Join our Newsletter — 33% off our NHI Course
Home FAQ Identity Beyond IAM How should tax agencies reduce refund fraud when…
Identity Beyond IAM

How should tax agencies reduce refund fraud when breached personal data is being used to take over taxpayer accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 19, 2026 Domain: Identity Beyond IAM

Tax agencies should treat refund fraud as both an identity problem and a workflow problem. Stronger account recovery, step up checks on high value filings, and tighter validation of changes to banking or mailing details reduce abuse. Agencies also need better monitoring of suspicious filing patterns, because attackers often combine stolen personal data with weak review processes to move money quickly.

Why refund fraud becomes an account takeover problem

When breached personal data is enough to pass account recovery or login checks, refund fraud stops being only a tax filing issue. The control failure is usually at the point where an attacker can impersonate a taxpayer, change the destination for funds, or file quickly before the real account owner notices. Agencies need to treat that path as an identity and workflow weakness together.

The practical lesson is that fraud usually succeeds through a chain of small trust assumptions: weak recovery questions, over-trusting static personal data, and insufficient review of high-risk changes. That is why agencies should harden the account lifecycle, not just the filing form. Research on 52 NHI Breaches Analysis shows how stolen credentials and poor access controls routinely combine with process gaps to create real compromise paths, even when the initial breach is elsewhere.

Controls that reduce abuse without blocking legitimate refunds

The strongest controls are the ones that make account takeover harder and make suspicious payout changes easier to stop. Step-up verification should trigger when a taxpayer requests a reset, changes bank details, updates contact information, or submits a filing that deviates from the account’s normal pattern. Agencies should also separate low-risk self-service from actions that can redirect money.

Good control design usually includes a mix of verification, throttling, and review. That means stronger recovery for high-risk events, short-lived validation for payout changes, and manual intervention where the financial impact is material or the filing pattern is unusual. A useful comparison is the broader account takeover and privileged-access pattern seen in The 52 NHI breaches Report, where attackers often win by moving from stolen data to trusted access faster than defenders can react.

  • Use step-up checks for bank account changes, mailing-address changes, and password or recovery resets.
  • Delay or hold first-time payout changes until they are separately verified.
  • Flag high-value or first-time filings for review before refund release.
  • Compare new filings against prior device, address, and timing patterns.

Monitoring patterns that reveal coordinated refund abuse

Fraud monitoring works best when it looks for clusters, not just single anomalies. Agencies should watch for repeated identity-recovery attempts, bursts of filings from related addresses or devices, rapid changes to payout details, and filing behavior that does not match the taxpayer’s established history. Those signals matter because attackers commonly use breached personal data to blend in, then rely on speed and process gaps to cash out.

The monitoring layer should feed both fraud review and security response. When multiple accounts show the same suspicious pattern, the agency should assume a campaign rather than isolated misuse and tighten controls around the affected workflow. Public-sector account takeover cases, such as GitLocker GitHub extortion campaign and Internet Archive breach, show why trusted accounts and tokens are attractive once an attacker has enough personal or session data to pass basic checks.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity Management, Authentication and Access ControlTaxpayer account recovery and payout changes depend on reliable access control.
DE.CM-7 — Monitoring for Unauthorized Personnel, Connections, Devices and SoftwareRefund fraud detection depends on spotting anomalous filing and access patterns.
Recommendation — Strengthen identity checks before allowing recovery or payment-direction changes. Monitor for abnormal filing bursts and suspicious account activity across channels.
CIS Controls v85.3 — Disable Dormant AccountsStale or unused taxpayer accounts can be abused in takeover-driven fraud.
6.3 — Access AgreementsHigh-risk account actions need explicit rules and user expectations.
Recommendation — Remove or tightly constrain inactive accounts and reduce takeover opportunities. Require stronger validation for account recovery and refund-destination changes.
MITRE ATT&CKT1078 — Valid AccountsAttackers often use breached personal data to gain access with legitimate-looking accounts.
T1110 — Brute ForceRepeated recovery attempts and credential guessing often precede account takeover.
Recommendation — Hunt for abuse of valid taxpayer accounts and suspicious login anomalies. Rate-limit and alert on repeated authentication or recovery attempts.

Practitioner Guidance

What to prioritise: Put the tightest controls on the actions that move money, especially account recovery and direct-deposit changes. If those paths are weak, refund fraud will keep outpacing detection.

What to verify: Test whether a breached-data attacker can reset access, change banking details, and submit a filing without a separate high-assurance challenge. If yes, the workflow is still too trustful.

Decision rule: If an event can redirect a refund or materially change taxpayer contact details, treat it as a high-risk transaction and require stronger validation than ordinary login checks.

Practitioner takeaway: The agencies that reduce refund fraud fastest are the ones that make payout changes harder to abuse than a normal account login, then back that up with monitoring that spots campaign behavior early.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 19, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org