Skip to main content

Scam Alert: Phishing Emails Impersonating GSA Contracting Officials

Over the past several weeks, a number of clients received an email with the subject line “Final Reminder:  <Contract Number> – NARA Records Digitization Non-Compliance” and have asked us the question: “We received this email from GSA — what do we need to do?” In every one of those cases, the answer was the same: nothing, because, despite appearing to come from the CS/CO, the email did not originate from GSA.

The GSA Office of Inspector General has issued a Scam Alert about an ongoing scheme in which fraudsters impersonate GSA contracting officials and email GSA contractors — including Multiple Award Schedule (MAS) contract holders and entities registered in SAM.gov. GSA’s MAS Program Management Office has echoed the warning to the contractor community.

What the fraudulent emails look like

These messages are convincing. Scammers use the real names, titles, and signature blocks of actual GSA employees, apply GSA branding, and send from look-alike domains designed to resemble official GSA addresses — for example, a domain such as “e-gsa.us” in place of gsa.gov. Because the signature block belongs to a real official, the sender domain is easy to miss.

Two versions have been reported to date:

  • Vendor credentialing fees. A form or notice claiming an annual fee is required to maintain your vendor status, paired with a request for credit card or other payment information.
  • Records digitization non-compliance. A notice alleging that your contract file is out of compliance with federal records digitization requirements, directing you to take action or to open an attachment.

Both are fraudulent. GSA does not charge vendors a credentialing fee to obtain or maintain a Schedule contract.

How to protect your organization

  • Verify the sender’s actual email domain, not the display name. Legitimate GSA email addresses end in @gsa.gov.
  • Do not rely on display names, signature blocks, or GSA logos and branding — all of these are easily copied.
  • Independently verify any unexpected request using contact information you already have on file for your Contracting Officer or Industrial Operations Analyst. Do not use phone numbers or links contained in the suspicious email itself.
  • Never provide payment, banking, or sensitive company information, and do not open unsolicited attachments without verifying first.
  • Be especially skeptical when urgency and money appear together. A deadline, a compliance threat, and a payment request in the same email is the pattern to watch for.

GSA has blocked the malicious domains reported so far and is monitoring the situation, but new look-alike domains can appear at any time.

If you receive a suspicious email

  1. Do not reply, click links, or open attachments.
  2. Retain the email, including the full headers if your IT team is able to capture them.
  3. Notify your GSA Contracting Officer or another verified GSA point of contact.
  4. Report it to the GSA OIG Hotline (gsaig.gov/hotline) and to the FBI Internet Crime Complaint Center (ic3.gov).
  5. If someone in your organization already replied or submitted payment information, notify your bank and your IT or security lead immediately.

Not sure whether an email is legitimate?

Forward it to BH Sky before you act on it. We work in GSA’s systems every day, and we can usually tell you within minutes whether a request is real.

Need Help?

Contact a BH Sky GSA Contract Schedule Expert today for assistance.