The General Services Administration (GSA) Office of Inspector General (OIG) is aware of an ongoing scheme in which scammers are impersonating GSA officials and sending fraudulent emails to GSA contractors, including companies holding Multiple Award Schedule contracts and entities registered in SAM.gov. GSA OIG has received multiple reports of this activity in recent weeks.
The Scheme
- Scammers obtain the name and title of an actual GSA official, create a realistic signature block, and use it to impersonate that official in an email.
- The emails are sent from a look-alike domain designed to resemble GSA’s official domain rather than the legitimate gsa.gov address (for example, e-gsa.us has been used in reported cases).
- Since the message includes a real official's name, title, and agency signature block, recipients may not immediately notice that the sending domain is not legitimate.
- GSA OIG has identified at least two variations of emails used in this scheme:
- Fake "Vendor Credentialing Form." The email claims an annual "credentialing fee" is due to keep the vendor's status active and attaches a credit card authorization form requesting payment card information.
- Fake "Records Digitization Non-Compliance" notice. The email claims the vendor's contract file has been flagged as non-compliant with federal records-digitization requirements and directs the recipient to review an attached notice for "resolution steps."
- Additional variations of emails may exist or emerge, but all reported cases share the same core method: a spoofed near-GSA domain combined with an impersonated official's identity.
How to Avoid Being Scammed
- Check the sender’s actual domain, not just the display name or signature block. Legitimate GSA email addresses end [email protected]. Hover over the sender’s name (without clicking) to reveal the true address.
- Independently verify unexpected requests. If you receive an email claiming a fee is owed, a form must be completed, or your contract file has a compliance issue, contact the named official directly using contact information you already have on file or can independently verify - not a phone number or reply address in the suspicious email.
- Do not open unsolicited attachments or provide payment card, banking, or other sensitive information based on an unverified email, even if it appears to come from a known contracting official.
- Be alert to urgency and fees. Treat any unsolicited request tied to a "credentialing fee," compliance deadline, or similar pressure with skepticism until verified.
- Report internally first. If your organization receives one of these emails, notify your GSA contracting officer or contracting officer's representative through a verified contact method so they are aware their identity may be spoofed.
Note: Fraudsters may use other look-alike domains beyond the one identified above. Always verify the full domain rather than relying on this example alone.
How to Report
- Report suspected GSA impersonation attempts to the GSA OIG hotline at https://www.gsaig.gov/hotline.
- Because this scheme seeks payment card and other financial information, also report it to the FBI's Internet Crime Complaint Center at https://www.ic3.gov/.
- If you receive one of these emails, retain a copy, including headers if possible, to include with your report.
If you have information about fraud, waste, abuse, mismanagement, or other crimes or violations of federal laws, rules, and regulations relating to GSA programs and operations, including contracts, please report it to the GSA OIG hotline. You can submit your complaint at https://www.gsaig.gov/hotline.
