Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 17 submissions in the queue.
posted by martyb on Thursday April 16 2015, @12:55PM   Printer-friendly
from the gone-phishin' dept.

If you filed your IRS (US Internal Revenue Service) income tax forms through someone else, and that list gets into the hands of phishers, do you think you could detect it?

A lot of people fall for this. Hard. Gizmodo reports:

A lot of people are falling for them: A study of 150,000 phishing emails by Verizon partners found that 23 percent of recipients open phishing messages, and 11 percent open attachments. Is that not crazy? One in 10 people opens an attachment when they have no idea what they’re opening.

And it happens fast: It takes an average of 82 seconds from the time a phishing campaign is launched, until the first sucker bites. And this isn’t just phishing in people’s Gmail accounts. It’s happening on sensitive business and government accounts where the targets should theoretically know better.

Another article in Wired is reporting:

Typically, it takes months if not years to uncover a breach. In 2012, for example, FireEye reported that the average cyber-espionage attack continued unabated for 458 days before the victim discovered the hack.

[More after the break.]

I have received numerous phishing emails. So far, I have recognized them because I knew the people I am dealing with and when something outlandish comes up, I call 'em. However, these days, who knows anybody at these big, monolithic, and automated tax-collection centers, and who wants to take the risk that an ignored IRS email is indeed fake?

I have been holding out as long as I can against having anything to do with the government on the internet. I flat out do not trust the internet when it comes to email. Any of us can tell if it's some casual friend chitchat, but when mail arrives looking like it's from your bank and money is involved, it gets noticed. With the the advent of things like Electronic Funds Transfer, things can happen behind our back, and we ignore the email at our peril....

Many of us here know just how easy it is to make an extremely legitimate looking business email. It would really bother me to receive demands from compliance from some entity purporting to represent the IRS via email, with no way for me to know for sure it's bogus without taking the bait.

How many of you filed your IRS returns electronically? How do you protect yourself from phishing attacks?

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Interesting) by GungnirSniper on Thursday April 16 2015, @03:00PM

    by GungnirSniper (1671) on Thursday April 16 2015, @03:00PM (#171611) Journal

    I tried doing my own taxes this year and used the IRS FreeFile site. It doesn't have a business logic check until after you submit. Twenty to thirty minutes later you get an email saying if it worked or not. Here's some of the post-mortem emailed errors, the links aren't clickable:

    Issue : Business Rule X0000-005 - The XML data has failed schema validation. cvc-complex-type.2.4.d. Invalid content was found starting with element 'LifetimeQualifiedExpensesAmt'. No child element is expected at this point.

    The following information may help you determine the form at issue:
    Field/Xpath: /efile:Return[1]/efile:ReturnData[1]/efile:IRS8863[1]/efile:StudentAndEducationalInstnGrp[1]/efile:LifetimeQualifiedExpensesAmt[1]

    So I fixed that by deleting a line item, and retried:

    Issue : Business Rule F1040A-297 - If Form 1040A, Line 19 'TuitionAndFeesDedAmt' has a non-zero value and Line 2 checkbox "Married filing jointly" is not checked (element 'IndividualReturnFilingStatusCd' does not have the value 2), then Line 6a 'ExemptPrimaryInd' must be checked.

    The following information may help you determine the form at issue:
    Field/Xpath: /efile:Return/efile:ReturnData/efile:IRS1040A

    Issue : Business Rule F8917-001 - Each 'StudentSSN' on Form 8917, Line 1b must not be equal to 'StudentSSN' on Form 8863, Line 21.

    The following information may help you determine the form at issue:
    Field/Xpath: /efile:Return/efile:ReturnData/efile:IRS8917/efile:Student/efile:StudentSSN

    And again after playing wack-a-mole:

    Issue : Business Rule F8917-001 - Each 'StudentSSN' on Form 8917, Line 1b must not be equal to 'StudentSSN' on Form 8863, Line 21.

    The following information may help you determine the form at issue:
    Field/Xpath: /efile:Return/efile:ReturnData/efile:IRS8917/efile:Student/efile:StudentSSN

    So while it's pretty cool they have this stuff online, it's also wonky. The help information is still in PDF form so you can't reference specifics in a single window.

    I make just a little too much money to qualify for the free software downloads, so it was this FreeFile site or paper forms.

    From the Massachusetts site, which worked better:

    Optional Tax Rate
    I would like to voluntarily pay tax at the increased rate of 5.85%: [empty checkbox]

    Starting Score:    1  point
    Moderation   +1  
       Interesting=1, Total=1
    Extra 'Interesting' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 0) by Anonymous Coward on Thursday April 16 2015, @08:28PM

    by Anonymous Coward on Thursday April 16 2015, @08:28PM (#171719)

    Of course it's wonky. It's designed that way. That's what you get when teams of bureaucrats (both government and corporate) work with no oversight and with the explicit purpose to separate the underclasses from their money.

  • (Score: 2) by el_oscuro on Friday April 17 2015, @12:55AM

    by el_oscuro (1711) on Friday April 17 2015, @12:55AM (#171809)

    So you are getting the actual XML errors? The IRS might as well post their DBA passwords on the front page of their website.

    --
    SoylentNews is Bacon! [nueskes.com]
  • (Score: 1) by anubi on Friday April 17 2015, @01:58AM

    by anubi (2828) on Friday April 17 2015, @01:58AM (#171843) Journal

    Your experience is exactly why I try to avoid "high tech" transactions. I got the same type of gibberish trying to sign up for healthcare.

    Just a whole bunch of pages that did not work. Dead links or required technology my browser does not have, or crap that would not make it through the corporate firewall.

    I gave up and paid the $95 "responsibility fee".

    Isn't there some way I can hold the ones forcing us to read and agree to all this stuff accountable as well?

    You don't know how bad I would like to shanghai those congresscritters that voted this thing into existence and have them show me how to run it.

    This runaway lawmaking to me is the prime reason we have to have a *major* housecleaning in Congress... and that means not voting for either of the ones the "party" puts up. We have to find one of our own to support, not one of "theirs". These party guys tell us they will "fight for us", but those words coming from a politician, and just about as solid as those styrofoam hats they wear when the red, white, and blue bunting is displayed every election cycle. We have 99% of the vote and its high time we stop voting the way the 1%'ers tell us to vote.

    --
    "Prove all things; hold fast that which is good." [KJV: I Thessalonians 5:21]