TurboTax halts all state e-filing amid data breach probe
blogs.wsj.com
blogs.wsj.com
Federal tax return fraud is huge. It's a growing problem that the IRS is struggling to cope with and it's been going on for years. State tax return fraud has been largely non-existent... so non-existent in fact that USA Today reported the state of Minnesota got suspicious when there were 2 reported cases of fraud[0].
So what's going on and why is TurboTax being called out by these states? First off, know that when a tax return is e-filed either to the fed (who also handles most state e-filing) or directly to the state, every software provider transmits an identifier along with it. So if you get a bunch of bogus tax returns submitted it's trivial to see where they're all originating from. Second, the rise in federal tax return fraud has grown steadily in relation to the number of software providers offering a free option... the reason we haven't seen state fraud as rampant is because it has always cost money to prepare your state return with software. But what's new this year besides a dramatic increase in state tax return fraud? TurboTax's Absolute Zero campaign. That's right, a whole lot more people can file their states taxes for free using TurboTax's software. That may seem great at first blush if you qualify, but an unintended consequence of that is it's now a completely free roll for a fraudster to file a state tax return IN ADDITION to a federal one.
[0] http://www.usatoday.com/story/money/personalfinance/2015/02/...
Can't it be that there's just more at stake with the Federal return in terms of total dollars, and far more tax deductions available?
I doubt it. Most states are poor at fraud detection, they are likely losing a lot but just don't know it.
Its more profitable to do fraud where the money is.
Intuit said its TurboTax unit took action Thursday after seeing attempts to use stolen personal information to file fraudulent returns for tax refunds.
The tax-software company said that after a preliminary examination with Palantir Technologies, which provides security and antifraud services, it believes there wasn’t a breach of Intuit systems and that “the information used to file fraudulent returns was obtained from other sources outside the tax preparation process.”
We just have to assume that anything anyone knows about you that is stored in a computer somewhere will at some point become public. Possession of any amount of personal information should no longer be adequate to prove identity. We need something else. I don't know what that is, but it has to be something that is already public or doesn't rely on secure computer systems.
There was a data breach.
Did you read the article?
Edit: including the part you quoted, information used to file fraudulent returns was obtained from other sources outside the tax preparation process.
I've used TurboTax almost every year for the last decade, except one in which I used TaxACT because it was a lot cheaper (my taxes are moderately complex enough to send me into the more expensive TurboTax price brackets).
At the time the software felt shoddy compared to TurboTax in almost every way; it was certainly better than form-filling myself but it didn't inspire confidence.
I'm an independent consultant, use QuickBooks throughout each year, and have used TurboTax for quite a while out of inertia from having my data already in a friendly format in QB. I finally decided to give an actual CPA a try last year. Among other things, she has already saved me an order of magnitude more than her fee just by amending my old TurboTax returns. Not to mention the value of the time that she has saved me.
I would never go back to TurboTax (or TaxACT or similar) unless I was a straight W-2 salaried employee (and only maybe then).
http://sunlightfoundation.com/blog/2013/04/15/tax-preparers-...
Unfortunately, even TaxACT is a member of a lobbying group which fights against making filing taxes easier (ACTR).
I find it hard to believe there are tons of them out there unless perhaps tax software is regional software and there's companies in some states that don't move beyond the state?
Disclosure - I'm the CEO of Common Form[2]. My co-founders and I are all ex-Intuit employees. We currently only cover the 1040EZ, but we're expanding as fast as we can.
[0] http://apps.irs.gov/app/freeFile/jsp/index.jsp?ck
edit: formatting.
I just did TT and it cost me $37 for what TaxACT wants $12. Further if you want to pay from your refund, there is hefty $37 extra with TT. It looks like TaxACT doesn't have this fee...
Most likely the result of your return should be the same from both companies, as long as they understand tax law, and I would assume they do otherwise they would be gone long time ago.
Here I thought you had found a unique zipcode.
1) File fraudulent tax returns
2) Fill bogus prescriptions
Prescription fraud is generally laid on the insurers who will pass it on as premium increases. In California it might be tough to do that as the Insurance Commissioner might be smart enough to realize they got into this mess themselves, but at the end of the day you can't really have the crooks putting the insurance companies out of business as that just devolves into anarchy. So look for some more rules like no filling prescriptions out of state, or more than 10 miles from your home address without calling in from your registered cell phone and requesting a code and then texting back the code you get. Or some other TFA that makes the lives of honest folks more difficult, and the opportunities for frictionless secure systems more lucrative.
But then it happens again 2 or 3 months later anyways ...
A lot of these attacks are trojan already breached the network and insider attacker. The latter is often due to infection (e.g. USB, browsing problematic website). Encrypting file, encrypting SSN field is not a full solution but is definitely a really good solution.
Sure you can physically intercept mail - but there is a huge difference in magnitude. I wager you could not in any practical way intercept millions (or even thousands) of paper records without being traced.
That's why these poorly protected digital records are such a gold mine.
Oh, right, decrypt it real quick in the app, right? How will you protect that decryption key?
From the way it looks, the security precautions they are failing at are so trivial that most developers probably have more secure personal servers / computers.
http://www.bloomberg.com/news/articles/2015-02-05/signs-of-c...
1. Scammer filed a tax return under my name/SSN, probably with a large return to their bank account/address
2. Later in the year I filed my tax return, but it was rejected because it thinks you have already filed
3. I called the IRS, then had to sign and mail affidavit confirming I am me and a fraudulent person filed my return. Then I mailed in my tax return.
4. ~8 months later the IRS mailed me something that confirmed fraud occurred and I wasn't liable for anything.
5. I wasn't audited so presumably they sorted it out and accepted my valid return
6. Now the IRS mails me a PIN number that needs to be used for filing my tax return [1]
I'll also note that in all the support phone calls with the IRS, they were really incredibly helpful, pleasant, and I never had any long wait times or anything.
1: http://www.irs.gov/Individuals/The-Identity-Protection-PIN-I...
1. The E-file PIN (5 digit PIN). This is the one most people use when they e-file. You either use a special IRS website or phone number to get it by verifying basic identification information about yourself. The problem is I believe all of this information is based on your 2013 tax return, so if a criminal has that, they can get your 5-digit PIN. This PIN is also delivered electronically, so there is no verification that the address information you enter is actually your address.
So when you are worried about somebody having your 2013 tax return, you are really worried about them stealing your e-file 5-digit PIN number.
2. Then you have the 6-digit PIN, which is generally only given out in the case of proven identity theft (though it seems as part of a pilot program they are giving it out more often). This PIN is mailed to your current address on file with the IRS, and is a randomly generated 6-digit PIN number which changes every year. If you are signed up for this program, your tax return will only be accepted if it has the proper 6 digit PIN number.
So if you have this, in order for somebody to fraudulently file a tax return under your name they'd have to steal your mail, which obviously is a lot harder.
More details:
https://ttlc.intuit.com/questions/2579455
http://www.irs.gov/Individuals/Get-An-Identity-Protection-PI...
It's not technically a PIN as there are letters in the code. Basically, we have a similar system to your second type.
By any other measure in a transaction that money ceases to be yours and becomes theirs. We can argue the merits of income tax or taxation in general, but in our (and many similar) systems, it's not your money if you wish to live in the country and thus partake in this transaction.
http://blog.turbotax.intuit.com/2015/02/06/intuit-working-wi...
(Shouldn't this be the proper link for the HN post?)
That would explain: * why it seems to be only hitting Turbotax users * the availability of 2013 data (Turbotax users usually buy every year) * the availability of logins to these sites
While I wouldn't go so far as to say that this is the source of the data/problem, malware + desktop app + efile through Turbotax online fits the public information really well.
It used to be a scam that prisoners did by requesting 1040 forms and having some help on the outside to make bank accounts to direct deposit the money for refunds into it. They would get fake W2 forms and make them from fictitious companies and enter a large withholding tax on them. File the 1040EZ form with the standard deduction and file a state form too for extra money. Everything was done via postal mail before Turbo Tax and others provided e-filing.
A friend of our family had someone file taxes as her, and we think the SSN got stolen from the church we go to by ex-employees because they need it for donation tracking. She hadn't filed taxes in a while and Turbo Tax would not help and she was seeking an accountant to find out someone else already filed taxes as her.
I buy the desktop Turbo Tax edition and I try to file early before anyone else can file as me. I am disabled and don't make a lot, but there have been many data breaches that include SSNs over the past decade or so. When I had a student loan, someone stole a laptop with a harddrive on it that had SSNs and other info on it from the company that managed my student loan.
Actually if people are getting SSNs from outside of Turbo Tax they can e-file with the other tax filing software as well.
Step 1. Take someone's W2.
Step 2. File.
Why would they stop all state filing because of this?http://www.irs.gov/uac/Newsroom/IRS-Combats-Identity-Theft-a...
It's called SIRF (Stolen Identity Refund Fraud) and it likely costs billions a year at the federal level (I could not find data on states).
The difference seems to be that Turbo Tax was just the vector because it could be automated. Not a lot of payoff in doing it by hand.
Claim that SSN 123-45-6789 worked a job where they made $19K in income, had $4K in taxes withheld, and owed a total tax of $0, so please mail the $4K refund check to 12A Main Street, Fraudville, MA 02341.
The tax authorities are often compelled to process the refund in a certain time window that precludes cross-checking all the information and certainly precludes waiting to see if the actual taxpayer will file an actual (non-fraudulent) return.
Call IRS? (Assuming you haven't filed it yet) Check TurboTax? (Essentially filing yours and wait for it to be rejected?)
Maybe TurboTax should have a tool that checks against their system(based on SSN and some credit history questions, etc) to see if you(the fraudster in this case) has filed your taxes or not.
If this happens to you you're forced to file by mail.
[0] Doesn't matter who you use to do your taxes. Even an accountant that has access to e-file.
We know an enormous amount of PI was leaked from various major breaches last year, if that is what happening TurboTax is really just a tool being exploited for profit.
[1] http://time.com/money/3419136/identity-theft-social-security...
HR Block was caught lobbying against simplification of the tax system for this very reason.
I'm sure people would be very happy to not have to file tax returns.
Eliminate advance tax withholding and pay all taxes in arrears with allowance for a no-penalty payment plan for up to one year after the end of the tax year. You have significant one-time cost from shifting obligations forward, and a bit of an ongoing cost from the time value of money, but you eliminate the problem of fraudulent refunds by simply eliminating routine refunds.
As others pointed out, it does look like one of those two entities above were breached, as data filed in forms is very similar to data from 2013.
edit: I'm also pretty sure the IRS and e-tax filers already do this for (edit: electronically filed) Federal returns, there it makes sense because if you're e-filing already, you can deal with a website for a PIN.
if you file without a PIN, they request more identifying information from you later, via mail.
http://www.irs.gov/Individuals/Identity-Protection-PIN-Pilot...