Article

Closing the visibility gap fueling federal fraud

Agencies need earlier insight into emerging threats to anticipate fraudulent activity, adapt defenses, and keep pace with fast-evolving attacks.

Summary 

 

  • Federal fraud threats are evolving faster than agencies can track via traditional reporting channels.
  • This intelligence gap limits agencies' ability to address emerging threats before they scale. 
  • A threat-intelligence framework that identifies signals, prioritizes risks, operationalizes intelligence, and continuously adapts controls can close that gap. 

 


 

Federal agencies have invested heavily in fraud prevention, cybersecurity, program integrity, and investigative capabilities. Yet many are confronting a new reality: Some of the most important indicators of fraud no longer originate within traditional reporting channels. 

The threat environment is evolving rapidly. According to the Identity Theft Resource Center’s Annual Data Breach Report, publicly reported data compromises reached a record 3,322 incidents in 2025, representing a 5% increase over 2024 and a 79% increase over the previous five years. 

At the same time, the report notes that nearly 279 million victim notices were issued, reflecting the significant number of individuals affected by data compromises and the growing availability of identities, credentials, and personal information that frequently underpin modern fraud schemes. 

Meanwhile, fraud campaigns are becoming faster, more sophisticated, and increasingly automated. Threat actors can rapidly share tactics, weaponize compromised credentials, and adopt new tools that lower barriers to entry while increasing operational scale. 

Artificial intelligence is accelerating both the speed and volume of these activities. Industry reporting identified approximately 3.8 million phishing attacks globally in 2025, while researchers observed widespread use of AI-generated phishing content and increasingly sophisticated social engineering tactics. 

This evolving environment has created an intelligence gap. Many indicators of emerging fraud activity exist beyond the visibility of fraud analysts, investigators, cybersecurity teams, and program administrators. By the time fraudulent activity appears in case data, customer complaints, or traditional reporting channels, threat actors may have already tested, refined, and expanded their campaigns. The challenge facing agency leaders isn’t simply seeing more—it’s gaining the visibility needed to anticipate threats earlier and convert emerging signals into proactive defense before fraud campaigns scale. 



Why traditional approaches are under strain 

Traditional fraud programs were designed around detecting and responding to known activity. That approach remains essential but is increasingly strained by a threat landscape characterized by speed, scale, and adaptation. Several trends driving this shift include: 

  • AI-driven increases in the volume and sophistication of phishing, impersonation, and social engineering campaigns 
  • Fraud actors rapidly testing and refining tactics across multiple channels 
  • Criminal communities routinely sharing successful techniques, tools, and operational guidance 
  • Compromised credentials and personal information becoming widely available through illicit ecosystems 
  • Cybersecurity and fraud threats becoming increasingly intertwined—particularly in areas such as account takeover, identity fraud, credentials abuse, and identity-verification circumvention 

These trends create a significant challenge for federal programs that rely primarily on internal visibility. Many agencies can respond effectively once fraud occurs. The challenge is identifying emerging threats before they generate losses or operational disruption. As threat actors adapt tactics in days or even hours, earlier warning becomes a strategic advantage. As a result, leaders face a growing need to complement traditional fraud detection with mechanisms that provide awareness of threats developing outside their immediate field of view. 

The consequences of this intelligence gap aren’t theoretical. At one large federal agency, external monitoring identified approximately $30 million in potential fraud exposure, more than 70,000 compromised user credentials, and hundreds of spoofed websites and fraud-enablement resources targeting government services. These findings provided valuable insight into the tactics, infrastructure, and opportunities being leveraged by threat actors. 

Many of these indicators may never have surfaced through traditional reporting channels despite having direct implications for fraud risk, account security, and program integrity. Increasingly, some of the most actionable fraud signals emerge long before an investigation is opened or suspicious activity is reported. 



Developing a threat-intelligence framework 

Visibility alone doesn’t reduce fraud. The value of intelligence lies in its ability to drive action across the organization. When emerging threats are identified early, agencies can: 

  • Strengthen controls before fraud campaigns scale 
  • Prioritize investigative resources against the highest-risk threats 
  • Identify vulnerabilities being actively targeted by threat actors 
  • Reduce exposure to credential theft and account-takeover activity 
  • Coordinate fraud, cybersecurity, investigative, and digital service teams around a common understanding of risk

Threat intelligence isn’t a replacement for investigations, fraud operations, or cybersecurity programs. Its value lies in providing earlier warning and broader context that investigators, analysts, platform owners, and program leaders can translate into defensive action. A practical framework organizes action into four phases. 

Phase 1: Identify external signals 

  • Monitor emerging fraud schemes and tactics 
  • Track discussions related to government services and programs 
  • Identify compromised and exposed information 
  • Observe new methods used to circumvent security controls

Phase 2: Prioritize threats by impact 

  • Validate the credibility of emerging threats 
  • Assess potential operational and financial impact 
  • Evaluate likelihood and severity  
  • Prioritize finite resources against the most consequential risks 

Phase 3: Connect intelligence to operations 

  • Establish processes that allow intelligence to be shared and operationalized 
  • Expose that intelligence across fraud prevention teams, investigative functions, cybersecurity teams, identity and access management groups, digital service leaders, and platform owners 

Phase 4: Continuously adapt controls 

  • Monitor changes in adversary tactics 
  • Evaluate whether current controls remain effective 
  • Conduct threat-informed testing against emerging fraud techniques 
  • Measure outcomes and identify gaps 
  • Refine controls as conditions change 


Keeping pace in a faster threat environment 

The most significant challenge facing federal fraud programs may not be the sophistication of individual threat actors but the growing speed at which fraud campaigns can emerge, evolve, and scale. Record numbers of data compromises continue to provide threat actors with vast quantities of identities, credentials, and personal information, while AI-enabled phishing and social engineering campaigns allow those actors to operationalize that information at unprecedented speed and scale.  

In the face of these challenges, agencies will face increasing pressure to shorten the time between awareness and action. By identifying emerging threats earlier, prioritizing risks more effectively, using threat-informed testing to evaluate real-world exposure, and integrating intelligence into operational decision-making, federal programs can better keep pace with an increasingly dynamic fraud landscape while continuing to protect critical services and the public they serve. 

insight_image

James Hickman, Director

insight_image

Erik Provitt, Director

Philip Burke, Associate Director

Max Barmack, Consultant


Let us guide you

Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.

Stay ahead of the curve with our latest insights, expertly tailored to your industry.