PIN system used by IRS to protect 724K victims of 2015 breach relies on same Knowledge-Based Authentication tech used in original breach
and it was just hacked” http://qz.com/... Ajay / @paladin63 : FML, it never ends.... #cybersecurity #infosec http://qz.com/... pic.twitter.com/hB6PUalt9v
Context & Ripple Effects
The IRS's remediation for its 2015 breach has come apart in sequence: in February, identity thieves pulled 100,000 electronic filing PINs straight out of an IRS application, and earlier reporting traced how attackers used stolen identities to file fraudulent returns worth tens of millions against victims of the original breach. This Quartz report identifies the root design flaw: the Get IP PIN tool meant to shield 724,000 breach victims authenticates users with the same knowledge-based questions whose answers were compromised in the breach itself.
The finding matters because it shows the fix reused the failure mode. Days after this report, the IRS suspended the Get IP PIN feature entirely after thieves stole at least 800 victim PINs to file fraudulent returns — confirming the vulnerability was live, not theoretical.
First-order effects
- The 724,000 taxpayers the IP PIN program was built to protect are guarded by credentials (name, SSN, date of birth, prior filing data) that the 2015 attackers already hold, so the protection layer offers them little real defense.
- The IRS must pull or re-engineer the Get IP PIN tool mid-filing season, leaving breach victims without the safeguard while fraudulent-return attempts continue.
Second-order effects
- Fraudsters shift toward the same weak point elsewhere in the identity ecosystem: Experian's own tools authenticate on trivially leakable data — its credit-freeze PIN retrieval asks for just four basic personal details (a gap Krebs documented in 2017) — giving thieves parallel targets when the IRS door closes.
- Tax-fraud economics favor whoever holds breached personal data, pushing stolen-identity rings to arbitrage every institution still using knowledge-based checks rather than any single agency's defenses.
Third-order effects
- If the pattern holds — the same KBA weaknesses resurfacing at Experian through 2022's hijacked-account reports and PIN reset flaws — knowledge-based authentication becomes untenable as a security control across government and credit bureaus alike, forcing a migration to verification methods that don't depend on already-leaked personal facts.
- Agencies and bureaus that treat remediation as a feature rollout rather than an authentication redesign will keep rebuilding breached systems on breached data, making independent security review of 'fixes' a structural requirement rather than an afterthought.
The trend: Identity verification built on personal data that has already been breached is collapsing as a control, pushing the IRS and credit bureaus toward authentication methods that don't rely on knowable answers.