IRS suffers another data breach

By Sally P. Schreiber, J.D.

The IRS revealed on Tuesday that it discovered and stopped an automated cyberattack on its e-filing personal identification number (PIN) system last month. According to the IRS, the cybercriminals used information stolen “elsewhere outside the IRS” to generate e-file PINs for stolen Social Security numbers (SSNs). E-file PINs are used by some taxpayers to electronically file their tax returns.

Although no personal taxpayer data were compromised or disclosed by the breach, the IRS noted that the cybercriminals succeeded in using 101,000 SSNs to access e-file PINs (out of 464,000 attempts).

The IRS is notifying the affected taxpayers and placing tax return identity theft markers on their accounts. It is also continuing to closely monitor the Electronic Filing PIN application against further breaches.

The IRS also said it is working with other agencies and the Treasury Inspector General for Tax Administration to assess the problem and has shared information with Security Summit state and industry partners. It said the breach was not related to last week’s e-filing shutdown.

The news follows closely on last summer’s announcement that a breach of the IRS Get Transcript system resulted in the theft of some 334,000 taxpayers’ tax data (see prior coverage here).

Sally P. Schreiber (sschreiber@aicpa.org) is a JofA senior editor. 

SPONSORED REPORT

Why cybercriminals are targeting CPAs

This free report expands on the most commonly found scams, why education and specialized IT knowledge help to lessen security vulnerabilities, and why every firm should plan carefully for how it would respond to a breach.

PODCAST

How tax reform — and Excel — are changing the CPA Exam

Mike Decker, the vice president of examinations at the AICPA, discusses changes being made to the exam as a result of tax reform — and about how Excel will now be available for use on the test.