IRS suspends $7.2 million Equifax contract

The move comes after the credit-reporting bureau suffers another security black eye.

Steven Musil Night Editor / News
Steven Musil is the night news editor at CNET News. He's been hooked on tech since learning BASIC in the late '70s. When not cleaning up after his daughter and son, Steven can be found pedaling around the San Francisco Bay Area. Before joining CNET in 2000, Steven spent 10 years at various Bay Area newspapers.
Expertise I have more than 30 years' experience in journalism in the heart of the Silicon Valley.
Steven Musil
2 min read
Equifax Headquarters

The IRS has put that contract it holds with Equifax on standby.

Getty Images

The IRS has temporarily suspended the $7.2 million contract it recently awarded Equifax to help verify taxpayer identity and validation for the government agency, the IRS said Thursday.

Equifax has been under intense scrutiny since disclosing last month it suffered a massive hack that may have exposed personal information for roughly half the US population. The move was announced amid reports the credit-reporting bureau had been attacked yet again, this time serving up malicious software to those who visited the company's website.

The IRS plans to review the security of Equifax's systems during the suspension, an agency spokesman told Politico. The move means millions of Americans won't be able to establish new accounts to access their online records.

"The IRS emphasized that there is still no indication of any compromise of the limited IRS data shared under the contract," agency spokesman Matthew Leas said in a statement. "The contract suspension is being taken as a precautionary step as the IRS continues its review."

Equifax revealed last month that hackers made off with a virtual treasure trove of financial data from as many as 145 million people in the US, including names, Social Security numbers, birth dates and addresses of customers. When queried about the contract in light of the hack earlier this month, the IRS told the House Ways and Means committee it was forced to extend its contract with Equifax.

The IRS actually awarded its authentication service contract to another company in July, Jeffrey Tribiano, the agency's deputy commissioner for operations support told members of Congress. 

Equifax protested losing the contract to the US Government Accountability Office on July 7, according to documents. The office will decide on the protest by Oct. 16. Until then, the IRS cannot move onto its new partner.

Equifax said it's working with the IRS to resolve the agency's concerns.

"Yesterday, the IRS notified us that they have issued a Stop-Work Order under our Transaction Support for Identity Management contract," Equifax said in a statement. "We remain confident that we are the best party to perform the services required in this contract. We are engaging IRS officials to review the facts and clarify available options."

Representatives for the IRS didn't respond to a request for comment.

Updated 10/13 at 10:40 a.m. PT with Equifax comment.

Solving for XX: The industry seeks to overcome outdated ideas about "women in tech."

Special Reports: All of CNET's most in-depth features in one easy spot.