Slashdot Mirror


IRS: Personal Info of 100,000 Taxpayers Accessed Illegally

An anonymous reader writes: The Associated Press reports that an online service provided by the IRS was used to gather the personal information of more than 100,000 taxpayers. Criminals were able to scrape the "Get Transcript" system to acquire tax return information. They already had a significant amount of information about these taxpayers, though — the system required a security check that included knowledge of a person's social security number, date of birth, and filing status. The system has been shut down while the IRS investigates and implements better security, and they're notifying the taxpayers whose information was accessed.

4 of 85 comments (clear)

  1. DoB, SSN & Filing Status?? by CrimsonAvenger · · Score: 4, Insightful

    That's all the ID the IRS requires to use their "secure" site???

    Jaysus, you can get most of that (SSN & DoB) by looking at someone's Driver License in most States.

    And guessing Married Filing Jointly will work more often than not, I expect....

    --

    "I do not agree with what you say, but I will defend to the death your right to say it"
    1. Re:DoB, SSN & Filing Status?? by Charliemopps · · Score: 4, Insightful

      That's all the ID the IRS requires to use their "secure" site???

      Jaysus, you can get most of that (SSN & DoB) by looking at someone's Driver License in most States.

      And guessing Married Filing Jointly will work more often than not, I expect....

      I know, it's hilarious. These agencies/companies get hacked due to their own willful negligence... then scream "Hackers did it!" like hackers have magic hacking wands that turn servers inside out. It seems that the only piece of info that would have been remotely hard to get was filing status... which the "hackers" just guessed at. It looks like they were 50% successful, and I bet if compared with the victims filing status, they likely had a 50% chance of filing jointly or something. What a joke. This is completely and entirely the IRS's fault.

      Make a new law, if you get hacked, you have to pay the person whos data you lost $100,000. Problem solved. You can then decide if spending time on securing the data is worth it, or if you just want to not store it. It IS possible to prevent this sort of thing. These agencies and companies just don't think it's profitable to do so when the penalty for losing a persons info is nothing more than a press release.

    2. Re:DoB, SSN & Filing Status?? by ShanghaiBill · · Score: 4, Insightful

      No-one should have your SSN beyond the government.

      That is silly. The original point of SSNs was so that employers could use them to identify workers when paying social security taxes to the government. So, obviously, your employer needs to know it.

      We need to get away from the ridiculous idea that something can be both widely known and secret. SSNs should only be used for identification, and should never be used for authentication. We should have a separate system for that.

  2. Mad Lib by Voyager529 · · Score: 4, Insightful

    [NEWS_OUTLET] reports that an online service provided by [ORGANIZATION_WITH_PERSONAL_DATA] was used to gather the personal information of [CUSTOMERS_OR_USERS]. Criminals were able to scrape [INSECURE_SYSTEM] to acquire [SUPPOSEDLY_SECURED_INFORMATION]. The system has been shut down while [OVERPAID_AND_INCOMPETENT_ANALYSTS] investigate and [PROMISE], and they're notifying [CUSTOMERS_OR_USERS] whose information was accessed.

    At this point, you can turn this story into a Mad Lib, and fill in the blanks with basically any set of nouns, and it'll mostly be true.