United States: Security Summit Warns Tax Professionals of Phishing Attacks

On August 4, 2026, the Internal Revenue Service and its Security Summit partners issued a joint warning to tax professionals about a surge in phishing emails and other cyber attacks targeting the tax community. The advisory highlights that malicious messages often impersonate IRS officials or tax software providers, contain malicious attachments or links, and attempt to harvest client data such as Social Security numbers, bank account details, and login credentials. The warning outlines several red flags, including unexpected attachments, urgent language, and mismatched sender domains. To mitigate risk, the IRS recommends that tax professionals enable multi‑factor authentication on all email accounts, verify sender addresses before clicking links, and employ up‑to‑date anti‑phishing filters. Additionally, professionals should educate staff on recognizing social engineering tactics and should report suspicious messages to the IRS via the phishing@irs.gov address. The advisory also provides a checklist for incident response, emphasizing the need to isolate compromised systems, preserve logs, and notify affected clients promptly. By following these best practices, tax preparers can safeguard sensitive taxpayer information and reduce the likelihood of data breaches.

Key Takeaways

  • Phishing Indicators: Unexpected attachments, urgent tone, spoofed sender addresses.
  • Preventive Measures: Multi‑factor authentication, anti‑phishing filters, staff training.
  • Response Protocol: Isolate systems, preserve evidence, report to IRS, notify clients.

Source: Read Original Announcement