What happened
In August 2015 the IRS disclosed that criminals had successfully retrieved prior-year tax transcripts for roughly 334,000 taxpayers through its online Get Transcript service, having attempted access against about 610,000 taxpayers. The Treasury Inspector General later put the potentially compromised total higher. Attackers defeated the service's knowledge-based authentication rather than breaching IRS systems.
How the deception worked
Get Transcript authenticated the requester with a name, date of birth, Social Security number and filing status, followed by four multiple-choice knowledge-based questions supplied by a credit bureau about matters such as previous addresses and loan amounts. Criminals already holding identity data from earlier breaches supplied the first tier and then guessed or looked up the multiple-choice answers, which were drawn from commercially available credit-header data. Success rates exceeded half of attempts. A retrieved transcript contains the prior year's income and withholding detail, which is exactly what is needed to file a convincing fraudulent refund claim.
AI involvement · No AI reported
No AI involvement; attackers answered static knowledge-based questions.
The control that would have caught it· our reading, not a claim from the sources
Static knowledge-based authentication should not gate access to sensitive government records once bulk consumer data is in criminal hands; identity proofing needs a possession or biometric factor.
Sources (1)
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.