Institutional Overreach

SSA Phone Update Triggers Direct Express Alert for Non-Card ACH Beneficiary

Discover the alarming case of unauthorized data exposure after a phone update on SSA.gov. What are the implications for privacy and accountability?

On July 8, 2026, a user updated their phone number on SSA.gov, yet received an unsolicited text on July 13 regarding a Direct Express account, which they never opened. This indicates unauthorized data exposure, contradicting SSA policy. The user demands an explanation and verification of data handling practices.

  • The evidence shows a verified Direct Express alert reached you via official channels after a SSA phone update, despite no enrollment or card relationship with Comerica, directly contradicting EM-26005 REV’s stated non-propagation rule.
  • This creates a concrete discrepancy between SSA policy language and observed system behavior during the bank transition, supporting the claim of unintended data exposure to the financial agent.
  • The documentation establishes a clear timeline and primary sources without interpretive overlay, highlighting a potential operational gap in how contact data is isolated between SSA ACH records and legacy Direct Express infrastructure.

On Wednesday, July 8, 2026, I updated my primary phone number in my official my Social Security account on SSA.gov. My SSDI benefits have always been paid via standard ACH direct deposit to my personal checking account. I have never enrolled in, applied for, or possessed a Direct Express prepaid debit card.

Five days later, on Monday, July 13 at 9:10 AM, I received an unsolicited automated text from short code 70846 — the official Direct Express Automatic Alerts gateway:

Direct Express
Address Change Alert

Address change on Acct
Not you? Call 1.888.741.1115
Reply STOP to Opt Out
HELP for Help

This should not have been possible.

Primary Source Evidence

1. Official SSA Confirmation Email — July 8, 2026

2. Direct Express Text Alert — July 13, 2026, 9:10 AM

Screenshot of a text message from 70846 notifying the recipient of an address change alert for Direct Express. Contains a contact number and instructions to opt out or seek help.

What EM-26005 REV Actually Says

The relevant internal directive is EM-26005 REV – Direct Express Program Transition (effective May 19, 2026). It covers the handoff of the Direct Express program from Comerica Bank to Fifth Third Bank.

The public-facing policy language is careful and limited. In Section D (Reminders), point 3 states explicitly:

“Remind customers to keep their contact information up to date with both the financial agent and SSA to avoid authentication issues. SSA systems do not automatically update the financial agent with address or phone number changes.

Source: EM-26005 REV on SSA PolicyNet

According to the agency’s own emergency message, a phone number change entered on SSA.gov is not supposed to propagate to Comerica / Direct Express.

Yet it did.

Documented Timeline

  • July 8 (Day 0) — Phone number updated in secure mySSA portal. Official confirmation email received from no-reply@ssa.gov. ACH direct deposit routing left completely untouched. No Direct Express card has ever existed on this account.
  • July 13 (Day 5) — Automated “Address Change Alert” text arrives from short code 70846 (official Direct Express Automatic Alerts). The message claims an address change on an account the recipient has never held.

Why This Matters

Short code 70846 is the verified official gateway used by Direct Express for automatic alerts. The customer service number in the text (1-888-741-1115) is the legitimate Direct Express line. This was not a phishing message.

The only logical explanation is that the SSA profile change was ingested by the legacy Direct Express / Comerica infrastructure despite:

  1. No Direct Express enrollment ever existing,
  2. Explicit policy language in EM-26005 REV stating SSA does not automatically update the financial agent with phone or address changes, and
  3. Benefits continuing to route solely via personal ACH checking.

This constitutes unauthorized third-party data exposure. A private banking contractor received and acted on personal contact data belonging to a non-customer without consent or operational need.

The Privacy Act of 1974 (5 U.S.C. § 552a) restricts federal agencies from disclosing personal identifiers to outside entities beyond defined routine uses. Broadcasting a phone update to a card program’s alert system when no card relationship exists exceeds those limits.

Demand for Accountability

I demand the following:

  1. Full technical explanation of how a non-enrolled ACH recipient’s phone update reached Comerica / Direct Express servers.
  2. Immediate verification that no shadow or placeholder profile was created under my SSN or contact data.
  3. Documented purge of any unauthorized records from Comerica and Fifth Third systems.
  4. Public clarification of the discrepancy between EM-26005 REV’s stated “do not automatically update” rule and the observed automated alert.

This is not a theoretical privacy debate. It is a concrete, timestamped event with primary-source screenshots and the agency’s own written policy as evidence.

Screenshots and confirmation email retained as primary evidence. All claims are limited to the documented facts of this single incident.



Discover more from Celestia Quixs™

Subscribe to get the latest posts sent to your email.