Security Summit closes summer series with data security reminder for tax pros

IRS Security Summit Warns Tax Professionals About Identity Theft, Data Breaches and Cybersecurity Threats

Week 5 of “Protect Your Clients; Protect Yourself” offers tools and advice to help protect sensitive data

Issue Number: IR-2026-111

WASHINGTON — The Internal Revenue Service and the Security Summit partners today urged tax professionals to stay vigilant against identity theft.

The IRS and Security Summit partners are reminding tax professionals and tax preparers to protect taxpayer data from identity theft, phishing scams, cyberattacks, data breaches and tax-related fraud. The agency recommends a Written Information Security Plan (WISP), multifactor authentication, Identity Protection PINs and immediate breach reporting procedures to help safeguard sensitive taxpayer information.

Key Takeaways for Tax Professionals

  • Protect taxpayer data with multifactor authentication, encryption and secure backups.
  • Create and maintain a Written Information Security Plan (WISP).
  • Watch for phishing emails, EFIN scams, PTIN scams and social engineering attacks.
  • Consider the IRS Identity Protection PIN program to help prevent tax-related identity theft.
  • Report suspected data theft immediately to the IRS and state tax agencies.

The reminder concludes the fifth and final week of the “Protect Your Clients; Protect Yourself” awareness series, which provides tax professionals with resources to strengthen safeguards and protect sensitive taxpayer information.

“Protecting taxpayer information is fundamental to maintaining confidence in our tax system,” said IRS Chief Executive Officer Frank J. Bisignano. “For more than a decade, the Security Summit has brought government, industry and the tax professional community together to strengthen that protection. As threats evolve, continued vigilance and partnership will remain essential to protecting taxpayers and the integrity of the tax system.”

The Security Summit, a public-private partnership of tax professionals, industry partners, state tax agencies, and the IRS, has worked since 2015 to protect the tax system from identity theft and fraud.

Tax professionals and tax preparers remain prime targets for identity theft, phishing attacks, data breaches, ransomware and other cybersecurity threats designed to steal sensitive taxpayer information.. Millions of taxpayers trust tax pros with highly sensitive information, making it important for tax professionals to stay informed, review security basics, and promptly report data theft.

What Identity Theft and Data Security Threats Target Tax Professionals?

Common schemes include:

  • “New client” schemes: Fraudsters pose as prospective clients and send malicious links or attachments disguised as tax documents.
  • EFIN, PTIN, and CAF scams: Scammers send phishing messages seeking tax professionals’ identification numbers and documents, including Electronic Filing Identification Numbers and related documentation, Preparer Tax Identification Numbers, and Centralized Authorization File numbers.
  • IRS impersonation by email, text, and phone: Scammers use email, text messages, direct messages, spoofed caller ID, and computer-generated calls to lure victims into clicking suspicious links, opening malware attachments, or sharing sensitive financial information.
  • Misleading tax advice on social media: Viral “tax hacks” can push taxpayers to file returns with false information or claim credits for which they do not qualify, leading to refund delays, audits, or penalties.

These scams target taxpayer data, tax preparation firms, accounting practices and independent tax professionals. Criminals often use phishing, credential theft and social engineering techniques to gain access to sensitive taxpayer records.

How Can Tax Professionals Tell if Their Data Has Been Compromised?

Tax professionals may notice:

  • Unusual computer activity, slow performance, or being locked out of systems.
  • Client e-filed returns being rejected because a Social Security number was already used.
  • Unexpected IRS authentication letters or e-filed acknowledgments.
  • IRS notifications involving clients they do not represent or a compromised CAF number.

Clients may receive:

  • Authentication letters such as 5071C, 4883C, or 5747C from the IRS even though they did not file a return.
  • Notice that an IRS Online Account was created in their name without their authorization.
  • Tax transcripts they did not request.
  • Tax refunds even though they did not file a return.

What IRS Tools Help Tax Professionals Protect Taxpayer Data?

The IRS offers tools to help tax professionals protect their clients and businesses:

What Is a Written Information Security Plan (WISP)?

A Written Information Security Plan (WISP) helps tax professionals identify security risks, protect taxpayer information, document safeguards, respond to security incidents and strengthen data security practices. IRS Publication 5708 provides guidance and templates that can help tax and accounting firms build a comprehensive security plan.

What Should Tax Professionals Do After a Data Breach?

If a breach occurs, tax professionals should:

Prompt reporting can help reduce fraud, limit taxpayer harm and support investigation of identity theft and unauthorized tax filings.

Where Can Tax Professionals Find IRS Data Security Resources?

Visit Identity Theft Central and Data Theft Information for Tax Professionals for more information and tools.

The IRS Security Summit encourages tax professionals to regularly review Publication 4557, Publication 5293, Publication 5708 and Publication 5709 to strengthen cybersecurity practices and protect taxpayer data from emerging threats.

Frequently Asked Questions

  • What should I do if my tax preparation business experiences a data breach?
  • What is an IRS Identity Protection PIN?
  • Why are tax professionals targeted by identity thieves?

    Conclusion

    As identity theft, tax fraud and cybersecurity threats continue to evolve, tax professionals should regularly review their security practices, strengthen authentication controls, update employee training and maintain a Written Information Security Plan. Taking proactive steps today can help safeguard taxpayer information and reduce the risk of fraud and data breaches.