WASHINGTON, D.C. – U.S. Senator Gary Peters (D-MI), Ranking Member of the Subcommittee on Federal Spending Oversight and Emergency Management, led eight of his colleagues in a letter demanding further scrutiny of the Internal Revenue Service’s (IRS) decision to award Equifax a sole-source contract to verify taxpayer identities and help prevent tax fraud despite the company’s recent disclosure of a massive cybersecurity breach exposing the personal information of as many as 145.5 million Americans.
“By awarding this no-bid contract, the Internal Revenue Service (IRS) is paying Equifax $7.25 million in taxpayer money to protect the very same taxpayers from an identity theft risk that Equifax helped create,” wrote the Senators. “The decision to award this contract to protect the identities of taxpayers and the integrity of federal tax dollars in light of Equifax’s recent and severe breach of the public trust is highly concerning.”
In September, Equifax disclosed a cybersecurity breach that potentially exposed the sensitive personal information of more than 145 million consumers, including Social Security numbers, home addresses, and driver’s license numbers. Equifax had known about the breach for months, but did not publicly disclose it until September. In the interest of protecting taxpayers’ money, the Senators urged IRS Commissioner John Koskinen to explain why Equifax was awarded the sole-source contract in light of this cybersecurity breach.
Peters was joined in sending the letter by U.S. Senators Kirsten Gillibrand (D-NY), Martin Heinrich (D-NM), Mazie Hirono (D-HI), Patrick Leahy (D-VT), Bob Menendez (D-NJ), Jeff Merkley (D-OR), Patty Murray (D-WA), and Jeanne Shaheen (D-NH).
Full text of the letter is copied below and available here:
October 5, 2017
The Honorable John Koskinen
Commissioner
Internal Revenue Service
1111 Constitution Avenue, NW
Washington, DC 20224
Dear Mr. Koskinen:
On Thursday, September 7, the credit reporting agency Equifax announced that a cybersecurity breach potentially exposed the sensitive personal information of more than 145 million Americans. The exposed information included names, Social Security numbers, birth dates, and addresses. Equifax had known about the breach for months. For those months, 145 million Americans were left unaware that they were at greater risk for identity theft and fraud, including tax-related identity theft.
On Tuesday, ousted Equifax CEO Richard Smith testified before the House Energy and Commerce Subcommittee on Digital Commerce and Consumer Protection that “Equifax was entrusted with Americans’ private data and we let them down.” However, just days prior, the Internal Revenue Service awarded Equifax a $7.25 million sole-source contract to “verify taxpayer identity and to assist in ongoing identity verification and validations.” By awarding this no-bid contract, the Internal Revenue Service (IRS) is paying Equifax $7.25 million in taxpayer money to protect the very same taxpayers from an identity theft risk that Equifax helped create.
As members of the United States Senate, it is our duty to ensure prudent management of taxpayer money. The choice to award a sole-source contract to Equifax to perform any vital services requires close scrutiny. The decision to award this contract to protect the identities of taxpayers and the integrity of federal tax dollars in light of Equifax’s recent and severe breach of the public trust is highly concerning. Please answer the following questions as soon as possible and no later than October 20, 2017:
We appreciate your attention to this matter and look forward to your prompt response.
###