Millions of Medicare beneficiaries started receiving unexpected letters about Medicare.gov accounts they never created, prompting the Centers for Medicare and Medicaid Services to investigate what turned out to be a breach involving fraudulently created accounts. CMS’s 1-800-MEDICARE call center began fielding those inquiries on May 2, 2025, and the agency confirmed that malicious actors were behind the unauthorized account activity. The fallout now raises pointed questions about how many people were affected, whether replacement Medicare cards sent in the breach’s wake can be distinguished from routine mailings, and what beneficiaries should do next.
Why fraudulent Medicare.gov accounts triggered a wave of new cards
The sequence of events is straightforward but alarming. CMS confirmed that its call center began receiving inquiries on May 2, 2025 from beneficiaries who had received official letters confirming the creation of Medicare.gov accounts they did not open. After investigating, the agency determined that malicious actors had fraudulently created those accounts. The letters themselves are part of a standard CMS process: Medicare.gov automatically sends correspondence whenever an account is created, a coverage change is recorded, or a new card is requested. That means the very safeguard designed to keep beneficiaries informed became the first signal that something had gone wrong.
Replacement Medicare cards follow a similar automated path. According to Medicare’s own mailing guidance, letters go out when actions are taken on an account, including name, coverage, or Medicare number changes. If a fraudulently created account triggered any of those downstream changes, a new card would follow automatically. That overlap between legitimate operational mailings and breach-driven correspondence is exactly what makes the situation difficult for beneficiaries to parse on their own.
Separating breach-driven mailings from routine card replacements
CMS has not released an exact count of how many accounts were fraudulently created or how many beneficiaries received breach-related notifications between 2023 and 2025. That gap matters because Medicare regularly sends replacement cards for reasons that have nothing to do with fraud. The agency completed a nationwide card redesign years earlier under its SSN Removal Initiative, which replaced Social Security number-based identifiers on Medicare cards to reduce identity theft. That earlier effort generated its own large volume of new-card mailings, and annual re-enrollment cycles produce additional routine correspondence every fall.
Even outside of breaches, beneficiaries can legitimately request a new card at any time. Medicare’s instructions for ordering a replacement card explain that people may need a new card if the original is lost, damaged, or if personal information changes. Those standard processes run in parallel with CMS’s incident response, so a spike in mail volume alone does not prove that any individual household was targeted by fraud.
Without public data on the total number of fraudulently created accounts, there is no way to measure how much of the post-May 2025 card volume traces directly to the breach versus standard coverage changes. The hypothesis that replacement cards issued after May 2025 correlate more with confirmed fraudulent activity than with normal enrollment cycles remains untested in any publicly available dataset. CMS has described its breach response process in general terms, outlining alignment with federal security policies and guidelines, but outcome-level numbers, such as how many accounts were locked, how many cards were reissued, or how many beneficiaries filed identity theft reports, have not appeared in any public disclosure so far.
What affected beneficiaries should do first
The practical risk for anyone who received an unexpected Medicare.gov letter is real. If a malicious actor created an account using a beneficiary’s personal information, that data could be used to view claims, change contact information, or request a replacement card that might then be used to facilitate medical identity theft or fraudulent billing. Even if no fraudulent claims have appeared yet, the existence of an unauthorized online account is a red flag that personal data is circulating beyond the beneficiary’s control.
Beneficiaries who receive a letter about an account they did not create should start by contacting 1-800-MEDICARE directly using the phone number printed on the back of their existing Medicare card or listed on Medicare.gov, rather than any number that appears in an unexpected letter. Call center representatives can confirm whether an online account exists, when it was created, and what actions have been taken. If the account is fraudulent, CMS can disable or secure it and, where appropriate, issue a new Medicare number and card.
People should also review recent Medicare Summary Notices or Explanation of Benefits statements for unfamiliar services or providers. Any suspicious claims should be reported to Medicare immediately so they can be investigated and, if necessary, reversed. In addition, beneficiaries may want to place fraud alerts with major credit bureaus and file identity theft reports with the Federal Trade Commission, especially if they suspect that other personal information beyond Medicare details has been compromised.
Finally, beneficiaries who do not yet have a legitimate Medicare.gov account may wish to create one proactively, using strong, unique passwords and updated contact information. Securing an official account in their own name can reduce the risk that someone else will successfully open one first, and it also gives beneficiaries a direct view into their claims history and coverage changes. While CMS continues to investigate and refine its safeguards, informed vigilance from beneficiaries remains a crucial line of defense against fraud that begins with something as simple-and as unsettling-as an unexpected letter in the mail.