Fraud Risks in Defense IT Systems Are Costing Taxpayers Billions and Threaten Cybersecurity
The Department of Defense (DOD) relies on IT systems to support its day-to-day operations—including human capital, health care, contracting, and financial management.
DOD plans to spend billions to update and maintain these IT systems. That’s a lot of money, and there are concerns that some of it might be lost to fraud. Historically, DOD has struggled to prevent fraud—losing as much as $11 billion in fiscal years 2017 through 2024.
Today’s WatchBlog post looks at our new report on the sources and risk of fraud in DOD’s IT plans, and how it can be prevented.
DOD’s Planned Costs for the Four Largest IT Business Systems, FY 2024-2026
Image
DOD’s IT modernization efforts failed to include fraud prevention
DOD has been working to modernize its IT systems for more than 3 decades with the goal of improving how it does business. During the last two fiscal years, the department planned to spend $10.3 billion to update and maintain 18 critical IT business systems. But DOD’s plans did not include training for staff to detect fraud in these systems. As a result, billions may have been lost to fraudsters and the systems were left vulnerable to possible cybersecurity attacks.
The full extent of fraud affecting DOD—including its major IT business systems—is unknown but potentially significant. From fiscal years 2017 through 2024, DOD reported almost $11 billion in confirmed fraud. The scope and scale of DOD contracting makes it inherently susceptible to fraud. For example,
- A contractor created a shell company that falsely claimed to be U.S.-based and owned in order to qualify for government contracts. The contractor then sent restricted military data to a foreign manufacturer and supplied DOD with defective military aircraft parts—putting pilots in danger.
- Two DOD contracting companies misrepresented their ownership statuses to qualify for contracts they weren’t eligible for, defrauding the U.S. of more than $200 million.
Similarly, the cybersecurity risks associated with fraud are also potentially significant:
- Recently, a DOD contractor paid $8.4 million to resolve allegations that it failed to implement required cybersecurity protections, putting sensitive information at risk.
- A software developer failed to comply with cybersecurity requirements outlined in its contract. It put DOD information at risk by using unapproved third-party email hosting and failing to put required system protections in place.
What is DOD doing to manage fraud risk and what more is needed?
DOD has struggled to manage fraud for decades, which is why we added fraud risk management at DOD to our High Risk List in 2025. DOD has a general anti-fraud strategy that includes some training regarding fraud and cybersecurity. But, despite this, we found that DOD hadn’t taken important steps to prevent fraud.
For example, it hadn’t assessed fraud risks to five of the 18 IT systems we looked at. And DOD didn’t know whether it had assessed fraud risks for another three of the systems. Similarly, the staff meant to manage these systems had not received training needed to detect and prevent fraud. We found that staff managing 11 of the 18 IT systems we looked at hadn’t received this training over the past 2 years.
DOD should do more to protect its critical IT systems. This includes taking steps to promote anti-fraud awareness. Without training to recognize fraud in IT systems, DOD could fail to recognize fraud when it occurs. This includes recognizing when contractors may use substandard software or omit key required protections. Without safeguards against fraud, DOD potentially puts sensitive information at risk and wastes taxpayer dollars.
Learn more about this issue by reading our full report.
- GAO’s fact-based, nonpartisan information helps Congress and federal agencies improve government. The WatchBlog lets us contextualize GAO’s work a little more for the public. Check out more of our posts at GAO.gov/blog.
- Got a comment, question? Email us at blog@gao.gov.
GAO Contacts
Image
Image
Related Products
GAO's mission is to provide Congress with fact-based, nonpartisan information that can help improve federal government performance and ensure accountability for the benefit of the American people. GAO launched its WatchBlog in January, 2014, as part of its continuing effort to reach its audiences—Congress and the American people—where they are currently looking for information.
The blog format allows GAO to provide a little more context about its work than it can offer on its other social media platforms. Posts will tie GAO work to current events and the news; show how GAO’s work is affecting agencies or legislation; highlight reports, testimonies, and issue areas where GAO does work; and provide information about GAO itself, among other things.
Please send any feedback on GAO's WatchBlog to blog@gao.gov.