Every tax professional—whether a large firm or a solo preparer—is a target for cybercriminals seeking taxpayer data. Their goal is simple: steal client information to file fraudulent returns that appear legitimate and are harder to detect. (“Their objective: to steal your clients’ data so they can file fraudulent tax returns…”)
Criminals use phishing emails, fake calls, malware, and attempts to obtain passwords, EFINs, or CAF numbers. Protecting taxpayer data is not optional—it is required by federal law.
FTC Safeguards Rule (16 CFR Part 314)
Professional tax preparers are considered financial institutions under the FTC Safeguards Rule. They must:
- Develop and maintain a written Information Security Program
- Implement administrative, technical, and physical safeguards
- Protect against unauthorized access and anticipated threats (“This Safeguards Rule requires… an Information Security Program.”)
IRS Publication 4557 provides a detailed checklist for compliance.
FTC Financial Privacy Rule (16 CFR Part 313)
This rule requires financial institutions to:
- Provide privacy notices explaining data collection and sharing
- Allow customers to limit certain types of information sharing
- Restrict how third parties may use shared financial information (“Customers have the right to limit some sharing of their information.”)
Security Best Practices
Whether required by law or not, all tax professionals should follow these core practices:
- Assign responsibility for data security
- Assess risks across operations, systems, and physical environments
- Create a written security plan
- Implement appropriate safeguards
- Use service providers with adequate security controls
- Continuously monitor and update the program (“Monitor, evaluate, and adjust your security program…”)
Examples of effective controls:
- Locked storage for files
- Password‑protected systems
- Encryption of stored data
- Secure backups
- Shredding sensitive paper
- Never emailing unencrypted personal information
IRS e‑File Security & Privacy Standards
Online Providers must meet six mandatory standards:
- Extended Validation SSL Certificate
Valid EV SSL certificate with minimum 1024‑bit RSA/128‑bit AES.
- Weekly External Vulnerability Scans
Performed by a PCI‑certified Approved Scanning Vendor located in the U.S.
- Written Privacy & Safeguard Policies
Must include: “We maintain physical, electronic and procedural safeguards that comply with applicable law and federal standards.”
- Protection Against Bulk Fraudulent Filing
Systems must block automated or mass fraudulent submissions.
- Public Domain Name Registration
Domain must be U.S.‑registered, ICANN‑accredited, and locked.
- Reporting Security Incidents
Incidents must be reported to the IRS no later than the next business day. If the provider’s website caused the breach, data collection must stop immediately.
Identity Theft
Tax‑related identity theft occurs when someone uses a stolen SSN or EIN to file a fraudulent return or create false wage documents. (“Tax‑related identity theft occurs when someone uses a stolen social security number…”)
The IRS never initiates contact by email, text, or social media to request personal information.
Phishing attempts should be reported to phishing@irs.gov.
Identity Protection PIN (IP PIN)
An IP PIN is a six‑digit number that prevents unauthorized filing. The IRS issues IP PINs to confirmed victims and allows voluntary enrollment after identity verification.
A missing or incorrect IP PIN will cause:
- Rejection of an e‑filed return
- Delays in processing a paper return
The IRS will never ask for an IP PIN.
Signs of Tax‑Related Identity Theft
- More than one return filed under the same SSN
- Unexpected balance due or collection notices
- IRS wage records showing unknown employers
- Business clients receiving notices about fictitious employees or amended returns
What To Do if Identity Is Stolen
FTC recommendations:
- File a report at identitytheft.gov
- Contact financial institutions
- Close compromised accounts
If tax‑related identity theft is suspected:
- Respond immediately to IRS notices
- File Form 14039 (Identity Theft Affidavit)
- Ensure a power of attorney is on file for practitioner inquiries
Victims may request a redacted copy of the fraudulent return if their name/SSN appears as primary or secondary taxpayer.
Business Identity Theft
Business identity theft involves unauthorized use of a business’s identifying information to obtain tax benefits or file fraudulent returns.
Tax‑related indicators:
- IRS notices about fictitious employees
- Activity on closed or dormant businesses
- Returns accepted as amended when none were filed
Non‑tax indicators:
- Unauthorized credit accounts
- Unexplained withdrawals
- Missing mail
- Data breach notifications
Protective actions:
- Respond to IRS notices immediately
- File a police report
- Review account statements
- Monitor business registrations
- Check credit reports
- Update security software
- Stay alert for unusual activity
A fraud alert may be placed with:
- Dun & Bradstreet
- Equifax
- Experian
- TransUnion