Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityCybersecurity News

COVID-19 Proves It’s Time for the IRS to Stop Identity Fraud at the Front Door

By Annie Bai
Security blog default
April 29, 2020

In light of the reports of theft of COVID-19 stimulus checks (which one headline called “​pure hell”​), it’s instructive to look back at recent breaches of IRS systems and processes. There’s a common thread in these publicized fraud attacks: inadequate identity proofing. To get a stimulus check, the IRS has been asking people to provide an SSN, date of birth, tax filing status and street address. Unfortunately, much of that data has long been compromised and available for exploitation, and far too many Americans suffer as a result.

For years, as a privacy officer, I’ve tried to educate the public on the risks of stolen tax information and identity theft in general. I’ve alerted colleagues, friends, and the public about the “GetTranscript” account feature that opened the door to ​334,000 stolen tax refunds​, as well as the risks exposed in 2016 by the t​heft of over 100,000 e-file PINS​. Now, during the COVID-19 pandemic, it’s happening all over again.

For years, the GAO (G​overnment Accountability Office)​ has recommended that the IRA shore up its identity verification and authentication methods. In 2015, it said that ​enhanced authentication could combat refund fraud​, but that the agency was lacking useful estimates of the costs, benefits, and risks of taking on improvements. I​n 2016, the GAO got more specific:​ it pointed out that knowledge-based authentication (KBA) procedures, such as taxpayer questions and checks against third-party submitted information, might have caused over $200M in tax refund payouts to be issued to illegitimate recipients. The 2016 report also called out the IRS’ reliance on remote authentication as incentivizing fraudsters because of the ease of making high volumes of attempts. Then in 2018, the GAO spoke to the dire reality that ​identity proofing had become harder​ in the wake of massive data breaches of PII — including the breaches at the IRS.

I submit that the IRs’ woes are not to be solved by making authentication harder, but rather by looking to innovative identity verification. Recently, my colleague Rivka Little pointed out this flaw to CNBC, “The IRS is asking consumers for their mailing addresses, email addresses – it’s all appropriate information. But all of those points of data are out there; they’re already breached and attainable.”

The 2018 GAO report also concluded that the IRS had made insufficient progress in prioritizing authentication improvements, assessing and monitoring multi-channel risks and evaluating available authentication technologies. In spite of all these findings, the agency continues to rely upon a number of tried-and-failed methods that facilitate unauthorized access to taxpayer accounts:

  • Submission of PII (personally identifying information)
  • KBA (knowledge-based authentication) questions
  • PINs (personal identification numbers) that are mailed to taxpayers

They also use methods that are hackable and/or costly to carry out.

  • Multi-factor authentication such as OTP (one-time passwords) delivered via mobile phone SMS
  • Submission of identity documents in person or via correspondence

If the IRS has already lamented that “ the sources of stolen identities are limitless,” — including the answers to KBA questions — then why do they continue to ask taxpayers to use these compromised sources to prove themselves?

What will it take for things to change? In short, the IRS needs to reboot its whole paradigm and stop putting the burden of identity proofing on the individual.

With a few simple inputs from the purported taxpayer, it is possible to independently judge the veracity of the soul that is on the other side of the Internet from you. Best-in-class solutions look at boatloads of online and offline data. They correlate that data with device and browser intelligence. They study the data to surface insights into all manner of fraudsters and fraudulent methods. They use artificial intelligence’s machine learning techniques. They iterate and improve to keep pace with developments on the fraudsters’ side. They are automated. So instead of asking more and more of genuine taxpayers, the IRS can ask for less but get better determinations as to the authenticity of requests for access.

It’s entirely possible to effectuate this paradigm shift because it’s already happened for most modern financial services organizations. They use data-driven solutions to catch fraud, improve automatic acceptance rates, comply with regulatory “know your customer (KYC)” obligations, and even to smooth out the consumer experience. ​The White House has urged governmental agencies to leverage AI​ ​to “help the Federal government work smarter in its own services and missions in trustworthy ways.” In addition to staunching the flow of fraud with stimulus payouts, there are more than 100 kinds of interactions between Americans and the IRS that require authentication and could benefit from ​smarter, ​technology-driven verification measures.

In the meantime, financial institutions will need to maintain laser-sharp focus in preventing COVID-19 stimulus funds from getting into fraudsters’ wallets. With hypervigilant money laundering and fraud prevention controls, FIs must do what they can to root out money mules and illegitimate transactions. While the IRS distributes these desperately needed checks, the banks can at least try to keep fraudulent checks from being cashed. All the while, we will be asking: ​IRS, Will you wake up to the new paradigm and deal with the root cause?

 

KEYWORDS: COVID-19 cyber security data breach fraud identity theft IRS pandemic

Share This Story

Annie1
Annie Bai is Global Privacy Lead at Socure. She is a privacy and data security lawyer with deep experience in assessing privacy and cyber risks. At Socure her responsibilities include privacy program management, technology law guidance, data security and IT governance compliance, as well as assessing emerging global data flows, privacy/cyber laws and regulations, big data and predictive analytics, and cybersecurity trends. She holds a law degree from New York University, is a certified Information Privacy Professional/US, a certified Information Privacy Manager, and a Fellow of Information Privacy of the IAPP.

Blog Topics

Security Blog

On the Track of OSAC

Blog Roll

Security Industry Association

Security Magazine's Daily News

SIA FREE Email News

SDM Blog

Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

Popular Stories

Rendered computer with keyboard

16B Login Credentials Exposed in World’s Largest Data Breach

Verizon on phone screen

61M Records Listed for Sale Online, Allegedly Belong to Verizon

Security’s 2025 Women in Security

Security’s 2025 Women in Security

Red spiderweb

From Retail to Insurance, Scattered Spider Changes Targets

blurry multicolored text on black screen

PowerSchool Education Technology Company Announces Data Breach

2025 Security Benchmark banner

Events

July 17, 2025

Tech in the Jungle: Leveraging Surveillance, Access Control, and Technology in Unique Environments

What do zebras, school groups and high-tech surveillance have in common? They're all part of a day’s work for the security team at the Toledo Zoo.

August 7, 2025

Threats to the Energy Sector: Implications for Corporate and National Security

The energy sector has found itself in the crosshairs of virtually every bad actor on the global stage.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!