The US Internal Revenue Service and Security Summit have issued a final warning urging tax professionals to strengthen safeguards against phishing, malware, identity theft, and other evolving threats targeting sensitive taxpayer information.

The US Internal Revenue Service (IRS) and the Security Summit have issued a final warning to tax professionals as part of their five-week awareness campaign on protecting client information on 16 September 2026.

The reminder concludes the fifth and final week of the “Protect Your Clients; Protect Yourself” awareness series, which provides tax professionals with resources to strengthen safeguards and protect sensitive taxpayer information.

Coordinated effort against fraud

The Security Summit, formed in 2015, brings together tax professionals, industry partners, state tax agencies, and the IRS to combat identity theft and fraud in the tax system. IRS CEO Frank J. Bisignano stated that protecting taxpayer information remains essential to maintaining public confidence in tax administration. The partnership emphasised that as fraud methods evolve, ongoing vigilance is critical.

Primary threats targeting tax firms

Tax professionals face increasingly complex attacks. Criminals pose as new clients to distribute malware disguised as tax documents. Scammers also target Electronic Filing Identification Numbers, Preparer Tax Identification Numbers, and Centralised Authorisation File credentials through phishing messages.

IRS impersonation continues through email, text, social media direct messages, spoofed phone numbers, and automated calls designed to trick victims into sharing financial data or opening infected files. On social media platforms, viral “tax hacks” mislead taxpayers into filing false returns or claiming ineligible credits, resulting in audit delays and penalties.

Detection and response

Tax firms should watch for unusual computer behaviour, system slowdowns, or locked access. Rejected e-filed returns due to duplicate Social Security numbers signal potential breaches. IRS authentication letters or e-filed acknowledgements sent without filing activity indicate compromised accounts. Clients may receive unexpected IRS Online Account creation notices or tax transcripts they never requested.

Available protections

The IRS provides Publication 5708 as a template for creating written information security plans. Essential safeguards include antivirus software, firewalls, data encryption, multi-factor authentication, and virtual private networks.

The Identity Protection PIN program assigns clients a six-digit PIN to block unauthorised filings. When breaches occur, tax professionals must report incidents to IRS Stakeholder Liaisons and state tax agencies through the Federation of Tax Administrators portal, then notify affected clients about protective measures like Form 14039, the Identity Theft Affidavit.

Earlier, the IRS issued guidance on 3 September 2026 during National Preparedness Month encouraging taxpayers to protect essential tax and financial records before emergencies occur.