IRS - Internal Revenue Service

08/04/2026 | Press release | Distributed by Public on 08/04/2026 08:15

Tax pros should watch out for phishing emails and other attacks, Security Summit warns

Week 2 of the Protect Your Clients; Protect Yourself series focuses on evolving threats and countermeasures

IR-2026-85, Aug. 4, 2026

WASHINGTON - The Internal Revenue Service and Security Summit partners today warned tax professionals to watch for phishing emails and other schemes designed to steal sensitive taxpayer data.

This is the second in the five-part Protect Your Clients; Protect Yourself summer series, organized annually by the Security Summit, which includes tax professionals, industry partners, state tax agencies, and the IRS. The public-private partnership has worked together since 2015 to protect the tax system and taxpayers from identity theft and fraud.

These security tips will be a key focus of the Nationwide Tax Forums this summer. In addition to the five news releases, tax professional security will be featured at the forums, which are three-day continuing education events.

The forums continue Aug. 18-20 in New York City, Sept. 1-3 in Orlando, and Sept. 15-17 in San Diego. Registration deadlines for the remaining forums are approaching quickly, and most forums sell out before the registration deadline.

Phishing, spear phishing, clone phishing, and whaling

Among the most common threats facing tax pros are phishing and related scams. These scams are designed to trick recipients into disclosing personal information such as passwords, bank account numbers, credit card numbers, or Social Security numbers.

Tax professionals and taxpayers should be aware of different phishing terms and what the scams might look like:

  • Phishing/Smishing: Phishing emails or SMS/texts, known as smishing, attempt to trick recipients into clicking a suspicious link, providing information, or downloading a malware file. Phishing attempts are often sent to multiple email addresses at a business or agency, increasing the chance someone will fall for the scam.
  • Spear phishing: Spear phishing targets a specific person or firm and delivers a more realistic email known as a lure. These scams can be harder to identify since they do not occur in large numbers.
  • Clone phishing: Clone phishing is a phishing scam that copies a legitimate email and resends a nearly identical message while pretending to be the original sender. The cloned message replaces a safe link or attachment with one that contains malware or directs the recipient to a fake site to verify accounts, enter personal information or claim refunds.
  • Whaling: Whaling attacks generally target leaders or other executives with access to large amounts of information at an organization or business. Additional whaling targets include payroll offices, human resource departments, and financial offices.
  • New client scam: New client scams target tax pros with emails from senders who pretend to be potential clients to trick practitioners into opening links or attachments that infect computer systems to steal client information.

Warning signs of a scam

Regardless of the type of phishing attempt, tax pros can protect themselves and their businesses by staying alert and looking for warning signs like these:

  • An unexpected email or text claiming to come from a known or trusted source, such as a colleague, bank, credit card company, cloud storage provider, tax software provider, the IRS, and other government agencies.
  • A duplicate email from what appears to be a known trusted source that contains a new attachment or hyperlink.
  • A message, often urgent in tone, pressuring the recipient to open a link or attachment using a false narrative, such as a request to update an expired password.
  • An email address, number, or link that is slightly misspelled or has a different domain name or URL, such as irs.com instead of IRS.gov. A closer look at these email addresses, including hovering the cursor over the email address, can show slight variations of legitimate addresses.

Security Six adds up to more protection

As data thieves continue evolving their tactics, the IRS and the Security Summit partners remind tax professionals of six essential steps to protect sensitive taxpayer information. The Security Six protections offer a relatively simple but essential starting point for tax pros to protect their offices, computers, data, and clients from thieves and hackers:

  • Anti-virus software: Install and maintain anti-virus software and the latest software updates. Anti-virus protection is a great first line of defense.
  • Firewalls: Use firewalls to shield computers and networks from malicious or unnecessary web traffic.
  • Multi-factor authentication: Use multi-factor authentication, which is a requirement under Federal Trade Commission Safeguards Rule, to protect against cloud-based schemes.
  • Backup software or services: Back up critical files routinely to protect against data loss from cyberattacks, device failures, or natural disasters.
  • Drive encryption: Use data encryption to transform sensitive client data on computers into protected files that are unreadable to outsiders.
  • Virtual private network: Use a virtual private network to create a secure, encrypted tunnel for transmitting data between a remote user and the company network.

What to do after a security incident

Tax professionals who are victims of any of these schemes or identity theft should quickly contact their IRS Stakeholder Liaison and provide details of the situation. Tax professionals can also share information with the appropriate state tax agency by visiting the Federation of Tax Administrators Report a Data Breach page.

IRS - Internal Revenue Service published this content on August 04, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on August 04, 2026 at 14:16 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]