Scammers are impersonating real GSA contracting officials to squeeze money and data out of Multiple Award Schedule (MAS) contractors. The tell is almost always the same: a look-alike domain instead of @gsa.gov, a fee or form nobody asked for, and a deadline designed to rush you. A real Contracting Officer never charges you to keep your contract active.
What did the GSA OIG scam alert actually say?
The GSA Office of Inspector General (OIG) warned that scammers are emailing MAS contractors and SAM.gov registrants while posing as named GSA officials. They copy a real official's name, title, and signature block, then send from a near-GSA domain such as e-gsa.us. Two versions have been reported so far.
- Fake "Vendor Credentialing Form": claims an annual credentialing fee is due to keep your vendor status active and attaches a credit card authorization form.
- Fake "Records Digitization Non-Compliance" notice: claims your contract file was flagged for failing federal records-digitization rules and points you to an attached notice for "resolution steps."
- The common thread: a spoofed near-GSA domain paired with a real official's identity. OIG says more variations may surface, and e-gsa.us is only one example.
You can read the full GSA OIG scam alert. The MAS Program Management Office relayed it to contractors on the MAS Interact community on August 6, 2026, and noted that GSA has blocked the reported malicious domains and is monitoring the situation.
Is this the first time scammers have posed as federal buyers?
No. GSA OIG has a separate, standing fraud alert on fake Requests for Quotations (RFQs) and fake purchase orders. That scheme targets product sellers: the scammer accepts your quote, issues a forged PO with a copied signature, and has you ship resellable goods on Net 30 terms to an address that belongs to no agency.
| Scheme | What the scammer wants | How it shows up |
|---|---|---|
| Fake credentialing fee | Payment card data | Email with a credit card authorization form attached |
| Fake compliance notice | A click, a download, or sensitive information | Email with an attached "notice" and resolution steps |
| Fake RFQ and purchase order | Your inventory, shipped on credit | Laptops, phones, toner, or medical equipment ordered in bulk, rush shipping, delivery to a storage unit or freight forwarder |
| Paid SAM.gov "registration" or "renewal" | A fee for something that is free | Official-looking email or site demanding payment to register, renew, or fix errors |
The OIG fake RFQ alert lists sample fake addresses built to look like agency mail, such as a gsa-org.com domain.
How do real GSA contract actions reach a MAS contractor?
Legitimate MAS contract actions move through GSA systems, not through email attachments with payment forms. Modifications you request go through eOffer/eMod. Mass modifications arrive through GSA's mass modification system. Agency buying opportunities come through eBuy, GSA Advantage, or SAM.gov. Email is a notification channel, never the place you pay or sign.
| Contract action | Where the real one lives | What a fake looks like |
|---|---|---|
| Your modification request | eOffer/eMod, signed electronically | An emailed form asking you to "confirm" changes and pay a processing fee |
| Mass modification (Refresh) | GSA mass modification system; you have 90 days to sign | An emailed PDF threatening cancellation within 48 hours |
| Agency RFQ under your Schedule | eBuy, tied to your contract and SINs | An unsolicited email RFQ for bulk electronics from a non-.gov address |
| SAM.gov registration or renewal | SAM.gov, signed in directly; always free | Any message asking for money to register, renew, or fix errors |
| Industrial Funding Fee | Reported and paid through GSA's sales reporting systems | An emailed "credentialing" or "status" fee with a card form |
GSA's own modification and mass modification guidance confirms both channels, and the MAS solicitation's modifications clause, GSAR 552.238-82 (Dec 2025 deviation), governs how Schedule changes are made. There is no clause anywhere in the MAS contract that creates an annual credentialing fee.
What red flags separate a real CO email from a fake one?
Check five things before you act: the actual sending domain, the Reply-To address, whether money or card data is requested, whether the request matches an action you already have pending, and whether the deadline is artificially short. If any one of them fails, stop and verify through a channel you already trust.
When I sat on the other side of the desk as a GSA Contracting Officer, my emails to contractors were boring by design. They referenced a contract number, a modification number, or a pending eMod action, and they came from a gsa.gov address. I never asked a vendor for a card number, and no Contracting Officer or Contracting Specialist I worked with at GSA, IRS, DoD, DOI, HHS, FTC, or Energy ever did either. The authority to change your contract sits with warranted officials under FAR 1.602-1, and FAR 43.102(a) is explicit that only contracting officers acting within their authority can execute contract modifications.
| Red flag | Real GSA CO | Likely scam |
|---|---|---|
| Sender domain | Ends in @gsa.gov | Near-miss domains such as e-gsa.us, gsa-org.com, or anything ending in .com, .net, .org, or .us |
| Reply-To header | Same gsa.gov address | Different address from the one displayed |
| Money | Never requests fees or card data by email | Credentialing fee, renewal fee, processing fee, gift cards, wire, or crypto |
| Context | Tied to your contract number and an action you can see in eMod or the mass mod system | Generic "your vendor status" or "your contract file" language with no mod number |
| Attachments | Documents you can also find in the system | Unsolicited forms or notices you can only get from the email |
| Deadline | Reasonable timelines, such as 90 days for a mass mod | Hours or days, with threats of suspension |
How do you verify that a contracting officer is real?
Verify the person against records you already hold, never against the suspicious email. Your award documents and your most recent executed modification name your assigned Contracting Officer and Contracting Specialist. Call or email that person using the contact information from those records and ask whether they sent the request.
- Pull your award package and your latest executed modification in eMod. Note the CO and Contracting Specialist named there.
- Confirm your contract number and status in GSA eLibrary. If the email cites a contract number that does not match, you are done.
- Hover over the sender name without clicking and read the full address. Then check the Reply-To header.
- Contact your CO through the gsa.gov address or phone number from your own records, not from the email signature.
- For SAM.gov claims, sign in to SAM.gov directly and check your registration yourself. The IAE team says SAM.gov will never ask for money and will never send a link that does not end in .gov.
As a Contracting Specialist, I noticed the contractors who handled odd requests best kept a one-page contact sheet with their CO and Contracting Specialist. The part most people miss: scammers can copy a real CO's name perfectly because contract data is public. The name proves nothing. The channel proves everything.
What should you do if you already clicked, paid, or shipped?
Move fast and document everything. Call your card issuer or bank to stop the charge, change any credentials you entered, and preserve the original email with full headers. Then report to the GSA OIG hotline and the FBI's Internet Crime Complaint Center, and tell your actual CO that their identity is being spoofed.
- Payment exposed: contact your card issuer or bank immediately and ask for a fraud block.
- Credentials exposed: reset passwords for any system you logged into, including your Login.gov account, and alert your IT or security lead.
- Goods shipped on a fake PO: contact the carrier to try to stop delivery, and compare the PO against any real order in your records.
- Evidence: keep the email, attachments, and headers. OIG specifically asks for them.
- Your real CO: notify them through a verified channel so they can warn other vendors.
If your team uses the self-audit checklist from our GSA fraud review post, add an inbound-email verification step to it.
Where do you report a GSA impersonation attempt?
Report suspected GSA impersonation to the GSA OIG hotline at gsaig.gov/hotline. Because these schemes chase payment and financial data, also file with the FBI's Internet Crime Complaint Center at ic3.gov. If the email impersonated a different agency, report to that agency's Inspector General as well.
| Where | When to use it |
|---|---|
| GSA OIG Hotline | Any email, call, RFQ, or PO impersonating GSA |
| FBI IC3 | Any attempt to obtain payment, banking, or login data, or goods on a fake PO |
| Other agency Inspectors General (listed at ignet.gov) | Impersonation of a non-GSA agency official |
| Your assigned GSA CO | Every time, through a verified contact, so they know their name is being used |
What should you do now?
- Build a one-page contact sheet with your contract number, CO, Contracting Specialist, and their gsa.gov addresses from your award documents.
- Set an internal rule: no one pays any fee to "GSA" or "SAM.gov" by email, card form, gift card, wire, or crypto. Ever.
- Match every contract action to a system: eMod for your mods, the mass modification system for Refreshes, eBuy for RFQs.
- Verify unsolicited RFQs for electronics or medical supplies with a phone call to an independently sourced number before you ship.
- Report every attempt to the GSA OIG hotline and IC3, and keep the headers.
I spent 18 years in federal acquisition, hold FAC-C Level III certification and a Harvard Master of Liberal Arts, and have supported 70+ GSA contract awards. If you want someone who knows what a real GSA contract action looks like watching your eMod queue, mass mods, and CO correspondence, our GSA contract maintenance program keeps your Schedule current and gives you a second set of eyes on anything that claims to come from GSA.
Frequently Asked Questions
Does GSA charge an annual credentialing fee to keep a MAS contract active?
No. GSA OIG flagged the "vendor credentialing fee" email as a scam. MAS contractors pay the Industrial Funding Fee on reported sales through GSA's reporting systems, not through emailed card authorization forms.
How can I tell if an email is really from a GSA contracting officer?
Check the actual sending address, not the display name. Legitimate GSA addresses end in @gsa.gov, and the Reply-To header should match. If the email asks for money, card data, or an urgent attachment review, verify with your CO using contact details from your own award documents.
What domain did the GSA impersonation scammers use?
GSA OIG cited e-gsa.us as one look-alike domain used in reported cases. OIG also warned that fraudsters may use other near-GSA domains, so check the full domain every time rather than watching for one example.
Does SAM.gov ever charge to register or renew?
No. Registration in SAM.gov is always free, and the government will never ask you to pay to register, update, or renew. Any email or site asking for money to register or fix errors is not a government source.
How do real GSA contract modifications arrive?
Modifications you request are submitted and signed through eOffer/eMod. Mass modifications come through GSA's mass modification system, and you have 90 days to sign them. Neither process involves paying a fee by email.
What are the warning signs of a fake government RFQ or purchase order?
The fake RFQ alert from GSA OIG describes non-government sender domains, bulk orders for resellable items like laptops and toner, rush shipping, Net 30 terms, and delivery to storage units or freight forwarders. Call the named buyer at an independently sourced number before shipping.
Where do I report a GSA impersonation scam?
Report it to the GSA OIG hotline at gsaig.gov/hotline and to the FBI's Internet Crime Complaint Center at ic3.gov. Keep the original email with headers, and notify your real GSA contracting officer through a verified channel.