A victim of the recent IRS breach that has affected over 330K Americans offers clues to how the attackers stole $50M by filing fraudulent tax returns
A rare detailed look inside the IRS's massive data breach, via a security expert who was a victim — Michael Kasper thought he was ahead …
Context & Ripple Effects
The IRS's 'Get Transcript' breach has been a story of expanding numbers: what began as 100K taxpayer accounts accessed via SSNs and birth dates was revised to 334K by August, then to 700K+ accounts with notification letters mailed starting Feb. 29. Sources traced the theft to Russia, and the IRS put direct losses at up to $39M.
Michael Kasper's first-person account matters because it shows the mechanics behind those figures — how attackers converted breached personal data into fraudulent returns and roughly $50M in refunds — rather than just the aggregate counts the IRS has been revising upward.
First-order effects
- Victims like Kasper face the direct consequence: attackers file returns using their SSN and birth dates before they can file themselves, diverting refunds and forcing them into IRS remediation.
Second-order effects
- The IRS's chosen fix — mailing Identity Protection PINs to the 724K victims — relies on the same Knowledge-Based Authentication technology that let the original attackers through, so the remedy reuses the broken control.
Third-order effects
- If KBA keeps failing against data that is already public or breached, government identity verification shifts structurally away from 'what do you know about yourself' toward out-of-band factors, with every agency running KBA facing the same exposure.
The trend: Knowledge-based authentication built on personal data is collapsing as a security boundary wherever that data has already leaked, pushing agencies toward verification methods that don't depend on it.