The Internal Revenue Service was the target of an attack that used stolen social security numbers and other taxpayer data to obtain PINs that can be used to file tax returns electronically.
The attack occurred in January and targeted an IRS Web application that taxpayers use to obtain their so-called Electronic Filing (E-file) PINs. The app requires taxpayer information such as name, Social Security number, date of birth and full address.
Attackers attempted to obtain E-file PINs corresponding to 464,000 unique SSNs using an automated bot, and did so successfully for 101,000 SSNs before the IRS blocked it.
The personal taxpayer data used during the attack was not obtained from the IRS, but was stolen elsewhere, the agency said in a statement. The IRS is notifying affected taxpayers via mail and will monitor their accounts to protect them from tax-related identity theft.
While the IRS said that externally-acquired taxpayer data was used, the agency did suffer a security breach last year that allowed attackers to gain information such as Social Security information, date of birth and street address for over 300,000 taxpayers.
That attack involved the IRS’ “Get Transcript” application and in that case too, the agency said that attackers were able to pass the app’s verification steps using information acquired from an external source.
In recent years there have been many data breaches that gave hackers access to personal information, including SSNs. Last year alone, health insurers Anthem, Premera, CareFirst and Excellus announced large data breaches that affected tens of millions of Americans. Another breach at the U.S. Office of Personnel Management exposed personal information on 21.5 million current and former U.S. government employees.
Given the sheer amount of personal data that’s now in the hands of cybercriminals, it’s likely that some of them will try to monetize it and one possible method is by filing fraudulent tax returns.