Media
Dr. David Maimon's Congressional Testimony on Emerging Fraud Threats and the Evolving Fraud Landscape
David Maimon
Published
July 17, 2026
On Wednesday, July 15, our Head of Fraud Insights, Dr. David Maimon, testified before the U.S. Congress.
Dr. Maimon studies fraud by going where it happens, including dark net markets, Telegram channels, and the shell addresses these operations use to look legitimate.
His oral statement below highlights how fraud against government programs has evolved, and the best way for Congress to fight back. Read his full testimony here.
WASHINGTON, D.C., June 15, 2026
"Chairman Sessions, Ranking Member Mfume, and members of the Subcommittee, thank you for the opportunity to testify today.
I serve as Head of Fraud Insights at SentiLink and as a professor of criminal justice and criminology at Georgia State University. For nearly two decades, I have studied cybercrime by going where it happens: into darknet markets, Telegram channels, and encrypted platforms where fraudsters buy, sell, and teach each other how to steal from government programs. I also go into the field myself, to the mail drops, virtual offices, and shell addresses these operations use to look legitimate. My testimony today is based on that firsthand work.
The central lesson from my research is this: fraud against government programs is no longer a series of isolated schemes. It is a durable, specialized criminal infrastructure, and it moves.
The pandemic did not create this infrastructure, but it supercharged it. Criminals learned how to acquire stolen and synthetic identities, stand up shell companies, open bank accounts, and recruit money mules at scale. When pandemic relief programs ended, none of that capacity disappeared. It migrated. Today my team is tracking that same infrastructure inside SNAP, Medicare, Medicaid, federal student aid, tax refunds, and SBA-backed loans.
A few examples illustrate how. We are watching criminals combine stolen identities with AI-generated faces and deepfake video to defeat liveness checks at digital banks and tax preparers, using nothing more exotic than face-swapping software available to anyone. We are watching an EBT fraud market where one criminal steals card data, a separate paid-service verifies the balance before the card is even used, and a third actor cashes it out. And my own field investigation of a Florida durable medical equipment company, whose office I found abandoned in Delray Beach, is now tied to a Department of Justice case alleging $3.76 billion in fraudulent Medicare and Medicaid claims.
Different programs, different agencies, same playbook: the same stolen identity, the same shell company, the same bank account, reused across systems that rarely talk to each other. That fragmentation is the vulnerability. Criminals exploit the seams between agencies precisely, because our defenses are built program by program, while their infrastructure is built to move across all of them.
Given my time today, I want to leave the Subcommittee with four priorities.
First, replace self-attestation with verified data wherever the risk is high. Too many programs still take applicants at their word on income, identity, or eligibility. That was the single biggest vulnerability exploited during the pandemic, and it remains one today.
Second, expand real-time, cross-agency data matching. The same identity that files a fraudulent tax return can apply for SNAP benefits the same week. Agencies that only compare notes in periodic batch runs, weeks after the money is gone, cannot see that pattern. They need to see it before disbursement, not after.
Third, strengthen pre-payment screening and move toward risk-based disbursement. Build on the model of Treasury's Do Not Pay system, but expand its authority and its reach, so that suspicious payments are held before they leave the government rather than chased afterward through recovery audits that criminals have already outrun.
Fourth, give agencies the flexibility to adopt smarter tools and keep it current. Much of today's verification infrastructure and the policies behind them were built for an earlier threat. And procurement and rulemaking cycles that take years, cannot keep pace with fraud tactics that shift in months or less. Agencies need standing authority to test and deploy technologies to meet the current threats, not just at the next scheduled audit.
None of this requires slowing down help for legitimate applicants. It requires distinguishing them from fraud earlier, using signals criminals cannot easily fabricate.
The federal government already has some of the tools it needs. What is missing is the authority, the coordination, and the sustained investment to use those tools before the money moves, not after. Every dollar we protect from organized fraud is a dollar that stays available for the people Congress intended to help."
About SentiLink
SentiLink, the leading provider of innovative identity verification and fraud prevention solutions, empowers organizations to accurately identify customers and detect synthetic fraud, identity theft, and other hard-to-detect forms of identity fraud. Headquartered in San Francisco, the company was founded in 2017 by Naftali Harris and Max Blumenfeld and has raised $85M to date from investors including Andreessen Horowitz, Craft Ventures, and NYCA Partners. Every day, SentiLink verifies 3M+ identities and flags 100K+ high-risk applications to help partners reduce fraud losses and verify more legitimate customers.
Media Contact:
Jason Kratovil
jason@sentilink.com
Related Content
Media
July 17, 2026
Dr. David Maimon's Congressional Testimony on Emerging Fraud Threats and the Evolving Fraud Landscape
Read article
Media
June 17, 2026
SentiLink Partners with Florida’s Agency for Health Care Administration to Combat Medicaid Fraud
Read article
Media
February 18, 2026