Fraudsters who break into a beneficiary’s my Social Security account can swap the direct deposit routing in minutes, sending monthly payments to bank accounts they control. Between January 2013 and May 2018, $33.5 million in Social Security benefits was successfully redirected from 20,878 beneficiaries through unauthorized online changes, while another $23.9 million was caught and stopped before funds left the system. Blocking electronic access to the account is the fastest countermeasure available to anyone who suspects a breach, yet the tool remains underused and its real-world effectiveness is poorly measured.
How a few clicks reroute a Social Security payment
The attack is simple. SSA allows beneficiaries to update direct deposit details through the My Profile tab inside their my Social Security account. That convenience, designed to let retirees switch banks without visiting a field office, also means anyone who obtains login credentials can redirect the next check. SSA’s own internal procedures treat reports of unauthorized deposit changes as potential fraud and direct field office technicians to follow a specific investigation workflow.
The online portal is not the only weak point. Banks can submit updated deposit information directly to SSA through an Automated Enrollment process, and phone-based changes have also produced unauthorized diversions. An OIG news release published today documents cases where beneficiaries did not always authorize telephone deposit changes, broadening the threat beyond the online channel alone. The electronic-access block covers online and automated-phone vectors but does not prevent a live agent from processing a fraudulent request if that agent is misled by convincing identity details.
$33.5 million redirected and the audit trail SSA built
The scale of the problem first surfaced in a 2015 OIG audit, report A-01-14-24011, which documented unauthorized direct deposit changes flowing through my Social Security accounts and recommended tighter monitoring of suspicious activity. That early audit work identified patterns such as multiple beneficiaries suddenly directing payments to the same bank account, a hallmark of organized fraud rings.
Congressional testimony delivered in May 2023 by the SSA Office of the Inspector General put hard numbers on the damage: $33.5 million redirected across 20,878 beneficiaries over roughly five years, with $23.9 million in additional diversions intercepted before release. Those figures cover only the January 2013 through May 2018 window; no comparable public dataset quantifies losses after 2018, leaving policymakers and beneficiaries without a clear picture of whether the situation has improved or simply changed shape.
SSA has since tightened controls. A March 2025 press release announced stricter identity-proofing requirements for online account access and plans to implement Treasury’s Account Verification Service, which would cross-check new bank details before a deposit change takes effect. These steps are intended to make it harder for criminals to open or take over accounts in the first place and to flag suspicious bank routing changes before benefits are sent out. Whether those upgrades have materially reduced diversion attempts is not yet documented in any published OIG report or audit, and the agency has not released updated statistics on confirmed losses.
What the electronic-access block does and does not cover
OIG testimony dating back to 2012 established that beneficiaries who learn they are victims of identity theft can block electronic access to their SSA records. Once activated, the block prevents anyone, including the account holder, from viewing or changing benefit information through the my Social Security portal or the automated phone system. Deposits continue to be issued to the last authorized account on file, but any future changes must be handled in person with identity documents or, in limited circumstances, through carefully controlled mail or phone procedures.
The block is powerful but blunt. It shuts off the fastest path criminals use to hijack benefits, yet it also removes the convenience of online self-service for legitimate users. Beneficiaries with mobility issues, those who live far from a field office, or people who rely on online access to track earnings and benefit estimates may hesitate to enable it unless they are certain their credentials have been compromised. SSA materials describe the block as optional and reversible, but there is no public data on how often it is requested, how quickly it is applied after a fraud report, or how frequently blocked accounts still experience unauthorized changes through human-assisted channels.
Another limitation is scope. The electronic-access block is designed to stop changes made through web and automated telephone systems, not to override every action an SSA employee can take. A fraudster who has assembled enough personal details to impersonate a beneficiary might still persuade a live agent to update direct deposit information, particularly in high-volume call centers where staff face pressure to resolve calls quickly. The OIG’s recent focus on unverified telephone changes underscores that risk and suggests that internal training and call-handling protocols remain as important as technical safeguards.
Beneficiaries left to balance convenience and security
For now, beneficiaries are effectively asked to make a trade-off. Leaving electronic access open preserves the ability to manage benefits online but exposes accounts to the same credential-theft risks that affect banking and email. Enabling an electronic-access block cuts off the most common digital attack paths but requires more effort to make legitimate changes and may complicate routine interactions with SSA.
Without updated statistics on post-2018 diversion losses or on how often the block has prevented fraud, it is difficult for individuals to make an informed choice. The documented $33.5 million in redirected payments and the thousands of affected beneficiaries show the stakes are real, yet the public record does not clearly show whether recent security upgrades and the expanded use of electronic-access blocks have turned the tide. Until SSA and its watchdogs publish more comprehensive data, beneficiaries will be left relying on partial information when deciding how tightly to lock down their own accounts.



