Skip to main content

The Money Overview

Locking your online Social Security account takes two minutes and blocks thieves from rerouting your check

Social Security beneficiaries who have not claimed their online accounts are leaving the door open for identity thieves to do it for them, redirect monthly payments, and collect benefits before the real recipient ever notices. The Social Security Administration and its Office of the Inspector General have documented thousands of cases in which stolen personal information was used to reroute direct deposits. Two account-level blocks, each taking only minutes to activate, can shut down the most common attack paths.

Why payment redirection fraud is spiking through open accounts

The scheme works because Social Security benefits can be rerouted through several channels. Direct deposit information can be changed online through a my Social Security account, over the phone through the SSA 800-number, at a field office, by mail, or through a bank using the Automated Enrollment process. Each channel represents a potential entry point for someone armed with a beneficiary’s name, Social Security number, and date of birth.

The SSA OIG warned that identity thieves obtain this information, open a my Social Security account in the victim’s name, and then change the direct deposit destination to an account they control. The OIG also found that before April 14, 2025, SSA staff at the national 800-number could process direct deposit changes using only basic personal information to verify identity. An OIG review covering October through December 2023 identified 3,109 beneficiaries whose direct deposit had been changed by 800-number staff and who subsequently reported non-receipt of their payments.

Concerns about this type of fraud are not new. In an earlier fraud advisory, the OIG described how criminals used stolen personal data to create online accounts, divert payments, and cash out benefits before victims or SSA could react. The pattern has remained consistent: once a criminal gains control of the payment destination, benefits can be drained for months unless the beneficiary notices quickly and reports the loss.

SSA has since ended phone-based direct deposit changes, and online changes now carry a 30-day hold. But the online and bank-enrollment channels remain active, which means a thief who beats a beneficiary to account creation can still attempt a redirect. Beneficiaries who never set up their online accounts are especially exposed because there is no existing login to block a criminal from registering first.

How two SSA blocks shut down the main attack paths

SSA offers two distinct protections through its fraud prevention page. The first is an eServices block, which prevents anyone, including the account holder, from viewing or changing personal information online. The second is a Direct Deposit Fraud Prevention block, which stops anyone from altering direct deposit details, including changes submitted by a financial institution through the bank enrollment process.

Both blocks are set through the same SSA portal and take effect immediately. The tradeoff is real: while the blocks are active, the beneficiary also loses the ability to make those changes online. Anyone who later needs to update banking information must visit a field office in person or contact SSA directly to have the block lifted first. For people who rarely change banks or addresses, that inconvenience is often outweighed by the protection from remote tampering.

The OIG has stated that simply creating a my Social Security account reduces the risk that a thief will be able to open one in the beneficiary’s name. Adding both blocks on top of that account creation covers the remaining channels. SSA’s internal policy manual, known as POMS GN 02402.012, instructs field offices on handling allegations of unauthorized direct deposit changes and unauthorized account information changes that commonly lead to payment redirection, and on reimbursing victims when fraud is confirmed.

What beneficiaries can do now

Beneficiaries who want to reduce their exposure can take three basic steps. First, if they have not already done so, they should create a my Social Security account in their own name using a secure device and a strong, unique password. Doing this closes off the easiest route for a criminal to register an account with stolen information.

Second, after logging in, they can request the eServices block and the Direct Deposit Fraud Prevention block through SSA’s online tools or by contacting the agency directly. These settings immediately restrict the ability to view or change sensitive data online or through bank-initiated enrollment, sharply limiting the ways a thief can redirect payments without appearing in person.

Third, beneficiaries should monitor their bank accounts and benefit statements for any irregularities, such as missing deposits or unexpected changes in payment amounts. If anything looks wrong, they should report it to SSA and their financial institution as quickly as possible, documenting dates, times, and the names of any representatives they speak with. Fast reporting can make the difference between a single missed payment and a months-long diversion.

None of these steps can eliminate fraud risk entirely, but together they significantly harden the target. By claiming their online accounts, activating the available blocks, and watching for anomalies, beneficiaries can make themselves far more difficult for identity thieves to exploit – and far more likely to have their benefits restored promptly if something does go wrong.


Plain-English help keeping more of your money in retirement. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.