Security

US taxmen pull plug on anti-identity-theft system used by identity thieves

That's not how this works, that's not how any of this works

By Iain Thomson in San Francisco

28 SHARE

The US Internal Revenue Service (IRS) has suspended its Identity Protection PIN tool, designed to safeguard people at risk from identity theft, because scammers are using it for identity theft.

American taxpayers can request a six-digit PIN code from the IRS that is supposed to lock down their account with the taxmen: no valid code, no login. When the IRS admitted last month that 700,000 people's old tax returns – which are full of sensitive personal information – had been sent to scammers, it enrolled those affected in the PIN system.

In total this year, the IRS has issued 2.7 million PIN codes. But the scammers got wise, and used 800 of them to file fraudulent tax returns to redirect people's refunds to the criminals' bank accounts. Now the IRS has stopped the system.

"As part of its ongoing security review, the Internal Revenue Service temporarily suspended the Identity Protection PIN tool on IRS.gov," the agency said in a statement.

"The IRS is conducting a further review of the application that allows taxpayers to retrieve their IP PINs online and is looking at further strengthening the security features on the tool."

The problem appears to stem from PIN codes issued by the IRS website. Applicants have to answer four questions about themselves to get a number, but if the scammer already has some of their personal data, and does some digging online, then they can guess the answers, get the code, and file a fraudulent return.

The IRS is in something of a bind with this one. On the one hand, its security systems need work, but on the other it is the logical target for scammers because, to quote bank robber Willie Sutton, "that's where the money is." ®

Sign up to our NewsletterGet IT in your inbox daily

28 Comments

More from The Register

Facebook stuck with IRS bill after court tosses $7 BEEELLION appeal

Not even Zuckerberg can escape the tax man

It's US Tax Day, so of course the IRS's servers have taken a swan dive

Updated 59% of our systems are obsolete, agency boss tells congressional hearing

They forked this one up: Microsoft modifies open-source code, blows hole in Windows Defender

Rar! That's a scary bug

Microsoft loves Linux so much its R Open install script rm'd /bin/sh

Machine-learning suite ends its sloppy packaging ways after Debian dev roasts Redmond

Open Source Security hit with bill for defamation claim

Judge okays $260K in defense costs to Bruce Perens and lawyers under anti-SLAPP

Open source community crams itself into big tent

Can't we just get along? At a sunny California inn with hors d'oeuvres, most definitely

Finally: Historic Eudora email code goes open source

'Member that innocent, pre-Zuckerberg time?

Seagate's Barracuda SSD bares its teeth at PC, laptop upgraders

SATA flash drives to put low-cap disk on endangered list

I got 257 problems, and they're all open source: Report shines light on Wild West of software

It's like a jungle sometimes, it makes me wonder how I keep from going under

No pain, no $1.3bn Bain gain: Seagate slips Tosh/WD chippery into Nytro SSD ranges

NAND that... is how you get skin in the flash game