On 4 September 2026, the Internal Revenue Service (IRS) and its Security Summit partners issued IR-2026-106 urging tax professionals and taxpayers to enhance safeguards against tax-related identity theft. The announcement comes amid rising cyber threats targeting sensitive taxpayer data during the extended filing season. The Security Summit, a collaborative effort between the IRS, state tax agencies, and the tax industry, emphasized the critical importance of multi-factor authentication, encryption, and regular security awareness training. Tax professionals are reminded of their legal obligation under the Gramm-Leach-Bliley Act to maintain a Written Information Security Plan (WISP) protecting client data. The IRS also highlighted common phishing schemes, such as fake e-file notifications and fraudulent refund requests, and directed practitioners to Publication 4557, Safeguarding Taxpayer Data, for detailed compliance steps.
Key Takeaways
- Mandatory Written Information Security Plan: All tax preparers must implement and annually review a WISP tailored to their firm’s size and complexity, including risk assessments, employee training, and incident response protocols.
- Multi-Factor Authentication (MFA) Adoption: The Summit strongly recommends enabling MFA on all tax software accounts, cloud storage, and email systems to prevent unauthorized access even if credentials are compromised.
- Phishing Awareness and Reporting: Tax professionals should educate staff to recognize sophisticated phishing emails impersonating the IRS, software providers, or clients, and report suspicious messages to phishing@irs.gov immediately.
Disclaimer: This article is compiled and summarized by the AI based on publicly available information and is for general information purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. Please consult a qualified professional tax advisor or legal counsel for tax advice.
Source: Read Official Announcement
