Live data from Hacker News

IRS says thieves stole tax info from 100,000

washingtonpost.com

91–100 of 106 posts

Re: IRS says thieves stole tax info from 100,000

#91
post #56

I believe that this actually happened to me -- which tells me the 100,000 number is way too low. To be more precise: when we went to electronically file our 2014 return, it was rejected because our return had already been filed (not by us, of course). I (like 80+ million others) am a victim of the Anthem breach, and I have assumed that my fraudulent return was part of that breach. (Regardless, I have opted into the i…

It's in the second paragraph of the article. They used a Get Transcript web form to get your prior year tax form from the info they had from the Anthem breach.

Which effectively confirmed what we already knew which is that the Anthem breach was made more damaging by the ease by which criminals can file a fake return for you.

Re: IRS says thieves stole tax info from 100,000

#92
post #83

Earlier quoted context omitted.

If you properly protect your security number, which requires some monthly commitment (such as $15 lifelock, or freecreditreport $5 per month), you can pretty much post your SSN online and really not much will happen. Any time someone uses it, you will get the alert and chance to act (stop the inquiry before it hit hard). It just that most people believe that not making their SSN public is enough for it to be safe.

1) There are free sites to monitor your credit such as Credit Karma. No need to pay hundreds a year. They even send out emails whenever you open up a new line of credit. Lifelock is a huge scam and has been fined by the FTC. 2) Just being alerted when someone else opens up credit in your name is hardly "protection." They still opened up credit in your name and you have to deal with that which is at the very very leas…

> I've had my identity stolen and I can tell you,it is truly awful.

You and half of America. You know how many people are in Anthem's system?

Re: IRS says thieves stole tax info from 100,000

#93

Something is wrong with the wording here. Thieves stole the tax info of 100,000 but they stole it from the IRS. Make no mistake: IRS needs to be held responsible for this. It is their fault.

So when the victim is someone you don't like, it's somehow their fault?? The fault should be with the person/people that stole the tax information, not the IRS. Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.

Shouldn't that work with companies as well, not just IRS?

Take for example some large corporations. I.e. if Amazon or Google stores their customer information carelessly, and someone steals it - then Amazon would be victim, and if you say that they should have protected the information, you are blaming the victim because you don't like them?

The American revenue service has even larger resources and also a larger responsibility than even the largest of multinational corporations. They should be held accountable for what they do (like the tax officials in any country).

Re: IRS says thieves stole tax info from 100,000

#94
post #5

Krebs wrote about this in March: http://krebsonsecurity.com/2015/03/sign-up-at-irs-gov-before... He has some good advice; claim your account before someone else does.

Yeah, I saw it then and got PDF's of all prior year taxes. Info needed was suprisingly little. I had way more trouble changing the first password I used than I did setting up my account in the first place.

Re: IRS says thieves stole tax info from 100,000

#96
post #54

Earlier quoted context omitted.

You can look at it from the other side too, maybe Americans are putting too much weight on the SSN. I could practically post my Spanish ID number next to my name online and nothing would probably happen. As a matter of fact, a stupid regional government agency posted it next to my name in 2011 and it's been up ever since.

Possible solution: require everyone to generate and register (in-person) public keys, which tax returns need to be signed with.

It's even more of an hassle for your average user because he cannot change computer anymore to fill taxes, it has already been tried & dropped.

Re: IRS says thieves stole tax info from 100,000

#97
post #89

I believe that this actually happened to me -- which tells me the 100,000 number is way too low. To be more precise: when we went to electronically file our 2014 return, it was rejected because our return had already been filed (not by us, of course). I (like 80+ million others) am a victim of the Anthem breach, and I have assumed that my fraudulent return was part of that breach. (Regardless, I have opted into the i…

Unbelievable that the IRS would have this "Get Transcript" feature readily available via the web without any password, or better two-factor authentication. It's already been taken offline, but was up for a long time. Will there be punitive lawsuits against the IRS as there were for Target and likely will be for Anthem?

I think the hackers were attacking the initial sign-up, not already created accounts. So I don't see how you could use 2FA.

Re: IRS says thieves stole tax info from 100,000

#98

Earlier quoted context omitted.

So when the victim is someone you don't like, it's somehow their fault?? The fault should be with the person/people that stole the tax information, not the IRS. Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.

Perhaps, but what I can blame them for is for having very poor monitoring (50% failure rate and nobody noticed??) and poor security, culminating in this data breach. People need to be held accountable for the security of their systems when they are storing personally identifiable information on customers or the public at large. Edit: Perhaps they shouldn't be blamed when someone leverages a zero-day to break in, but…

50% failure rate is probably pretty normal for a form asking for SSN, name, address, and birth date - I fail my bank's security questions at least 1/3 of the time because things like "Anywhere Street" and "Anywhere St" are not the same.

Re: IRS says thieves stole tax info from 100,000

#99

Earlier quoted context omitted.

"Kasper said the detective learned that money was deposited into her account, and that she sent the money out to locations in Nigeria via Western Union wire transfer, keeping some as a profit, and apparently never suspecting that she might be doing something illegal." I am having a really tough time believing she never suspected she was doing something illegal.

> I am having a really tough time believing she never suspected she was doing something illegal. Why? People fall for the "I have $20 million for you, I just need a few hundred bucks to do the paperwork" scam all the time.

I'm a little shocked a college student fell for it. I would have a tough time hiring such a person because they would be a serious security risk.

Re: IRS says thieves stole tax info from 100,000

#100

Earlier quoted context omitted.

So when the victim is someone you don't like, it's somehow their fault?? The fault should be with the person/people that stole the tax information, not the IRS. Blaming the IRS would be like blaming a home owner for not installing a good enough security system when they get robbed instead of the criminals.

Shouldn't that work with companies as well, not just IRS? Take for example some large corporations. I.e. if Amazon or Google stores their customer information carelessly, and someone steals it - then Amazon would be victim, and if you say that they should have protected the information, you are blaming the victim because you don't like them? The American revenue service has even larger resources and also a larger res…

"and if you say that they should have protected the information, you are blaming the victim because you don't like them?"

If we only blamed Amazon in your example, then yes, we would only be blaming the victim.

How do we know they were "careless"?? They could have been using all of the correct security precautions and still got the data stolen.

It could have been an employee that installed malware because they fell for a phishing attack. Should they also be brought up on charges?

If my HN account gets compromised, should PG get brought up on charges? After all, he was supposed to protect my data, right?

Why aren't we even discussing the hackers that stole the data? Is it because they are supported here on HN?

Post reply on HN