The Internal Revenue Service (IRS) and its Security Summit partners issued a warning to tax professionals regarding the increasing threat of phishing emails and other sophisticated schemes designed to steal sensitive taxpayer data. This alert marks the second week of their annual "Protect Your Clients; Protect Yourself" summer series, emphasizing evolving cyber threats and necessary countermeasures.

The Security Summit, a collaborative effort since 2015 involving the IRS, state tax agencies, and industry partners, aims to safeguard the tax system and taxpayers from identity theft and fraud. These crucial security tips will also be a primary focus at the upcoming Nationwide Tax Forums, three-day continuing education events scheduled for New York City (Aug. 18-20), Orlando (Sept. 1-3), and San Diego (Sept. 15-17).

Tax professionals face various phishing tactics, including general phishing and smishing via text, targeted spear phishing, deceptive clone phishing that mimics legitimate emails, and whaling attacks aimed at high-level executives. A new client scam also attempts to trick practitioners into opening malicious links or attachments by posing as potential clients. Warning signs include unexpected messages from trusted sources, duplicate emails with new links, urgent requests to open attachments, and slightly misspelled email addresses or URLs.

To combat these threats, the IRS and Security Summit partners recommend "Security Six" protections. These include installing and maintaining anti-virus software, using firewalls, implementing multi-factor authentication as required by the Federal Trade Commission Safeguards Rule, routinely backing up critical files, employing drive encryption for sensitive data, and utilizing a virtual private network for secure data transmission.

In the event of a security incident or identity theft, tax professionals are advised to promptly contact their IRS Stakeholder Liaison and report details to the appropriate state tax agency through the Federation of Tax Administrators.