IRS suspends contract with Equifax after malware discovered

Published: Oct. 4, 2017 at 5:24 AM EDT
Email This Link
Share on Pinterest
Share on LinkedIn
By: CBS News

October 13, 2017

The IRS said late Thursday that it has temporarily suspended the agency's $7.1 million data security contract with Equifax after malware found on the credit bureau's website again called its security systems into question.

Equifax, now notorious for exposing more than half of all adult Americans to identify theft, maintained the latest security breach was not officially a hack.

An Equifax vendor was "running code that was serving malicious content" on the Equifax site, the company said in a statement. "Since we learned of the issue, the vendor's code was removed from the webpage and we have taken the webpage offline to conduct further analysis."

However, consumers who were using the site could easily have been tricked into downloading malware when visiting the Equifax help page, an oversight that experts said put people further at risk. The nation's largest information technology trade group is urging the government to cancel Equifax's now suspended contract with the IRS.

"Equifax is known publicly to have security breaches, and they are not correcting them," said Barbara Rembiesa, president and CEO of the International Association of IT Asset Managers, which represents 50,000 IT managers in 126 countries. "Why are we spending all this money to give our data to a company that has clear problems with the technology?"

Equifax's latest problem was discovered Wednesday by a private security consultant who realized the company's consumer help page was serving up malware that aimed to get unsuspecting consumers to download fraudulent Adobe updates.

In September, Equifax revealed that it had exposed 143 million consumer files -- containing names, addresses, Social Security numbers and even bank account information -- to hackers in an unprecedented security lapse. The number of consumer potentially affect by the data breach was later raised to 145.5 million.

The company's former CEO blamed a single careless employee for the entire snafu. But even as he was getting grilled in Congress earlier this month, the IRS was awarding the company with a no-bid contract to provide "fraud prevention and taxpayer identification services."

"On the very day that Equifax's former chief executive misled Congress by scapegoating a single employee for their second major data breach in four years, the IRS announced that it was awarding the company with a contract which will allow it to leak out even more personally identifiable information about taxpayers," Rembiesa said.

"The prospect of this happening should horrify any elected official who is charged with looking out for the welfare of American consumers," she added. "Congress needs to slam on the brakes here and kill this IRS contract."

The tax agency stopped short of that, at least for the moment.

"Following new information available today, the IRS temporarily suspended its short-term contract with Equifax for identity proofing services," the agency said in a statement. "During this suspension, the IRS will continue its review of Equifax systems and security."

The agency does not believe that any data the IRS has shared with Equifax to date has been compromised, but the suspension was taken as "a precautionary step."

In the meantime, the IRS will be unable to create new "Secure Access" accounts, which can be used to order tax court transcripts online. Although people can't create new accounts, current Secure Access users aren't affected by this contract change and will continue to have access to their accounts, the agency said. And these transcripts can still be ordered by mail.

Other IRS services are unaffected.

By: Associated Press

October 4, 2017

WASHINGTON (AP) -- The company at the center of one of the biggest breaches of personal information in history just signed a contract with the federal government to provide, well, personal information.

The Internal Revenue Service signed a $7.25 million contract with Equifax last month.

The no-bid contract, first reported by Politico, is for Equifax to provide the IRS with taxpayer and personal identity verification services. The contract stated that Equifax was the only company capable of providing these services to the IRS, and it was deemed a "critical" service that couldn't lapse.

The company is dealing with a

by hackers who accessed or stole the information of more than 145 million Americans.