After recent breaches, IRS promises to add additional security measures to protect against fraud and identity theft by early 2016
I.R.S. Adds New Safeguards to Thwart Identity Theft and Fraud — Reeling from an online attack that allowed criminals to steal personal information …
Context & Ripple Effects
The pledge lands days after a watchdog finding that the IRS ignored known computer security weaknesses, leaving it exposed to the attack that hit 104,000 taxpayers through its online services. The promise of new safeguards by early 2016 is effectively the agency's answer to criticism that the breach was preventable.
The arc since has not been kind to that promise: within months the IRS more than doubled its breach estimate in a revision to 700K+ hacked taxpayer accounts from an initial 334K, and then had to pull the very tool meant to protect victims when thieves stole their PINs.
First-order effects
- Taxpayers whose data was siphoned through the IRS's online transcript services face fraudulent-return risk while waiting on the promised early-2016 rollout of stronger authentication measures.
- IRS operations staff must implement the new safeguards against a deadline set under congressional and watchdog pressure, with funding and credibility both on the line.
Second-order effects
- Protective tools themselves became attack surface: identity thieves harvested at least 800 PINs from the 'Get IP PIN' program, forcing its suspension just as it was supposed to shield 2015 breach victims.
- The widening disclosure to 700K+ accounts forced the IRS into mass notification mailings beginning February 29, 2016, converting a security incident into a sustained customer-service and cost burden.
Third-order effects
- The pattern points to a structural arms race: each IRS verification mechanism — knowledge-based questions, IP PINs, and later the ID.me facial-recognition system it retreated from in 2022 — gets probed and defeated by actors armed with breached personal data, pushing the agency toward repeated wholesale redesigns of taxpayer identity proofing.
- If every safeguard cycle ends in expanded breach counts and pulled features, oversight bodies are likely to keep tightening requirements on how quickly federal agencies must remediate flagged vulnerabilities rather than trusting internal timelines.
The trend: Government identity verification is locked in a losing tempo battle with data-breach-fueled fraud, where each fix — from PINs to biometrics — becomes the next target.