IRS data breach bigger than previously thought
Loading...
| WASHINGTON
A computer breach at the US tax collecting agency in which thieves stole tax information from thousands of taxpayers is much bigger than the agency originally disclosed.
An additional 220,000 potential victims had information stolen from an Internal Revenue Service website as part of a sophisticated scheme to use stolen identities to claim fraudulent tax refunds, the聽IRS聽said Monday. The revelation more than doubles the total number of potential victims, to 334,000.
The breach also started earlier than investigators initially thought. The tax agency first disclosed the breach in May.
The thieves accessed a system called "Get Transcript," where taxpayers can get tax returns and other filings from previous years. In order to access the information, the thieves cleared a security screen that required knowledge about the taxpayer, including federal pension identification number, date of birth, tax filing status and street address, the聽IRS聽said.
The personal information was presumably stolen from other sources. The聽IRS believes the thieves were accessing the聽IRS聽website to get even more information about the taxpayers, which could help them claim fraudulent tax refunds in the future.
In all, the thieves used personal information from about 610,000 taxpayers in an effort to access old tax returns. They were successful in getting information from about 334,000 taxpayers.
The聽IRS聽isn't the first agency 鈥 public or private 鈥 to initially underestimate the magnitude of a data breach. The Office of Personnel Management announced earlier this year that hackers had stolen sensitive information on 4.2 million people. The number of affected people has since grown to more than 21 million.
The聽IRS聽said it is notifying all potential victims and offering free credit monitoring services. The聽IRS聽is also offering to enroll potential victims in a program that assigns them special ID numbers that they must use to file their tax returns.
The聽IRS聽said Monday that thieves started targeting the website in November. Originally, investigators thought it started in February. The website was shut down in May.
On Monday, the聽IRS聽did not identify a potential source of the crime. But in May, officials said聽IRS聽investigators believe the identity thieves are part of a sophisticated criminal operation based in Russia.