/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

PIN system used by IRS to protect 724K victims of 2015 breach relies on same Knowledge-Based Authentication tech used in original breach

and it was just hacked” http://qz.com/... Ajay / @paladin63 : FML, it never ends.... #cybersecurity #infosec http://qz.com/... pic.twitter.com/hB6PUalt9v

Quartz Keith Collins

Context & Ripple Effects

The IRS's remediation for its 2015 breach has come apart in sequence: in February, identity thieves pulled 100,000 electronic filing PINs straight out of an IRS application, and earlier reporting traced how attackers used stolen identities to file fraudulent returns worth tens of millions against victims of the original breach. This Quartz report identifies the root design flaw: the Get IP PIN tool meant to shield 724,000 breach victims authenticates users with the same knowledge-based questions whose answers were compromised in the breach itself.

The finding matters because it shows the fix reused the failure mode. Days after this report, the IRS suspended the Get IP PIN feature entirely after thieves stole at least 800 victim PINs to file fraudulent returns — confirming the vulnerability was live, not theoretical.

First-order effects

  • The 724,000 taxpayers the IP PIN program was built to protect are guarded by credentials (name, SSN, date of birth, prior filing data) that the 2015 attackers already hold, so the protection layer offers them little real defense.
  • The IRS must pull or re-engineer the Get IP PIN tool mid-filing season, leaving breach victims without the safeguard while fraudulent-return attempts continue.

Second-order effects

  • Fraudsters shift toward the same weak point elsewhere in the identity ecosystem: Experian's own tools authenticate on trivially leakable data — its credit-freeze PIN retrieval asks for just four basic personal details (a gap Krebs documented in 2017) — giving thieves parallel targets when the IRS door closes.
  • Tax-fraud economics favor whoever holds breached personal data, pushing stolen-identity rings to arbitrage every institution still using knowledge-based checks rather than any single agency's defenses.

Third-order effects

  • If the pattern holds — the same KBA weaknesses resurfacing at Experian through 2022's hijacked-account reports and PIN reset flaws — knowledge-based authentication becomes untenable as a security control across government and credit bureaus alike, forcing a migration to verification methods that don't depend on already-leaked personal facts.
  • Agencies and bureaus that treat remediation as a feature rollout rather than an authentication redesign will keep rebuilding breached systems on breached data, making independent security review of 'fixes' a structural requirement rather than an afterthought.

The trend: Identity verification built on personal data that has already been breached is collapsing as a control, pushing the IRS and credit bureaus toward authentication methods that don't rely on knowable answers.