IRS and Security Summit Urge Stronger Defenses Against Tax Identity Theft
Summary
The IRS and its Security Summit partners are urging taxpayers and tax professionals to strengthen their defenses against tax-related identity theft, in the fourth installment of the "Protect Your Clients; Protect Yourself" summer series (IR-2026-106, Sept. 4, 2026). The guidance highlights multifactor authentication (MFA), Identity Protection PINs (IP PINs) and secure IRS online accounts. Under the Federal Trade Commission's Safeguards Rule, tax preparation firms must use MFA to protect access to customer information unless a Qualified Individual approves an equivalent secure access control in writing — and the requirement applies to firms of every size. An IP PIN is a six-digit number, valid for one calendar year and regenerated each year, that helps the IRS verify a taxpayer's identity when a return is filed; taxpayers must obtain their own, because tax professionals cannot request one on a client's behalf. A companion release (IR-2026-92, Aug. 18, 2026) reminded tax professionals that federal law — the Gramm-Leach-Bliley Act as implemented through the FTC's Safeguards Rule — treats tax and accounting practices as financial institutions required to maintain a Written Information Security Plan (WISP), and pointed to IRS Publication 5708 as a template for developing one, particularly for smaller practices.
Sources
- Internal Revenue Service — Security Summit: Strengthen defenses against tax identity theft — https://www.irs.gov/newsroom/security-summit-strengthen-defenses-against-tax-identity-theft
- Internal Revenue Service — IRS, Security Summit remind tax pros they need a Written Information Security Plan to protect client data — https://www.irs.gov/newsroom/irs-security-summit-remind-tax-pros-they-need-a-written-information-security-plan-to-protect-client-data
Our Take
Cross-border filers and the professionals who serve them sit at a vulnerable intersection: U.S. obligations must be filed, but the taxpayer often lives in Canada, and the identifiers involved — passports, U.S. and Canadian social insurance numbers, foreign addresses — are exactly what identity thieves target. The security rules apply to any firm that prepares U.S. returns regardless of where the preparer sits: MFA, a written security plan, and breach reporting obligations (including reporting to the FTC for security events affecting 500 or more people, generally within 30 days of discovery) are not optional extras. For individuals, an IP PIN adds a layer that can stop a fraudster from filing a return in your name — and it is worth remembering the IRS will never call, email or text to request one. Firms should review their safeguards before the next filing season, and U.S.-tied clients should treat unsolicited "IRS" communications with healthy skepticism. When in doubt about a notice or a suspected breach, consult a CPA.
Disclaimer: This article is general information only and does not constitute tax advice; it should not substitute professional tax counsel. Please consult a licensed CPA for advice specific to your situation.
