IRS suspends ‘Get IP PIN’ feature designed to protect 2015 breach victims after identity thieves stole at least 800 of those PINs to file fraudulent returns
IRS Suspends Insecure ‘Get IP PIN’ Feature — Citing ongoing security concerns, the Internal Revenue Service (IRS) …
Context & Ripple Effects
The IRS's remediation arc has been running backwards. After hackers used stolen SSNs and birth dates to pull returns through the Get Transcript service in May 2015, the agency promised additional security measures by early 2016. Its fix — IP PINs for the breach's victims — was itself built on the same Knowledge-Based Authentication that failed the first time, as Quartz reported days ago.
That design flaw is now being exploited end to end: thieves pulled 100,000 electronic filing PINs from an IRS system last month (PCWorld), and have since used at least 800 victim IP PINs to file fraudulent returns, forcing today's suspension of the Get IP PIN feature entirely.
First-order effects
- Roughly 724K victims of the 2015 breach lose their primary fraud-protection tool mid-filing season, since the IRS has shut down the only way to retrieve an IP PIN online.
Second-order effects
- Fraudulent-return attempts will shift toward the remaining channels — including the electronic filing PIN system already shown to leak 100,000 PINs — putting pressure on the IRS to suspend or re-architect that pathway too before peak filing volume.
Third-order effects
- If knowledge-based authentication keeps failing against data thieves who already hold SSNs and birth dates, the IRS's remediation strategy collapses into a cycle of patch-and-suspend, forcing a move toward out-of-band identity verification rather than question-and-answer gatekeeping.
The trend: Government identity-proofing built on static personal data is failing repeatedly against attackers who already possess that data, pushing agencies toward suspending self-service features faster than they can replace them.