On September 16, 2026, the IRS and its Security Summit partners issued IR-2026-111, urging tax professionals to remain vigilant against identity theft and protect sensitive taxpayer information.
What the IRS Announced
The release concludes the 2026 “Protect Your Clients; Protect Yourself” summer awareness series. The Security Summit—a partnership among the IRS, state tax agencies, tax professionals, and industry partners—has worked since 2015 to combat tax-related identity theft and fraud.
The IRS emphasized that tax professionals remain targets because they hold sensitive client information. It encouraged firms to review basic safeguards, stay informed about evolving schemes, and report suspected data theft promptly.
Threats Tax Professionals Should Watch For
The IRS highlighted several recurring schemes:
- “New client” scams, in which a fraudster posing as a prospective client sends a malicious link or attachment disguised as a tax document.
- EFIN, PTIN, and CAF scams seeking preparer identification numbers or related documents.
- IRS impersonation through email, text, direct messages, spoofed calls, or automated calls designed to obtain information or deliver malware.
- Misleading social media tax advice that encourages taxpayers to submit false information or claim credits for which they do not qualify.
Warning Signs of Possible Data Theft
Possible indicators for a tax practice include unusual computer activity, rejected e-filed returns because a client’s Social Security number was already used, unexpected authentication letters or e-file acknowledgments, and IRS notices involving unknown clients or a compromised Centralized Authorization File number.
Clients may also receive an IRS authentication letter despite not filing a return, notice that an IRS Online Account was created without authorization, an unrequested tax transcript, or a refund tied to a return they did not file.
Prevention and Incident Response
The IRS pointed tax professionals to Publication 5708 for creating a written information security plan and to its Security Six protections: antivirus software, firewalls, backups, encrypted drives, multifactor authentication, and virtual private networks.
If data theft occurs, the IRS advises tax professionals to contact their local IRS Stakeholder Liaison immediately and report the breach to the appropriate state tax agency. Affected clients should be informed and directed to appropriate protective steps, which may include obtaining an Identity Protection PIN or filing Form 14039 when applicable.
Why It Matters for Small Business Owners
A Schedule C filer may share tax returns, identification details, and financial records with a preparer. Before sending records, confirm how the preparer accepts documents, verify unexpected requests through a known contact method, and avoid opening unsolicited attachments or links.
Simple-C helps Schedule C filers keep income, expenses, and supporting records organized — making it easier to prepare the records a trusted tax professional requests without sending unrelated documents.
This article provides general information, not tax, legal, or cybersecurity advice. Security threats and IRS guidance can change. Confirm current reporting and protection steps on IRS.gov.