US taxmen pull plug on anti-identity-theft system used by identity thieves

That's not how this works, that's not how any of this works

By Iain Thomson in San Francisco


The US Internal Revenue Service (IRS) has suspended its Identity Protection PIN tool, designed to safeguard people at risk from identity theft, because scammers are using it for identity theft.

American taxpayers can request a six-digit PIN code from the IRS that is supposed to lock down their account with the taxmen: no valid code, no login. When the IRS admitted last month that 700,000 people's old tax returns – which are full of sensitive personal information – had been sent to scammers, it enrolled those affected in the PIN system.

In total this year, the IRS has issued 2.7 million PIN codes. But the scammers got wise, and used 800 of them to file fraudulent tax returns to redirect people's refunds to the criminals' bank accounts. Now the IRS has stopped the system.

"As part of its ongoing security review, the Internal Revenue Service temporarily suspended the Identity Protection PIN tool on," the agency said in a statement.

"The IRS is conducting a further review of the application that allows taxpayers to retrieve their IP PINs online and is looking at further strengthening the security features on the tool."

The problem appears to stem from PIN codes issued by the IRS website. Applicants have to answer four questions about themselves to get a number, but if the scammer already has some of their personal data, and does some digging online, then they can guess the answers, get the code, and file a fraudulent return.

The IRS is in something of a bind with this one. On the one hand, its security systems need work, but on the other it is the logical target for scammers because, to quote bank robber Willie Sutton, "that's where the money is." ®

Sign up to our NewsletterGet IT in your inbox daily


More from The Register

*taps on glass* Hellooo, IRS? Anyone in? Anyone guarding taxpayers' data from crooks? Hellooo?

Could someone slide a note on identity-theft protection under the door? Helloooo?

Facebook stuck with IRS bill after court tosses $7 BEEELLION appeal

Not even Zuckerberg can escape the tax man

Open-source this, open-source that, and the end of the Windows 10 Creators Update

Minecraft? In The Reg? Call the Brigadier!

Microsoft gets open-sourcey with Windows Forms and Windows Presentation Foundation

Connect(); .NET Foundation to become engorged, ONNX for all, and check out our bundles

Bethesda blunders, IRS sounds the alarm, China ransomware, and more

Roundup Plus, US Congress wants more cybersec training, better breach laws

'Pure technical contributions aren’t enough'.... Intel commits to code of conduct for open-source projects

Chipzilla joins strangely controversial movement to encourage civility, inclusion

It's US Tax Day, so of course the IRS's servers have taken a swan dive

Updated 59% of our systems are obsolete, agency boss tells congressional hearing

They forked this one up: Microsoft modifies open-source code, blows hole in Windows Defender

Rar! That's a scary bug

On the first day of Christmas, MIPS sent to me: An open-source-ish alternative to RISC-V

Well, if you pronounce it 'Vee' and not 'Five'... Anyway, instruction set to be touted under undisclosed license

IBM's Red Hat gobble: Storage will be a test of Big Blue's commitment to open-source software

Comment Bringing home the bacon