Identity thieves obtain 100,000 electronic filing PINs from IRS system
The automated attack attempted to obtain E-file PINS for over 460,000 people using previously stolen personal data — The Internal Revenue Service was the target of an attack that used stolen social security numbers …
Context & Ripple Effects
This attack is the second wave of a single failure: the same stolen identities that powered the Get Transcript breach of more than 100K taxpayer records last May were replayed against a different IRS front door, the e-file PIN application, succeeding for about 100,000 of more than 460,000 attempted matches.
The deeper problem was flagged before either breach: a watchdog found the IRS had left known computer security weaknesses unaddressed ahead of the transcript attack, and reporting later showed the replacement PIN system still leaned on the same Knowledge-Based Authentication that stolen SSNs and birth dates defeat by design.
First-order effects
- Roughly 100,000 taxpayers now have valid e-file PINs in criminals' hands, giving attackers exactly what they need to file fraudulent returns and intercept refunds during the current filing season.
- The IRS must identify and notify affected filers out of the 460,000-plus targeted, while absorbing the political cost of a repeat breach months after the transcript incident.
Second-order effects
- IRS protective tooling built for prior victims becomes its own liability — the agency later suspends its Get IP PIN feature for 2015 breach victims after thieves steal at least 800 of those very PINs, as covered in the subsequent suspension.
- Every additional cache of confirmed-valid identity data pushes tax-prep firms, state revenue agencies, and lenders toward their own fraud controls, since refund fraud migrates to whichever channel the IRS hardens slowest.
Third-order effects
- If the pattern holds — the same KBA approach failing in 2015, again here, and then via a student financial-aid tool in 2017 per the later financial aid tool breach — identity-based authentication collapses as a control wherever SSNs are already compromised, forcing the IRS toward out-of-band verification rather than knowledge questions.
- Repeated watchdog-documented failures give Congress and oversight bodies a standing case to mandate authentication reform across federal data services, not just patch individual tools.
The trend: Federal identity verification built on Knowledge-Based Authentication keeps failing against criminals armed with previously breached personal data, and each IRS remediation inherits the flaw it was meant to fix.