Computer Crime Investigative Unit of the U.S. Army Criminal Investigation Command has issued a Cyber Crime Alert Notice (2CAN) to inform Department of the Army personnel of third party mobile applications that reference the Department Finance and Accounting Services (DFAS) myPay system for federal employees and members of the uniformed services, but are not sponsored by the Department of Defense or U.S. Government.
DFAS processes pay for all DoD military and civilian personnel, retirees and annuitants, and also supports other government agencies. Using non-sanctioned applications to access myPay accounts can potentially lead to the compromise of myPay account information and theft of funds.
The “myPay DFAS LES” was initially released in July as a free application on Google Play Android App Store. The app provides the user with the ability to control their military pay after the user enters their myPay login information to access their individual account. Google Play estimates that between 10,000 and 50,000 members have installed the myPay app.