Identity Theft

Summer is around the corner and whether you are shopping online to get ready for a vacation or relaxing while on vacation and decide to indulge, BE AWARE!  Your financial information, tax information and Social Security number could be at risk. 

Cybercriminals want to turn stolen data into quick cash. They do this by draining financial accounts, charging credit cards, creating new credit accounts or even using stolen identities to file a fraudulent tax return for a refund.

Here are seven steps for taxpayers the IRS has provided, which can be followed to help protect their accounts and their money:

  • Avoid unprotected Wi-Fi. Unprotected public Wi-Fi hotspots may allow thieves to view transactions.  Think about hotel rooms, free Wi-Fi in restaurants and other public places.
  • Shop at familiar online retailers. Generally, sites using the “s” designation in “https” at the start of the URL are secure. User can also look for the “lock” icon in the browser’s URL bar. That said, some thieves can get a security certificate, so the “s” may not always vouch for the site’s legitimacy. Beware of purchases at unfamiliar sites or clicks on links from pop-up ads.
  • Learn to recognize and avoid phishing emails. Thieves send these emails, posing as a trusted source, such a financial institution or the IRS. The criminal’s goal is to entice users to open a link or attachment. The link may take users to a fake website that will steal usernames and passwords. An attachment may download malware that tracks keystrokes.
  • Keep a clean machine. This applies to computers, phones and tablets. Taxpayers should use security software to protect against malware that may steal data and viruses that may damage files.
  • Use passwords that are strong, long and unique. Experts suggest a minimum of 10 characters but longer is better. People should also avoid using a specific word in the password. They should also use a combination of letters, numbers and special characters.
  • Use multi-factor authentication when available. This means users may need a security code, usually sent as a text from a financial institution or email provider to a mobile phone. People use this code in addition to usernames and passwords.
  • Encrypt and password-protect sensitive data. If keeping financial records, tax returns or any personally identifiable information on computers, this data should be encrypted and protected by a strong password.

Be a savvy shopper – not only by looking for deals on items you want to purchase but also by keeping your information secure. 

Data thieves don’t take a break.  EVER.  They are always working.  One might say they are workaholics. 
 
The most common way for cybercriminals to steal money, bank account information, passwords, credit cards and Social Security numbers is to simply ask for them. Every day, people fall victim to phishing scams or phone scams that cost them their time and their cash.

Here are a few steps taxpayers can take to protect against phishing and other email scams. When reading emails, people should:

  • Be vigilant and skeptical. Never open a link or attachment from an unknown or suspicious source. Even if the email is from a known source, the recipient should approach with caution. Cybercrooks are good at acting like trusted businesses, friends and family. This even includes the IRS.
  • Double check the email address. Thieves may have compromised a friend’s email address. They might also be spoofing the address with a slight change in text. For example, using narne@example.com  instead of name@example.com.  Merely changing the “m” to an “r” and “n” can trick people. Look closely.
  • Remember that the IRS doesn’t initiate spontaneous contact with taxpayers by email to ask for personal or financial information. This includes asking for information via text messages and social media channels. The IRS does not call taxpayers with aggressive threats of lawsuits or arrests.
  • Not click on hyperlinks in suspicious emails. When in doubt, users should not use hyperlinks and go directly to the source’s main web page. They should also remember that no legitimate business or organization will ask for sensitive financial information by email.
  • Use security software to protect against malware and viruses found in phishing emails. Some security software can help identity suspicious websites that are used by cybercriminals.
  • Use strong passwords to protect online accounts. Experts recommend the use of a passphrase, instead of a password, use a minimum of 10 digits, including letters, numbers and special characters.
  • Use multi-factor authentication when offered. Two-factor authentication means that in addition to entering a username and password, the user must enter a security code. This code is usually sent as a text to the user’s mobile phone. Even if a thief manages to steal usernames and passwords, it’s unlikely the crook would also have a victim’s phone.
  • Report phishing scams. Taxpayers can forward suspicious emails to phishing@irs.gov.

(a reprint from an IRS notice)

Taxpayers should protect their personal and financial data from criminals who continue to steal large amounts of information. Thieves use the data to file bogus tax returns and commit crimes while impersonating the victim.

All taxpayers should follow these steps to protect themselves and their data.

Keep a secure computer. Taxpayers should:

  • Use security software that updates automatically. Essential tools for keeping a secure computer include a firewall, virus and malware protection, and file encryption for sensitive data.
  • Treat personal information like cash; don’t leave it lying around.
  • Give personal information only over encrypted and trusted websites.
  • Use strong passwords and protect them.

Avoid Phishing and Malware. Taxpayers should:

  • Not respond to emails, texts or calls that appear to be from the IRS, tax companies and other well-known businesses. Instead, verify contact information about companies or agencies by going directly to their website.
  • Be cautious of email attachments. Think twice before opening them.
  • Turn off the option to automatically download attachments.
  • Download and install software only from known and trusted websites.

Protect personal information. Taxpayers should:

  • Not routinely carry a Social Security card or other documents showing a Social Security number.
  • Not overshare personal information on social media. This includes information about past addresses, a new car, a new home and children.
  • Keep old tax returns and tax records under lock and key.
  • Safeguard electronic files by encrypting and properly disposing them.
  • Shred tax documents before trashing.

Taxpayers should forward IRS-related scam emails to phishing@irs.gov. They can report IRS impersonation telephone calls at www.tigta.gov.

More Information:

We hear about identity theft often these days. Yes, we may get tired of hearing about it, but identity theft is running rampant and we all need to protect ourselves as best as we can. 

What should you look for and what to do if you suspect being the target of identity theft?

  • Did you receive notification that your tax return had already been filed? 
  • Were you entitled to a refund on income taxes but never received your refund?  When you inquired, you were informed that the refund had been issued?  BUT, you never received it?
  • Did you receive a letter from the IRS regarding your identity?  This would be a paper letter.  A telephone call, fax, text or email would not be from the IRS, so don’t fall prey to the scam.  And, if someone showed up at your door claiming to be the IRS, be suspicious.  Don’t fall for contacts through social media as well.
  • You filed your return and received notification that additional tax was owed.
  • Did you receive a collection notice from the IRS when your returns were filed and no tax was due?
  • There was an offset of a refund. You may not find this out until you file your return the following year expecting to receive a refund.
  • Did the IRS notify you that you didn’t claim income from an employer or financial institution that you were not employed by or had accounts with?

OK, so you have experienced one of the above situations. What do you do now?

  • File a complaint with the FTC at identitytheft.gov.
  • Contact one of the three major credit bureaus to place a fraud alert on their credit records.
  • Contact your financial institutions to close any financial or credit accounts opened without permission or that were tampered with by identity thieves.
  • Respond immediately to any IRS notice and call the number provided in the letter.
  • Complete IRS Form 14039, Identity Theft Affidavit. You can use a fillable form on IRS.gov, print it, then attach the form to your tax return and mail according to instructions.

If you have previously been in contact with the IRS and did not have a resolution to your matter, you can contact the specialized Assistance Agency at 1-800-908-4490 for further assistance.

You can do your civic duty by reporting suspicious online or emailed phishing scams to phishing@irs.gov or by calling 1-800-366-4484. 

Be proactive, not reactive.

This term is becoming increasingly heard – but do you know what it is and how it may affect you?

OK, so what is it?  According to Wikipedia, the darknet websites are accessible through specific networks and certain accessible sites used widely among darknet users and provides anonymous access to the internet.  Specializing on allowing the anonymous hosting of websites, the identities and locations of darknet users stay anonymous and cannot be tracked due to the layered encryption system.  It is a complicated system which makes it almost impossible to track the geolocation and IP of the users.

The darknet is used for illegal activity such as illegal trade, forums and media exchange for pedophiles and terrorists.

So, how do you know if your information is on the darknet?  As part of the National Tax Security Awareness campaign, the IRS is offering a free public webinar on how identity thieves use the Dark Web.  This 100-minute webinar to be held on Monday, December 3, 2018 at 2:00 PM EST will help taxpayers understand the Dark Web and how it is used as a repository for stolen identities, credit data, tax information and banking/financial information.

If you would like to register for this FREE webinar to hear an overview of the Dark Web and answers to questions to help you recognize the risks and use of the Dark Web by cyber criminals, go to https://www.webcaster4.com/Webcast/Page/1148/28472.

 

 

As tax professionals, we most likely have more firewalls and tools in place than individuals to protect the information residing on our servers.  We are constantly checking to see if any breach has occurred and take steps to prevent any such breach.

Many individuals prepare their own income taxes using any one of the various software packages on the market to accomplish the same.  BUT, is that information as safe and secure as you think it is?  Maybe, maybe not.  But, let’s hope so. You can’t expect a criminal to wave a red flag to let you know that they have stolen your information.

So, how can you as an individual determine if your information may have been stolen?  Here are some highlights of what to look for:

  • If a return was filed electronically and was rejected by the IRS, it could be that someone has already filed a return using your Social Security Number.
  • You haven’t filed tax returns but begin to receive taxpayer authentication letters from the IRS. These letters include the 5071C, 4883C and 5747C.
  • You haven’t filed tax returns but receive refunds.
  • You receive tax transcripts that were not requested.
  • If you created an IRS online services account, you receive an IRS notice that your account was accessed and even perhaps disabled.
  • You unexpectedly receive an IRS notice that an online account was created in your name.
  • Your computer cursor is moving or changing numbers without someone touching the keyboard.
  • You get locked out of your computer.

The IRS and its partners in the Security Summit are alerting taxpayers about the signs of an ID theft as part of the Tax Security 101 awareness initiative. The goal is to provide basic information needed to better protect data and to help prevent the filing of fraudulent tax returns.

STAY ALERT, BE AWARE!

 

Capehart Blogs

Subscribe to Blog Updates

Choose the blogs and newsletters you would like to receive.

Categories