Every tax professional—whether a large firm or a solo preparer—is a target for cybercriminals seeking taxpayer data. Their goal is simple: steal client information to file fraudulent returns that appear legitimate and are harder to detect. (“Their objective: to steal your clients’ data so they can file fraudulent tax returns…”)

Criminals use phishing emails, fake calls, malware, and attempts to obtain passwords, EFINs, or CAF numbers. Protecting taxpayer data is not optional—it is required by federal law.

FTC Safeguards Rule (16 CFR Part 314)

Professional tax preparers are considered financial institutions under the FTC Safeguards Rule. They must:

  • Develop and maintain a written Information Security Program
  • Implement administrative, technical, and physical safeguards
  • Protect against unauthorized access and anticipated threats (“This Safeguards Rule requires… an Information Security Program.”)

IRS Publication 4557 provides a detailed checklist for compliance.

FTC Financial Privacy Rule (16 CFR Part 313)

This rule requires financial institutions to:

  • Provide privacy notices explaining data collection and sharing
  • Allow customers to limit certain types of information sharing
  • Restrict how third parties may use shared financial information (“Customers have the right to limit some sharing of their information.”)

Security Best Practices

Whether required by law or not, all tax professionals should follow these core practices:

  • Assign responsibility for data security
  • Assess risks across operations, systems, and physical environments
  • Create a written security plan
  • Implement appropriate safeguards
  • Use service providers with adequate security controls
  • Continuously monitor and update the program (“Monitor, evaluate, and adjust your security program…”)

Examples of effective controls:

  • Locked storage for files
  • Password‑protected systems
  • Encryption of stored data
  • Secure backups
  • Shredding sensitive paper
  • Never emailing unencrypted personal information

IRS e‑File Security & Privacy Standards

Online Providers must meet six mandatory standards:

  1. Extended Validation SSL Certificate

Valid EV SSL certificate with minimum 1024‑bit RSA/128‑bit AES.

  1. Weekly External Vulnerability Scans

Performed by a PCI‑certified Approved Scanning Vendor located in the U.S.

  1. Written Privacy & Safeguard Policies

Must include: “We maintain physical, electronic and procedural safeguards that comply with applicable law and federal standards.”

  1. Protection Against Bulk Fraudulent Filing

Systems must block automated or mass fraudulent submissions.

  1. Public Domain Name Registration

Domain must be U.S.‑registered, ICANN‑accredited, and locked.

  1. Reporting Security Incidents

Incidents must be reported to the IRS no later than the next business day. If the provider’s website caused the breach, data collection must stop immediately.

Identity Theft

Tax‑related identity theft occurs when someone uses a stolen SSN or EIN to file a fraudulent return or create false wage documents. (“Tax‑related identity theft occurs when someone uses a stolen social security number…”)

The IRS never initiates contact by email, text, or social media to request personal information.

Phishing attempts should be reported to phishing@irs.gov.

Identity Protection PIN (IP PIN)

An IP PIN is a six‑digit number that prevents unauthorized filing. The IRS issues IP PINs to confirmed victims and allows voluntary enrollment after identity verification.

A missing or incorrect IP PIN will cause:

  • Rejection of an e‑filed return
  • Delays in processing a paper return

The IRS will never ask for an IP PIN.

Signs of Tax‑Related Identity Theft

  • More than one return filed under the same SSN
  • Unexpected balance due or collection notices
  • IRS wage records showing unknown employers
  • Business clients receiving notices about fictitious employees or amended returns

What To Do if Identity Is Stolen

FTC recommendations:

  • File a report at identitytheft.gov
  • Contact financial institutions
  • Close compromised accounts

If tax‑related identity theft is suspected:

  • Respond immediately to IRS notices
  • File Form 14039 (Identity Theft Affidavit)
  • Ensure a power of attorney is on file for practitioner inquiries

Victims may request a redacted copy of the fraudulent return if their name/SSN appears as primary or secondary taxpayer.

Business Identity Theft

Business identity theft involves unauthorized use of a business’s identifying information to obtain tax benefits or file fraudulent returns.

Tax‑related indicators:

  • IRS notices about fictitious employees
  • Activity on closed or dormant businesses
  • Returns accepted as amended when none were filed

Non‑tax indicators:

  • Unauthorized credit accounts
  • Unexplained withdrawals
  • Missing mail
  • Data breach notifications

Protective actions:

  • Respond to IRS notices immediately
  • File a police report
  • Review account statements
  • Monitor business registrations
  • Check credit reports
  • Update security software
  • Stay alert for unusual activity

A fraud alert may be placed with:

  • Dun & Bradstreet
  • Equifax
  • Experian
  • TransUnion