Categories: Tech

Security flaw in Florida tax website exposed filers’ sensitive data

Some Florida residents may be keeping a close eye on their finances after a security incident. Researcher Kamran Mohsin tells TechCrunch that Florida’s Department of Revenue website had a flaw that exposed hundreds of filers’ bank account and Social Security numbers. Anyone who logged in to the state business tax registration site could see, modify and even delete personal data just by modifying the web address pointing to a taxpayer’s application number — you just needed to change the digits in the link.

There were over 713,000 applications in the Department’s pipeline at the time of the discovery, Mohsin said. Mohsin warned the Department about the flaw on October 27th.

Department representative Bethany Wester said in a statement that the government fixed the flaw within four days of the report, and that two unnamed firms have deemed the site secure. She added there was “no sign” attackers abused the flaw, but didn’t say how officials might have spotted any misuse. The agency contacted every affected taxpayers by phone or writing within four days of learning about the issue, and has offered a year of free credit monitoring.

Bugs like these, known as insecure direct object references, are relatively easy to fix. The damage might also be limited compared to other tax-related breaches, such as a Healthcare.gov intrusion that compromised about 75,000 people in 2018. However, the incident underscores the potential harm from weak security — even a small-scale exposure like this could be used to commit tax fraud and steal refunds.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission. All prices are correct at the time of publishing.

Read More

Udit Ghosh

Udit Ghosh is a Journalist at Flaunt Weekly.

Share
Published by
Udit Ghosh

Recent Posts

All about John Legend’s ‘Move Afrika tour’ in Rwanda and Nigeria

Flaunt Weeekly Renowned American music producer and musician John Legend will headline the Move Afrika…

4 hours ago

DJ Clen Talks Creative Process Behind His Album Too Viral: “I’m More of a Musician Than a DJ”

Flaunt Weeekly DJ Clen Talks Creative Process Behind His Album Too Viral: “I’m More of…

4 hours ago

ANTI WORLD GANGSTARS – THUNDERSTORM Ft AGUNNA, FATBOY E, SHAGBA, ODUMODUBLVCK, REEPLAY, HOTYCE, PSYCHO YP & TOMI

Flaunt Weeekly Nigerian rapper and music star, ANTI WORLD GANGSTARScomes through with a new single…

5 hours ago

‘I Was Very Naive At The Beginning Of My Career’ – Nigerian Singer Tems Reveals

Flaunt Weeekly NigeriaTemilade Openiyi, famously known as Tems, has shared a candid insight into her…

6 hours ago

Pabrymo Ft. Davido – Bum Bum

Flaunt Weeekly Flaunt Weeekly Emphasis added Ft. Davido – Bum Bum Mp3 DownloadWoke Entertainment singer…

6 hours ago

“I’ll win a Grammy next year”

Flaunt Weeekly Controversial influencer, Saidabshas once again ignited social media debates with her latest audacious…

6 hours ago