A new report from the U.S. Government Accountability Office (GAO) has identified systemic failures in how the U.S. Department of Defense (DoD) manages fraud risks within its major information technology business programs. The report, published on September 28, 2026, reveals that these shortcomings have contributed to billions of dollars in financial losses and have significantly increased the cybersecurity risk to critical defense systems. The GAO found that many multi-billion dollar IT programs have not undergone required fraud risk assessments and that program staff lack the necessary training to identify fraud, leading to vulnerabilities and contractor non-compliance. The findings underscore the need for the DoD to urgently implement a comprehensive anti-fraud strategy to protect both taxpayer money and national security information.
The report, titled "IT Systems Annual Assessment: DOD Should Improve IT Fraud Risk Management Practices" (GAO-26-108596), is part of the GAO's ongoing oversight of federal government operations. It assesses the DoD's adherence to the 'Framework for Managing Fraud Risks in Federal Programs,' a set of leading practices for establishing an effective anti-fraud program. The GAO's review focused on 18 major DoD IT business programs, for which the department planned to spend $10.3 billion between fiscal years 2024 and 2026. The core issue identified is a lack of institutionalized processes for assessing and mitigating fraud risks throughout the IT system lifecycle.
The primary organization affected is the U.S. Department of Defense, including its various agencies and branches that manage and procure major IT systems. The report's findings have implications for the entire defense industrial base, particularly contractors involved in software development and IT services for the DoD.
The GAO's findings indicate a failure to comply with established federal fraud risk management principles. Key compliance gaps include:
The impact of these failures is twofold:
Financial Loss: The GAO reports that the DoD confirmed nearly $11 billion in fraud losses between fiscal years 2017 and 2024. The poor risk management in IT programs directly contributes to this, for example, through contracts being awarded to ineligible companies, as seen in a case where two firms misrepresented their status to win over $200 million in contracts.
Cybersecurity Risk: More critically, the lack of oversight exposes sensitive DoD systems to cyber threats. The report cites an example where a developer's failure to use approved hosting and implement system protections put DoD information at risk. This creates vulnerabilities that could be exploited by adversaries for espionage or sabotage, directly threatening national security.
Due to these persistent issues, the GAO added DoD's fraud risk management to its High-Risk List in 2025, a designation for programs highly vulnerable to waste, fraud, abuse, and mismanagement.
While the GAO report itself does not carry direct penalties, it serves as a powerful tool for congressional oversight. It can lead to congressional hearings, budget restrictions, and mandated changes in DoD policy and practice. The report's findings can also trigger investigations by the DoD Inspector General, which could lead to civil and criminal penalties for fraudulent contractors and potential disciplinary action for government employees.
The GAO report implicitly and explicitly provides a roadmap for the DoD to improve its posture:
Providing specialized training to DoD staff to recognize and report IT-related fraud.
Enforcing contractual cybersecurity requirements and verifying contractor compliance.
Mapped D3FEND Techniques:
GAO adds fraud risk management at the DoD to its High-Risk List.
GAO publishes report GAO-26-108596 detailing failures in DoD IT fraud risk management.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.