Compliance
Protecting Your Tax Practice from Identity Theft Attacks: Best Practices for Tax Professionals in Summer 2026
The IRS kicks off its 2026 ‘Protect Your Clients; Protect Yourself’ campaign—learn what tax pros must do now to shield client data from escalating identity-theft threats.
By NomadicTax Research Team • 5-8 min read • July 23, 2026
## Why risk is rising now
The IRS and its Security Summit partners launched a five-week campaign starting July 2026 called **Protect Your Clients; Protect Yourself**, designed to help tax professionals stay ahead of modern identity‐theft threats. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai)) Scammers are targeting preparers via phishing, spoofed documents, compromised credentials like PTINs or CAF numbers, and social media misinformation. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
## Key threats to watch out for
- **Emails, texts, calls** impersonating IRS or state tax agency officials; may include malicious attachments or spoofed caller IDs. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- **“New client” schemes**: scammers pose as clients with fake documents requests that actually install malware. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- **Misleading tax advice via social media** offering fake credit or refund claims. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- **Risk of PTIN, EFIN or CAF number theft**, which can facilitate fraudulent filings. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
## What security safeguards you should put in place now
- **Security Six** essentials:
* Anti-virus / anti-malware software
* Firewalls
* Regular backups (secure and encrypted)
* Multi-factor authentication (MFA)
* Encryption of sensitive drives and networks
* Virtual private networks (VPNs) for remote access or cloud storage use
([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- Create and maintain a **Written Information Security Plan (WISP)** that outlines controls, breach response, employee training, and system responsibilities. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- Train staff to recognize phishing, social engineering, and unusual client requests. Test procedures—don’t assume all emails are legitimate.
- Use official channels and verify identities—if a “client” asks for login credentials or personal IDs, verify with another method.
## How to respond if there’s a breach or incident
- Act immediately: notify your IRS Stakeholder Liaison if client data is compromised. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- Also notify state tax agency via Federation of Tax Administrators’ Report a Data Breach portal. ([irs.gov](https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft?utm_source=openai))
- Inform impacted clients; follow IRS guidance on Identity Protection PINs (IP PIN) and Form 14039 (Identity Theft Affidavit).
## Real-world example
Suppose an accounting firm receives a tax return via email from a “new client.” The return has attachments. One attachment claims to be a scanned W-2 but when opened, executes malware. The cybercriminal now has access to the system, steals PTIN, and later files fraudulent returns in clients’ names. If the firm had MFA on its email and WISP in place, the attack surface shrinks dramatically.
## Action plan checklist for tax pros
- Conduct a security audit of your systems this month.
- Ensure anti-virus, firewalls, backups are in place.
- Move to MFA everywhere possible.
- Draft or update your WISP document—include procedures for breach detection and incident response.
- Regular staff training on spotting scams, phishing.
- Stay plugged into IRS Security Summit resources and IRS news releases weekly.
---
This article was written by the NomadicTax Research Team under the US tax rules as of July 2026. Stay secure—your practice depends on it.