Equifax

March 7, 2016

IRS Suspends Insecure ‘Get IP PIN’ Feature

This post was originally published on this site Citing ongoing security concerns, the Internal Revenue Service (IRS) has suspended a service offered via its Web site that allowed taxpayers to retrieve so-called IP Protection PINs (IP PINs), codes that the IRS has mailed to some 2.7 million taxpayers to help prevent those individuals from becoming victims of tax refund fraud two years in a row. The move comes just days after KrebsOnSecurity first exposed how ID thieves were abusing the service to revisit tax refund on innocent taxpayers two years running. Last week, this blog told the story of Becky Wittrock, […]
March 14, 2016

From Stolen Wallet to ID Theft, Wrongful Arrest

This post was originally published on this site It’s remarkable how quickly a stolen purse or wallet can morph into full-blow identity theft, and possibly even result in the victim’s wrongful arrest. All of the above was visited recently on a fellow infosec professional whose admitted lapse in physical security lead to a mistaken early morning arrest in front of his kids. The guy police say stole Miller’s wallet and got him wrongfully arrested was himself apprehended earlier this month. On the morning of Feb. 20, Lance Miller was arrested in front of his two children by local sheriffs in Golden, […]
June 10, 2016

IRS Re-Enables ‘Get Transcript’ Feature

This post was originally published on this siteThe Internal Revenue Service has re-enabled a service on its Web site that allows taxpayers to get a copy of their previous year’s tax transcript. The renewed effort to beef up taxpayer authentication methods at irs.gov comes more than a year after the agency disabled the transcript service because tax refund fraudsters were using it to steal sensitive data on consumers. During the height of tax-filing season in 2015, KrebsOnSecurity warned that identity thieves involved in tax refund fraud with the IRS were using irs.gov’s “Get Transcript” feature to glean salary and personal information they […]
August 16, 2016

SSA: Ixnay on txt msg reqmnt 4 e-acct, sry

This post was originally published on this siteThe U.S. Social Security Administration says it is reversing a newly enacted policy that required a cell phone number from all Americans who wished to manage their retirement benefits at ssa.gov. The move comes after a policy rollout marred by technical difficulties and criticism that the new requirement did little to prevent identity thieves from siphoning benefits from Americans who hadn’t yet created accounts at ssa.gov for themselves. In an announcement last month, the SSA said all new and existing ‘my Social Security’ account holders would need to provide a cell phone number. The SSA said […]