IRS Security Summit Warns Tax Pros: Data Theft Threats Evolve

By Manoj Sharma

Published on:

IRS Security Summit Warns Tax Pros: Data Theft Threats Evolve
The Internal Revenue Service and the Security Summit partners today urged tax professionals to stay vigilant against identity theft.

The Internal Revenue Service and the Security Summit partners today urged tax professionals to stay vigilant against identity theft. 

The reminder concludes the fifth and final week of the “Protect Your Clients; Protect Yourself” awareness series, which provides tax professionals with resources to strengthen safeguards and protect sensitive taxpayer information. 

“Protecting taxpayer information is fundamental to maintaining confidence in our tax system,” said IRS Chief Executive Officer Frank J. Bisignano. “For more than a decade, the Security Summit has brought government, industry and the tax professional community together to strengthen that protection. As threats evolve, continued vigilance and partnership will remain essential to protecting taxpayers and the integrity of the tax system.”

The Security Summit, a public-private partnership of tax professionals, industry partners, state tax agencies, and the IRS, has worked since 2015 to protect the tax system from identity theft and fraud. 

Tax professionals remain prime targets for increasingly sophisticated identity thieves. Millions of taxpayers trust tax pros with highly sensitive information, making it important for tax professionals to stay informed, review security basics, and promptly report data theft. 

Ongoing threats

Common schemes include:

  • “New client” schemes: Fraudsters pose as prospective clients and send malicious links or attachments disguised as tax documents.
  • EFIN, PTIN, and CAF scams: Scammers send phishing messages seeking tax professionals’ identification numbers and documents, including Electronic Filing Identification Numbers and related documentation, Preparer Tax Identification Numbers, and Centralized Authorization File numbers.
  • IRS impersonation by email, text, and phone: Scammers use email, text messages, direct messages, spoofed caller ID, and computer-generated calls to lure victims into clicking suspicious links, opening malware attachments, or sharing sensitive financial information.
  • Misleading tax advice on social media: Viral “tax hacks” can push taxpayers to file returns with false information or claim credits for which they do not qualify, leading to refund delays, audits, or penalties.

Know the warning signs

Tax professionals may notice:

  • Unusual computer activity, slow performance, or being locked out of systems.
  • Client e-filed returns being rejected because a Social Security number was already used.
  • Unexpected IRS authentication letters or e-filed acknowledgments.
  • IRS notifications involving clients they do not represent or a compromised CAF number.

Clients may receive:

  • Authentication letters such as 5071C, 4883C, or 5747C from the IRS even though they did not file a return.
  • Notice that an IRS Online Account was created in their name without their authorization.
  • Tax transcripts they did not request.
  • Tax refunds even though they did not file a return.

Prevention tools

The IRS offers tools to help tax professionals protect their clients and businesses:

Report data theft immediately

If a breach occurs, tax professionals should:

  • Report the incident to a local IRS Stakeholder Liaison so the IRS can take steps to block fraudulent returns.
  • Report the breach to the appropriate state tax agency through the Federation of Tax Administrators’ Report a Data Breach webpage.
  • Inform affected clients and recommend protective steps, such as obtaining an Identity Protection PIN or, when appropriate, completing Form 14039, Identity Theft Affidavit PDF.

Stay informed

Q1: What is the primary purpose of the “Protect Your Clients; Protect Yourself” campaign?

A: Organized by the IRS and its Security Summit partners (state tax agencies and tax industry leaders), the five-week campaign aims to raise awareness among tax professionals. It provides actionable guidance, security resources, and tools to help tax practices strengthen their defenses against identity theft, phishing scams, and client data breaches.

Q2: What is a Written Information Security Plan (WISP), and is it required for tax professionals?

A: Yes, maintaining a Written Information Security Plan (WISP) is required by federal law for tax and accounting practices. A WISP outlines a firm’s administrative, technical, and physical safeguards to protect sensitive client data. The IRS provides templates and setup guidance in Publication 5708 and Publication 5709.

Q3: What are the “Security Six” basic protections recommended by the IRS?

A: The “Security Six” are fundamental security measures that every tax professional should implement to safeguard client credentials and devices:
Antivirus software
Firewalls
Data backup software/services
Encrypted hard drives
Multi-Factor Authentication (MFA) Virtual Private Networks (VPNs)

Q4: How can an Identity Protection PIN (IP PIN) protect my clients from tax-related identity theft?

A: An IP PIN is a unique six-digit number assigned to a taxpayer that prevents someone else from filing a federal tax return using their Social Security number (SSN). The IRS will reject any electronic or paper return filed without the correct IP PIN. Tax pros can encourage clients to voluntarily enroll in the IRS IP PIN Opt-In Program.

Q5: What steps should a tax professional take immediately if they suffer a data breach?

A: If a breach occurs, tax pros should immediately:
Contact a local IRS Stakeholder Liaison to report the breach so the IRS can block fraudulent returns. Report the incident to state tax authorities through the Federation of Tax Administrators’ breach portal.
Notify affected clients and advise them to protect their identity (e.g., obtaining an IP PIN or filing IRS Form 14039, Identity Theft Affidavit).