Congress

House speaker criticizes IRS cybersecurity

tax form and keyboard

The Office of the Speaker of the House posted a scathing blog entry criticizing the IRS for not getting all its security controls in order in time for tax season.

"Right now, as you’re sending the IRS just about everything there is to know about you, it remains highly vulnerable to hackers and cyberattacks," Michael Shapiro, communications adviser to House Speaker Paul Ryan, wrote in the March 30 post. "And the agency has no intention of doing anything about it."

In a report released March 28, the Government Accountability Office issued 43 recommendations for the IRS to patch its information security vulnerabilities. GAO found that weaknesses in security controls threaten to compromise taxpayers’ sensitive data. Of the 12 systems GAO reviewed, two lacked critical patches.

The blog post accuses the IRS of “the usual excuses and evasions” in response to the report and calls for the agency to take steps to implement the recommendations and report back to Congress on its progress.

The IRS implemented an automated tool to manage password requirements, but several systems did not force periodic password resets despite an IRS policy mandating new passwords every 90 days for user accounts and every year for service accounts.

In early March, the IRS suspended its Identity Protection Personal Identification Number retrieval tool over concerns that it could be vulnerable to hackers.

In 2015, hackers might have accessed more than 700,000 taxpayer accounts and targeted another 576,000 accounts unsuccessfully, according to an inspector general investigation

About the Author

Bianca Spinosa is an Editorial Fellow at FCW.

Spinosa covers a variety of federal technology news for FCW including workforce development, women in tech, and the intersection of start-ups and agencies. Prior to joining FCW, she was a TV journalist for more than six years, reporting local news in Virginia, Kentucky, and North Carolina. Spinosa is currently pursuing her Master’s degree in Writing at George Mason University, where she also teaches composition. She earned her B.A. from the University of Virginia.

Click here for previous articles by Spinosa, or connect with her on Twitter: @BSpinosa.


Featured

  • Defense
    Ryan D. McCarthy being sworn in as Army Secretary Oct. 10, 2019. (Photo credit: Sgt. Dana Clarke/U.S. Army)

    Army wants to spend nearly $1B on cloud, data by 2025

    Army Secretary Ryan McCarthy said lack of funding or a potential delay in the JEDI cloud bid "strikes to the heart of our concern."

  • Congress
    Rep. Jim Langevin (D-R.I.) at the Hack the Capitol conference Sept. 20, 2018

    Jim Langevin's view from the Hill

    As chairman of of the Intelligence and Emerging Threats and Capabilities subcommittee of the House Armed Services Committe and a member of the House Homeland Security Committee, Rhode Island Democrat Jim Langevin is one of the most influential voices on cybersecurity in Congress.

Stay Connected

FCW INSIDER

Sign up for our newsletter.

I agree to this site's Privacy Policy.