[
    {
        "Example": [
            "Incident involving an IRS contractor, Charles Littlejohn, who leaked thousands of tax returns of wealthy individuals, including former President Donald Trump."
        ],
        "url": "https://news.bloombergtax.com/daily-tax-report/house-votes-to-hike-penalties-on-leaking-tax-data-after-irs-breach",
        "summary": "[[Summary: On September 17, 2024, the House of Representatives voted to increase penalties for the unlawful disclosure of personal tax information. This legislative action was spurred by a recent incident involving an IRS contractor, Charles Littlejohn, who leaked thousands of tax returns of wealthy individuals, including former President Donald Trump. The new bill, which was supported almost unanimously by the House Ways and Means Committee, proposes to raise the maximum prison sentence and fines for violators. However, the bill's progress in the Senate remains uncertain. Littlejohn was charged with unauthorized disclosure and received a maximum sentence of five years in prison.]]",
        "access_time": "2024-10-26T14:31:19.790000"
    },
    {
        "Example": [
            "A significant identity theft scheme affected veterans, costing them millions.",
            "If a taxpayer suffers a loss due to identity theft of securities, the loss may not be deductible under current law."
        ],
        "url": "https://www.journalofaccountancy.com/issues/2020/oct/tax-consequences-of-data-breaches-identity-theft.html",
        "summary": "[[Summary: \n\n**Article Title:** Tax Consequences of Data Breaches and Identity Theft  \n**Authors:** Patrick M. Ryle, J.D.; Leonard Goodman, CPA, Ph.D.; Jay A. Soled, J.D.  \n**Publication Date:** October 2020 (snapshot from 2024/10/20)  \n**Related Topics:** Technology, Information Security & Privacy, Tax, IRS Practice & Procedure\n\n**Key Points:**\n\n1. **Prevalence of Data Breaches and Identity Theft:**\n   - Data breaches are common, with 4.1 billion private records exposed in the first half of 2019.\n   - A significant identity theft scheme affected veterans, costing them millions.\n\n2. **Financial Impact:**\n   - Data breaches cost U.S. companies an average of $8.19 million each.\n   - Global cybersecurity spending from 2017 to 2021 is expected to exceed $1 trillion.\n\n3. **Tax Deduction Issues:**\n   - Business losses from data breaches can be deducted under Section 165(a) or Section 162(a).\n   - Individual taxpayers face restrictions under Section 165(c), allowing deductions only for losses related to federally declared disasters, which does not typically include data breaches or identity theft.\n\n4. **Example of Tax Treatment:**\n   - If a taxpayer suffers a loss due to identity theft of securities, the loss may not be deductible under current law.\n   - Businesses can deduct cybersecurity expenses as ordinary and necessary expenses.\n\n5. **Preventive Measures:**\n   - Businesses can deduct expenditures for cybersecurity measures.\n   - Individual taxpayers cannot currently deduct expenses related to protecting against data breaches due to changes in tax law (TCJA).\n\n6. **Income-Related Issues:**\n   - Reimbursements for losses due to breaches are generally taxable unless they are classified as a recovery of capital.\n   - In-kind benefits (e.g., credit monitoring services) provided by companies after a data breach are not considered taxable income according to IRS announcements.\n\n7. **IRS Guidance:**\n   - The IRS will not assert that individuals must include the value of identity protection services in their gross income, regardless of when they are provided.\n   - This guidance lacks statutory support and may be politically motivated to avoid backlash.\n\n8. **Conclusion:**\n   - While some IRS provisions offer relief for taxpayers affected by data breaches and identity theft, comprehensive tax relief remains limited.\n   - Future amendments to tax laws may be necessary for more substantial relief.\n\n**Authors' Background:**\n- Patrick M. Ryle is an assistant professor at Dalton State College, Georgia.\n- Leonard Goodman and Jay A. Soled are tax professors at Rutgers Business School, New Jersey.\n\n**Contact Information for Comments:**\n- Paul Bonner, JofA senior editor, email: Paul.Bonner@aicpa-cima.com, phone: 919-402-4434.\n\n**Additional Resources:**\n- AICPA offers various resources and tools related to cybersecurity and data breaches.]]",
        "access_time": "2024-10-26T14:31:23.874413"
    },
    {
        "Example": [
            "Proposed class actions against Alphabet Inc.'s Google, H&R Block Inc., and TaxAct Holdings Inc. for alleged privacy violations concerning taxpayers' sensitive financial data.",
            "Lawsuits were filed against Google and H&R Block on July 14, 2023, and against TaxAct on July 15, 2023, claiming that the companies shared sensitive financial data through embedded pixels that track user interactions on their websites."
        ],
        "url": "https://news.bloomberglaw.com/privacy-and-data-security/google-tax-firms-see-data-privacy-suits-after-congress-report",
        "summary": "[[Summary: \n1. **Main Topic**: Proposed class actions against Alphabet Inc.'s Google, H&R Block Inc., and TaxAct Holdings Inc. for alleged privacy violations concerning taxpayers' sensitive financial data.\n\n2. **Key Events**: \n   - Lawsuits were filed against Google and H&R Block on July 14, 2023, and against TaxAct on July 15, 2023.\n   - The lawsuits claim that the companies shared sensitive financial data through embedded pixels that track user interactions on their websites.\n\n3. **Background**: The lawsuits were prompted by findings from a recent congressional report that highlighted privacy concerns regarding the sharing of financial data by these companies.\n\n4. **Legal Claims**: The lawsuits seek damages for the alleged violation of taxpayer privacy due to the unauthorized sharing of data.\n\n5. **Implications**: These actions may have broader implications for data privacy practices in the digital tax preparation industry.\n\n6. **Sources**: The information is derived from a Bloomberg Law analysis of court dockets and related news reporting.\n]]",
        "access_time": "2024-10-26T14:31:22.242973"
    },
    {
        "Example": [
            "On April 12, 2024, the IRS notified over 70,000 taxpayers that their tax return information was compromised due to a data breach involving an IRS independent contractor, Mr. Littlejohn.",
            "Mr. Littlejohn stole tax return information between 2018 and 2020, disclosing it to ProPublica and The New York Times.",
            "Two affected taxpayers have filed lawsuits against the IRS regarding the unauthorized disclosures."
        ],
        "url": "https://www.mondaq.com/unitedstates/tax/1466522/irs-issues-supplementary-letters-to-affected-taxpayers-who-requested-more-information-about-data-breach-scope-of-disclosure-remains-unknown",
        "summary": "[[Summary: \n1. **Data Breach Notification**: On April 12, 2024, the IRS notified over 70,000 taxpayers that their tax return information was compromised due to a data breach involving an IRS independent contractor, Mr. Littlejohn.\n\n2. **Supplementary Letters**: The IRS issued supplementary letters to affected taxpayers who sought more information about the breach. These letters acknowledge the IRS's responsibility to protect taxpayer information and outline limitations on the information provided due to legal and practical constraints.\n\n3. **Details of the Breach**: \n   - Mr. Littlejohn stole tax return information between 2018 and 2020, disclosing it to ProPublica and The New York Times.\n   - The IRS is still determining the full scope of the disclosures and has stated that there is currently no evidence indicating that the disclosed information has been used for identity theft or fraud.\n   - The IRS has recovered the stolen return information.\n\n4. **Limitations on Information Disclosure**: \n   - The IRS could not access information about affected taxpayers until after Mr. Littlejohn's sentencing in February 2024.\n   - The data set received from the Treasury Inspector General for Tax Administration (TIGTA) is complex, delaying the identification of affected taxpayers.\n\n5. **Next Steps for IRS**: The IRS plans to continue working with TIGTA to understand the breach's impact and notify additional affected taxpayers, including those who received Schedules K-1 from impacted entities. \n\n6. **Preventive Measures**: On May 10, 2024, the IRS announced ten new measures to enhance taxpayer protections, including stricter access controls, improved security measures, and continuous monitoring of data usage.\n\n7. **Legislative Response**: The House Ways and Means Committee is proposing legislation to increase penalties for unauthorized disclosures, raising maximum fines from $5,000 to $250,000 and prison sentences from five to ten years.\n\n8. **Ongoing Legal Actions**: Two affected taxpayers have filed lawsuits against the IRS regarding the unauthorized disclosures.\n\n9. **Advice for Affected Taxpayers**: Taxpayers are advised to safeguard their identities by consulting with advisors and monitoring their tax transcripts for fraudulent activity. They can request further information from the IRS via a designated email address.\n\n10. **Conclusion**: The scope of the data breach remains uncertain, but the IRS is taking steps to mitigate its impact and prevent future incidents. \n]]",
        "access_time": "2024-10-26T14:31:23.781458"
    },
    {
        "Example": [
            "In McGlenn v. Driveline Retail Merch., Inc., sensitive tax information of employees was allegedly disclosed due to a phishing attack."
        ],
        "url": "https://www.privacyworld.blog/2021/01/denied-court-rejects-motion-to-certify-class-in-data-breach-alleging-disclosure-of-employees-sensitive-tax-information/",
        "summary": "[[Summary: \nThe article discusses a federal court's decision to deny a motion for class certification in a data breach case, McGlenn v. Driveline Retail Merch., Inc., where sensitive tax information of employees was allegedly disclosed due to a phishing attack. The court ruled that the plaintiff failed to meet the commonality requirement under Rule 23(a) because issues of causation and injury required individual inquiries. The court also found that certification under Rule 23(b)(2) for injunctive relief was inappropriate, as enhanced security measures would not remedy the harm already caused by the disclosure of personally identifiable information (PII). Additionally, certification under Rule 23(b)(3) was denied because the plaintiff could not demonstrate that all class members suffered compensable injuries, as many claims were based on speculative future harm. The court expressed doubts about whether the employer had a legal duty to protect employee PII beyond providing notice of the breach. This case highlights the challenges in certifying class actions related to data breaches and the ongoing complexities in data privacy litigation.]]\n\nKey Information Extracted:\n- Case Name: McGlenn v. Driveline Retail Merch., Inc.\n- Court Decision Date: January 19, 2021\n- Key Issues: Data breach, phishing attack, disclosure of employees' sensitive tax information.\n- Plaintiff's Claims: \n  - Criminals could misuse disclosed information for fraudulent activities.\n  - Plaintiff experienced identity theft (e.g., credit card account opened in her name).\n  - Sought monetary damages and injunctive relief for improved data security.\n- Legal Framework: Federal Rule of Civil Procedure 23(a) and 23(b).\n- Court Findings:\n  - Commonality requirement not met; individual inquiries needed for causation and injury.\n  - Injunctive relief under Rule 23(b)(2) inappropriate due to already disclosed PII.\n  - Rule 23(b)(3) certification denied; lack of evidence for compensable injuries.\n- Implications: Highlights difficulties in certifying class actions in data breach cases and the evolving landscape of data privacy litigation.",
        "access_time": "2024-10-26T14:31:22.589466"
    },
    {
        "Example": [
            "Collection of passengers' facial recognition images and personal details (ages, occupations, family relationships, addresses).",
            "Collection of excessive geolocation data.",
            "Unauthorized analysis of passengers' travel plans.",
            "Illegal collection of screenshots from users' mobile albums.",
            "Excessive collection of information from users\u2019 clipboards and app lists.",
            "Frequent and unnecessary requests for phone call permissions.",
            "64.709 billion personal data records were illegally collected across 41 distinct apps."
        ],
        "url": "https://www.reedsmith.com/en/perspectives/2022/07/china-imposes-largest-data-protection-penalty",
        "summary": "[[Summary: \n\n**Main Topic**: China's Largest Data Protection Penalty Imposed on Didi Global Inc.\n\n**Key Facts**:\n- **Date of Announcement**: July 21, 2022.\n- **Regulatory Body**: Cyberspace Administration of China (CAC).\n- **Company Involved**: Didi Global Inc., incorporated in the Cayman Islands.\n- **Penalty Amount**: $1.2 billion (RMB 8.026 billion), marking the highest penalty in a data protection case in China.\n\n**Details of Violations**:\n- **Nature of Violations**:\n  - Illegal collection of screenshots from users' mobile albums.\n  - Excessive collection of information from users\u2019 clipboards and app lists.\n  - Collection of passengers' facial recognition images and personal details (ages, occupations, family relationships, addresses).\n  - Excessive geolocation data collection.\n  - Unauthorized analysis of passengers' travel plans.\n  - Frequent and unnecessary requests for phone call permissions.\n  - Failure to clearly state the purpose of data processing.\n\n**Penalties Imposed**:\n- Fine of RMB 8.026 billion on Didi Global, about 4.6% of its total revenue of RMB 173.827 billion.\n- Individual fines of RMB 1 million for Didi\u2019s CEO and president.\n- Didi's apps were removed from app stores, and the company was banned from accepting new users during the investigation.\n\n**Factors Influencing the Penalty**:\n- Didi Global's non-compliance even after receiving regulatory requests to rectify violations.\n- The company's IPO on the NYSE proceeded without CAC pre-approval.\n- Violations persisted since 2015, continuing even after the enactment of the Personal Information Protection Law.\n- Significant potential harm to individuals due to excessive data collection.\n- A total of 64.709 billion personal data records were illegally collected across 41 distinct apps.\n\n**Implications**:\n- The case highlights the seriousness of compliance with China\u2019s data protection laws.\n- The CAC's decision sets a precedent for future investigations and penalties.\n- Companies in tech and life sciences sectors are particularly at risk if they fail to adhere to these regulations.\n- Emphasizes the importance of robust data processing reviews to mitigate risks associated with privacy and data protection.\n\n**Authors**: Amy Yin, Gerard M. Stegmaier, Bryan Tan, Asha Sharma.\n\n**Context**: The incident underscores China's emergence as a significant enforcer of data protection regulations, paralleling trends in other markets like the United States. Businesses are advised to take compliance seriously to avoid severe penalties.]]",
        "access_time": "2024-10-26T14:31:23.368423"
    },
    {
        "Example": [
            "Accounting firms hold sensitive client information, such as Social Security numbers (SSNs), making them targets for hackers.",
            "132 breaches reported among accounting firms, with approximately 90% involving firms smaller than the largest 300 by revenue.",
            "Breaches reported increased from zero in 2014 to 79 in 2017, indicating a troubling upward trend.",
            "Breaches are not confined to Maryland; firms in various states are affected, complicating the identification of unique breaches due to differing state reporting requirements.",
            "Most breaches involved SSNs and tax information, with only 5% compromising credit card or password information."
        ],
        "url": "https://www.journalofaccountancy.com/issues/2019/jun/accounting-firm-data-breaches.html",
        "summary": "[[Summary: \n\n1. **Cookies and Consent**: The website uses cookies for functionality and user experience improvement, requiring user consent for placement.\n\n2. **AICPA & CIMA Overview**: The site encompasses various topics including Technology & AI, Tax, Practice Management, Financial Reporting, Audit, and Management Accounting.\n\n3. **Data Breaches in Accounting Firms**:\n   - Accounting firms hold sensitive client information, such as Social Security numbers (SSNs), making them targets for hackers.\n   - The IRS has issued warnings regarding the risks associated with holding such valuable information.\n\n4. **Data Breach Reporting**:\n   - All states have laws mandating the reporting of data breaches, typically to the state attorney general.\n   - Maryland is highlighted for its transparency in breach reporting, providing specific details about breaches affecting its residents.\n\n5. **Findings from Maryland Data (Jan 2014 - Feb 2018)**:\n   - 132 breaches reported among accounting firms, with approximately 90% involving firms smaller than the largest 300 by revenue.\n   - Types of breaches: unauthorized access, hacking, and unknown (unspecified).\n   - Over 1,100 Maryland residents were affected, with many breaches categorized as unknown, indicating a lack of clarity on breach specifics.\n\n6. **Trend Analysis**:\n   - Breaches reported increased from zero in 2014 to 79 in 2017, indicating a troubling upward trend.\n   - Delays in public disclosure of breaches suggest the actual threat may be greater than reported.\n\n7. **Widespread Impact**:\n   - Breaches are not confined to Maryland; firms in various states are affected, complicating the identification of unique breaches due to differing state reporting requirements.\n\n8. **Data Compromised**:\n   - Most breaches involved SSNs and tax information, with only 5% compromising credit card or password information.\n\n9. **Preventive Measures**:\n   - Firms must maintain updated systems, solid IT controls, and employee education regarding data security.\n   - Recommendations include encryption, awareness training, and establishing a corrective action plan for potential breaches.\n\n10. **Reputational Risks**:\n    - Breaches pose a significant reputational threat to firms, potentially leading to legal consequences for failing to protect client information.\n\n11. **Future Considerations**:\n    - Continuous investment in data security measures and employee training is crucial as technology evolves and threats become more sophisticated.\n\n12. **Authors**:\n    - Christine Cheng, Ph.D. (University of Mississippi), Renee Flasher, CPA, Ph.D. (Penn State Harrisburg), James P. Higgins, CPA, CGMA (LWG CPAs & Advisors).\n\n13. **Resources Available**:\n    - Various articles, publications, and web resources related to cybersecurity and data breach management are provided by AICPA.\n\n]]",
        "access_time": "2024-10-26T14:31:25.799582"
    },
    {
        "Example": [
            "Identity Theft and Fraudulent Tax Returns: Cybercriminals can file fraudulent tax returns using stolen tax information, potentially stealing refunds.",
            "Delayed Tax Refunds: The IRS may delay refunds if they suspect fraudulent activity, leading to financial strain.",
            "Financial Losses and Credit Damage: Victims may experience significant financial losses and damage to their credit scores due to identity theft and fraudulent activities.",
            "Exposure of Sensitive Information: Tax information often contains sensitive data (e.g., Social Security numbers), which can be exploited for identity theft."
        ],
        "url": "https://databreachclassaction.io/blog/how-data-breaches-affect-your-tax-information",
        "summary": "[[Summary: \n\n**Main Topic:** The impact of data breaches on tax information.\n\n**Published Date:** September 04, 2024.\n\n**Key Points:**\n\n1. **Consequences of Data Breaches:**\n   - **Identity Theft and Fraudulent Tax Returns:** Cybercriminals can file fraudulent tax returns using stolen tax information, potentially stealing refunds.\n   - **Delayed Tax Refunds:** The IRS may delay refunds if they suspect fraudulent activity, leading to financial strain.\n   - **Financial Losses and Credit Damage:** Victims may experience significant financial losses and damage to their credit scores due to identity theft and fraudulent activities.\n   - **Exposure of Sensitive Information:** Tax information often contains sensitive data (e.g., Social Security numbers), which can be exploited for identity theft.\n\n2. **Protective Steps After a Data Breach:**\n   - **Verify Compromise:** Contact the affected company to confirm if tax information was compromised.\n   - **Fraud Alert or Credit Freeze:** Place alerts or freezes with the three major credit bureaus (Equifax, Experian, TransUnion) to prevent identity theft.\n   - **Monitor Accounts:** Regularly check credit reports and financial accounts for suspicious activity.\n   - **Consider Identity Theft Protection:** Explore services that monitor accounts and alert users to suspicious activities.\n   - **Beware of Phishing Attempts:** Be cautious of unsolicited communications that may attempt to steal personal information.\n\n3. **Legal Options for Victims:**\n   - Individuals whose tax information has been compromised may be eligible to join a class action lawsuit for compensation.\n   - Console & Associates, P.C. offers free consultations and works on a contingency basis, meaning no legal fees unless compensation is recovered.\n\n4. **Assistance from Console & Associates, P.C.:**\n   - The firm provides free consultations to discuss legal options and next steps for victims of tax information data breaches.\n\n**Contact Information:** \n- Console & Associates, P.C. is located at One Holtec Drive, Suite #100, Marlton, NJ 08053. They can be reached at 866-778-5500.\n\n**Legal Disclaimer:** \n- The information presented is for general informational purposes and does not constitute formal legal advice. An attorney-client relationship is not created by visiting the site or contacting the firm. \n\n**Privacy Commitment:** \n- The firm is committed to protecting user privacy and does not sell or rent personal information to third parties. \n\n**Additional Notes:** \n- The page also mentions ongoing investigations into other data breaches (e.g., CBIZ and Illinois Bone & Joint Institute) but does not provide specific details about them. \n\n]]",
        "access_time": "2024-10-26T14:31:23.781186"
    }
]