United States: Security Summit Urges Tax Pros to Bolster Identity Theft Defenses

On 16 September 2026, the IRS and Security Summit partners—state tax agencies and private-sector tax industry leaders—released IR-2026-111, closing the summer awareness campaign with a renewed call for tax professionals to implement written information security plans (WISPs) required by the Gramm-Leach-Bliley Act and IRS Publication 4557. The notice highlights a surge in spear-phishing campaigns targeting practitioner credentials to access client data and file fraudulent returns ahead of the October 15 extension deadline.

Key Takeaways

  • Mandatory Safeguards: All paid preparers must maintain a WISP addressing risk assessment, employee training, access controls, and incident response; failure exposes firms to FTC enforcement and IRS Office of Professional Responsibility sanctions.
  • Multi-Factor Authentication: Summit partners mandate MFA for all tax software accounts, cloud storage, and remote access portals, citing that 94% of breached firms in 2025 lacked MFA on at least one critical system.

Disclaimer: This article is compiled and summarized by the AI based on publicly available information and is for general information purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. Please consult a qualified professional tax advisor or legal counsel for tax advice.

Source: Read Official Announcement