The Internal Revenue Service (IRS) and its Security Summit partners issued a warning today to tax professionals, urging vigilance against phishing emails and other sophisticated schemes designed to steal sensitive taxpayer data. This alert marks the second installment of the annual five-part “Protect Your Clients; Protect Yourself” summer series, a collaborative effort since 2015 involving tax professionals, industry partners, state tax agencies, and the IRS to combat identity theft and fraud.
Common threats include various forms of phishing, such as spear phishing, which targets specific individuals or firms with realistic lures, and clone phishing, which mimics legitimate emails to deliver malware or direct users to fake sites. Whaling attacks specifically target executives or departments like payroll and human resources, while new client scams trick tax pros into opening malicious links or attachments by posing as potential clients.
Tax professionals are advised to look for warning signs, including unexpected emails from trusted sources, duplicate messages with new attachments, urgent requests to click links, and misspelled email addresses or URLs. These security tips will be a primary focus at the upcoming Nationwide Tax Forums in New York City (August 18-20), Orlando (September 1-3), and San Diego (September 15-17).
To enhance protection, the Security Summit recommends six essential steps: installing and maintaining anti-virus software, using firewalls, implementing multi-factor authentication as required by the Federal Trade Commission Safeguards Rule, routinely backing up critical files, employing drive encryption, and utilizing a virtual private network. In the event of a security incident or identity theft, tax professionals should promptly contact their IRS Stakeholder Liaison and report the data breach to the appropriate state tax agency via the Federation of Tax Administrators.