IRS Tool Designed To Protect Identity Theft Victims -- Exposes Users To Identity Theft

  • Share:
March 06, 2017

Every day I see more and more issues with all types of identity theft. I read this from a publication called “DailyDirt”. It reminds me of the issue with Apple cell phones. Can you imagine the government obtaining a 'backdoor' program for iPhones? How quickly do you think that software would be hacked? Read on . . .

Last year, the personal records of 100,000 taxpayers wound up in the hands of criminals, thanks to a flimsy authentication process in the agency's "Get Transcript" application. In short, the IRS used all-too-common static identifiers to verify taxpayer identity (information that could be found anywhere), allowing criminals to use the system to then obtain notably more sensitive taxpayer information and ultimately steal finances. At the time, the IRS breathlessly insisted it would be shoring up its security standards, though it failed to really detail how it would accomplish this. 

Tax return fraud has since become a burgeoning industry unto itself, with crooks consistently gaming IRS systems to fool the IRS into sending your money to a criminal's account, something victims only discover when they find their own, legitimate tax returns rejected. To protect these compromised users, the IRS has employed a system wherein it mails these victims a six-digit "Identity Protection (IP) PIN." That pin has been mailed to some 2.7 million victims, and must be entered into the following year's tax return. But not-too-surprisingly, this pin system is also notably easy to game, 
relying heavily on commonly available user data:

...The trouble with this approach is that the IRS allows IP PIN recipients to retrieve their PIN via the agency’s Web site, after supplying the answers to four easy-to-guess questions from consumer credit bureau Equifax. These so-called knowledge-based authentication (KBA) or “out-of-wallet” questions focus on things such as previous address, loan amounts and dates and can be successfully enumerated with random guessing. In many cases, the answers can be found by consulting free online services, such as Zillow and Facebook.

So yes, that's an agency already hit several times by fraud and internal scandals providing an identity theft tool -- that can be used to help steal your identity. A CPA by the name of Becky Wittrock, who had fallen victim to identity theft in 2014, notes she's now been a repeat victim after thieves impersonated her, then used the IRS's crappy pin system to impersonate her again:

Becky Wittrock, a certified public accountant (CPA) from Sioux Falls, S.D., said she received an IP PIN in 2014 after crooks tried to impersonate her to the IRS. Wittrock said she found out her IP PIN had been compromised by thieves this year after she tried to file her tax return on Feb. 25, 2016. Turns out, the crooks beat her to the punch by more than three weeks, filing a large refund request with the IRS on Feb. 2, 2016. “So, last year I was devastated by this,” Wittrock said, “But this year I’m just pissed.”

After spending more time trying to prove her identity to the IRS than the thief apparently did, Wittrock was told that next year the IRS will be ditching the pin system for a murky system that may rely on users' driver's licenses (my bold). Granted, we do seem to enjoy gutting IRS funding, staffing, authority and overall resources, only to complain that the agency sucks at doing its job. Still, that's no excuse for not implementing some fundamental authentication common sense. Meanwhile, the IRS's repeated failures are troubling for a government that's intent on viewing itself as the foremost expert in cyber-warfare and security, yet still can't manage to keep wolves out of its own henhouse.”

Can you imagine if instead of a PIN number, your drivers' license number is out there?! Our Identity theft protection plan, not only monitors your financial records, but also the four other areas that are just as vulnerable.

Click here for more information on our IDShield plan. at the very least, have the ability to speak with a licensed consultant FOR FREE, as part of our monthly plan.

To learn more watch our six short videos by clicking here.

Have you ever needed a quick answer to a legal question? With Ask LegalShield, you now have access to over 1,200 commonly asked legal questions and answers right in your pocket, and it's free!

Phil Liso, Contact
(562) 322-7376