On August 4, 2026, the IRS and its Security Summit partners issued a warning to tax professionals: phishing emails and related scams are actively targeting tax offices to steal sensitive taxpayer data.
The alert (IR-2026-85) is the second release in the five-part “Protect Your Clients; Protect Yourself” summer series, organized annually by the Security Summit — the public-private partnership of tax professionals, industry partners, state tax agencies, and the IRS that has worked together since 2015 to protect the tax system from identity theft and fraud.
The Phishing Landscape: Four Scams Tax Pros Face
The IRS identified four overlapping types of email-based attacks that currently target tax professionals:
Phishing / Smishing
Phishing emails or SMS/texts (smishing) attempt to trick recipients into clicking a suspicious link, providing personal information, or downloading malware. These attempts are often sent to multiple email addresses at a business or agency, increasing the chance that someone will fall for the scam.
Spear Phishing
Spear phishing targets a specific person or firm and delivers a more realistic email known as a lure. Because these scams are tailored and do not arrive in large batches, they can be much harder to identify than mass phishing campaigns.
Clone Phishing
Clone phishing takes a legitimate email and resends a nearly identical copy, pretending to be the original sender. The cloned message replaces a safe link or attachment with one that contains malware or directs the recipient to a fake website to verify accounts, enter personal information, or claim refunds.
Whaling
Whaling attacks target leaders or executives with access to large amounts of organizational information. Payroll offices, human resources departments, and financial offices are also frequent targets.
The “New Client” Scam
The IRS highlighted a particularly effective lure: the new client scam. A sender pretends to be a potential client and sends a tax professional an email with links or attachments. Opening them can infect the practitioner’s computer systems and expose client data — including names, Social Security numbers, and bank details.
Since tax professionals handle exactly this kind of sensitive information, the stakes are high.
Warning Signs of a Scam
The IRS says tax pros should watch for:
- An unexpected email or text claiming to come from a trusted source — a colleague, bank, cloud storage provider, tax software provider, or a government agency.
- A duplicate email from what looks like a trusted source, but with a new attachment or hyperlink.
- A message with an urgent tone, pressuring the recipient to open a link or attachment — like a request to update an expired password.
- An email address, number, or link that is slightly misspelled or has a different domain —
irs.cominstead ofIRS.gov. Hovering over the sender address reveals these variations.
The Security Six
The IRS and Security Summit partners recommend six essential protections — known as the Security Six:
- Anti-virus software — install, maintain, and update regularly.
- Firewalls — shield computers and networks from malicious or unnecessary web traffic.
- Multi-factor authentication — required under the Federal Trade Commission Safeguards Rule.
- Backup software or services — back up critical files routinely.
- Drive encryption — transform sensitive client data into protected, unreadable files.
- Virtual Private Network (VPN) — create a secure, encrypted tunnel for transmitting data.
What to Do After a Security Incident
Tax professionals who fall victim to any of these schemes should quickly contact their IRS Stakeholder Liaison and provide details. They can also share information with the appropriate state tax agency through the Federation of Tax Administrators’ Report a Data Breach page.
What Small Business Owners Should Take Away
Even if you are not a tax professional, this warning is relevant if your business handles customer or employee data:
- Train your team to spot phishing emails and verify unusual requests before acting.
- Use multi-factor authentication on every account that offers it.
- Back up your books regularly so a ransomware or data-loss incident does not wipe out your records.
- Check sender addresses carefully — small misspellings are the most common tell.
A breach can mean months of cleanup, delayed refunds, and stolen identities. For a Schedule C filer, stolen SSN/ITIN information can enable fraudulent individual returns filed in your name; a stolen EIN creates a separate business identity-theft risk, and a compromised business bank account is a separate financial-account risk that should be reported to your bank immediately.
Simple-C keeps your Schedule C income and expenses organized in one secure place — so when you work with a tax preparer, you can share clean, accurate records without exposing more than you need to.
This article provides general information, not tax or legal advice. Security guidance from the IRS can change. Confirm the current recommendations on IRS.gov.