FAFSA Tool Vulnerability May Have Exposed 100K Individuals’ Personal Info

"… The New York Times reports that the personal information of as many as 100,000 consumers may have been compromised when hackers used the Data Retrieval Tool to generate tax information and then fill out fraudulent tax returns.

The Data Retrieval Tool was introduced by the Department of Education as an attempt to streamline the FAFSA process. The tool allows families filling out the FAFSA forms to retrieve their tax information directly from the Internal Revenue Service." …

Update.

https://consumerist.com/2017/04/07/fafsa-tool-vulnerability-may-have-exposed-100k-individuals-personal-info/

From what years?

I believe that it just involved the current FAFSA (2017-2018).

Lovely. I’ll let my kid know. She did her fafsa in October…and used the DRT. Just lovely.

This is a current issue. Here is the NYT article:
https://www.nytimes.com/2017/04/06/us/politics/internal-revenue-service-breach-taxpayer-data.html?_r=0

“your data is secure/safe with us”…over and over and over we see that it is NOT SAFE.

We used drt this year. It’s unclear to me if the breach was to those who used it or those who didn’t or just any taxpayer?

I believe the breach was for those who USED the DRT.

Sounds like if you filed FAFSA and taxes successfully you probably weren’t affected?

The hackers used the drt themselves to file false returns, right? So if you filed successfully that would suggest you weren’t hacked. I will read more.

@OHMomof2

Well…maybe for 2016 taxes. But if there was a breach, these folks could hold onto your info and use it in subsequent years.

I was so upset that the DRT wouldn’t merge my information when I did the FAFSA, apparently because of an issue with my maiden name. I had to enter everything by hand and it took forever. Now, I am very happy that was the case.

If the institutions don’t use our social security numbers to identify individuals then the breaches and damages are minimized.

Bigger issue- looks liek $30M has been stolen https://www.cnet.com/news/hackers-used-college-student-loans-tool-to-steal-30-million/#ftag=CAD590a51e

What a giant mess.

Tax refund fraud isn’t new, using the DRT to do it is.

Does anybody know, I’ve asked and gotten different answers! When the kids get loans from the government is a credit report pulled on them?

My DH and I have frozen our credit probably 5 years ago. I’d freeze the kids too just to avoid issues like this. But in my state we have to pay to freeze and unfreeze so I don’t want to freeze their credit if a report needs to be pulled for their loans. As it is, I just make sure to diligently pull an annual credit report for them, alternating the bureaus every 4 months to monitor their reports.

@seekingknowledge

I don’t think a credit report is pulled for the Direct Loan. Don’t you have to give permission for a credit report to be pulled? I know I’ve had to for other purposes.

My kids have never been asked for permission to do a credit check…and one is still getting federally funded loans.

Related: does a Direct go on your credit report while you’re in school? Say, if you take one and pay it back very quickly?

Thumper are you talking about do my kids give me their permission to pull their annual credit reports? Then yes, we sit down and do it together because I want them to get in the habit of pulling them and checking them to scan for things that shouldn’t be there, loans and such.

If on the other hand are you asking do we give our permission for loan places to pull our report, no they do that as it is their process to determine our credit worthiness.

I would think the gov’t isn’t pulling credit reports on kids they give loans to but it was the 800# at Fafsa and I believe I checked with my kids loan originators who said a report is pulled. I don’t know where else to check.

Although looking at the kids credit report it does show the loans from the dept of Ed but it also shows this:

Inquiries - Requests for your Credit History

Inquiries in the Last 2 Years 0
Most Recent Inquiry N/A

^ so I should be able to interpret that to mean a report hasn’t been pulled right? But why are those two places telling me they do pull them. Maybe I should call again and see if I get another answer.

One of my DD was offered a free freeze because of the anthem hack, but because of her taking loans I didn’t take advantage of it. But I do have up to a year to get it, mmm???