5 ms·
The title of the article is misleading. "Data breach" implies a release of sensitive data, which is not what appears to have happened. Intuit said its TurboTax
by valar_m 12y ago
The title of the article is misleading. "Data breach" implies a release of sensitive data, which is not what appears to have happened.
Intuit said its TurboTax unit took action Thursday after seeing attempts to use stolen personal information to file fraudulent returns for tax refunds.
The tax-software company said that after a preliminary examination with Palantir Technologies, which provides security and antifraud services, it believes there wasn’t a breach of Intuit systems and that “the information used to file fraudulent returns was obtained from other sources outside the tax preparation process.”
- sp332 12y ago“Fraudsters obtained information that’s generally only found on income-tax returns.” In some cases, the fraudulent 2014 returns closely resemble 2013 returns, with only minor alterations—implying that the scammer had access to the taxpayers’ 2013 returns. There was a data breach.
- valar_m 12y agoWhere?
- ChristianBundy 12y agoThe tax-software company said that after a preliminary examination with Palantir Technologies, which provides security and antifraud services, it believes there wasn’t a breach of Intuit systems and that "the information used to file fraudulent returns was obtained from other sources outside the tax preparation process." Did you read the article?
- sp332 12y agoThere is a single, solitary sentence in this article that implies there might not be a data breach: Perhaps someone got a name and guessed a password,” she said. The rest of the article is full of evidence that there was a data breach. Edit: including the part you quoted, information used to file fraudulent returns was obtained from other sources outside the tax preparation process.
- ams6110 12y agoSomeone getting a name and guessing a password would be a data breach. What else can you call it?
- ceejayoz 12y agoThe question is where, though. Intercepted mail? IRS systems? State systems? TurboTax? Weak passwords and brute forcing?
- eli 12y agoWell, there was a breach -- just not at TurboTax. If I were Intuit I'd be pissed about that headline, but it's not technically wrong.
- sp332 12y agoIt's not just the headline. "A TaxAct spokeswoman said that company is not seeing similar fraud issues and that customers can file state and federal returns as usual." "Minnesota announced it has stopped accepting tax returns submitted by individuals using TurboTax, although it is still accepting returns filed using Intuit professional-preparer products."
- Agathos 12y agoIts use of the singular is technically wrong. This is a downstream effect of the thousands of data breaches that have occurred in the past few years. Anything that provides a name and social security number could do it.
- eli 12y agoActually I'm pretty sure it's referring correctly to a singular probe. And unless you know something I don't, it's entirely plausible it's the result of a single data breach (e.g. the recent one at Anthem).
- Steuard 12y agoThe article indicated that the fraudulent returns seemed to be based on last year's returns for the individuals in question, so it sounds like a lot more than name and SSN were involved here.
- anigbrowl 12y agoSomeone's security seems to have compromised on a large scale, just not necessarily Intuit's. It might be the IRS, it might be malware on customer computers that is set up to look for prior years' tax data, or something else. It is a bit ambiguous but that's a general problem with headlines.
- ams6110 12y agoThis is the key point. Internet-connected systems have proven to be fundamentally insecure. Sorry to say it but the biggest organizations with the most to lose and the most resources to devote to security still fail. Smaller organizations and individuals probably leak like sieves. We just have to assume that anything anyone knows about you that is stored in a computer somewhere will at some point become public. Possession of any amount of personal information should no longer be adequate to prove identity. We need something else. I don't know what that is, but it has to be something that is already public or doesn't rely on secure computer systems.
- ryanlol 12y agoServices like SSNDOB have been around for years now. We're talking 10 years old breaches here.