IRS says thieves stole tax info from 100,000
washingtonpost.com
washingtonpost.com
Lo and behold, there was a data breach of employee and volunteer records. Volunteers had to have background checks, which required the SSN. Thousands of people had their IRS return hijacked due to this breach. I personally know dozens of people who were impacted.
From what I've seen of their information security, I remain completely unsurprised that they had this breach and that to this date they have no idea how it happened.
It just that most people believe that not making their SSN public is enough for it to be safe.
2) Just being alerted when someone else opens up credit in your name is hardly "protection." They still opened up credit in your name and you have to deal with that which is at the very very least inconvenient.
3) Posting you SSN online makes products more expensive for everyone because companies at the very least have to devote extra man hours every time someone else tries to take out credit in your name. Even if nothing happens to you they may have already issued a loan to the person and now has to write that off.
4) This is about fraudulent tax returns which credit monitoring companies wouldn't have info on.
I've had my identity stolen and I can tell you,it is truly awful.
You and half of America. You know how many people are in Anthem's system?
As part of clearing this up with the IRS, I had to verify my own identity and validate that the return that we (physically) sent was the true and correct return. After a whopping 2+ hours on hold, I ran a grueling gauntlet of rather obscure questions that amount to some flimsy shared secrets I happen to have with the IRS. Once my identity was confirmed, I learned that the thieves had filed a 2014 AGI that exactly matched my 2013 AGI. The IRS representative told me that this was unusual (that is, that they normally they just make numbers up), and it's clearly stupid (my return was flagged and didn't pay out), but it obviously left me concerned that someone had somehow located my 2013 return. With this latest revelation, it's now clear that this could have easily happened via the IRS itself.
Assuming that my experience is indicative of a larger trend, I expect many more similar revelations as the IRS picks up the debris from the 2014 tax season -- and it wouldn't surprise me at all if the true target of the Anthem breach wasn't in fact the IRS: this crime is just too damn easy to pull off and get away with. The bright side of all this: things very clearly have to change, and I wouldn't be at all surprised if the IRS ends up issuing PINs to all e-filers this coming year.
Also - I'm confused - I have an e-file PIN. You don't?
So having an e-file PIN, or even using an e-file PIN to e-file, does not imply that your tax return can't be e-filed by someone else who only has your previous year's AGI.
1) Prior year AGI
2) Electronic filing PIN
They can also issue a taxpayer a special Identity Protection PIN. If you're issued one of these you MUST use it.
There are two groups of people that don't need to "authenticate" at all:
1) Anyone who didn't file the previous tax year
2) Anyone filing by mail
Will there be punitive lawsuits against the IRS as there were for Target and likely will be for Anthem?
The real headline is that the IRS is hackable.
They spun it even better than that. The headline is "thieves stole tax info from 100,000 people" (i.e. not from the IRS, but from the people themselves)
That's not borne out in the slightest by what we know from the article. These people might've been phishing victims - you wouldn't claim a bank is hackable because people entered their bank password on a phishing site.
He has some good advice; claim your account before someone else does.
I am having a really tough time believing she never suspected she was doing something illegal.
Why? People fall for the "I have $20 million for you, I just need a few hundred bucks to do the paperwork" scam all the time.
Our luck ... our data was stolen in the Anthem fiasco and used to submit fraudulent returns. No problem. The IRS contacted us to let us know and asked us to use the verification system to prove we were ourselves.
I cannot wait for the auto notification we were part of this data issue. lol
What I cannot understand about the issue is no one noticed a 50% failure rate in the process.
Make no mistake: IRS needs to be held responsible for this. It is their fault.
I'd suspect the information needed to access the tax returns was obtained via phishing or a data breach elsewhere like a tax preparation service.
The budget cuts will continue until security improves!
The fault should be with the person/people that stole the tax information, not the IRS.
Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.
People need to be held accountable for the security of their systems when they are storing personally identifiable information on customers or the public at large.
Edit: Perhaps they shouldn't be blamed when someone leverages a zero-day to break in, but if this is due to their failure to patch their systems, IMO their 100% liable for everything that follows.
If I pay my bank for a safe deposit box, good security is part of what I am paying for. If it can be shown that they were lax/careless/negligent in the event of a theft, then I certainly would lay blame with both the bank and the thief for loss of my assets.
This is even more the case for a government with vast resources.
Take for example some large corporations. I.e. if Amazon or Google stores their customer information carelessly, and someone steals it - then Amazon would be victim, and if you say that they should have protected the information, you are blaming the victim because you don't like them?
The American revenue service has even larger resources and also a larger responsibility than even the largest of multinational corporations. They should be held accountable for what they do (like the tax officials in any country).
If we only blamed Amazon in your example, then yes, we would only be blaming the victim.
How do we know they were "careless"?? They could have been using all of the correct security precautions and still got the data stolen.
It could have been an employee that installed malware because they fell for a phishing attack. Should they also be brought up on charges?
If my HN account gets compromised, should PG get brought up on charges? After all, he was supposed to protect my data, right?
Why aren't we even discussing the hackers that stole the data? Is it because they are supported here on HN?
In my opinion, this sets the required standard to a completely different class. The tax services have an important responsibility to process their information in a secure way. The information needs to be protected against leaks.
And from the outcome we can see that the protections are not adequate.
There is no way to protect leaks 100%. So you have unrealistic expectations.
The problem seems to be trying to carve out exemptions for little things here and there.
Just use a decent tax rate, get rid of all that crap, calculate what I owe and send me a bill or send me a check if I over-withheld or something.
Ugh it's so hard building a proper civilization.
We wanted to; the tax-preparation lobby killed it.
Because Intuit, H&R Block, and others like them who have built substantial businesses doing all that empty-work for you have made damn sure that Congress doesn't legislate their meal ticket away.
Do we know if the system was compromised, or if the thieves just had access to the personal information of those taxpayers?
You'd think we'd have a better system by now than a short-ish unique number which never changes during your lifetime as the key for much of your financial / credit-related authorization.
http://securekey.com/press-releases/securekey-technologies-w...
SecureKey IIRC is used by Canada. USPS is in a unique position in that they have a ton of employees literally who can verify mailing addresses by brute force. Every day (except holidays). Rain, Snow or shine.
Having USPS in charge of the US's future "online identity" would be a good way of transforming the ailing agency and giving them a very useful purpose that only USPS can do. There's a lot of win/win potential here.
It's too bad their hands are so tied by Congress (and a malicious one at that - having to pay pension fund 75 years early)... they might have made this move a decade or so earlier.
Especially since they get passed all around like that's not the case by employers, insurers, creditors, etc, etc.
The problem is it wasn't a designed system, it just came about by itself slowly over time. Social security numbers were never designed to be used in any way outside of social security.
https://faq.ssa.gov/link/portal/34011/34019/Article/3789/Can...
"We can assign a different number only if:
* Sequential numbers assigned to members of the same family are causing problems;
* More than one person is assigned or using the same number;
* A victim of identity theft continues to be disadvantaged by using the original number;
* There is a situation of harassment, abuse or life endangerment; or
* An individual has religious or cultural objections to certain numbers or digits in the original number. (We require written documentation in support of the objection from a religious group with which the number holder has an established relationship.)"
In the more mundane act of fraudulently bypassing the IRS's trivial security to steal a tax return… thieves got me, probably as a result of Anthem's inadequate security. The thieves didn't even have the courtesy to pay what I owed! I say you file my tax return, you take your chances.
The maddening part, aside from the scramble when the April 14th filing from the tax people failed, is that no one in law enforcement is the slightest bit interested in enforcing the law.
Per the article, the attackers had to put "the taxpayer’s Social Security number, date of birth, address and tax filing status" into a form to get access.
Not to mention save all of us from the headache of things like this.
You have to understand individuality and apply it broadly. If you don't, then it's cognitively easier to lump people into groups that you don't have to care about, and can even grow to hate.
I liked Adam Gopnik's summation last week:
“What we have, uniquely in America, is a political class, and an entire political party, devoted to the idea that any money spent on public goods is money misplaced, not because the state goods might not be good but because they would distract us from the larger principle that no ultimate good can be found in the state. Ride a fast train to Washington today and you’ll start thinking about national health insurance tomorrow.”
http://www.newyorker.com/news/daily-comment/the-plot-against...
Feel like expanding that point? I mean shrinking government and changing society so people depend on it less is literally part of the national GOP platform. Is your argument just that they're not willing to sabotage things for political advantage? (and, if so, how are we to explain the billions spent shutting down the federal government as a negotiating tactic?)
So you really think whatever they tell you is true? The GOP has not actually shrunk the government. Even when they had full control over the senate, house, and the presidency, they did not shrink the government... in fact, they made it bigger.
1. Most young scientists are leaving research due to budget cuts at NIH, NSF, NASA, etc. They're unlikely to ever come back so we've lost a large chunk of an entire generation of research in most fields. Sure, many of them are going to industry but I would submit that a crop of data scientists selling ads is less productive for the country long-term than all of the foundational pure research which industry rarely funds.
A short-term sabotage is not out of the question.
Actually, I have a graph showing how gov actually increases more under GOP control than democrats. Hold on.
That might necessitate a token effort somewhere to cut things but the real goal is the posture, not the results, so maximizing inefficiency isn't something they're concerned with. In most cases, they'll try to cut things which affect people who don't vote for them anyway – mass transit, funding for the poor, etc.
Alert: The online Get Transcript service is currently unavailable. Transcripts may still be ordered using the Get Transcript by Mail service. We apologize for any inconvenience.
The number quoted in the article is 104,000.
Obvious questions:
1. Is 104,000 the exact count, or has it been rounded?
2. Did the hackers stop when their success count got there?
3. Does nobody else think it is funny that 1040 is a factor of 104,000? :)
[edited a lot]
(I can't comment on the rest of that rant though)