GSA’s MAS PMO has warned contractors about an active phishing scheme involving scammers posing as GSA officials. The GSA Office of Inspector General has also issued a scam alert after fraudulent messages were sent to MAS contractors and SAM.gov-registered entities.
What the Scammers Are Doing
The emails may include the names, titles, and signature blocks of real GSA employees. However, they are sent from look-alike domains designed to resemble official government email addresses.
Reported examples include:
- Requests for payment of fraudulent “vendor credentialing fees”
- Notices alleging “records digitization non-compliance”
- Requests for banking, payment, company, or credential information
- Unsolicited attachments or links requiring immediate action
How Contractors Should Respond
- Check the sender’s complete email address, not just the displayed name. Legitimate GSA addresses end in @gsa.gov.
- Do not assume an email is authentic because it contains GSA branding or a familiar employee signature.
- Independently verify unexpected requests using contact information already known to your organization.
- Do not provide payment, banking, login, or sensitive business information until the request is confirmed.
- Preserve suspicious emails, including their headers, and contact your verified Contracting Officer or GSA point of contact.
Practical Takeaway
Contractors routinely receive time-sensitive communications involving modifications, compliance reviews, registrations, and contract records. That familiarity can make a professionally written phishing email especially convincing.
A simple internal rule can reduce the risk: any unexpected request involving payment, credentials, attachments, or urgent corrective action should be verified through a separate communication channel.
Suspected impersonation attempts should also be reported to the GSA OIG Hotline and the FBI Internet Crime Complaint Center.





