It took the IRS a few months to uncover the full scope of last year’s Get Transcript application breach but it’s taking the agency even longer to inform all the affected taxpayers.
A newly released report from the Treasury Inspector General for Tax Administration (TIGTA) shows the agency neglected to send notices to almost 2,500 taxpayers, failed to put incident markers — warning of potential identity theft — on 3,200 accounts and have yet to offer secure identity protection personal identification numbers (IP PIN) and credit monitoring to more than 79,000 affected persons.
“TIGTA is concerned that the lack of prompt action on this issue leave these taxpayers’ accounts at an increased risk of fraud,” according to the report.
In total, the hackers in last year’s breach accessed or attempted to access more than 943,000 tax returns through the app, the bulk of which — more than 620,000 — went unidentified for months until TIGTA investigators conducted a full audit of the incident.
The IG offered eight recommendations, mostly urging the IRS to provide the information and services for the previously mentioned groups. IRS officials agreed with all but one of those recommendations, pushing back against the need to issue IP PINs, which they didn’t deem as necessary since the hackers only attempted to access those 79,000 accounts but were not successful.
“The information these thieves used to pass authentication was obtained from sources outside the IRS,” officials explained in the management response. “When they obtained additional information from an IRS system, the IRS provided the affected taxpayers with the appropriate mitigating protection. However, the population referenced in this recommendation is a different group and did not have any of their personal information exposed from IRS systems.”
While that decision conforms to IRS policy, officials admitted that policy might not be consistent across the board and might be in need of updating.
Since the issuance of the IG report, officials said the IRS has sent the appropriate letters to 2,400 taxpayers it initially missed and has plans to place incident markers on the 3,200 accounts identified by TIGTA.
The IRS has also taken steps to ensure a breach like this — in which hackers were able to dupe the knowledge-based authorization questions — doesn’t happen again.
The agency rolled out a new multi-factor identification system on June 7 that was developed in concert with the U.S. Digital Service team.




