IRS warns tax professionals to watch for phishing emails targeting client data

The Internal Revenue Service and its Security Summit partners issued a warning on August 4, 2026, alerting tax professionals to watch for phishing emails and other cyberattacks designed to steal sensitive client data.

The alert, released as news release IR-2026-85, marks the second installment of the “Protect Your Clients; Protect Yourself” summer series, a five-week educational campaign organized annually by the Security Summit, according to the IRS. The public-private partnership brings together tax professionals, industry partners, state tax agencies, and the IRS—a coalition that has operated since 2015 to combat tax-related identity theft and fraud.

The IRS identified five distinct phishing tactics targeting tax professionals. Phishing and smishing (SMS text-based phishing) attempt to trick recipients into clicking suspicious links, providing credentials, or downloading malware. Spear phishing targets specific individuals or firms with more convincing, personalized emails. Clone phishing copies legitimate messages and replaces safe links or attachments with malicious ones or fake verification sites. Whaling attacks focus on executives, payroll staff, human resources, and financial offices with access to sensitive information. New client scams impersonate prospective clients seeking tax preparation services, with emails containing links or attachments designed to infect systems and steal client information.

Warning signs include unexpected emails from trusted sources, duplicate messages with new attachments, urgent-toned requests to click links using false narratives like password updates, and slightly misspelled email addresses or domain names—such as irs.com instead of irs.gov. Hovering over email addresses can reveal subtle variations from legitimate senders.

The IRS and Security Summit partners recommend six essential protections, known as the “Security Six,” to defend against evolving threats. These include installing and maintaining anti-virus software with latest updates, using firewalls to shield computers and networks from malicious traffic, enabling multi-factor authentication (a requirement under the Federal Trade Commission Safeguards Rule), routinely backing up critical files to protect against data loss from cyberattacks or device failures, using drive encryption to make sensitive client data unreadable to outsiders, and deploying virtual private networks to create secure, encrypted tunnels for remote data transmission.

The warning arrives amid a broader surge in data compromises. The Identity Theft Resource Center tracked 3,322 data breaches in 2025, representing a 5 percent increase over 2024 and underscoring the persistent threat to organizations holding sensitive information. Tax professionals who become victims of phishing schemes or identity theft should immediately contact their IRS Stakeholder Liaison and report details to their state tax agency through the Federation of Tax Administrators’ Report a Data Breach portal.

The Security Summit’s guidance will be featured at Nationwide Tax Forums this summer, three-day continuing education events scheduled for August 18-20 in New York City, September 1-3 in Orlando, and September 15-17 in San Diego. Most forums sell out before registration deadlines close.

Sources

  • Internal Revenue Service — Official news release IR-2026-85 (August 4, 2026) warning tax professionals about phishing emails and cyberattacks targeting client data, describing five types of phishing scams and the Security Six safeguards.
  • CPA Practice Advisor — August 4, 2026 article detailing the IRS and Security Summit warning, including specific phishing tactics, warning signs, and protective measures.
  • Identity Theft Resource Center — 2025 Annual Data Breach Report documenting 3,322 data breaches in 2025, a 5% increase over 2024.

Give your feedback

Be the first to rate this post
or leave a detailed review



ECIKS.org is an independent media. Support us by adding us to your Google News favorites:

Post a comment

Publish a comment