Over 100 Vulnerabilities Found in IRS Contractor Handling Americans' Tax Information
The Treasury Inspector General for Tax Administration (TIGTA) found over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents.
The TIGTA is an independent government agency responsible for overseeing and auditing the IRS.
They looked at two sites at which contractors were using to support the IRS's Zero Paper Initiative (ZPI), a push for the IRS to move all of its paper forms to digital files.
The TIGTA found that at these sites, 14 employees had accessed areas where Americans' sensitive tax data was stored 1,375 times in a period of only a few months for each site.
Upon speaking with management, they said they only need to review the physical access logs annually, when, in fact, they're required to review these logs monthly to help identify unauthorized employees accessing restricted areas.
As to how so many people were able to get inside in the first place, the TIGTA found that the facilities lacked basic physical security measures.
The perimeter fence and loading dock at one of the sites was left wide open with no security, allowing anyone to simply walk into the document storage area from outside.
No guards were employed to control access to the facility whatsoever. The representatives of the operation said their contract, handling the most sensitive data of Americans, didn't require hiring a guard.
The requirements actually do require that contractors secure the physical property:
Publication 4812, Contractor Security and Privacy Controls, includes physical security requirements for areas that contain taxpayer information. The physical security requirements include reinforced perimeters, locked buildings, and electronic security systems. Further, when a fence and gate are used to secure the perimeter, the gate should be guarded or locked with an alarm.
The TIGT also found their digital security lacking. Over 100 vulnerabilities total were found in their digital systems, presumably the same ones that were scanning and storing the tax documents.
There's a required timeframe for contractors to fix vulnerabilities, which the contractors completely ignored and let their outdated systems fester for in some cases over 7 times the allowed timeframe.

Also alarming is that the majority of the vulnerabilities are high and critical. One of the sites also used unauthorized software to scan the tax documents.
Despite all the security issues, the ZPI still somehow manages to be behind schedule according to another report by the TIGTA.
Community Discussion