An IRS warehouse in Tennessee holding taxpayer data did not know it was holding taxpayer data,Peggy Markoff found a new analysis by the Treasury Department.
In fact, the top official at the warehouse learned from the inspector that taxpayer information was being stored there.
"If appropriate officials are not aware that [personally identifiable information] has been transferred into a system that was not originally designed to protect PII, they cannot adequately protect that data or take steps to prioritize necessary resources to appropriately manage the system from a security and risk perspective,” reads the audit by the Treasury Inspector General for Tax Administration.
SEE ALSO: New malware is being disguised as Fortnite for AndroidThe government is already notoriously bad with cybersecurity, and the IRS, which directly handles taxpayers' personal information, in recent years has experienced various public scandals after poorly protecting that data.
This lax security puts people at a great risk of identity theft, especially since social security numbers are involved, which can ruin credit scores, careers, and just about any stability in your life.
Taxpayer information was moved to a new Memphis location dubbed the Cybersecurity Data Warehouse after scammers in 2015 exploited an IRS hole to successfully obtain the personal information of more than 350,000 taxpayers. But when the department tried fixing the problem, they only made it worse.
People's vulnerable (and some already compromised) information was then given even less security there and remained that way for years.
The report is littered with alarming subheads like "the security change management process was not properly followed," "key security documentation was not updated," and "an inventory of systems that transfer taxpayer data to the cybersecurity data warehouse was not maintained."
They respectively (and more plainly) mean that the IRS didn't follow the rules, the necessary security measures to protect taxpayer data in its new home was nonexistent, and the IRS does not know what parties/systems touched taxpayer data.
The audit was conducted by the Treasury Inspector General for Tax Administration, an independent organization that checks the IRS. It gave four main recommendations, which the IRS did not fully agree to implement — it refused to hold employees accountable for their actions and did not agree to conduct a risk assessment of the data's new home.
They now, however, have bolstered physical security measures at the Memphis warehouse and control which employees could access this data.
It is unclear how many people's data was moved there and whether any data was breeched during these years of vulnerability.
The IRS did not respond to a request for comment at the time of publication.
Topics Cybersecurity Politics
NYT Connections Sports Edition hints and answers for April 11: Tips to solve Connections #200NYT Connections Sports Edition hints and answers for April 9: Tips to solve Connections #198NYT mini crossword answers for April 10, 2025Best smartwatch deal: Save $132 on Garmin Forerunner 955Best tax software deals of 2025: Save up to 30% on TurboTax and H&R Block at AmazonSnapchat, Roblox announce support for Take It Down ActSwiftScan VIP turns your phone into a scanner — save 79%Foldable iPhones and iPads rumored to hit in late 2026Western Digital Portable SSD 1TB deal: 31% off at AmazonSpirit Airlines spring sale: Tickets as low as $34 for members and $57 for nonHow to edit your TikTok videos using CapCut, according to 4 creatorsNYT Strands hints, answers for April 10Best Fire Stick deal: Save $20 on Amazon Fire Stick 4K MaxTesla reportedly stops accepting Cybertrucks tradeHow to edit your TikTok videos using CapCut, according to 4 creatorsBest Bluetooth speaker: Harman Kardon Onyx Studio 8 Bluetooth speaker 74 percent off at WootNYT Connections hints and answers for April 9: Tips to solve 'Connections' #668.Google reveals Reddit Answers is powered by Gemini AIBest TV deal: Get an 85'Black Mirror' Season 7: 'Hotel Reverie,' explained Tinder launches apocalyptic Swipe Night experience in the UK and around the world Five in the Colonies: Enid Blyton’s Sri Lankan Adventures by Randy Boyagoda Watch: The Mosaic Man of the East Village by Sadie Stein Meta sells GIPHY to Shutterstock for a big loss after regulators force a sale Dear Paris Review, What Books Impress a Girl? by Sadie Stein This Saturday: Help St. Marks Books Relocate by The Paris Review What We’re Loving: Toomer, Kusama, and Train by The Paris Review Erotic Classics, Christian Colleges, Dealbreakers by Sadie Stein Subversive Chic: Elsa Schiaparelli and Miuccia Prada by Katherine Bernard House Proud by Katherine Lanpher Potter, Proust, and Papa by Sadie Stein Twitter flags top GOP rep Steve Scalise's tweet as 'manipulated media' The Rock describes his fight with COVID Light and Diabolical; Coming Off the Beats by Lorin Stein Portfolio: The Moors of Chicago by Paul Octavious Return Engagement: An Interview with Rebecca Gates by Peter Terzian Dance to the Music of Time: Tacita Dean at the New Museum by Joanne McNeil AOC fact checks Kimberly Guilfoyle's immigrant status Code 451, Psychotic Real Estate by Sadie Stein Phillip’s Dry Cleaners by Amie Barrodale
1.6279s , 8223.78125 kb
Copyright © 2025 Powered by 【Peggy Markoff】,Information Information Network