Skip to main content

IRS hack affects 100,000 Americans, Russia may be to blame

Hacker
hamburg_berlin/Shutterstock
As if there weren’t already enough reasons to resent the IRS, the agency that houses more of your personal information than most has announced that a data breach has compromised the sensitive data of around 100,000 taxpayers. The Internal Revenue Service is the latest organization to fall victim to a cyberattack, and somehow, experienced hackers managed to make away with a considerable amount of information that could be used to steal identities and claim fraudulent tax refunds.

On Wednesday, CNN reported that it is now believed that Russian hackers were behind the attacks, which were carried out from February to around mid-May. In order to access the accounts of the affected individuals, the hackers needed to have the name, Social Security number, date of birth, filing status (single, married, etc.) and street address of the victim, and then had to answer a security question, the kind that is often branded as one “that only you can answer.”

But as was reported last week, many of these questions are not so difficult to answer at all, and of the 200,000 accounts that hackers attempted to gain access to, they managed a 50 percent success rate, ultimately breaking into 100,000 user accounts. As Elizabeth Weise of USA Today points out, the relative ease with which hackers managed to steal personal information is indicative of a more insidious problem with data — once you have a little, it’s easy to get a lot.

In fact, much of the most sensitive information, like social security numbers, birthdays, and addresses, were obtained before the hackers ever made it to the IRS by way of third parties. And ultimately, the IRS admits, it is possible that the cybercriminals ultimately left with their victims’ full tax returns, including line-by-line descriptions of their wage, income, tax liabilities, and more.

The IRS will be sending letters to all affected parties, and for those whose information was compromised, will also be paying for credit monitoring. The Department of Homeland Security is also investigating the attack, so at the very least, taxpayers can be assured that no one is taking this matter lightly.

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
A dangerous new jailbreak for AI chatbots was just discovered
the side of a Microsoft building

Microsoft has released more details about a troubling new generative AI jailbreak technique it has discovered, called "Skeleton Key." Using this prompt injection method, malicious users can effectively bypass a chatbot's safety guardrails, the security features that keeps ChatGPT from going full Taye.

Skeleton Key is an example of a prompt injection or prompt engineering attack. It's a multi-turn strategy designed to essentially convince an AI model to ignore its ingrained safety guardrails, "[causing] the system to violate its operators’ policies, make decisions unduly influenced by a user, or execute malicious instructions," Mark Russinovich, CTO of Microsoft Azure, wrote in the announcement.

Read more