Login-dot-gov explores more device fingerprinting to combat fraud, AI agents and bots The General Services Administration is seeking to add more device fingerprinting to Login.gov, the government's unified account manager, to combat identity fraud, according to a request for information posted Tuesday. The solution would integrate fingerprinting into account creation and sign-in, detect automated traffic including AI agents from ChatGPT, Claude, and Gemini, and identify returning devices even when users use VPNs or incognito browsing. Responses are due Sept. 11. Login-dot-gov explores more device fingerprinting to combat fraud, AI agents and bots The General Services Administration is seeking to combat identity fraud by adding more device fingerprinting to Login-dot-gov, the government’s unified account manager, according to contracting documents https://sam.gov/workspace/contract/opp/a6de63ce78ec4f28b250d3d3c8cf34de/view posted Tuesday. The “sophistication and volume” of fraud attempts have grown as the service’s user base and agency adoption have expanded, the request for information said. While Login-dot-gov already uses fingerprinting within its identity verification flow, “there is an opportunity to enhance the platform’s comprehensive fraud prevention strategy,” documents said. “This capability is essential for detecting sophisticated fraud attacks including account takeover, synthetic identity fraud, automated bot activity, residential proxy abuse, and emerging agentic artificial intelligence threats,” they said. Device fingerprinting identifies visitors through browser, device and network signals rather than just traditional identifiers like IP addresses or cookies, the request said. The solution GSA is exploring would integrate fingerprinting into account creation and sign-in, provide real-time risk signals for fraud detection and identify returning devices, “even when users attempt to evade detection through VPNs, residential proxies, incognito browsing, cookie clearing, or browser tampering,” the documents said. GSA is hoping to find a provider for these capabilities alone, not a full app suite or platform, unless other components are required, it said. The request said the solution should also detect and classify automated traffic like bots and agentic AI, including large language model-based agents from ChatGPT, Claude and Gemini, and “future-proof” to adapt to the rapidly changing technology. Responses are due Sept. 11. The RFI comes at a time of change for Login-dot-gov, which recently named https://fedscoop.com/sam-corcos-gsa-management-treasury-doge/ Treasury Department CIO Sam Corcos as its acting assistant commissioner. Marisol Cruz Cain, the Government Accountability Office’s director of IT and cybersecurity, told the House Oversight and Government Reform Subcommittee on Government Operations in July https://fedscoop.com/digital-identity-fraud-login-dot-gov-federal-response/ that GSA has not taken all the recommended https://www.gao.gov/products/gao-26-109261 steps to collaborate with agencies to address the single sign-on platform’s technical challenges. Agencies reported that they lacked visibility into authentications, the system had a high failure rate and lacked fraud controls, she said. “To their credit, they have been taking the issue very seriously and partnering with new technologies and new companies to enhance their fraud controls, but they need to partner with the users,” she said. “If the users can’t use it, the technologies can be great, but if your users are still having issues using the system, you’re going to lose that user base.”