login. Gov. has over one hundred million users across more than fifty agencies and five hundred applications across federal, state, and local government. Now that doesn't mean that the work to ensure digital identity verification across the entire federal government is finished. I look forward, like many of you, to hearing our witnesses today about how we can effectively implement the next generation of log-in dot gov and identity management. However, we must be carefully consider the difficulties and the pitfalls of the new technologies and just not assume that they don't have any. Innovations like digital ID can better combat fraud and electronically safeguard identity, much more so than a nine-digit number on a piece of paper. Digital ID sounds great. Um, I wouldn't need to carry around a plastic license, just a smart phone if I'm the average American citizen with cutting-edge technology to safeguard my personal information. The problem is, however, that that very phone provides a new vector of attack, and any computer is vulnerable to a cyber-attack, as we know, regardless of its level of sophistication. Digital ID can also limit access for people who have trouble using technology, even for people who cannot afford a smartphone. Sometimes people just break their phones and can't take time out of their busy day to immediately go and get a new one. So I don't think we can afford to lock people out of government or private services because they cannot access or afford a smartphone. Any time the government can revoke access to services even for benevolent purposes, we must find a way to protect against abuse. The Trump administration's Doge program, uh the Department of Government Efficiency, which many of us thought was the department of government evil, used a key social security administration identity database to mark thousands of living people as dead. in order to exert financial hardship. A whistleblower recently said that he planned to expand this to millions of people. Now, do we really want to move to a system where the government can invalidate any ID it wants to just by sending an instruction to the phone that's in your pocket? I can absolutely think of places where digital ID has valid uses, for age verification and for fraud prevention. But every place that an American taps their phone to access services cannot be a bread crumb to the track or bread crumb follow the track process in their daily lives. So I'm excited to have those of you who are here to discuss the new technologies to prevent fraud against the American taxpayer. Uh, we must also ensure that we keep an eye on the horizon to prevent any sort of mass surveillance and government surveillance that can literally decide if in fact we are considered live or dead. So I want to thank the chairman again, uh, for keeping his commitment on this issue, uh, for members on both sides of the aisle that continue to plow through this. It's been a couple of years now and we're gonna continue to do what we have to do, until we can't do it anymore. And I Uh, appreciate the opportunity to have all of you here, hear what you have to say on the record. And, Mr. Chairman, I yield back to you.
The gentleman yields back his time. Thank you very much. I'd like to ask you now, let's consider if I can, to uh allow the distinguished gentleman uh who has a meeting that he has to attend to very quickly give some brief remarks.
Mm-hmm.
I'd like to uh yield time now to the distinguished gentleman, Chairman Gary Palmer. Chairman Palmer, you're recognized.
Thank you, Mister Chairman, uh thank you for holding this hearing and and I'd like to thank the ranking member for the bipartisanship uh that we've seen throughout this process in trying to address um the fraud and and also other issues related to improper payments. Um this is an extremely important issue. I just came out of a meeting with Doctor Philip Swagle, the Director of the uh Congressional Budget Office, and we estimate just uh the initial uh investigations in the fraud that - that will have about a hundred and sixty-eight billion dollars in savings. Uh, I wanna make certain that - that people understand this is not just about the money. Um, so much of this uh fraud uh mismanagement occurs in programs that are designed to help people who need help. When - when we're losing that - that much money, we're being defrauded of that much money, Those are funds that are not available for for people who are truly in need. So this this is a huge issue for us and it's not uh limited to domestic fraud. Uh, we what we saw during the COVID pandemic, uh the programs at the federal level were being defrauded by a massive network of of foreign actors and uh um But we also have other issues uh aside from the fraud. I think uh one of the things that we found is that there's a tremendous need to to modernize uh federal data systems, bring them into the twenty-first century, because a lot of the issues that we have with improper payments are directly related to antiquated data systems. So, Mister Chairman, uh I I really hate that I'm I'm not gonna be able to participate in this hearing. I think it's extremely important and uh would have benefited greatly from hearing the questions and answers uh uh the questions to our witnesses and their answers. With that, uh, Mister Chairman, again, uh, thank you for the privilege of being able to address the issue. I yield back.
Gentleman yields back his time. Thank you very much. Without objection, uh, Congressman Walkinshaw of Virginia is waived onto the subcommittee for the purpose of questioning the witnesses at today's subcommittee hearing. I now would like to move to, uh, welcome our witnesses who have taken, uh, their time today to be with us And I'm very delighted to say that I I think that you will find and the uh the the members will find their uh input very valuable to exactly the same things that the Chairman uh was talking about and that is that we need to understand what's out there today. It's easy for us to think that we understand a lot and we're gonna learn it all today. So I'm pleased to welcome our witnesses, Mister Jordan Burris, is Vice President and the Head of Public Sector at SoCure, where he partners with government leaders to develop and implement private sector solutions for identity verification and fraud risk management. Next, we have Marisol Cruz-Cain, is Director of Information Technology and Cybersecurity at the GAO. The Government Accounting Office has experts that provide not only expert testimony but have an idea of the day-to-day uh activities that move across the government. She oversees federal cyber security and privacy work. Her port portfolio includes emerging technologies, the national cyber security strategy, and agency efforts to protect privacy, sensitive data, and critical computing infrastructure. Next we have David Mayman, and he is the Head of Fraud Insights at Cynilink, a company that combines technology and expertise to stop identity fraud at the application stage. He's also a professor in the Department of Criminal Justice and Criminology at Georgia State University where he directs the evidence-based cyber security research group group. Lastly, Mister J. Stanley is a senior policy analyst at the American Civil Liberties Union. His work focuses on technology-related privacy and civil liberties issues and that future and how it impacts public policy. Thank you to each of you for joining us. Uh, I would now ask that each of you rise in pursuance committee rule nine. Gee, the witnesses will each, as they stand, to take the You can all stand please to take the uh uh uh the oath to the witnesses, and I would ask that you please raise your right hand. I will read this and then let you affirm or choose as you would do. Do you solemnly swear or affirm that the testimony that you're about to give is the truth, the whole truth and nothing but the truth so help you God? That's a question. Please let the record reflect that the witnesses have answered in the affirmative. Thank you very much. You may all take your seat. Uh, I have had an opportunity to uh speak with e- each of you hopefully. Uh, except Mister Stanley, Mister Stanley, I want you to know that I have advised the other witnesses here that we appreciate you being here as we do them, that I run the committee hearings uh differently. I'd like for you to be able to finish your sentence. for you to be able to complete your thought. I'd like for you to be able to thoughtfully respond and provide this subcommittee with the things which you have come professionally to do to us. Uh, I I I'm not gonna at five minutes, uh, I'm not gonna bang the gavel. You're here, you're a professional, we need to hear from you, and I try and give that same uh type of of uh leverage to each of our members, so I am delighted. But with that said, If you don't take advantage of it, I will not either. We have an idea that we're trying to move our business and make our mem let allow our members an opportunity uh to um to come and do their business also. So, we will now move uh forward uh with the uh feedback from our uh witnesses and we will first move to the distinguished gentleman, Mister Burris. Mister Burris,
Chairman Sessions, Ranking Member Mfume, and members of the subcommittee, thank you for your leadership on this critical topic and for the opportunity to be back here to be part of the conversation. For the last fifteen years, I have worked on one question from inside and outside the government. How do we know with confidence that the person on the other side of a digital transaction is who they claim to be? Today, that question has become far more difficult to answer. And here's the blunt truth. The way the federal government verifies identity was designed for a threat that no longer exists. Every day, however, we defend that old model, as though it still does, and give fraud networks another opportunity to steal taxpayer dollars and undermine public trust. GAO estimates federal fraud losses at as high as five hundred and twenty-one billion dollars Further, the pandemic exposed just how far our identity infrastructure has fallen behind. Those losses were a warning. Today, the gap has widened dramatically. And by the time we update the next set of estimates, it will be double or triple the size. My name is Jordan Burris, and I lead the public sector business at Socur. Socur was founded on a simple premise. In a digital world, proving who someone is should be accurate, fast, and fair. Today, our AI-native identity and fraud intelligence platform helps more than three thousand organizations globally, including over one hundred and fifty public sector organizations make trusted identity decisions. That broad view allows us to see how fraud evolves across the economy, and increasingly targets the government. Before joining Socare, I served as chief of staff in the White House Office of the Federal Chief Information Officer, helping shape federal identity policy through the COVID response and the government's transition to zero trust after solar winds. Working inside the government and in the private sector has shown me just how rapidly this threat has evolved. Some in the identity industry are have begun calling this moment " world war fraud", and I understand why. We are no longer confronting isolated fraudsters. We are facing organized, increasingly sophisticated transnational fraud rings using AI at industrial scale. One fraud ring we profiled created nearly twenty-five thousand synthetic identities and launched more than thirty-five thousand attacks in just thirty days. The adversary has changed. Our federal identity model, however, has not. and yet many in the government believe it will hold up to today or even tomorrow's fraud threat. For decades, the government has treated matching a name, date of birth, and social security number validated against government authoritative records as proof of identity. That approach is no longer sufficient.
I can't.
Further, fraud does not stop at enrollment and identity verification cannot either. It must become a continuous discipline that evaluates risk throughout the life cycle of an account. From where I sit, identity should be considered critical infrastructure. Nearly every interaction Americans have with their government, benefits, tax administration, disaster relief, veteran services, and health care depends on getting this decision right. Done correctly, better security means better access. It makes it easier to say yes to legitimate Americans and no to industrialized fraud rings. This year, SOCUR supported the Department of Education in deploying real-time risk-based identity screening in the FAFSA process, protecting more than one billion dollars in taxpayer funds while allowing over ninety-two percent of legitimate applicants to pass automatically. That's the model the government should continue pursuing. Prevention before payment Risk-based rather than one size fits all. Continuous rather than point in time. And outcomes rather than checklists. To make this the federal model, I would leave the committee with five recommendations. First, measure outcomes not compliance, requiring systems to prove that they can stop the changing fraud threat. Second, make continuous identity verification the standard across the life cycle of an account. Third, expand secure data sharing where we know it works through trusted resources like Do Not Pay and other cross-government solutions. Fourth, reward fraud prevention instead of recovery, where agencies are incentivized to stop fraud before taxpayer dollars ever leave the treasury. And finally, treat identity verification as dynamic infrastructure that must be resourced to evolve continuously. not built once, certified once, and left in place for a decade. To be clear, Congress does not need uh to prescribe a specific technology, but Congress can establish a new expectation. The technology exists and the evidence is clear. Now our policies and practices must catch up to the threat so Americans can trust their government in the AI era. Thank you, and I look forward to your questions.
Miss Burris, thank you very much. Uh, we now move to Lou - move to the gentleman, Miss Kane. Miss Kane, you're recognized for five minutes.
Chairman Sessions, Ranking Member Infume, and members of the subcommittee. Thank you for inviting GAO to contribute to this important discussion on identity-related fraud threats and federal efforts to improve identity verification processes. As you know, federal agencies use personally identifiable information to verify the identity of individuals who access accounts on government websites. An increase in sophisticated cyber-attacks has led to a greater risk of that PII being stolen and used to commit different types of fraud. Malicious actors can then use that information to fraudulently receive government benefits, commit tax or wage related fraud, or create new credit cards or take over people's accounts. These attacks can harm individuals, result in financial loss, or damage the reputation of federal agencies and financial institutions. Because of this, GAO has long emphasized the urgent need for the federal government to improve its ability to protect against these cyber attacks. Today I'll focus on issues related to identity related fraud threats. I'll also discuss the recent actions that GSA has taken to improve Login.gov's identity verification services and alignment with federal guidelines. Fraud has been a long-standing issue within the federal government. One particular type is identity-related fraud, which can include thieves opening new accounts in someone else's name, or stealing PII to obtain government benefits. For example, we have report reported that hundreds of billions of dollars were lost to the in the pandemic to potentially fraudulent payments. The harms caused by breaches of PII or identity theft can extend beyond tangible financial loss to include lost time such as when those victims spend months or years even working to restore their identities. Additionally, there can be reputational harm or emotional distress. To address these issues, GSA developed Login. Gov as a means to verify users' identities who wanna create an account to access Accordingly, GSA has a significant responsibility for protecting users' PII that they collect during that process. In twenty twenty-four and twenty twenty-five, we reported on Login. Gov's process for identity verification, its misalignment with federal guidelines for identity verification and fraud prevention measures. In our reports, we identified several weaknesses in GSA's implementation of Login. Gov. including that the system did not meet the requirements to verify a person at the ILA-two level. And that was because the system never included a physical or biometric comparison to link a user to a specific real-life identity. As a result, we recommended that GSA take four actions to ensure that the PII is better protected and to lessen the risk of identity theft. To its credit, GSA has fully implemented three of those actions. Most importantly, they have completed their remote identity proofing pilot, ensuring that the system is compliant with NIST's ILA-two standards. However, GSA hasn't taken important steps to collaborate with agencies to address Login.gov's technical challenges. GSA has developed a road map that outlines planned and ongoing efforts to improve its system functionality. However, this action alone does not fully address all of the technical challenges that we identified in our report. For instance, agencies reported that they lacked visibility into authentications, that the system had a high failure rate, and also it lacked fraud controls. GSA's roadmap did not contain efforts directly aimed at addressing these challenges. It's important for GSA to work with agencies to solve these issues, as doing so will help ensure that Login.gov delivers the functionality agencies need to effectively verify users' identities while also combating fraud threats. In summary, identity related fraud threats are pervasive and likely to continue to escalate. Protecting individuals' PII is critical, as the harms can be significant. GSA has taken several actions to improve login dot gov, but needs to continue to address fraud address fraud and technical challenges. This concludes my remarks and I look forward to answering any questions you may have. Thank you.
Ms. Cruz, thank you very much. Uh, Dr. Maimon, you were now recognized.
Chairman Sessions, Ranking Member Mfume, and member of sub- the subcommittee, thank you so much for the opportunity to testify today. I serve as Head of Fraud Insights at Centrelink and as a Professor of Criminal Justice and Criminology at Georgia State University. For nearly two decades, I have studied cybercrime by going where it happens, into darknet markets, telegram channels, and encrypted platforms where fraudsters buy, sell, and teach each other how to steal from government programs. I also go into the field myself, to the mail drops, virtual offices, and shell addresses these operations use to look legitimate. My testimony today is based on that first-hand work. The central lesson from my research is this. Fraud against government programs is no longer a series of isolated schemes. It is a durable, specialized criminal infrastructure, and it moves. The pandemic did not create this infrastructure, but it supercharged it. Criminals learned how to acquire stolen and synthetic identities, stand up shell companies, open bank accounts, and recruit money mules at scale. When pandem- pandemic relief programs ended, none of that capacity disappeared. It simply migrated. Today, my team is tracking that same infrastructure inside SNAP, Medicare, Medicaid, federal student aid, tax refunds, and SBA-backed loans. A few examples illustrate how. We are watching criminals combine stone identities with AI generated faces and deep fake video to defeat liveness checks at digital banks and tax preparers using nothing more exotic than face-swapping software available to anyone. We are watching an EBT fraud market where one criminal criminal's still card data a separate paid service verifies the balance before the card is even used and a third actor caches it out. And my own field investigation of a Florida durable medical medical equipment company whose office I found abandoned in Delray Beach, is now tied to a Department of Justice case alleging three point seventy-six billion dollars in fraudulent Medicare and Medicaid uh uh claims. Different programs, different agencies, same playbook. The same stolen identity, the same shell company, the same bank account, reused across systems that rarely talk to each other. That fragmentation is the vulnerability. Criminals exploit the seams between agencies precisely because our defenses are built program by program, while their infrastructure is built to move across all of them. Given my time today, I want to leave the subcommittee with four priorities. First, replace self-attestation with verified data wherever the risk is high. Too many programs still take applicants at their word on income, identity, or eligibility. That was the single biggest vulnerability exploited during the pandemic, and it remains one today. Second, expend real-time cross-agency data matching. The same identity that files a fraudulent tax return can apply for a snap benefit the same week. Agences that only compare notes in periodic bet runs weeks after the money is gone cannot see that pattern. They need to see it before disbursement, not after. Third, strengthen prepayment screening and move toward risk-based disbursement. Build on the model of treasuries do not pay system, but expand its authority and its reach so that suspicious payments are held before they leave the government rather than chased afterward through recovery audits that criminals have already outrun. Fourth, give agencies the flexibility to adopt smarter tools and keep it current. Much of today's verification infrastructure and the policies behind them were built for an earlier threat. And procurement and role-making cycles that take years cannot keep pace with fraud tactics that shift in months or less. Agencies need standing authority to test and deploy technologies, to meet the current threats, not just at the next scheduled audit. None of this requires slowing down help for legitimate applicants. It requires distinguishing them from fraud earlier, using signals criminals cannot easily fabricate. The federal government already has some of the tools it needs. which is uh what is missing is the authority, the coordination, and the sustained investment to use those tools before the money moves, not after. Every dollar we protect from organized fraud is a dollar that stays available for the people Congress intended to help. Thank you and I look forward to your questions.
Doctor Maimon, thank you very much. Mister Stanley, welcome, we're delighted that you're with us with us, gentlemen is recognized.
Thank you so much, Chairman Sessions, Ranking Member Mfume and members of the subcommittee. Thank you for inviting me to testify today, and thank you for your attention to the subject of digital identification, which I don't think has received the attention it deserves. I hope to leave you with three overarching points today. First, a digital ID system would be a disaster for individual liberties if it's not done right. If any such system is to become standardized, it must be built with great care and awareness of big potential downsides. We have to ensure America does not become a checkpoint society, and that digital IDs don't become virtual ankle monitors, something that tracks us but we can't turn off or escape. Second, the digital ID system that is most likely to become dominant, mobile driver's licenses or MDLs issued by the States, is not being done right. Driver's licenses are already in most Americans' wallets and are by far the most likely form of digital ID to become standard. Login. Gov itself is moving towards relying on them. Third, there are much better alternatives if we just do it right. So let me start by explaining my first two points, that digital IDs have the potential to be a disaster if they're not done right, and that they are not being done right today. One big problem is that once this infrastructure is built, we start getting identity requests from every direction. Wanna enter a seven eleven? Scan your ID. Wanna buy a cup of coffee? Park your car? Tap here, please. Want to watch a video, log into social media, look at a news site, shopping site, click here to send us your driver's license. There is already far too much tracking that takes place online, and polls show Americans are very uncomfortable with it. But there's been a steady push-back and that tracking has been getting harder for companies in some ways. A digital ID could lock it down and make it inescapable. You can't just run to the DMV and get a new identity, the way you can get a new username and password. Those pushing MDLs in the States have done nothing to counter easily predictable side effect. We may create a digital ID to solve government fraud, or identity theft, or other problems. But there's a horde of others waiting in the shadows who will instantly pounce on this infrastructure to use it for their own purposes once it's created. The result will be a checkpoint society of constant ID proofing. With a digital ID that will be really easy, just tap, click, or scan. And a digital ID system, if not built carefully, could send a report back to the government every time you show your ID. a record of every beer purchase, bank, and doctor's office visit, and online, every web site you visit. This is called phone home. This capability was built into the MDL standard as an option. There's also the issue of accessibility. If digital IDs become mandatory, either legally or as a practical matter, that would harm the surprisingly large number of people who don't have a smartphone about one in ten people in the US according to studies including over a fifth of people over age sixty-five. Some may lack the resources to afford one, others the technological literacy to use them. That's why off-line options for doing business are vital to protect. If we don't make sure that digital IDs are an empowering option for people, rather than an imprisoning requirement, then people without smartphones will be shut out of many necessary functions of life and often benefits that they they sorely need. So these are easily foreseeable, predictable consequences of a digital ID. But that brings me to my third po- point. If a digital ID is to be created, there are alternative paths that would prevent many of these harms. In terms of alternatives, I have two quick points to make before I stop. First, the field of privacy enhancing cryptography is advancing fast and already can do amazing things that allow us to have our cake and eat it too when it comes to privacy and security. One example is privacy enhancing technology called zero knowledge proofs. Using that kind of tech, digital IDs can let me prove I'm over twenty-one without sharing my date, or my identi- date of birth or my identity. And it can do that in a way that if I prove my age multiple times to the same seller, they don't even know that I'm the same person. That's the kind of thing that is needed to stop ID_s from being this kind of ankle bracelet tracker. But that kind of technology is useless if we don't bother to build it in, and it has not been built into the MDL standard. If a system can reduce fraud and provide other benefits without enabling tracking, why would we build one that does enable tracking? There are other key protections we can build. On our web site we've outlined twelve key protections that we think are necessary in a digital ID system. There's more about that in my written testimony. And then second, there are some states that are moving in the right direction here. Some, like New Jersey and Illinois, have put up some important protections in place into their digital ID enabling legislation. And the state of Utah is the most notable. It has set out a separate path, which they call state endorsed digital identity, or SEDI, that is emerging as a far more privacy
Mr. Stanley, thank you very much. Mr. Stanley, thank you very much. Uh, I appreciate each of the witnesses being here. Uh, I appreciate each of the witnesses being here, uh. I'd like to move first to the uh distinguished gentleman uh mister jack for his uh question gentlemen is recognized
thank you very much mr. chairman and i appreciate your testimony this morning mister burst my first question is for you uh the public increasingly relies on the internet to access government services and i'm just curious from your perspective what fraud threats might my constituents be facing that they're not even aware of yet
representative thank you for the question when it comes to the fraud threats and the way that they're evolving across the landscape every single interaction, every single time that an individual is engaging both with their government and in their commercial life, uh there is the chance, the opportunity that an adversary could be attempting to pose as them, could be attempting to enroll in an account. Uh we see this across financial services where we work, we see this across um various aspects of the gig economy uh where we work, uh and then of course with government organizations. The the reality here is that all of the information, all the PII that exists for many folks within this room, uh has been stolen uh by the adversary and they are using that to attempt to become them and therefore that they can access what would be either their bank accounts uh and help move money uh all across the economy.
You know I've heard folks uh mention anecdotally that now with artificial intelligence people are trying to impersonate you know a loved one by virtue of maybe their voice or their mannerisms what have you and using some of that information that may have been stolen have you seen that and could you elaborate on that for us?
Yeah, absolutely, we are in a what I would consider a national crisis uh from what I've said. I've I've highlighted uh and and our team has highlighted, so Kir, for a number of years now that the moment that we're in is unlike any other in the sense that AI is being used uh as an accelerator for what attacks that typically would take weeks uh to occur uh and further it's also becoming more cost-effective for the adversary to launch those attacks so these attacks could be everything from launching deepfakes things where we've seen an eight thousand percent increase year over year. Um, this can also be in terms of the velocity by which attacks are happening. This means the speed by which they are occurring. And in these instances, these moments, we are seeing things that where attacks used to take weeks in order to be conducted, they have been broken down to under forty-eight hours. And this would mean that an adversary has launched an attack where they have stolen my information or yours or even worse, fabricated an identity, attempted to open an account and or move money, take over an account that may have existed because they went through a call center, uh and were pretending to be you using your voice or something that was cloned, an an image of yours, a biometric, et cetera. And they've used all these patterns and uh if like for say they were blocked in some way, shape or form, they then just adapt and iterate uh and the cycle continues all over again.
Thank you very much. Uh Doctor Maimon, um do I understand, uh are you a professor at Georgia State University? So I wanted to acknowledge first and foremost uh both my mother and father went to Georgia State University I represent many people who have uh degrees from Georgia State University and I also host Panthers in the District from time to time so bringing students up here. So I'm curious to build off that last question. Um you obviously you understand you know criminology, you're a professor of it. Help us understand uh are most of these threats coming from inside our country or we starting to see foreign adversaries exploit some of this data to um to, you know fraudulently impact some of our constituents?
Thank you so much for the question, really appreciate it. Um a lot is coming from abroad, we have a lot going uh going on uh internally as well, it really depends on the type of fraud we're looking at, in the context of the type of fraud you just mentioned with uh folks engaging in online romance fraud, we're seeing a lot coming from places like South Asia, uh a lot is moving right now to Africa, and uh some of the online fraud markets that I infiltrate uh uh I spend a lot of time sort of trying to infiltrate to uh Yahoo Boys uh channels as well as channels where I actually see them using those deepfakes to swap faces while engaging with some of the victims uh uh here in the United States it's uh heartbreaking to see the level of conversations that uh these guys are able to get uh uh with uh those those targets and it's also um heartbreaking to see the different modus operandi and different types of buckets that those criminals are engaging I can tell you that as of uh this this morning uh we're seeing more and more Yahoo boys and and Sakawa boys targeting um uh our four O one Ks, victims' four O one Ks. So, you know, we're seeing them convincing targets to borrow against the four O one Ks, as well as uh hand over control completely uh on the four O one Ks accounts. So this is what we're up against. We're seeing those uh deepfakes being used to swap faces, uh lure targets to uh give away access to the uh four O one K accounts, and then unfortunately victims funnel the money to bank accounts criminals uh create along with the with the uh targets and then uh the money leaves the country. So it depends on the type of fraud, the type of fraud that you're referring to uh definitely comes more from abroad.
Well I appreciate all of your testimony today, and Mister Chairman I'm grateful you convened this hearing, I've learned a lot already in just this interchange, so thank you very much. Mister Chairman, I yield the remainder of my time.
The gentleman uh uh yields back his time, thank you very much. Distinguished gentlemen, Mister and you're now recognized.
Thank you, Mr. Chairman. Um, Mr. Barris, I want to start with you because something you said struck me and I it might be the basis of why we are here and why we will want to come back this way. Again, and added was that you said if I'm paraphrasing you correctly, that we are spending years and millions of dollars preparing for a threat that does not continue to exist. Can you expand on that, please?
Absolutely, and - and in particular the - part of my testimony that I was highlighting was the fact that much of the - how the federal government has thought about its standards for how to prevent or protect digital identity, and to be very clear, digital identity is just the makeup of how we present ourselves in cyberspace, right? Much of how the government has designed that standard today effectively was, worked about a decade ago. And so if we're looking at today's fraud threat, how it has evolved, how the adversary moves, it no longer can keep pace with what we are seeing today. So much so, one of the efforts that, you know, our our company led was as we were engaging with NIST as part of their most recent update to the standard, was highlighting that fraud should become an underpinning of part of what we evaluate in digital identity and when it's established. Not because we want it to be harder for people to prove who they are,
Right.
but because the alternative is that we are leaving a floodgate open for nation-states, uh, to launch their attacks. And from where we see it today, you know, there's over seventy-five hundred fraud rings that are operating, uh, in - in their own different ways, uh, to attempt to attack what would be government services or even, uh, the commercial sector.
And, Mister Burris, um, as artificial intelligence advances at an alarming rate, what does the government, and in particular what, uh, does Login.gov need to do to stay ahead of those scammers and to be able to identify them as we move forward.
It all starts with admitting that there is a problem, so we're gonna begin there and say that the this is a crisis moment for where we are in. I think it's important that we understand that as the federal government we need to basically embrace and understand that we need to use AI to fight AI at this point. The adversary does not care um uh about how anything is constructed, they do not care about our norms, they do not care rules and regulations, they do not care about the ages of those who they're engaging with or their political affiliation. What they are attempting to do is to take money and resources to disrupt what would be the status qu- uh the the norms that uh we hold dear. And what we need to do is engage uh aggressively to basically put in place the types of controls and measures, many of which have been adopted in other sectors for years, uh in order to help prevent against this threat. Uh for Login.gov in particular, I would say, and you know full disclosure, again we are one of the vendors that are now have been added in order to power uh what login.gov is doing. They are taking this threat absolutely seriously. Uh this day and age another fraud team has engaged diligently to understand what needs to evolve with the program.
And Miss Cruz-Cain, you mentioned at some point in your testimony, I'm trying to get back to it here, where GSA implemented four of five recommendations. What was the fifth recommendation? Is that still standing?
We made four. They implemented three. And the last one was um the agencies, the twenty-four CFO act agencies that we talked to had technical challenges with log in dot gov. So as users they were not necessarily able to use with ease and they had some issues with the platform such as they would like to know when the users are verified and authenticated, why they were not. So if they fail, the person just says hey I failed. They have no way in knowing why they failed how they can remedy that so then you just don't have access to your government account so you can't get your benefit you have no recourse of knowing how that happened so either you just have to try again or you have to go to the post office that was one of the issues another issue is at the time they had a high failure rate so they were just getting problems of even logging into the system or being able to use it and at that time they were not having such strong fraud controls and again to their they have been taking the issue very seriously and partnering with new technologies and new companies to enhance their fraud controls. But they need to partner with the users to make sure that they're also helping them with the issues that they're having with Login. Dot. Gov. Because if the users can't use it, the technologies can be great, but if your users are still having issues using the system, you're going to use that lose that user base.
Thank you very much. Uh, just one other quick question. Mister Stanley, I appreciated your description of a digital ankle bracelet or ankle monitor. Um, and you referenced driver IDs. Are they the most vulnerable?
I think that in many ways cryptographically secured um
Driver licenses.
digital driver's licenses
Mm-hmm. Are they the most vulnerable?
that uh are are less vulnerable probably than many other techniques for validating identity. Um, Mister Burris talked about use AI to fight AI, there are many technologists who say that that is a losing battle, and that you will never, it will always be a constant arms race because any AI that can be used to identify who is real versus who is not, the a- that same AI can be used to fake somebody who's not real.
Mm-hmm.
Um, and so um, that is why a lot of people in the technology world are turning to cryptographically secured uh tokens or identities so that basically um the dmv or other issuer takes the data on your driver's license digitally signs it with encryption with a secret key um and then publishes a
Mm-hmm.
public key and a verifier can look at the public key and and it if it matches it could only have been signed by the dmv and not a single bit could have been changed and that's cryptography um and so somebody can prove that they the the thing they have in their phone the file they have in their phone was issued by the dmv and signed by the dmv um and um that is one of the reasons why we think that digital driver's licenses are poised to move to the forefront in online verification and why we worry about all the side effects of that kind of a system that i talked about
i see thank you thank you very much you're back mr. chairman
gentleman yields back his time Mr. Norton, you're now recognized.
Thank you. D- di- di- di- digital identification and modernized technology systems can help verify d- identities and reduce fraudulent claims, but they should not come at the expense or access to vital social safety net programs. Mister Stanley, as more federal, state, and local governments adopt digital identification systems, who risks getting left behind?
Yeah, so exclusion is a big potential side effect of this kind of a system and we will need to ensure that a digital identity is not mandatory, and we will need to pay the costs of ensuring that there are other options, uh lest we dial up the security dial too high and leave a lot of people who have genuine needs and are genuinely qualified for benefits being locked out. Um we know i- in addition to what I said about uh twenty percent of people over age sixty five and ten percent of Americans not having smartphones. Um, studies have found that people with disabilities are twenty percent less likely to have smartphones, um, people with incomes under thirty thousand dollars a year, twenty five percent don't have smartphones, thirty percent of rural Americans lack fixed broad band and good internet access, um, and many people with low incomes are on limited data plans. Um, and, and, and so, we need to ensure that we never assume and a lot of things will these things will improve over time some of these studies are a few years old um and probably are out of date already but we're never gonna get to the point and we should never make policy based on an assumption of one hundred percent adoption of technology because there will always be people who can't or won't or simply don't want to and should have the freedom not to um use all of these advanced technological systems uh so I hope that answers your question. Representative Norton.
Um m m m Mr. Stanley, which populations are most likely to own uh most likely not own smartphones?
Sorry, the population's most likely not to own smartphones?
Yeah.
Yeah, it's um again um older Americans um and low income Americans, disabled Americans, low income Americans, of course,
Well, Mr. Stanley, given the increased adoption of digital identification, are people without smartphones at risk of reduced access to government services?
Well, yes, I think that it what we see is that um someth- a a technology like a digital ID tends to move over time from being an option that empowers people, to being expected, to becoming normalized, and then people who don't have it end up as freaks and edge cases, that just aren't accounted for by the systems that that that run our governments, our benefits, um and many priv- private sector goods as well. Um and so because often it is expensive to maintain off-line
Mm-hmm.
um real world uh options for people, but it is important that it d- that a digital identity system do remain an option. There are post offices in every town in America where people can do things in person. Um there are there are other off-line ways of doing s- things, and we need to make a conscious policy decision to protect those ways, those alternatives, um to protect American freedom a- and to protect people who are are vulnerable and and need the benefits that they are qualified for.
Uh even w- even for those who do own smartphones, a lost, stolen, damaged, or non-functioning device could temporarily prevent them from accessing the accessing the programs they rely on. While we should embrace new technology to minimize fraud, we must ensure all Americans have access to programs. I yield back.
Joe Ullman yields back her time. Thank you very much. I now recognize for a UC anonymous consent request. I'd like to enter into the record two letters that have been provided to the committee, both Mister Infume and myself. The first is a letter from the Better Identity Coalition. They highlight how digital identity credentials like a mobil- mobile driver's licenses and investments in digital identity infrastructure could help address this emerging fraud threat that we are talking about. Secondly, The second letter is from the Defense Credit Union Council. It reinforces how critical it is to protect the nation's military and veteran communities against scammers, who specifically look to exploit vulnerabilities, uh, created by their life in the military and to take advantage of that. So, that objection so ordered. Thank you very much. Uh, it is intuitively obvious to each of us that, uh, my side, the Republican side, the majority side, does not have many witness or many members here that we are in the middle of receiving a briefing on the conflict in the Middle East at this time by the administration. And so I've chosen not to cancel this hearing, but rather to stay myself. And so uh I may take uh the place of several of my members, so I would yield myself uh my time uh right now. Mister Stanley, thank you for being here. Mister Stanley, I'd like to ask a question. It really came to me today, and I find very interesting not only your comments, that I find common sense and I find myself, I would have to struggle with myself to disagree with you, but it brought up one issue and that is we generally see fraud as an overwhelming factor that we need to defeat. That when fraud is involved, and fraud could be something that then becomes tangible, where it's been established, necessarily established, as opposed to questioned to establish whether it is fraud, where fraud is involved, are there limitations uh at uh on behalf of the government to uh to to to uh satisfy the requirement of protect themselves. And the for instance I'd like to give is at an airport that I go to every week, uh, called Reagan Airport. There is a sign from, uh, from the government that says, if you're in this area, you are subject completely to search and seizure. In other words, you we can do, by and large, within some balance what we wanna do to ask you, to demand you, to comply with our orders and those things. Is there a point at which we should be careful once we know fraud is involved. And I can give you probably several instances, but I wanna ask that question to you.
Mr. Sheridan, I'm not sure I totally understand the question. My apologies.
Okay, so I'll I'll I'll try and help it out. When we think that we have established the standard of fraud by a government agency and they then are saying we are dealing with fraud, Is there a limit to how far they can go within a reason but to establish something? For instance, could they pick up the phone and call a bank, know your customer, and a bank would have an idea of what of of that they're involved. And we're trying to move a lot of this, uh, these issues to, uh, professionals in law enforcement and professional otherwise Could they call a bank and say, can you please tell me I've got a customer that lives at fifteen fifteen Smith Avenue and this is their name and they tell me they're sixty eight years old, and they told me that they do this and this and this. Is that is that okay? Because they've established fraud and they're trying to then run it down. What are the limits? What is the expectation that you have? Because you've mentioned civil liberties a few times, and I respect that. But we're talking about fraud and we're talking about how would you expect the government are there parameters, the government can only go so far, are we gonna give the criminals that upper hand? So that's the question, sir.
Okay, yeah. So if you're talking about investigating fraud that you have evidence has already happened,
I am.
I think that it would become a criminal investigation like any other, and that has been - that is subject to the constitution - the limits of the constitution. Um, you know, presumption of innocence and the fourth amendment of the constitution, prohibiting unreasonable searches and seizures, um, uh, uh, and - and other provisions of the constitution that have been well litigated over the years um so I - I would think that a professional law enforcement officer would know what those limits are in many ways. Um, And w- whether or wa-
Have you had a chance, Mister Stanley, to look at the piece of legislation that was passed by this committee a few weeks ago that's waiting for floor arrival, that would take these options and move them to the IG in the treasury department in a specialized unit that are law enforcement type people. Have you looked at that?
I've, I confess that I have not. I would be happy to and get back to the committee with uh with our with our views on that.
Okay. Okay. If you could do that, I'm interested in your feedback because we are trying to say that we believe once a standard of fraud has been established, that there needs to be specialized sure, but the ability that investigators have to go and vet this, we just have to find a way. Is it truthful? How widespread is it? And how are we gonna handle this? Okay, I'm gonna ask you another question. Got five seconds left, but we're kind of being a little careful, really, we're not as tight on this. Uh, the second one is, is there a limitation on someone if they are presently on social security, uh, they they've taken out a loan SBA, something where they in the government system. And we find some instances where there might be questions that arise. And I know once again you're very careful, and I agree with that, within the law, within the Bill of Rights, within the Constitution, within all the things that we could establish. Is it fair game to go back and run people back through if they think there's something that might be amiss? through this this organization, even though a person has been on government benefits. Because you see, we think that a lot of people that presently are receiving government benefits might not be exactly as we thought they were. Is that fair game?
I think it is with some cautions. Uh, I think if if the if a government agency sees signs of fraud, there is no reason why it shouldn't um look at those.
Right, that has to be established.
Um, there are cautions, especially if you are looking at, for example, using AI algorithms in order to do that, um, that may have been trained on, um, sets of pre-existing data that, uh, contain biases, that there - there was a man, it was - there was an NBC report which I could share with the committee about it, who, uh, paid his credit card off every month in full and he got a letter from his credit card and they said we're we're reducing your credit limit. And he said, why? A payoff in full? I mean, they said because we have found that the other store, other customers at some of the stores you shop at have been bad credit. And I think that that strikes most people as just unfair and guilt by association.
That would be a smell test. How about if AI d-
Yeah, and but I think that a lot of uh AI algorithms do basically the same thing in a hidden way.
How about if AI discovered that there are seventy-four people at your home address that receive benefits uh because ai discovered it and uh we uh think that you might be one of them and we'd like to do some sort of our our review about this, is that fair game?
i think that there are good uses of ai and that flagging that kind of anomaly as long as there is human review um might make sense um but for example for examples like that there are other examples where we see unfortunately um government agencies not building in the checks and balances the due process and using ai not only to figure out who it thinks is suspicion but then to take actions against people that they have trouble um uh you know getting due process and fighting back we've seen for example in states people losing their disability benefits based on algorithms
ok so uh let me give you the act it would then at some point require uh human intervention to review data to then make some decision as opposed to a computer automatically assuming something.
I think that's right. The only other caveat I would add is that um some of the fraud prevention techniques are based on gathering an enormous amount of intrusive data about individuals from
Oh, and we spoke about this. but you had indicated earlier without human intervention, that meant that someone else, a computer or an AI modeling, decided they could send you a letter and cut off your uh benefits. I'm saying that they we could use these to then go to a human who is trained, who does have this professional experience, who would be able to apply it, and then would be able to use some rational basis Okay, so you would agree with that.
Yeah, but what I'm saying is that, for example, there are industries that um that use unethical apps on people's smartphones to track their location without their knowledge or permission. Uh, I I'm sure that uh many people in this room are being tracked by these companies without knowing. Um, and that some of that data can be fed into these algorithms for deciding who is suspicious, and a lot of other very privacy invading data. And so if the algorithm you're talking about is
Okay, well I could bring up lots of examples. I'm not going to. I wanna thank you. I think this is an important question. That's why you're here today. We'd now like to move to the distinguished gentleman from Florida, Mister Frost. Mister Frost, I yield back my time. We now move to you, the gentleman's recognized.
Yes, thank you so much. Um You know, part of my concern as it relates to digital ID becoming mandatory is the risk of widespread data collection and exposing millions of Americans to harm, which is already an issue that this country seeped into many different ways, um, social media, um, uh, online and different things like that. Mister Stanley, how could digital ID systems become a barrier for Americans trying to access services, benefits, or programs?
That could happen if Um, first of all you are unable to get a digital identity system because you don't have a smart phone. There are also a lot of Americans who don't have access to - uh, who don't have - currently have any kind of driver's license or um non-driver ID from DMVs who - There are people whose birth certificates were burned in a fire in - in Tennessee, in - in nineteen fifty-five and don't have access to them. Um, it is a messy world out there, and I think that digital IDs seek to impose a sort of neatness and bureaucratic uh you know regimentation on it on all of us and and so we in in making policy we have to make sure that people who um don't have access to those things are not left out so you you can't get a there are people who can't get a driver's license there are people who maybe they have a driver's license but they won't be able to get a digital driver's license because of the things that we talked about in terms of not having access to the technology or the technological literacy to use it um there was one study that found that a very large portion of people over sixty five you know weren't able to install an app on a self on a smart phone um uh there could be situations where um people's id's are abusively revoked um you know we've seen uh there has been mentioned that the trump administration put some people in the social security dead file we also saw in california a democratic uh candidate for governor propose that uh that um, federal agents who wear masks should have their driver's licenses stripped from them, and whatever you think of mask wearing by federal agents, which is a controversial issue, that is u- that is u- using an identity infrastructure for polit- political purposes, which is something that we may see in the future, left, right, or center. Um, and, um, so - so that could be a threat, and we have called for protections against people having their um - their - their IDs yanked by um abusive governors or the like. Um, so those are some of the ways in which, um, people could find that they are left out of a digital identity infrastructure.
Yeah. Part of my concern too is, I mean, when you look at this administration, um, we know they've empowered big tech companies like Palantir to create databases of Americans' personal data for government use. We know that during the, you know, Doge era, similar things were done during that as well. This data collection could make it easier for private companies to abuse our data. I know some proponents will say, " Well, you know this is mainly for government use but we know it never it's not only for government use um and and that's part of my concern with this or just so much collaboration between private companies data sharing um how how should we legislate on balancing the the convenience and the real dangers of digital id which also will lead to losing anonymity online Um, which is something else I'm concerned about as well.
Yeah, we have a piece on our site that outlines twelve protections that we we call for, that that we think state legislatures should enact that govern any um, you know, mobile driver's license or digital ID that's created in their state. I won't go through them all, but they include such things as uh, protecting people against incessant demands from every quarter. If you wanna if you wanna do business with us or come in our candy store, you have to tap your ID.
Yeah, this this is part of my concern too, that making it easier to prove who you are will lead to more services companies asking you to do so for every service that is not expected of you right now.
Yeah, it's an excellent point because um one of the things that, you know, if you're a web site and it's really, really hard to prove your identity online, you have to se- take a photo of your ID, you have to send it in, you have to get a video, you have to do proof of libeness, all this stuff. You're not gonna ask your visitors, your users to do that unless you really need to. So that imposes a limit. But by getting rid of all the friction of proving who you are online, you get a pop-up like the privacy pop-ups we get today, click here to send us your digital ID. It bec- not only become easier for me to share my digital ID, that means that it makes it much easier for them to ask me to, or demand that I do so. Um, and that's one of the big things we've and that's one of the protections that policy makers can make which is to say these are super ID_s, they're cryptographically locked down, DMV vetted, everything like that, this is, you know, a- and that you shouldn't be forced to use a super ID to prove your identity unless it's legally required, we have called for, uh maybe in certain other specific situations. But um people n- are gonna need protection against this absolute, you know, waterfall of demands that - that - that we - you can easily anticipate are gonna happen once this is created.
Yeah.
And then other protections like privacy protections to make sure that the wallet holders don't - aren't spying on everybody, um and that um you know that these cryptographical things that I talked about are - are built in to protect privacy, so that you know you can prove things about yourself without having to you know create a lifelong relationship with somebody by identifying yourself to them
mmm how can um i know we're over from indulge me mister jerry uh just my last question is how can digital id lead to complete loss of anonymity online
yeah so i mean websites are gonna want everybody to identify themselves all the time they're gonna wanna do it because their ads will be worth more if they know who you are and they can plug in uh you they the data they have about you to other other data they get um they're gonna wanna do it to make sure that you're of age so they can market to you under kappa which is you know you can't market to people under thirteen
mmm
identity verification uh which has become a a a big controversial issue um and uh bots a lot of sites have are having problems with ai impersonating humans and they're gonna wanna know that you're a human um for various reasons and so there's gonna be a lot of pressure
yes
for a lot of websites to start demanding this all the time.
Yeah. And part of the concern, right, is the fact that this information can be weaponized against consumers, working people who are looking to purchase things online, and have that information leveraged against them when they're making decisions on what they wanna buy and how much those items cost, correct?
Yeah, surveillance pricing, uh, where c- stores get a bunch of data about their customers and then they charge you based on what they know about you and the how much they think you'll pay and w- whether you're desperate and - and so forth. that's become a very controversial issue um and and states as uh you know um regulation of surveillance pricing has been attracting support in the state legislatures from both left and right and digital ID_s will make that much easier because if you know they're gonna charge, if the store's gonna charge you more like let's say the the airline happens to know that you have just lost a love a close loved one and you have to fly they can they can up your price um and so you're gonna wanna see
Mm-hmm. Yeah.
what the price is without them knowing who you are right? but they're gonna wanna know who you are and there will be this arms race, and a digital ID would sort of end that arms race and you can't escape them knowing who you are,
Yeah. Yeah, thank you.
if it's done badly.
Yeah, appreciate it. Thank you for indulging me, Mr. Chair. I just think, uh, you know, I'm not a Luddite and, uh, I just think like these conversations are important because it shows how much care and intentionality needs to be put into this oftentimes. We're very excited about something, we move quickly on it without thinking the next ten, twenty years into the future and then it's an emergency for another generation to handle. I think we have to have these conversations now and legislate accordingly. Thank you. I yield back.
Gentleman yields back his time. Thank you very much. The gentlewoman from Washington is now recognized.
Thank you, um, so much, Mister Chair. And thank you to our panelists for joining us. You know, login dot gov gives every American a one-stop portal, so they can use a single user name and password to log in across a variety of federal programs. Sounds like a a benefit and a you know um customer service improvement. This is a portal that state and local governments can use as well, and it saves taxpayers time and money and generally makes life easier. Mister Burris, can you briefly describe how Login.gov has leveraged SoCure's technology to help reduce identity fraud for government programs?
Absolutely, and I think a lot of this comes down to trust and basically leveraging what would be considered generation uh technologies to try to help balance uh a lot of the conversation I've heard around access and speed and confirming that the right people uh ultimately can access these services so login dot gov uh conducted a competitive procurement uh where they evaluated our technology uh against that of seventeen others uh at the time uh and they incorporated different components of our solutions everything from uh solutions that we have around document verification so confirming that it's legitimate uh government issued ID and or uh what would be um facial uh biometric comparison, so the idea is comparing it and confirming that it is actually the right person on the other end of the screen. They also incorporated uh what would be additional fraud models uh to their stack, uh things that they're incorporating such as uh identifying and understanding what's happening with the device a person may be using, because it's all too often that the adversary would do something such as uh uh take a jailbroken device that is overseas and attempt to say that they are operating within New York or DC for that instance. Um also doing comparisons with things like the phone or the address and individuals using their email. And then um some of the w- see flagship offerings that we have uh related to helping to paint a picture or prediction of whether or not it is someone who is engaging in what would be a pattern that is associated with identity theft and or synthetic identity and far too often what we see in the industry is that kind of weaknesses in these technologies have led to this unfortunate conversation about folks who've been left out and forced down alternative paths. It's always been my belief that if someone is choosing to engage with a digital service in government they should be able to do so and the technology should adapt to meet them where they are so the addition of SoCure's tools have been uh have enabled Login.gov to take uh strides towards being able to address that and make their um service more accessible while simultaneously combating fraud.
Thank you so much. It's really great news that we're innovating in this way to provide access that the people want and to smooth some of these like barriers to accessing services. But like you've mentioned and based on other testimony that we've heard today, we know that scammers and identities are constantly trying to find new ways to evade ID verification, and that means that Login. Dot. Gov. has to remain alert and prepared to fight new forms of fraud. We have to keep innovating. Miss Cruz-Cain, in GAO's assessment, will there be ever be a day when Login. Gov will be finished and no longer need to adapt to face new fraud tactics?
I don't think so. I think criminals are working every day, twenty-four hours a day, to get better at what they do,
Yep.
and largely in the federal government we're reactive.
Absolutely.
So, um, Login. Gov procured the tools because they're being reactive
Mm-hmm.
Yep.
to what has been happening within their tools. So I think largely federal systems are pro reactive to what is going on and rather than being proactive.
Yeah. So would it be safe to say um that competent and technically capable leadership of the Login dot Gov program is critical to um effectively sustain prod fraud prevention?
Yes.
And is it critical that leadership has experience in effectively managing and protecting sensitive data programs?
Yes.
Would it be very concerning to you, Mr. Cruz-Cain, if leadership at login dot gov came from an organization that had, say, an extensive history of mismanaging private data and endangering the privacy and financial security of the American people?
Without, I mean, knowing a little bit more about the situation, it'd be hard to opine, but, you know, we like to look at facts and situations, but I mean, just like I told you, we would really need to have experience with technology, leadership with good technology, and knowledge of how to implement good technology.
Absolutely, but if if someone who had previously been proven to mismanage private data and endanger privacy and financial security was moved into leadership that would be concerning.
Yes, if it was proven.
Yeah.
Yeah. Um, Mister Chairman, I'd like to ask unanimous consent to submit um these following articles to the record, Doge put critical social security data at risk, Uh, from the New York Times, from NPR, the Trump administration admits even more ways Doge access sensitive personal data Washington Post, Washington Post and Wired, similar subject matter.
Without objection.
And just in my remaining time, I'd like to say what these articles say, that President Trump took one of the Doge bros who oversaw the looting of the federal government's data and endangered the privacy of every American, and put him in charge of identity verification and log-in systems. for every American and based on our previous line of questioning that doesn't sound like a way to safeguard the American people's information and I yield back.
Gentlewoman yields back her time. We'd now like to move to the second round uh with with with your understanding we're doing that, sir. Uh Doctor Maimon uh you and I spent some time yesterday uh maybe it was today days run together But you most expressly indicated that you have not only great knowledge but work on a day-to-day basis with many people who are criminals and who are attempting to be fraudsters at our systems. And I did not have a chance, you did not really uh delve into this area very much, but I think, Mister Mfume, and I need to hear this about not only that it exists, that they're very active, that they're on the uh dark web or open web, that they uh uh target certain people and that they learn uh areas that are uh vulnerable and that they openly talk about it. This is no it's no longer behind anybody's back anymore. Do you mind taking the time that you need to express the things that we need to understand about the attack that's against us and uh our our agencies.
With pleasure, uh, Mr. Chairman. Um, uh, as as uh you mentioned, Mr. Chairman, I spent um my time, my days, uh, infiltrating darknet platforms, telegram groups, uh, trying to understand what fraudsters put out there and how they bypass a lot of the security solutions that uh we deploy uh on financial institutions as well as on the government side um often time what we find in in platforms are tutorials which will walk you through how to bypass many of the security solutions that uh we have out there. Uh the tutorials sometimes will be offered for free, other times you will pay for them, uh amounts ranging from one hundred and fifty to two hundred and fifty uh dollars, uh specific guidelines with respect to how to bypass um and and obtain SBA loans, uh FAFSA uh aid um we're seeing uh a a a as of earlier this morning, people talking about how to um get targets for a one k's uh account which i think is is a is a major issue uh to our country um and we simply see that on scale we see that uh as i mentioned earlier uh on darknet and telegram but also more and more on facebook on twitter on instagram uh a lot of what we see also on is available on on the internet on the clear net uh web sites that the criminal put together and simply offer fake driver licenses for sale. Um, this is the reality that uh we're dealing with. Uh, organized crime groups with very detailed supply chains which will have our identities offered for sale. Uh, they will have f- uh, uh, uh, services which will allow the uh uh allow the uh fraudsters to build histories uh around the identi identities. They will walk you through how to create uh deep fakes, high quality deep fakes. um both images as well as videos they will teach you how to take those videos and images and inject them in the cameras uh of uh the computers or the smartphone that uh folks are using in order to uh apply for benefits or apply apply for sba loans um and then uh secure all those uh resources uh that they get from the government so this is what we are up against we are seeing that happen domestically with a lot of organized crime groups uh uh operating within the United States, but a lot is happening from uh abroad as well. We're infiltrating Russian uh crime groups, uh we were able to infiltrate some Chinese crime groups uh who operate the scam compounds in South Asia and are explicit about the type of operations and and our identity and how uh you know how how they essentially offer those identities for sale um and essentially walk you through uh the list of steps you need to uh engage in in order to target uh uh our benefit program. This is what we're up against unfortunately at this point.
So furthering this uh development that you're talking about, I spoke with you about how we had looked at during twenty-one, twenty-two, twenty-three, twenty-four uh numbers of agencies that did not have their workers at work. They were not engaging the people who were seeking services Uh, they were not able to, even when working from home necessarily, did not have a full array of opportunities to vet who people were, know your customer, to look at things. And so this huge amount of money that we were talking about today in testimony for this subcommittee that is very consistent with what we've heard GAO say in the past, uh, it it has found a a real home to where this is a cottage more than a kaj industry, it is people who literally are figuring out how to do this. And you said to me, whenever we last spoke this morning, you do believe human interaction, and I brought up my circumstance of talking to social security,
Yeah.
how they vetted me, how they talked to me about things that I would know about myself, that I would probably not a lot of people would understand. Is this the kind of fair game that would be used to vet people uh on a regular basis and how can we cross get this type of information to where if you're at SBA you may or may not have that available to you. If you're at social security you probably could ask some detailed questions about uh working history, about doing other things. Do we need to expand or develop some way for agencies that take a new um perhaps a new request from a person. It could be about uh not VA because you could ask about those questions, but about someone who's recently unemployed uh in asking about a de- depth of knowledge. How do we really help those agencies to make the determination even when speaking to a person?
This is a a great question uh, Mr. Chairman. Um, And and I I agree with with your statement. I think um and maybe go back to my career as a sociology in in the Ohio State University, uh first class uh in in uh in in the degree uh we were taught about uh the difference between Gemeinschaft and Gesellschaft, community and society. The reason why I'm bringing this important uh distinction is that in the past, here in the United States or any other place, when we when you went into the bank or to the IRS, and asked for opening a new bank account or a loan or getting some governmental benefits, the guys sitting across from you knew who you were. He knew your family, he knew uh where you worked, he knew your history, so to speaking. So they were able to assess the risk you posed to the organization more effectively. Now, you know, we're uh at this point in a point of uh a society, we have a lot of people um uh living in in this uh a great country, uh very difficult to assess uh in the same way we assessed in the past folks' history, but uh fortunately we do have solutions out there which will allow you to uh tackle the signals uh create and and look at some historical signals around uh identities. So um if the government is um uh willing to sort of uh use some of those solutions to uh try and assess uh the historical evidence around those uh individuals who needs to be verified, then I think we'll be in a better place to uh sort of determine whether individuals are uh who they say they are uh who they say they are or they're completely different individuals stealing identities or u or using synthetic identities. Um and in that sense uh I just uh uh wanna refer to uh uh the arg uh the conversation we had earlier about the driver licenses and MDL one of the things that uh we proved already um you know during uh uh ten years or so is that uh pretty much everything could be faked. Uh that I think will go also to the MDL, I mean criminals will be able to find ways to use this technology to their benefit. What they're will not be able to fake is the historical evidence and that that that goes uh as well to the AI solutions out there, right? I mean AI will be able to give you an amazing picture of a person who does not exist, or it w- it uh AI will be able to take my face and bring it to life when I'm abroad so to speaking and and uh try and authenticate me when I'm trying to get unemployment benefits. But one thing that AI tools will not be able to do at this point is to create historical signals uh around uh around me or around anyone who is trying to identify themself and I think that is where the solution lies being able to find solutions which will allow us to look at historical evidence around individuals around their name date of birth addresses uh uh telephone numbers and uh uh make assessment with respect to whether they are uh who they say they are.
Uh, Mrs. uh, Cain, uh, r- furthering this discussion, I had a chance to engage you also yesterday and part a part of this was about the viewpoint that when there was a failure, meaning a person came through login dot gov, provided information, but it was not what I would call successful, so there'd be a failure, Then evidently it is not unusual for someone, not as a challenge, but to ask for authentication of who they are to go to a post office. You had indicated that one of the things which you have engaged government agencies on, and perhaps GSA, is data and information back about what caused that failure. the uh was it a question we asked, was it the uh picture, was any number of facts and factors. Following up on Doctor Maimon, I I you're the cyber security person also at GSA and you are aware of the power of technology, the power of these things that can be used to fool people to uh give false positives to to do things. Do you see that in this process that we need to go go with new areas that would have some more depth to where you didn't fail off one or two or three, you failed off five different questions because you were looking for them How do we go and and ascertain when someone falls out whether that was fraud, whether that was someone you were openly challenging and they see you later, and so they never went to the post office, and to where we then learn what they did, how they did it, were they asked the question who they were, we could move them to the organization we talked about this morning, to PRAC.
I think it's an important question because the people who are failing and are legitimately the person that they say they are, are gonna keep trying because they want that government benefit that they're entitled to.
And they could go to a post office.
Right, they could go to the post office and go take their documents and verify who they are that way, but there's also barriers to that. So if you're in a rural area, your post office may be far, you may not have a reliable transportation there, there may be lots of barriers for you to do that, so it might not be that easy. So a lot of the agencies reported to us that they would like to have visibility into that authentication and why it failed, so they might be able to help that person on the end and say, well yes, it was because the name that you put in was not the name that HUD had on, or there was a letter transposed, or your new address was never updated in HUD's database, and there was a privacy principle. You know, you are supposed to be able to get the most updated or whatever information an agency has on you so you're able to correct it if it's wrong. That process can be easy or GAO has reported that process can take very long for you to be able to update your information. So if that takes me months to years to get my address updated in a government database, I'm going to fail for that whole year on every government agency that I use, log in, to try to access, which is going to be a very big barrier for me to get any government benefits that I am eligible for. So that was something that many agencies brought up for us, and giving those agencies that ability to insight into that and to be able to say, hey, this is why you failed, you know, here's your options, and again some of them may not even be able to go to a post office and have that secondary option available to them, but, you know, you're gonna have to do that if you want your um benefits. that was of one thing that was really helpful to them, because some people would le- Fraud stores would probably legitimately stop. If they were not able to go somewhere and prove who they say they were, nine times out of ten they're stopped, they'll take their other synthetic identities and keep trying to get through. But they would stop probably with that fraud name and say, okay look I've got three hundred others that I just paid three dollars for, I'm gonna keep pushing those. So I think the difference is you really need to think about the people who are really who they say they are, who are having that false positive that they are going to keep trying and they need that reason why so that they can go remedy that so they can continue to be not be found ineligible for the benefits that they are legally entitled to.
Interesting, thank you. Mister Mfume.
Thank you, Mister Chairman, it's been an interesting hearing to say the very least. Um One of the things that I hope comes out of these sort of interactions, our ideas that would affect and change existing law and policy. And I know all of you in your work have come across items, matters, and issues that you said if this were only changed or if this could be in place. So I wanna come back to that in just a minute and and it'll be a quick minute too, but I want you to give some thought to that because as legislators that's very important to all of us, no matter what side of the aisle we serve on, if we're in fact trying to deal with an issue and a problem, and certainly uh this is one of them. Um I wanna, if I might, Doctor Maimon, go back to something you said earlier and then I'll come back and we'll try to wrap this up on this side anyway. I'm interested in your work that you have been doing tracking Russian and Chinese cyber networks and their ability uh to infiltrate this country, but more importantly their ability to take advantage of the citizens of the United States. It sounds like fascinating work, but I'm sure it's also leading you to some ideas about how we can do things better. What I really want to know, though, on this matter, the evidence that you are coming up with, as you track these crime syndicates and cyber networks, whether they're Russian or Chinese. Are you or your organization sharing that information with the director of national intelligence or sharing it with the FBI? Or are they about doing what they do in their own silo, developing their own intelligence and not doing a comparative analysis of both? Could you speak about that for a minute?
Of course. Thank you so much for this question. Um, I do what I do in order to make sure that the American public is aware of what's going on there, and and when I investigate, uh my investigations usually result in publications. I put together white papers, um I put together uh news articles, and let the public know about what I find. Um often time uh we will reach out to law enforcement and then we'll simply l uh give it to them and then they ne need to make a decision with respect to whether they wanna pursue, investigation or not. Uh, I can tell you that uh in the past we had very strong relationship uh as a professor, uh in Georgia State University with Department of Homeland Security. What we've done back then, that was during the pandemic time, we essentially um had a monthly meeting with local folks in uh DHS, and we simply talked about what is it that we find out there. Uh, what is it that the uh uh DHS did with that information? Obviously I have no idea, uh because oftentimes what happens is that law enforcement take this information and do their own thing sort of speaking and so uh i can tell you um that uh i'm doing my best to make sure that everybody is aware of what i find out there but i have limited visibility with respect to the actions folks take uh once i put the information out there
well if i could be the devil's advocate if i'm the director of national intelligence or the head of the fbi i might say well he's never given that information to us so you you forward that to them are you in contact is there a liaison that shares the information so they can match it up with their own intelligence.
So, in in the past, what I was doing is essentially having a monthly meeting with Department of Homeland Security. Um, that was during COVID time. We had very strong relationship at the time, uh, where we essentially provided, uh,
Right, but I'm I'm specifically speaking about the Director of National Intelligence and the Federal Bureau of Investigation.
Yeah, I I do not have relationship with, uh, the FBI. Uh, I do not stand in touch with the FBI, I'm more than happy uh to uh be in touch with them and let them know about what what I know.
Yeah, because it seems like you've done an extensive amount of work, and I can appreciate white papers and editorials and that sort of thing, but everybody doesn't read, and if it's something so pertinent or hot or game-changing, those two agencies, more than anyone else, I think, needs to know. So let's pray that they're listening. They obviously are. I hope that they would take advantage of the work that you've already done, just to match it up against their own intelligence. Um, this is a very serious issue, as we all agree, and the more we can do to to be effective,
Of course.
the better. And now I just want to come back to all of you just very briefly, with respect to this notion about policy changes or about proposed legislative avenues to address some of the more glaring aspects of this, or maybe just to address things that right now are not getting any attention. I'm gonna start with you, Mister Barris, and I'll end up with you, Mister Stanley.
Thank you, thank you, member, uh, for the opportunity to address this item. You know, there were a number of recommendations that I provided as part of my testimony, as far as where we could be pursuing policy levers. I actually will leave with one that wasn't in there, and it's really around mindset shift and culture. Um, and if you'll indulge me for just a moment, there wa- it shows you the depth of my nerd. Uh, it goes into I was thinking actually back to the Avengers movie, the last one, Captain America and how uh there was like the darkest moment where they were uh basically up against an insurmountable threat uh basically took all the Avengers coming together at the same time out of nowhere in order to try to combat what they were seeing or what was about to happen I think that generally culturally has to change within the federal government in the sense that right now when you're talking about who is fighting fraud within an agency and organization they're doing it siloed they're doing it without sharing intelligence they're doing it without having the types of conversations that need to happen, uh so much so that FEMA could be having an existential fraud threat, and they're not talking to the SBA, they're not talking to treasury, they're not talking to GSA even. And so there is an opportunity to basically culturally shift this, say that we all have to get on the same page about what we are fighting against, uh and then change that dynamic so that way we can actually can take some of these more proactive measures that I've outlined in my testimony.
Uh, thank you very much. Um, I'm gonna, I appreciate that. I didn't see the movie, but I appreciate your context. Um, but I'm talking now about policy, more so than mindset. Mindset's gonna take a while. But if we can implement minor or major policy changes, that'll make a difference right now. Miss Cruz-Cain?
I'll go for a big one.
Mm-hmm.
But I think we do need to revamp the Federal Privacy Act. So the Privacy Act goes back to nineteen seventy-four. GAO has plugged many times in its reports that that was created way before policy and technology has updated, and um we need to revisit that, but I also think that there is a great need for a consumer privacy law as well, that starts at the federal level but also allows states to have some input into it, because uh right now there is no federal consumer privacy law and it's a sort of framework of mismatched state laws, local laws, and there there's nothing really governing at a higher level of what needs to be done.
Thank you. Dr. Memo, and about Dr. Memo, I appreciate the extensive nature of your written remarks. I tried to get through all twenty pages. I don't know if I did or not, but thank you very much for that.
Thank you so much. Uh um Uh I think I think uh in terms of uh uh policy, and and I really appreciate this question because uh I sit uh at Georgia State University in the school of policy, one of the things that I would strongly strongly recommend is an evidence-based approach. I think Um, you know, we're in a point in time where uh science has advanced dramatically. Uh, we have evidence-based medicine, evidence-based uh policing. Um, all essentially suggest that in order to make decisions with respect to policy or the implementation and tools what we need to do is essentially test what works and what doesn't. Unfortunately we don't have that in the context of fraud. So I think if we're thinking about policies and and policy changes, the first thing we need to sort of uh have in mind is is a different state of mind and that is of evidence-based, what works and what doesn't in the context of fraud prevention. Uh in the context of the government operation, we're in a very difficult position I would say because to be honest we don't really know how much fraud we have. Uh we have reports on uh improper payments, but we don't know how much fraud we have uh uh on the government side. We we hear numbers and and very large numbers, so it's definitely an issue, but we need to be able to quantify how much fraud we have and then after we quantify that number we need to try and assess how to reduce that number to the minimum possible in order to make sure the taxpayer get uh their money worth in terms of benefits in terms of program that they they should have access to. So I think if if we need to sort of have something in mind when we think about a policy uh change then then it's definitely an evidence-based approach to fighting fraud.
Mister Stanley. Uh, could you turn your mike on, please?
So, sorry about that. I would agree with Ms. Cruz-Cain that strengthening the Privacy Act of nineteen seventy-four is sorely needed as well as overarching consumer privacy legislation I believe that the US is the only uh advanced industrial OECD nation that doesn't have an overarching privacy law that sets baseline expectations for both individuals and businesses about what's fair and what's not in terms of how people's information is treated. And then as - as I've been arguing, I - I - I think that we need to set standards for digital driver's licenses in the States and other digital IDs um that put in place bu- put in place both um requirements for how they are built technically, they should have certain encryption um uh capabilities that protect privacy while still allowing for people to authenticate themselves and there should be a leg- an envelope of legal protections around them. um to make sure that they remain optional and not mandatory for example and to limit um uh overuse um and so those would be the top of uh the top things that i think the congress should consider
yeah yeah thank thank you very much i want to thank all of you mister chairman you may recall this idea of revamping the federal privacy act continues to come up we did the last hearing we did like this that same thing came up so i have i wanna commit myself and i'm sure you know, you and I will get together on this and figure out how in fact we might be able to move forward with some joint legislation that at least starts to move the ball regarding the Federal Privacy Act that's been a long time uh since nineteen seventy-two. The world has changed and the least we can do, I think, is to try to find a way uh to protect the privacy of Americans by updating the federal policy that we have. Um and I want to commit myself to working with you in that regard. I yield back.
Gentleman yields back his time. Um, did was that your closing statement also?
Yes. Yes, it was.
The gentleman did make a closing statement. I too wanna join in with my dear friend, Mister Infume, and thank each of you for being here. This uh issue is not gonna go away. The question is, are we serious enough to continue the the search, the to look for these things? And I think all four of you have proven to us today that there is not just much ground to go, but there's much to learn. And I think both Mister Mfume and I uh need to provide some perhaps guidance back to Inspector General's, their attention to this, uh to uh uh help GAO to reinforce the things that they're after, to have the GSA follow up. I I find myself in a position where I don't wanna say that they're not paying attention. I think they're trying trying to do a number of things that are important. But Mr. Mfume and I find ourself on the on this end of the uh trying to save the taxpayer, trying to understand that the people, whether it's one of my sons or it's one of his constituents, that that need government benefits and government services to work properly, to be legally bound to to recognize these things, but that we'll we'll bleed ourself out. We can bleed ourself out by people who are outside the system, uh, uh, causing us to to completely miss the mark. So we're gonna stay after this. Uh, we're going to make sure that we approach every single angle, uh, and challenge government to do that. We're we've we've by and large decided we do understand the We do understand the importance of data. We do understand the need to make sure that it survives, uh, in perpetuity, yeah, probably for a lot longer, uh, that it, we give it the the authority and the responsibility to evolve itself, to, you know, and meet the emerging and new threats, and to provide information back. Uh, but I wanna thank you for your insistence that we will w- continue to work together. And I wanna thank each of you. Um, so with that said, uh, without objection, all members have five legislative days within which to submit materials and additional written questions for the witnesses, which would be forwarded to the witnesses. If there is no such further business, the objection subcommittee stands adjourned.
Morning digest
Start every morning briefed on yesterday’s hearings
A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.



