Benefit payment redirection: the cheapest attack on a state program
Every control proposed for public benefits runs into the same constraint, and most proposals ignore it: the people you are protecting are the people your control will exclude if you get it wrong. That constraint has to come first, not in a paragraph at the end.
How do you protect benefit payments without excluding recipients?
By putting the friction on the change, not on the person. Benefit redirection works by editing a deposit destination in a portal. A control that demands smartphones or documents at every interaction excludes exactly the population the programme exists to serve; a control that gates the destination change does not.
- GAO reported in August 2026 on significant fraud risks across the twenty largest state-administered federal programs.
- Benefit systems were designed for accessibility and low friction, correctly. Payment destination was modelled as a profile attribute, which was the error.
- The coverage model comes first: what share of the caseload can satisfy each option? A control that excludes eligible people has failed, whatever its fraud numbers.
Part of Public sector identity
Start with who is affected
A state benefits caseload is not a general population sample. It skews toward people with unstable housing, limited or shared device access, intermittent connectivity, disabilities, limited English proficiency, and no banking relationship.
Every one of those characteristics is a reason someone qualifies for the benefit. They are not edge cases; they are the distribution.
So the first artefact of any control design here is not a threat model. It is a coverage model.
The coverage model
| Authorisation option | Caseload reach | Excluded without an alternative |
|---|---|---|
| Device-bound credential on a personal smartphone | [measure] | No smartphone; shared device; no data plan |
| Credential on a shared or borrowed device | [measure] | Household coercion risk |
| In-person at a county office | [measure] | Transport, hours, disability, work schedule |
| Telephone with knowledge verification | [measure] | Hearing impairment; language; the knowledge is also known to the fraudster |
| Mailed confirmation with delay | [measure] | Unstable address; the address may be what changed |
No single row reaches everyone. That is the finding, and it means the design is necessarily a combination with a funded assisted path rather than a single mechanism.
Setting the exclusion budget
Decide, explicitly and in advance, what share of the caseload a control may delay or exclude before it should not ship.
Then do the arithmetic honestly. A control reaching ninety-six percent of a two million person caseload leaves eighty thousand people needing an assisted path. If the assisted path is a county office with a six-week appointment backlog, the control has excluded eighty thousand entitled people and the fraud reduction does not offset that.
An unstated exclusion rate is still an exclusion rate. Publishing it is what makes the decision reviewable.
What the federal record says about the risk
GAO reported in August 2026 on significant fraud risks in the twenty largest state-administered federal programs, following earlier 2026 work on improper payments and fraud risk management. Large-scale benefits fraud in recent years has established that these programmes are targeted systematically rather than opportunistically.
None of that reporting quantifies payment-destination diversion separately, and this article does not estimate it. What is clear is that the payment destination is the cheapest field to attack and the least protected.
A design that respects the constraint
- Tier by value. A monthly benefit of a few hundred dollars and a lump-sum disbursement of several thousand do not warrant the same friction.
- Enrol opportunistically. Offer credential enrolment at every existing touchpoint — application, recertification, office visit — rather than as a campaign.
- Never gate access to the benefit. The control applies to changing the destination, never to receiving the payment.
- Dual notification with delay. Notify the old and the new destination and the address of record, and hold the change. This costs nothing and reaches everyone.
- Fund the assisted path properly. If the fallback is understaffed, the control has excluded people by operational design.
Item four deserves emphasis because it is the cheapest intervention in this entire series and the most universally applicable. It requires no enrolment, no credential and no technology procurement.
The state's own incentive
States frequently replace diverted benefits, because the alternative is a family without food assistance for a month and a caseworker escalation. That means the loss is already being absorbed by the state in practice.
Framed that way, prevention is a budget question rather than a program integrity question, and it tends to get further with a legislature.
Designing for the actual population
| Control | Security value | Accessibility cost |
|---|---|---|
| Document upload at every login | Low | Very high |
| Smartphone app requirement | Moderate | High — excludes by device |
| Knowledge questions | Low — answers are in breach data | Moderate — excludes the unbanked and recently moved |
| Gate the destination change only | High | Low — a rare event |
| In-person for total credential loss | High | Low if rare, high if default |
Objections and honest limits
“Any added step reduces access.” Which is why it belongs on a change most claimants make rarely or never, rather than on the claim itself. Frequency is the variable that decides accessibility cost.
“Some claimants have no device at all.” Then the in-person path is theirs, and it must be genuinely staffed. A fallback that exists on paper but not in practice is exclusion with extra steps.
A control that does not exclude
- Gate the change, never the claim. Claims are frequent; destination changes are rare.
- Offer more than one credential type. A phone, a hardware key, or an in-person path.
- Staff the in-person path properly. An unstaffed fallback is exclusion.
- Notify on the old channel. So a redirect is visible to the real claimant.
Terms used here
- Benefit redirection
- Changing the deposit destination on a legitimate claim so payments go to an attacker.
- Digital exclusion
- Loss of access caused by a control's device, connectivity or documentation requirements.
- Frequency-weighted friction
- Placing authentication cost on rare, high-consequence events rather than on routine ones.
Frequently asked questions
Why lead with exclusion rather than fraud? Because in this population exclusion causes immediate hardship and fraud causes delayed loss, and controls designed without a coverage model routinely produce more of the first than they prevent of the second.
What is the single cheapest improvement? Dual notification with a hold period on destination changes. No enrolment, no technology, reaches the entire caseload.
Should the exclusion budget be published? Internally at minimum, and to oversight bodies where a program is under review. An unpublished budget is still a budget.
Does a credential requirement risk denying benefits? Only if it gates receipt rather than destination changes. It must never gate receipt, and any design that does should be rejected.
Does adding a control reduce access? It depends entirely on frequency. On the claim itself, yes. On a destination change most claimants make rarely, the cost is minimal.
What about claimants with no device? An in-person path, genuinely staffed. A fallback that exists only on paper is exclusion with extra steps.
Why not knowledge questions? The answers are in breach compilations, and they exclude the recently moved and the thinly documented — poor on both axes.
Where this fits in Manav
Manav binds the authorising official to the exact release, award or disbursement being authorised, and produces a receipt an inspector general, an auditor or another agency can verify without access to the issuing system.
Sources and further reading
- U.S. Government Accountability Office reports
- GAO-26-109100, July 2026 — managing fraud risks in federally funded programs
- U.S. Department of Labor — unemployment insurance program integrity
- Published accessibility and digital inclusion guidance for public benefit systems.
- PaymentAccuracy.gov — federal improper payment data
- GAO-15-593SP — A Framework for Managing Fraud Risks in Federal Programs