The Internal Revenue Service today encouraged taxpayers to take simple steps to strengthen online security during Cybersecurity Awareness Month.
Cybersecurity Awareness Month highlights the role everyone can play in protecting personal, financial and tax information from identity thieves and scammers. For taxpayers, tax professionals and organizations across the tax community, that starts with everyday actions that help strengthen online security.
“Criminals continue to look for new ways to steal taxpayer information and exploit trusted partnerships,” said IRS Chief Executive Officer Frank J. Bisignano. “Taxpayers and tax professionals can help protect sensitive information and strengthen the security of the tax system by making cybersecurity practices part of their routine year-round.”
The IRS joins the Cybersecurity and Infrastructure Security Agency and Security Summit partners in encouraging taxpayers to make cybersecurity part of their daily routine. The Cybersecurity and Infrastructure Security Agency (CISA) offers cybersecurity resources that individuals, families, businesses and organizations can use to strengthen their online security.
Take simple steps to strengthen cybersecurity
The IRS encourages taxpayers and tax professionals, businesses and other organizations to take these steps:
- Use strong, unique passwords. Use different passwords for important accounts and consider using a password manager.
- Turn on multifactor authentication if available, to add an extra layer of protection to online accounts.
- Update software and devices. Install updates on computers, phones, tablets, apps, browsers and security software. Turn on automatic updates when possible.
- Recognize and report scams. Be cautious of unexpected emails, text messages, social media messages, phone calls or letters that request personal or financial information or pressure taxpayers to act immediately.
- Protect tax records. Store digital tax records securely, encrypt sensitive files and back up important information.
- Use secure networks. Avoid using public Wi-Fi to access financial accounts, tax records or IRS online services.
Watch for tax scams
Scammers continue to use U.S. mail, emails, text messages, social media and phone calls to impersonate the IRS and other trusted organizations. These scams may promise a larger refund, claim a taxpayer’s account is locked, demand immediate payment or direct taxpayers to fake websites.
Businesses, payroll professionals and human resources offices should remain alert for phishing, fake invoices, W-2 and payroll-related schemes designed to steal employee information, credentials or money. Requests to change sensitive employee or payment information should be verified through a trusted channel.
Tax professionals, including enrolled agents, payroll professionals, certified public accountants (CPA), attorneys, or other tax return preparers, should watch for phishing emails and other schemes designed to steal sensitive taxpayer data. Scammers may pose as a prospective client or use a compromised email account to persuade tax professionals to open malicious links or attachments.
IRS tools can help
The IRS offers secure online tools and resources that can help protect accounts and tax information:
- Get an Identity Protection PIN. An Identity Protection PIN is a six-digit number that helps prevent someone else from filing a federal tax return using a taxpayer’s Social Security number or individual taxpayer identification number.
- Online Account for Individuals. Taxpayers can securely access personal tax information, view notices, make payments and manage other tax tasks.
- Business Tax Account. Businesses can securely access available tax information and manage certain tax responsibilities online.
- Tax Pro Account. Tax professionals can securely manage active client authorizations and submit authorization requests online.
- Written Information Security Plan. Federal law requires tax and accounting professionals to create and maintain a WISP to protect client information.
How to know it’s the IRS
The IRS normally contacts taxpayers the first time by mail. The IRS sends emails or text messages only when taxpayers opt in and never sends direct messages through social media. The IRS or private collection agencies may call about account matters, but the IRS will never call to demand immediate payment, threaten arrest or tell taxpayers they are due a refund.
Taxpayers should not click links, open attachments or respond to unexpected messages claiming to be from the IRS.
Report scams and suspicious contacts
Taxpayers who receive suspicious tax-related U.S. mail, emails, text messages, or social media messages should visit IRS.gov/SubmitATip to find the appropriate way to report the issue. Taxpayers can also report suspected tax fraud, scams, identity theft, or other tax-related wrongdoing.
The IRS initiates contact primarily through regular U.S. Mail. The IRS will never:
Initiate contact via social media direct messages or unprompted text messages.
Call to demand immediate payment using prepaid debit cards, gift cards, or wire transfers.
Threaten immediate police arrest or legal action over the phone.
Promise guaranteed refunds or claim your account is locked via unsolicited links.
An Identity Protection PIN (IP PIN) is a secure six-digit number assigned to taxpayers to prevent fraudsters from filing a federal tax return using their Social Security Number (SSN) or Individual Taxpayer Identification Number (ITIN). You can obtain an IP PIN directly through your secure Online Account for Individuals on IRS.gov.
The IRS recommends implementing the following everyday cybersecurity habits:
Password Management: Use strong, unique passwords for every account and utilize a password manager.
Multi-Factor Authentication (MFA): Enable MFA on all online banking, tax, and personal accounts.
Software Updates: Turn on automatic updates for devices, operating systems, web browsers, and antivirus software.
Secure Browsing: Avoid logging into financial or IRS accounts while connected to public Wi-Fi networks.
Tax Professionals & CPAs: Federal law requires tax preparers, attorneys, and accounting professionals to create and maintain a Written Information Security Plan (WISP) to safeguard client data.
Businesses & HR Departments: Organizations must watch for payroll schemes, phishing, and fake W-2 requests. Always verify requests to alter sensitive employee records or payment routes using a separate, trusted communication channel.
Do not click any links, open attachments, or reply to suspicious messages. Instead:
Visit IRS.gov/SubmitATip to find the appropriate reporting process.
Forward phishing emails claiming to be from the IRS to phishing@irs.gov.
Report suspected tax fraud, identity theft, or impersonation scams through official channels at IRS.gov.

Suresh holds a Master of Commerce (M.Com) degree and is a dedicated personal finance researcher and writer. Combining his advanced academic background in commerce with deep industry research, he covers complex topics like taxation, banking systems, credit analysis, and personal finance strategies. As the founder of Tax Assistant (taxassistant.org), Suresh is committed to translating complicated financial guidelines and economic data into simple, accurate, and actionable educational resources for everyday readers.
















