- Tax professionals face ongoing threats including IRS impersonation scams, misleading social media advice, new client schemes and credential abuses.
- Federal law requires a Written Information Security Plan; IRS Publication 5708 provides guidance for developing and updating it.
- If a data breach occurs, report immediately to the IRS Stakeholder Liaison, state agencies via the Federation of Tax Administrators, and notify affected clients.
Timeline of the 2026 Security Summit Summer Series
On October 1, 2026, the IRS released Tax Tip 2026-72 announcing the conclusion of the annual five-week Protect Your Clients; Protect Yourself campaign. The series, organized with Security Summit partners, targeted tax professionals and focused on current scams, security practices and steps to take after data theft.
The campaign ran throughout the summer of 2026, delivering weekly information on evolving threats. Although the formal series has ended with the arrival of fall, the IRS emphasized that the material covered remains applicable year-round for tax and accounting practices.
Scams and Threats Highlighted During the Series
Throughout the five weeks, participants learned about new and emerging scams aimed at tax professionals. Common tactics include IRS impersonation through email, text or phone calls, misleading tax advice shared on social media, “new client” schemes, and fraudulent activity involving EFIN, PTIN and CAF numbers.
The series also addressed evolving phishing threats such as spear phishing, clone phishing and whaling. These attacks are designed to trick recipients into revealing sensitive information. The IRS outlined warning signs, preventive security measures and the specific actions professionals should take if they experience a security incident.
Mandatory Written Information Security Plan
A key focus was the federal legal requirement for tax and accounting professionals to maintain a Written Information Security Plan, or WISP. This plan must detail specific ways to safeguard client data against identity theft and data breaches.
To assist practitioners, the IRS provides Publication 5708, which offers practical instructions for creating, maintaining and updating a WISP. The document was referenced repeatedly during the summer series as an essential resource.
Tools for Strengthening Defenses and Responding to Breaches
The campaign highlighted authentication tools including multifactor authentication, Identity Protection PINs (IP PINs) and secure IRS online accounts. Best practices for each were explained to help tax professionals better protect client information.
If a breach does occur, the IRS advised immediate reporting to a local IRS Stakeholder Liaison to help block fraudulent returns. Professionals should also notify the relevant state tax agency using the Federation of Tax Administrators’ Report a Data Breach webpage. Affected clients must be informed and encouraged to take protective steps such as applying for an IP PIN or filing Form 14039 when appropriate.
Tax professionals were reminded to rely on verified IRS social media channels and e-News subscriptions for accurate updates rather than unverified sources.
Where to Find Ongoing Resources
The IRS directed tax professionals to Identity Theft Central and the Data Theft Information For Tax Professionals page for additional tools and detailed guidance. These resources remain available beyond the summer series.
Republic Tax Relief notes that tax professionals who discover they have existing tax debts or compliance issues stemming from a data breach may face separate challenges communicating with the IRS. The firm offers a free, no-obligation initial consultation to discuss private tax-resolution services and evaluate whether its help communicating with the IRS could suit an individual or business situation.
Announcement covered: Oct 1, 2026.
General information only, not individual tax, legal, or financial advice. Rules, deadlines, and eligibility depend on your circumstances. Check current official guidance or consult a qualified professional.
Request a correction →



