IRS breached, hackers access data of more 100,000 taxpayers

The Internal Revenue Service (IRS) was breached by hackers that “used an online service provided by the agency” to access data for more than 100,000 taxpayers.

According to the Associated Press, the Internal Revenue Service (IRS) suffered a data breach, hackers “used an online service provided by the agency” to access data for more than 100,000 taxpayers.

The IRS issued an official statement on the incident and specified that the compromised system was “Get Transcript.” The Transcript service could be used by taxpayers to get a transcript online or by mail to view their tax account transactions.

The Get Transcript Online feature of IRS.gov allows taxpayers to get “tax account transactions, line-by-line tax return information or wage and income reported to us for a specific tax year,” according to the official page of the IRS.

In order to obtain a transcript online, the users have to provide a Social Security number and an active e-mail address. Once the e-mail address was confirmed as legitimate, the IRS procedure requests a number of questions about personal, financial, and tax information of the users before making the transcript available for the download.

The hackers bypassed the security screen requiring user information such as SSN, date of birth, and street address in order to access taxpayers’ data.

The IRS counted more than 200,000 attempts, about half of them were successful. The IRS has temporarily interrupted the service, explained that the service was targeted by the hackers in a two-month period between February and mid-May.

“The online Get Transcript service is currently unavailable. Transcripts may still be ordered using the Get Transcript by Mail service. We apologize for any inconvenience.” states the message on the IRS page.

“In all, about 200,000 attempts were made from questionable email domains, with more than 100,000 of those attempts successfully clearing authentication hurdles,” an IRS spokesperson said in a statement to reporters. “During this filing season, taxpayers successfully and safely downloaded a total of approximately 23 million transcripts.”

The Government Office hasn’t provided further details on the attack neither revealed how hackers bypassed authentication mechanisms.login screen has not been revealed at this time. In March 2015, the popular security expert Brian Krebs reported for first the risks related to the access for the IRS’ transcript service.

The expert explained that someone had already registered through the IRS’s site using his Social Security number and an unknown email address. The hackers had used the personal information of the taxpayers to get a refund direct deposit.

“If you’re an American and haven’t yet created an account at irs.gov, you may want to take care of that before tax fraudsters create an account in your name and steal your personal and tax data in the process.” worte Krebs on this blog.

 

The process of authentication implemented by the IRS service is based on the knowledge of user personal information (knowledge-based authentication) that never changes making possible for an attacker to gain them in various ways.

SSN numbers, for example, along with other PII are easy to acquire in the various black markets, recent data breaches of Anthem and CareFirst have made available on the market data related to million customers.

“The IRS is continuing to conduct further reviews on those instances where the transcript application was accessed, including how many of these households filed taxes in 2015. It’s possible that some of these transcript accesses were made with an eye toward using them for identity theft for next year’s tax season,” a statement form the IRS explained.

Pierluigi Paganini

(Security Affairs –  IRS, data breach)

Pierluigi Paganini

Pierluigi Paganini is member of the ENISA (European Union Agency for Network and Information Security) Threat Landscape Stakeholder Group and Cyber G7 Group, he is also a Security Evangelist, Security Analyst and Freelance Writer. Editor-in-Chief at "Cyber Defense Magazine", Pierluigi is a cyber security expert with over 20 years experience in the field, he is Certified Ethical Hacker at EC Council in London. The passion for writing and a strong belief that security is founded on sharing and awareness led Pierluigi to find the security blog "Security Affairs" recently named a Top National Security Resource for US. Pierluigi is a member of the "The Hacker News" team and he is a writer for some major publications in the field such as Cyber War Zone, ICTTF, Infosec Island, Infosec Institute, The Hacker News Magazine and for many other Security magazines. Author of the Books "The Deep Dark Web" and “Digital Virtual Currency and Bitcoin”.

Recent Posts

Fintech firm Figure disclosed data breach after employee phishing attack

Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…

20 hours ago

U.S. CISA adds a flaw in BeyondTrust RS and PRA to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…

21 hours ago

Suspected Russian hackers deploy CANFAIL malware against Ukraine

A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…

1 day ago

New threat actor UAT-9921 deploys VoidLink against enterprise sectors

A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…

2 days ago

Attackers exploit BeyondTrust CVE-2026-1731 within hours of PoC release

Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…

2 days ago

Google: state-backed hackers exploit Gemini AI for cyber recon and attacks

Google says nation-state actors used Gemini AI for reconnaissance and attack support in cyber operations.…

2 days ago

This website uses cookies.