10 ms·
IRS says thieves stole tax info from 100,000
- byoung2 11y agoThe IRS said the thieves accessed a system called “Get Transcript.” In order to access the information, the thieves cleared a security screen that required knowledge about the taxpayer, including Social Security number, date of birth, tax filing status and street address. Do we know if the system was compromised, or if the thieves just had access to the personal information of those taxpayers?
- ceejayoz 11y agoIf the system were compromised I'd expect more than 100k attacked in this manner. Bet they were phishing victims or something.
- NoMoreNicksLeft 11y agoFunny, I'm more inclined to believe that the IRS is underreporting the number.
- seanp2k2 11y agoThis happened to a few people I work with. 100k seems low. They found out by the IRS rejecting their return as they had "already filed". You'd think we'd have a better system by now than a short-ish unique number which never changes during your lifetime as the key for much of your financial / credit-related authorization.
- eli 11y agoThat's a much larger problem than this current breach in the linked article. People have been filing early fraudulent returns for a long time because it's not that hard to do. I seem to recall reading the tricky part if figuring out how to actually get the money, since it will be issued in the name of the person who filed. The good news is it's often detected when people file their real return. I'm sure it's a giant hassle though.
- dragontamer 11y agoUSPS is rumored to be working on such a system actually. http://securekey.com/press-releases/securekey-technologies-wins-contract-with-u-s-postal-service-to-implement-federal-cloud-credential-exchange/ http://securekey.com/press-releases/securekey-technologies-w... SecureKey IIRC is used by Canada. USPS is in a unique position in that they have a ton of employees literally who can verify mailing addresses by brute force. Every day (except holidays). Rain, Snow or shine. Having USPS in charge of the US's future "online identity" would be a good way of transforming the ailing agency and giving them a very useful purpose that only USPS can do. There's a lot of win/win potential here.
- r00fus 11y agoThis is/should be the main offering of the USPS - secure identity location verification. It's too bad their hands are so tied by Congress (and a malicious one at that - having to pay pension fund 75 years early)... they might have made this move a decade or so earlier.
- xrange 11y ago...isn't that 75 year thing incorrect? http://www.cnbc.com/id/45018432 http://www.cnbc.com/id/45018432
- deleted 11y ago[deleted]
- elihu 11y agoI believe that verifying and vouching for the identity of it's citizens is one of the legitimate roles of government. I find it odd that we can have government issued social security numbers, passports, and driver's licenses, but I can't go to some office and have the US government sign my public key or SSL certificate. For some reason, if it's electronic, government is expected to defer to the free market.
- bitJericho 11y agoThe SSN was never designed or intended to be an ID number for anything but social security.
- scrollaway 11y agoAs a french citizen, and on behalf of everybody I know who doesn't live in the US (and some that do), the idea that knowing somebody's SSN basically puts you in control of their life and gives you the ability to ruin it is unbelievably ridiculous.
- iak8god 11y ago> the idea that knowing somebody's SSN basically puts you in control of their life and gives you the ability to ruin it is unbelievably ridiculous Especially since they get passed all around like that's not the case by employers, insurers, creditors, etc, etc.
- __z 11y agoSomeone fraudulently used my social security number. It is such a sick and terrible feeling knowing that your number is "out there" and can be used by anyone for a whole host of things. It feels horrible and really, really violating.
- scrollaway 11y agoI'm really sorry to hear that. Being a victim of an ill-designed system you're forced to be a part of is not a great feeling. :/
- __z 11y agoThank you for the empathy. The problem is it wasn't a designed system, it just came about by itself slowly over time. Social security numbers were never designed to be used in any way outside of social security.
- seanp2k2 11y ago
- jws 11y agoThis isn't about the normal theft of someone's tax refund by fraudulently filing a tax return. This about the IRS itself divulging the sensitive data required to fraudulently file tax returns. Someone tried about 200k times and got about 100k sets of people's tax histories. In the more mundane act of fraudulently bypassing the IRS's trivial security to steal a tax return… thieves got me, probably as a result of Anthem's inadequate security. The thieves didn't even have the courtesy to pay what I owed! I say you file my tax return, you take your chances. The maddening part, aside from the scramble when the April 14th filing from the tax people failed, is that no one in law enforcement is the slightest bit interested in enforcing the law.
- zaroth 11y agoKrebs wrote about this in March: http://krebsonsecurity.com/2015/03/sign-up-at-irs-gov-before-crooks-do-it-for-you/ http://krebsonsecurity.com/2015/03/sign-up-at-irs-gov-before... He has some good advice; claim your account before someone else does.
- protomyth 11y ago"Kasper said the detective learned that money was deposited into her account, and that she sent the money out to locations in Nigeria via Western Union wire transfer, keeping some as a profit, and apparently never suspecting that she might be doing something illegal." I am having a really tough time believing she never suspected she was doing something illegal.
- pki 11y agoto be fair, a lot of these money mules advertise as 'legitimate jobs' and stuff, targetting the less-smart people generally..
- __z 11y agoIts actually more common than you think, people can be pretty naive. These people create a fake company name and website and then post "work from home" jobs listings on monster.com.
- ceejayoz 11y ago> I am having a really tough time believing she never suspected she was doing something illegal. Why? People fall for the "I have $20 million for you, I just need a few hundred bucks to do the paperwork" scam all the time.
- protomyth 11y agoI'm a little shocked a college student fell for it. I would have a tough time hiring such a person because they would be a serious security risk.
- pecanpie 11y ago
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- vinhboy 11y agoI'll never understand why our politicians continue to cut funding to the one organization that could help the government save AND make more money. Not to mention save all of us from the headache of things like this.
- x3n0ph3n3 11y agoBecause politicians don't all belong to the same ideology and different camps have competing goals. This really isn't that complicated to understand.
- stephengillie 11y agoIt's not complicated to understand if you already understand the prerequisite concept of individuality - that each person acts somewhat independently of everyone else in the world. You have to understand individuality and apply it broadly. If you don't, then it's cognitively easier to lump people into groups that you don't have to care about, and can even grow to hate.
- acdha 11y agoYou assume that the goal is to make society better. Currently one of the two major parties has aggressively staked out the position that government cannot work and should be privatized – from that perspective dysfunction is a goal, not a problem. I liked Adam Gopnik's summation last week: “What we have, uniquely in America, is a political class, and an entire political party, devoted to the idea that any money spent on public goods is money misplaced, not because the state goods might not be good but because they would distract us from the larger principle that no ultimate good can be found in the state. Ride a fast train to Washington today and you’ll start thinking about national health insurance tomorrow.” http://www.newyorker.com/news/daily-comment/the-plot-against-trains http://www.newyorker.com/news/daily-comment/the-plot-against...
- ahallock 11y agoJust a talking point--empirically that's not true.
- bcantrill 11y agoI believe that this actually happened to me -- which tells me the 100,000 number is way too low. To be more precise: when we went to electronically file our 2014 return, it was rejected because our return had already been filed (not by us, of course). I (like 80+ million others) am a victim of the Anthem breach, and I have assumed that my fraudulent return was part of that breach. (Regardless, I have opted into the identity protection that Anthem has provided as restitution to victims of the breach.[1]) As part of clearing this up with the IRS, I had to verify my own identity and validate that the return that we (physically) sent was the true and correct return. After a whopping 2+ hours on hold, I ran a grueling gauntlet of rather obscure questions that amount to some flimsy shared secrets I happen to have with the IRS. Once my identity was confirmed, I learned that the thieves had filed a 2014 AGI that exactly matched my 2013 AGI. The IRS representative told me that this was unusual (that is, that they normally they just make numbers up), and it's clearly stupid (my return was flagged and didn't pay out), but it obviously left me concerned that someone had somehow located my 2013 return. With this latest revelation, it's now clear that this could have easily happened via the IRS itself. Assuming that my experience is indicative of a larger trend, I expect many more similar revelations as the IRS picks up the debris from the 2014 tax season -- and it wouldn't surprise me at all if the true target of the Anthem breach wasn't in fact the IRS: this crime is just too damn easy to pull off and get away with. The bright side of all this: things very clearly have to change, and I wouldn't be at all surprised if the IRS ends up issuing PINs to all e-filers this coming year. [1] https://www.anthemfacts.com https://www.anthemfacts.com
- __z 11y agoSo the IRS has a form you can send in to put a fraud alert or some type with them so I guess they will give your tax return special attention to see if it is really you next time. Also - I'm confused - I have an e-file PIN. You don't?
- jjnoakes 11y agoYou can e-file without an IRS-issued e-file PIN. I know of at least one tax filing software program that uses only your previous year's AGI to verify your identity to the IRS. So having an e-file PIN, or even using an e-file PIN to e-file, does not imply that your tax return can't be e-filed by someone else who only has your previous year's AGI.
- patja 11y agoI started "working" a few hours a week teaching programming at my kids' school. When they put me on the payroll I was astounded by the number of forms I had to fill out. I counted 15 forms requiring my signature, no less than 5 of which required my SSN. Lo and behold, there was a data breach of employee and volunteer records. Volunteers had to have background checks, which required the SSN. Thousands of people had their IRS return hijacked due to this breach. I personally know dozens of people who were impacted. From what I've seen of their information security, I remain completely unsurprised that they had this breach and that to this date they have no idea how it happened.
- josu 11y agoYou can look at it from the other side too, maybe Americans are putting too much weight on the SSN. I could practically post my Spanish ID number next to my name online and nothing would probably happen. As a matter of fact, a stupid regional government agency posted it next to my name in 2011 and it's been up ever since.
- joering2 11y agoIf you properly protect your security number, which requires some monthly commitment (such as $15 lifelock, or freecreditreport $5 per month), you can pretty much post your SSN online and really not much will happen. Any time someone uses it, you will get the alert and chance to act (stop the inquiry before it hit hard). It just that most people believe that not making their SSN public is enough for it to be safe.
- jfuhrman 11y agoDon't think lifelock will prevent fraudulent tax returns.
- ohitsdom 11y agoThe CEO of Lifelock posted his SSN in several ad campaigns to tout the effectiveness of Lifelock. And, surprise, his identity was "stolen" 13 times[0]. [0] http://www.wired.com/2010/05/lifelock-identity-theft/ http://www.wired.com/2010/05/lifelock-identity-theft/
- davidcelis 11y agoIf you're wondering whether or not this happened to you, one way to know is if you were able to file your own return. If your own tax return was rejected because it had already been filed, it means someone was able to attempt to file a fraudulent return using your identity. Of course, this is only assuming that they managed to submit a return as you at all. It's possible your information was taken but not used.
- newman8r 11y agoyeah this happened to me last year
- revelation 11y agoSomething is wrong with the wording here. Thieves stole the tax info of 100,000 but they stole it from the IRS. Make no mistake: IRS needs to be held responsible for this. It is their fault.
- ceejayoz 11y agoWhy is it necessarily their fault? I'd suspect the information needed to access the tax returns was obtained via phishing or a data breach elsewhere like a tax preparation service.
- Estragon 11y agoIt's their fault because the information needed is widely available.
- sliverstorm 11y agoYes! Clearly the only appropriate action is to cut their budget another 20%. Maybe then they'll learn their lesson and fix the problem! The budget cuts will continue until security improves!
- paulhauggis 11y agoSo when the victim is someone you don't like, it's somehow their fault?? The fault should be with the person/people that stole the tax information, not the IRS. Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.
- scottm01 11y agoIt looks like they've at least pulled the link to request transcripts online. Alert: The online Get Transcript service is currently unavailable. Transcripts may still be ordered using the Get Transcript by Mail service. We apologize for any inconvenience.
- jsat 11y agoImagine if all government software was open source and significant bug reports and contributions were rewarded with cash... I hope we reach some happy medium between that and what we have today in the future.
- ceejayoz 11y agoThis wasn't a hack or a bug - open source software built to do the same thing would've been just as vulnerable to this. Per the article, the attackers had to put "the taxpayer’s Social Security number, date of birth, address and tax filing status" into a form to get access.
- jsat 11y agoI see. Maybe the additional exposure would have shed light on the risk involved?
- daveloyall 11y agoMultiple commenters have said that ~100,000 is "too low". The number quoted in the article is 104,000. Obvious questions: 1. Is 104,000 the exact count, or has it been rounded? 2. Did the hackers stop when their success count got there? 3. Does nobody else think it is funny that 1040 is a factor of 104,000? :) [edited a lot]
- iamlolz 11y agoHow is 1040 a famous number?(Australian here)
- agildehaus 11y agohttp://en.wikipedia.org/wiki/IRS_tax_forms#1040 http://en.wikipedia.org/wiki/IRS_tax_forms#1040
- ketralnis 11y ago1040 is the name of the primary income tax reporting form in the US (and has variants like 1040A & 1040EZ). (I can't comment on the rest of that rant though)
- iamlolz 11y agoAh, that makes sense - thanks.
- benjarrell 11y agoForm 1040 is for US income tax return. It is what you fill out to file your taxes.
- deleted 11y ago[deleted]
- malchow 11y agoIf this were a company, the headline would have been "IRS hacked; tax information stolen from 100,000." Instead the IRS was able to spin it to The Washington Post. The headline is "thieves stole tax info." Thieves! The real headline is that the IRS is hackable.
- grecy 11y ago> Instead the IRS was able to spin it to The Washington Post. The headline is "thieves stole tax info." Thieves! They spun it even better than that. The headline is "thieves stole tax info from 100,000 people" (i.e. not from the IRS, but from the people themselves)
- ljk 11y agowhy does the realization of this sneaky tactic make me so mad
- ceejayoz 11y ago> The real headline is that the IRS is hackable. That's not borne out in the slightest by what we know from the article. These people might've been phishing victims - you wouldn't claim a bank is hackable because people entered their bank password on a phishing site.
- mdavidn 11y agoBut these aren't phishing victims. The IRS deployed a system which returns a treasure trove of personal information to anyone who presents a few shared secrets. This is a fundamentally flawed authentication mechanism devised by the IRS.
- ceejayoz 11y agoThose shared secrets were likely obtained by either phishing or a data breach. There's no indication thus far that the IRS was the source of the information that let people obtain these returns.
- bane 11y agoTaxes in the U.S. are absolutely ridiculous. Nearly everything is already reported to the IRS by employers, banks, brokers, etc. Why spend hours filling out and copying all that crap, and signing thing after thing after thing just to send the IRS information they already have? The problem seems to be trying to carve out exemptions for little things here and there. Just use a decent tax rate, get rid of all that crap, calculate what I owe and send me a bill or send me a check if I over-withheld or something. Ugh it's so hard building a proper civilization.
- superuser2 11y ago>Why spend hours filling out and copying all that crap, and signing thing after thing after thing just to send the IRS information they already have? We wanted to; the tax-preparation lobby killed it.
- alexqgb 11y agoWhy spend hours filling out and copying all that crap, and signing thing after thing after thing just to send the IRS information they already have? Because Intuit, H&R Block, and others like them who have built substantial businesses doing all that empty-work for you have made damn sure that Congress doesn't legislate their meal ticket away.
- deleted 11y ago[deleted]
- teammatters 11y agoI'M SO SICK OF BEING HACKED & MONEY STOLEN FROM ME AND THEN EXERTING A TON OF EFFORT (WEEKS) TO GET IT BACK. Something drastic needs to be done. It's been two times in the last five years and that's too many times for me!!! Recently, a phantom Uber account of mine was hacked; phantom because I signed up years ago and must have connected my PayPal account & never used it. Needless to say, I was shocked that some worthless piece of shit/thief hacked into my Uber account and supposedly took a $800 ride in London on my bank(im in NYC). What's even worse is Uber doesn't give one rats ass about it's customers/users (try to delete your Uber account yourself.. try to deactivate your Uber payment method - HA good luck). This hack has been going on for many months and those smug, greedy pigs at Uber haven't done a damn thing besides blame it's users/customers for choosing similar usernames/passwords used on other sites. Check out all the poor souls being hacked per this twitter search https://twitter.com/search?q=%40uber_support%20london&src=ty.. https://twitter.com/search?q=%40uber_support%20london&src=ty.... Hackers unite, let's please come up with better tools to secure ourselves from all this stress and insanity!!!
- jakeogh 11y agoTranslation: We are going to collect your data. Give it to us, or else. If it's stolen, that's your problem. You dont get to choose.