Federal agencies have invested heavily in fraud prevention, cybersecurity, program integrity, and investigative capabilities. Yet many are confronting a new reality: Some of the most important indicators of fraud no longer originate within traditional reporting channels.
The threat environment is evolving rapidly. According to the Identity Theft Resource Center’s Annual Data Breach Report, publicly reported data compromises reached a record 3,322 incidents in 2025, representing a 5% increase over 2024 and a 79% increase over the previous five years.
At the same time, the report notes that nearly 279 million victim notices were issued, reflecting the significant number of individuals affected by data compromises and the growing availability of identities, credentials, and personal information that frequently underpin modern fraud schemes.
Meanwhile, fraud campaigns are becoming faster, more sophisticated, and increasingly automated. Threat actors can rapidly share tactics, weaponize compromised credentials, and adopt new tools that lower barriers to entry while increasing operational scale.
Artificial intelligence is accelerating both the speed and volume of these activities. Industry reporting identified approximately 3.8 million phishing attacks globally in 2025, while researchers observed widespread use of AI-generated phishing content and increasingly sophisticated social engineering tactics.
This evolving environment has created an intelligence gap. Many indicators of emerging fraud activity exist beyond the visibility of fraud analysts, investigators, cybersecurity teams, and program administrators. By the time fraudulent activity appears in case data, customer complaints, or traditional reporting channels, threat actors may have already tested, refined, and expanded their campaigns. The challenge facing agency leaders isn’t simply seeing more—it’s gaining the visibility needed to anticipate threats earlier and convert emerging signals into proactive defense before fraud campaigns scale.
Traditional fraud programs were designed around detecting and responding to known activity. That approach remains essential but is increasingly strained by a threat landscape characterized by speed, scale, and adaptation. Several trends driving this shift include:
These trends create a significant challenge for federal programs that rely primarily on internal visibility. Many agencies can respond effectively once fraud occurs. The challenge is identifying emerging threats before they generate losses or operational disruption. As threat actors adapt tactics in days or even hours, earlier warning becomes a strategic advantage. As a result, leaders face a growing need to complement traditional fraud detection with mechanisms that provide awareness of threats developing outside their immediate field of view.
The consequences of this intelligence gap aren’t theoretical. At one large federal agency, external monitoring identified approximately $30 million in potential fraud exposure, more than 70,000 compromised user credentials, and hundreds of spoofed websites and fraud-enablement resources targeting government services. These findings provided valuable insight into the tactics, infrastructure, and opportunities being leveraged by threat actors.
Many of these indicators may never have surfaced through traditional reporting channels despite having direct implications for fraud risk, account security, and program integrity. Increasingly, some of the most actionable fraud signals emerge long before an investigation is opened or suspicious activity is reported.
Visibility alone doesn’t reduce fraud. The value of intelligence lies in its ability to drive action across the organization. When emerging threats are identified early, agencies can:
Threat intelligence isn’t a replacement for investigations, fraud operations, or cybersecurity programs. Its value lies in providing earlier warning and broader context that investigators, analysts, platform owners, and program leaders can translate into defensive action. A practical framework organizes action into four phases.
Phase 1: Identify external signals
Phase 2: Prioritize threats by impact
Phase 3: Connect intelligence to operations
Phase 4: Continuously adapt controls
The most significant challenge facing federal fraud programs may not be the sophistication of individual threat actors but the growing speed at which fraud campaigns can emerge, evolve, and scale. Record numbers of data compromises continue to provide threat actors with vast quantities of identities, credentials, and personal information, while AI-enabled phishing and social engineering campaigns allow those actors to operationalize that information at unprecedented speed and scale.
In the face of these challenges, agencies will face increasing pressure to shorten the time between awareness and action. By identifying emerging threats earlier, prioritizing risks more effectively, using threat-informed testing to evaluate real-world exposure, and integrating intelligence into operational decision-making, federal programs can better keep pace with an increasingly dynamic fraud landscape while continuing to protect critical services and the public they serve.
Guidehouse is a global AI-led professional services firm delivering advisory, technology, and managed services to the commercial and government sectors. With an integrated business technology approach, Guidehouse drives efficiency and resilience in the healthcare, financial services, energy, infrastructure, and national security markets.