In short: Your government online account (Login.gov, ID.me, HMRC, your national tax or benefits portal) is a gateway to your documents, taxes and the ability to take out credit in your name — which makes it a top target for fraud. Solid protection rests on three things: two-factor authentication (an authenticator app, not SMS), a credit freeze, and one iron rule — never read out a one-time code over the phone. Real agencies don't call and ask for your codes. If your account is already compromised, freeze it, change the password, and report the fraud right away.
Why scammers target government accounts
Account-takeover fraud aimed at government portals has become one of the most-discussed scam themes of 2026. The reason is simple: a single login opens your entire digital life. Inside are your identity documents, tax records, property and vehicle data, national insurance or social-security number, and often linked bank details and a digital signature.
Once inside, an attacker can apply for a payday loan, register a company or a SIM in your name, change linked contact details, or file official requests. It takes minutes to do and months for the victim to unwind — cancelling loans and proving the applications weren't theirs. That's why protecting a government account belongs in the same tier as protecting your banking app, not "later."
The scams that actually work in 2026
Portals themselves are rarely "hacked" — they're well defended. Fraudsters attack the person instead: their whole job is to get you to hand over the password or confirmation code yourself. The recurring playbooks:
- The multi-step official impersonation. First a call "from a courier" about a delivery. A minute later a "notification" says the call was unsafe, then an "agency officer" phones claiming someone accessed your account and is applying for a loan. You're asked to read out codes "to cancel it" — those codes are exactly what confirms the login or the loan.
- The callback trap. A message tells you to call an "official" number. On the other end is a fake call centre posing as support and fishing for your secret codes.
- Look-alike sites. A link in an email or chat leads to a page visually identical to the real portal but on a different address. Everything you type — login, password, code — goes to the scammer.
- Phishing by SMS and chat. "Your account is locked," "confirm your details," "you have a refund" — with a link to a fake sign-in form.
Every scheme shares one tell: you're rushed, frightened, and asked to share a code. Real services never work that way.
Two-factor authentication: which second factor is stronger
Two-factor authentication is the single biggest upgrade you can make — but not every second factor protects equally. Here's how the common options compare:
| Second factor | How it works | How strong |
|---|---|---|
| SMS code | A one-time code arrives by text at sign-in | Baseline: can be intercepted via a SIM-swap or talked out of you |
| Authenticator app | A code is generated on your phone (TOTP), no network or SMS needed | High: the code lives 30 seconds and never travels over the mobile network |
| Biometrics / passkey | Sign-in is confirmed by face or fingerprint, tied to your device | High: bound to your hardware and hard to phish remotely |
If your portal offers it, switch the second factor from SMS to an authenticator app — that closes a whole class of attacks where codes are grabbed on the mobile network. Also check the security settings: most portals show login history and active sessions, so review them for anything you don't recognise.
How to tell a real service from a scammer
Almost every attack gives itself away with the same signs. If you spot even one, hang up and don't click:
- You're asked to read out a one-time code or password. No bank, agency or police force ever does this.
- The caller manufactures urgency: "act now," "or a loan gets approved," "your account locks in 10 minutes."
- You're pushed into a messaging app or told to call back a given number.
- A link points to an address only similar to the official one — check it first with our guide on spotting a fake website.
- The voice sounds "official" but leans on emotion — these calls increasingly use AI voice cloning.
- An alarming text arrives with a link — classic smishing; don't tap it.
Simple rule: treat any inbound contact "about your account" as untrusted. Hang up and go to the portal yourself — via a bookmark or the official app, never the link you were sent.
Where VPN and public Wi-Fi fit in
Some takeovers start not with a call but with data captured on an untrusted network. On open Wi-Fi in a café, hotel or airport, traffic between your phone and a site can be observed by a stranger — logins included. Signing into a government portal, bank or email over unencrypted public Wi-Fi is a bad idea; see our piece on public Wi-Fi security.
A VPN encrypts the whole connection, so there's nothing to intercept on someone else's network. That's exactly what LiMP VPN is for: it opens an encrypted tunnel on iPhone and Android, keeps no logs, and costs about $1 a month — you can see the plans on the pricing page.
But be honest about the limits: a VPN protects the channel, not against social engineering. If you read a code out to a scammer yourself, no encryption helps — you handed the data over. A VPN closes network interception; resisting persuasion is on you and your two-factor setup.
Financial locks: credit freeze and alerts
Even if an account is ever compromised, you can strip the attack of its point — money — in advance. A credit freeze with the major credit bureaus blocks new loans and accounts from being opened in your name; while it's active, lenders can't approve credit even with correct data. Lifting it takes a deliberate step from you, so a scammer can't instantly undo it.
On top of that, turn on transaction and application alerts with your bank, and periodically check your credit report for inquiries you didn't make. It doesn't get in your way, but it turns a fraudulent loan attempt into wasted effort.
What to do if your account is already hacked
Speed matters: the longer the attacker is inside, the more requests they can file. Work through this in order:
- Freeze or lock the account through the portal's official support line, and change the password from a trusted device.
- End every active session in the security settings and remove any unknown linked devices.
- Review the activity log: filed requests, linked banks, changed phone or email — revoke anything that isn't yours.
- Place a credit freeze and alert your bank to pause suspicious activity.
- Report the fraud to the relevant authority (in the US, IdentityTheft.gov and the FTC; in the UK, Action Fraud). You'll need the report to dispute loans opened in your name.
When in doubt about the recovery process, confirm the steps only through the official support line — never through "helpers" who reach you in a messaging app.
Checklist: secure your government account in 15 minutes
- Enable two-factor authentication and switch the second factor from SMS to an authenticator app.
- Set a long, unique password and store it in a password manager, not in notes.
- Place a credit freeze with the major bureaus.
- Review login history and active sessions — end anything unfamiliar.
- Memorise the rule: one-time codes are never shared with anyone.
- Sign in only via a bookmark or the official app, never links from emails or chats.
- Don't access the portal on open Wi-Fi without a VPN — encrypt the connection on untrusted networks.
- Refresh your general account-protection habits — the same principles cover email and banking.
Frequently asked questions
Can my account be hacked if two-factor authentication is on?
Cracking a password and a second factor at once is extremely hard. But 2FA is useless if you read the code out to a scammer over the phone — which is exactly what every scheme is built around. The code is the second factor; hand it over and you open the door yourself.
What if I already gave a code over the phone?
Act immediately: sign in, change the password, end all sessions, contact official support to lock the account, and place a credit freeze. The faster you take back control, the less an attacker can do.
Do real agency or bank staff ever call?
They may call about service matters, but never ask you to read out a password, a one-time code, or move money to a "safe account." Any such request is a scam: hang up and call the organisation back on the official number from its website.
Does a VPN protect against account takeover?
A VPN encrypts your traffic so data can't be intercepted on public Wi-Fi, but it does nothing against social engineering — if you share the code yourself, encryption won't help. It's connection hygiene, not a replacement for two-factor authentication.
What is a credit freeze and how do I set one?
It's a voluntary block on opening new credit in your name, placed with the major credit bureaus. While active, lenders must decline new loans even if a fraudster has your data. Lifting it requires a deliberate step from you.
Is it safe to sign in over public Wi-Fi?
Not without encryption — traffic on an open network can be observed. If you must, use a VPN or mobile data instead of the public hotspot, and keep sensitive actions to a trusted home network.
How do I know a call isn't really from the agency?
The tells are a request for a code or password, pressure and urgency, moving the chat to a messenger, and links to "official" sites. A genuine service does none of these. When in doubt, end the call and go to the portal yourself.
