IRS data breach bigger than previously thought

The Internal Revenue Service says it underestimated the scope of a cyberattack, first disclosed in May, that compromises the personal and financial information of thousands of taxpayers.  

|
J. David Ake/AP Photo/File
The Internal Revenue Service headquarters is seen in Washington. The IRS says thieves used an agency website to steal tax information from as many as 220,000 additional taxpayers. The agency first disclosed the breach in May. Monday’s revelation more than doubles the total number of potential victims, to 334,000.

A computer breach at the US tax collecting agency in which thieves stole tax information from thousands of taxpayers is much bigger than the agency originally disclosed.

An additional 220,000 potential victims had information stolen from an Internal Revenue Service website as part of a sophisticated scheme to use stolen identities to claim fraudulent tax refunds, the IRS said Monday. The revelation more than doubles the total number of potential victims, to 334,000.

The breach also started earlier than investigators initially thought. The tax agency first disclosed the breach in May.

The thieves accessed a system called "Get Transcript," where taxpayers can get tax returns and other filings from previous years. In order to access the information, the thieves cleared a security screen that required knowledge about the taxpayer, including federal pension identification number, date of birth, tax filing status and street address, the IRS said.

The personal information was presumably stolen from other sources. The IRS believes the thieves were accessing the IRS website to get even more information about the taxpayers, which could help them claim fraudulent tax refunds in the future.

In all, the thieves used personal information from about 610,000 taxpayers in an effort to access old tax returns. They were successful in getting information from about 334,000 taxpayers.

The IRS isn't the first agency – public or private – to initially underestimate the magnitude of a data breach. The Office of Personnel Management announced earlier this year that hackers had stolen sensitive information on 4.2 million people. The number of affected people has since grown to more than 21 million.

The IRS said it is notifying all potential victims and offering free credit monitoring services. The IRS is also offering to enroll potential victims in a program that assigns them special ID numbers that they must use to file their tax returns.

The IRS said Monday that thieves started targeting the website in November. Originally, investigators thought it started in February. The website was shut down in May.

On Monday, the IRS did not identify a potential source of the crime. But in May, officials said IRS investigators believe the identity thieves are part of a sophisticated criminal operation based in Russia.

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
What is the Monitor difference? Tackling the tough headlines – with humanity. Listening to sources – with respect. Seeing the story that others are missing by reporting what so often gets overlooked: the values that connect us. That’s Monitor reporting – news that changes how you see the world.

Dear Reader,

About a year ago, I happened upon this statement about the Monitor in the Harvard Business Review – under the charming heading of “do things that don’t interest you”:

“Many things that end up” being meaningful, writes social scientist Joseph Grenny, “have come from conference workshops, articles, or online videos that began as a chore and ended with an insight. My work in Kenya, for example, was heavily influenced by a Christian Science Monitor article I had forced myself to read 10 years earlier. Sometimes, we call things ‘boring’ simply because they lie outside the box we are currently in.”

If you were to come up with a punchline to a joke about the Monitor, that would probably be it. We’re seen as being global, fair, insightful, and perhaps a bit too earnest. We’re the bran muffin of journalism.

But you know what? We change lives. And I’m going to argue that we change lives precisely because we force open that too-small box that most human beings think they live in.

The Monitor is a peculiar little publication that’s hard for the world to figure out. We’re run by a church, but we’re not only for church members and we’re not about converting people. We’re known as being fair even as the world becomes as polarized as at any time since the newspaper’s founding in 1908.

We have a mission beyond circulation, we want to bridge divides. We’re about kicking down the door of thought everywhere and saying, “You are bigger and more capable than you realize. And we can prove it.”

If you’re looking for bran muffin journalism, you can subscribe to the Monitor for $15. You’ll get the Monitor Weekly magazine, the Monitor Daily email, and unlimited access to CSMonitor.com.

QR Code to IRS data breach bigger than previously thought
Read this article in
https://www.csmonitor.com/USA/2015/0817/IRS-data-breach-bigger-than-previously-thought
QR Code to Subscription page
Start your subscription today
https://www.csmonitor.com/subscribe