If you received a new Medicare card this year for no reason you could pin down, this is probably why: in 2025, the Centers for Medicare & Medicaid Services (CMS) discovered that bad actors had used stolen personal information to create unauthorized Medicare.gov accounts for roughly 103,000 beneficiaries across the United States, and mailed new Medicare Numbers and cards to everyone affected. The fix that would have prevented it in the first place, and that still matters now, is locking down your own Medicare.gov account with multi-factor authentication (MFA) before anyone else gets there first.
According to a CMS press release, the Centers for Medicare & Medicaid Services (CMS) began hearing from beneficiaries in May 2025 who had received letters confirming Medicare.gov accounts had been created in their name, accounts they never set up themselves. The investigation that followed found that bad actors had used valid beneficiary information, including Medicare Beneficiary Identifiers (MBIs), coverage start dates, names, birth dates, and ZIP codes, obtained from an unknown external source, to fraudulently create these accounts between 2023 and 2025.
Once inside, whoever created those accounts could potentially see mailing addresses, diagnosis codes, provider information, dates of service, and plan premium details. CMS said it hadn’t confirmed any misuse of that information, but it deactivated every fraudulently created account, disabled new account creation from foreign IP addresses, and issued new Medicare Numbers and cards to everyone affected.
The tactic here didn’t rely on hacking Medicare’s systems. It relied on personal information that was already out there, and on nobody having claimed the Medicare.gov account first. If you’ve never created your own Medicare.gov account, that’s not a neutral, wait-and-see situation. It’s an open seat someone else can fill using information about you that may already be circulating from an unrelated data breach.
Creating and securing your own account is the single step that closes that door.
Given a story like this, it’s a fair question to ask: is Medicare.gov safe to use in the first place? The 2025 incident wasn’t caused by a flaw in Medicare.gov itself being hacked. It happened because bad actors had enough personal information to create an account before the real beneficiary did. Medicare.gov, run directly by CMS, remains the legitimate, official place to manage your Medicare information; the safety issue is about who claims the account first and how well it’s locked down afterward, not whether the site itself is trustworthy.
According to the Centers for Medicare & Medicaid Services (CMS), Medicare.gov account creation and sign-in now go through one of three approved identity-verification services: Login.gov, ID.me, or CLEAR. All three are free, and all three meet the federal government’s IAL2 identity-verification standard, requiring Medicare.gov multi-factor authentication as part of setup, not as an optional add-on.
Agent tip:
“Set up a second, backup Multi-Factor Authentication (MFA) method during this process if you’re given the option, not just your phone number. If you ever lose access to your primary method, a backup code or authenticator app can save you a much longer account-recovery process later.”
Setting up your account isn’t just about locking the door. It’s also your chance to check what’s already behind it.
If anything looks unfamiliar, follow up directly with 1-800-MEDICARE, not a number or link from an email or text.
If you received a new Medicare card and Medicare Number without requesting one, you were likely one of the beneficiaries affected by the 2025 incident. Start using the new card and number right away, and stop using the old one. You don’t need to do anything else to “activate” it, and Medicare will never call, text, or email asking you to verify or pay for a new card. If you get a message like that, it’s a scam, not a real card replacement process.
Locking your Medicare.gov account isn’t a one-time reaction to a single incident. It’s a basic habit that closes off one of the easiest ways someone else could quietly access your Medicare information: an account that was never claimed in the first place. Set up multi-factor authentication now, review your claims while you’re in there, and you’ve closed the exact gap the 2025 incident exposed.
Have questions about your Medicare account or a card you received unexpectedly? Call (623) 223-8884 to speak with a local, licensed agent at no cost.
If you didn’t request it, you were likely one of the roughly 103,000 beneficiaries the Centers for Medicare & Medicaid Services (CMS) identified as affected by a 2025 incident involving fraudulently created Medicare.gov accounts. CMS mailed new Medicare Numbers and cards to everyone affected.
Yes. Medicare.gov is the official site run by the Centers for Medicare & Medicaid Services (CMS), and it remains the legitimate way to manage your Medicare information. The 2025 incident happened because bad actors had enough personal information to create an account before the real beneficiary claimed it, not because of a flaw in the site itself. Setting up your own account with multi-factor authentication is what closes that gap.
No. If your account was affected, CMS already deactivated it and issued you a new Medicare Number. Creating a new, secure account now with multi-factor authentication protects that new number going forward.
All three are free and meet the same federal security standard. The right choice usually comes down to which one you may already use for another government service, since you can often reuse that verified identity instead of starting over.
No. Medicare doesn’t call, text, or email asking you to verify your account or personal information. Treat any unsolicited request like that as a scam and verify independently through Medicare.gov or 1-800-MEDICARE.
Read more by Renee van Staveren
Since 2009, I've been writing about complicated, technical issues, with the goal of making topics like Medicare and healthcare easier to understand. I've been writing about Medicare since 2021 and healthcare since 2019. I am an AmeriCorps alumni. I enjoy gardening, reading, and DIYing.