The IRS suspends hacked tool meant to help identity theft victims

  • The Washington Post.
  • Tuesday, March 8, 2016 1:27pm
  • Business

The IRS has suspended an online tool used to retrieve Identity Protection PINs — a six-digit number needed by victims of tax refund fraud to file their taxes electronically — after reports that the system suffered the same security weakness that allowed fraudsters to trick another agency tool into giving up taxpayer information last year.

“The IRS is conducting a further review of the application that allows taxpayers to retrieve their IP PINs online and is looking at further strengthening the security features on the tool,” the IRS said in a statement Monday.

Concerns about the tool were thrust into the spotlight last week after journalist Brian Krebs wrote about a South Dakota woman, Becky Wittrock, who said fraudulent tax returns were filed in her name two years in a row — and that the phony filing this year included her stolen IP PIN. That PIN was meant to add a layer of security to prevent this exact type of problem.

Wittrock was an apparent victim of a type of identity theft known as tax refund fraud, a scam where criminals file phony, often inflated, tax returns in an attempt to steal other people’s refunds.

The IRS said in the statement that it had mailed out 2.7 million IP PINS to taxpayers this year and that only abut 130,000 of them used the “Get an IP PIN” tool on the agency’s website to access a lost or forgotten PIN.

The online IP PIN retrieval tool required information such as a taxpayer’s name, date of birth, Social Security number, last filing status and the mailing address from their last tax return. It also asked a handful of “knowledge-based authentication” questions drawn from a person’s credit history.

Unfortunately, answers to those questions can often be figured out by consulting public online sources such as social media networks or real estate tracking sites like Zillow — or even by guessing. And the other personal information could have fallen into fraudsters’ hands through past breaches, including an incident involving the IRS’s “Get Transcript” tool last year.

The “Get Transcript” tool also relied on “knowledge based authentication” to prove a taxpayer’s identity and may have allowed criminals to access the tax information of more than 700,000 people, according to the IRS’s latest update on the scale of that breach. The agency took the “Get Transcript” system offline after the problems last year, but it left the “Get an IP PIN” tool up.

In an interview with The Washington Post last week, IRS Commissioner John Koskinen said the agency was taking a number of steps on the back end of its systems to ensure the security of taxpayers using IP PINs. He also said the agency is giving extra scrutiny to returns filed with lost IP PINs retrieved through the online tool.

The IRS said Monday that it has stopped 800 fraudulent returns using IP PINs through the end of February, more than four times the “less than 200” figure it cited to The Post last week. In the “Get Transcript” case, the IRS repeatedly raised its estimates of the number of victims. When the agency first acknowledged the problem last May, it estimated that 100,000 people’s tax accounts were affected. By late last month, that figure had jumped to more than 700,000 accounts.

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

A semi truck and a unicycler move along two sections of Marine View Drive and Port Gardner Landing that will be closed due to bulkhead construction on Wednesday, Sept. 3, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Port of Everett set to begin final phase of bulkhead work, wharf rebuild

The $6.75 million project will reduce southbound lanes on West Marine View Drive and is expected to last until May 2026.

Customers walk in and out of Fred Meyer along Evergreen Way on Monday, Oct. 31, 2022 in Everett, Washington. (Olivia Vanni / The Herald)
Kroger said theft a reason for Everett Fred Meyer closure. Numbers say differently.

Statistics from Everett Police Department show shoplifting cut in half from 2023 to 2024.

Funko headquarters in downtown Everett. (Sue Misao / Herald file)
FUNKO taps Netflix executive to lead company

FUNKO’s new CEO comes from Netflix

Inside El Sid, where the cocktail bar will also serve as a coffee house during the day on Tuesday, Aug. 12, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
New upscale bar El Sid opens in APEX complex

Upscale bar is latest venue to open in APEX Everett.

Mattie Hanley, wife of DARPA director Stephen Winchell, smashes a bottle to christen the USX-1 Defiant, first-of-its kind autonomous naval ship, at Everett Ship Repair on Monday, Aug. 11, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
No crew required: Christening held for autonomous ship prototype in Everett

Built in Whidbey Island, the USX-1 Defiant is part of a larger goal to bring unmanned surface vessels to the US Navy.

Cassie Smith, inventory manager, stocks shelves with vinyl figures in 2020 at the Funko store on Wetmore Avenue in Everett. (Andy Bronson / The Herald)
Everett-based Funko reports $41M loss in the 2nd quarter

The pop culture collectables company reported the news during an earnings call on Thursday.

A Boeing 737 Max 10 prepares to take off in Seattle on June 18, 2021. MUST CREDIT: Bloomberg photo by Chona Kasinger.
When Boeing expects to start production of 737 MAX 10 plane in Everett

Boeing CEO says latest timeline depends on expected FAA certification of the plane in 2026.

Kongsberg Director of Government Relations Jake Tobin talks to Rep. Rick Larsen about the HUGIN Edge on Thursday, July 31, 2025 in Lynnwood, Washington. (Olivia Vanni / The Herald)
Norwegian underwater vehicle company expands to Lynnwood

Kongsberg Discovery will start manufacturing autonomous underwater vehicles in 2026 out of its U.S. headquarters in Lynnwood.

Logo for news use featuring the municipality of Snohomish in Snohomish County, Washington. 220118
Garbage strike over for now in Lynnwood, Edmonds and Snohomish

Union leaders say strike could return if “fair” negotiations do not happen.

Richard Wong, center, the 777-X wing engineering senior manager, cheers as the first hole is drilled in the 777-8 Freighter wing spar on Monday, July 21, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Boeing starts production of first 777X Freighter

The drilling of a hole in Everett starts a new chapter at Boeing.

Eisley Lewis, 9, demonstrates a basic stitch with her lavender sewing machine on Wednesday, Aug. 27, 2025 in Everett, Washington. (Olivia Vanni / The Herald)
Everett fourth grader stitches summer boredom into business

Rice bags, tote bags and entrepreneurial grit made Eisley Lewis, 9, proud of herself and $400.

Isaac Peterson, owner of the Reptile Zoo, outside of his business on Tuesday, Aug. 19, 2025 in Monroe, Washington. (Olivia Vanni / The Herald)
The Reptile Zoo, Monroe’s roadside zoo, slated to close

The Reptile Zoo has been a unique Snohomish County tourist attraction for nearly 30 years.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.