Preparer Security and Tax Identity Theft

This page is designed to give tax preparers the information they need to meet their security obligations and to improve their defenses against tax related identity theft, which includes safeguarding their computer systems from cybercriminals.

Tax preparers play a critical role in safeguarding sensitive taxpayer information and are increasingly becoming targets of sophisticated cybercriminals. This page provides guidance to help tax professionals meet their security obligations, strengthen their defenses against tax-related identity theft, and protect their businesses, clients, and computer systems from evolving threats.

Cybercriminals target tax professionals because they have access to highly sensitive personal and financial information that can be used to file fraudulent tax returns and claim false refunds. In many cases, criminals also seek to steal a preparer’s professional credentials, including PTINs, EFINs, and CAF numbers, to file fraudulent returns or gain access to additional taxpayer data.

The threat continues to grow. During the first half of 2026 alone, nearly 300 data breaches were reported, affecting as many as 250,000 taxpayers.

In addition, federal law requires tax professionals to maintain appropriate security measures. Under the Gramm-Leach-Bliley Act (GLBA) and the Federal Trade Commission’s (FTC) Safeguards Rule, tax preparers must create and maintain a Written Information Security Plan (WISP).

Essential Security Steps for Tax Preparers

1. Learn to Recognize Phishing Scams

Phishing remains one of the most common methods criminals use to steal sensitive information. Never click links or open attachments from suspicious emails.

Additional resources:

2. Create a Written Information Security Plan (WISP)

Every tax preparation business, regardless of size, should have a Written Information Security Plan. A WISP helps identify safeguards and establishes procedures for responding to security incidents, data loss, or theft.

The IRS provides Publication 5708, Creating a Written Information Security Plan, to help tax professionals develop a compliant security plan.

Additional resources:

3. Use Strong Passwords and Passphrases

Tax professionals should review all online account credentials and adopt stronger authentication practices.

Current guidance recommends using passphrases—such as a favorite movie quote or a series of memorable words—instead of traditional passwords.

Additional resources:

4. Review and Strengthen Internal Controls

Implement the following security measures throughout your organization:

  • Install anti-malware and anti-virus software on all devices, including desktops, laptops, tablets, smartphones, and routers.
  • Enable automatic software updates whenever possible.
  • Encrypt sensitive files and email communications.
  • Back up sensitive data to a secure external source that is not connected to your network.
  • Properly wipe and destroy old hard drives, printers, and other devices containing taxpayer information.
  • Restrict access to taxpayer data to authorized personnel only.
  • Monitor your IRS e-Services account weekly and verify the number of returns filed under your EFIN.
  • Implement a Virtual Private Network (VPN) to create a secure, encrypted connection between remote users and your business network.

5. Implement Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) is one of the most effective ways to protect sensitive taxpayer information. MFA requires users to verify their identity using more than one authentication factor before accessing systems, applications, or devices.

Authentication factors may include:

  • Something you know (username and password)
  • Something you have (security token or code sent to a mobile device)
  • Something you are (biometric verification such as fingerprint or facial recognition)

Important MFA requirements:

  • All tax professionals are required to use MFA under the FTC Safeguards Rule.
  • MFA should protect access to taxpayer data stored on computers, networks, and tax preparation software.
  • The requirement applies to organizations of all sizes.
  • Failure to implement MFA in tax preparation software may result in noncompliance with FTC Safeguards Rule requirements.

For additional information, see IRS News Release IR-2025-83, Protect Against Tax Identity Theft with Multi-Factor IDs, Identity Protection PINs, and IRS Online Accounts.

6. Report Data Theft or Data Loss Immediately

If your business experiences a data theft, security breach, or data loss incident, contact the appropriate IRS Stakeholder Liaison as soon as possible.

For additional guidance, see IRS Security 101 News Release: Data Theft Reporting Process.

7. Stay Informed About Emerging Threats

Tax professionals should regularly review IRS resources to remain aware of new risks and attack methods.

Recommended resources:

Additional Resources

For more information about identity theft prevention and data security, visit the following resources:

Protecting taxpayer data is not only a legal requirement—it is essential to maintaining client trust and safeguarding your business. By implementing strong security practices and remaining vigilant against emerging threats, tax professionals can significantly reduce the risk of identity theft and data breaches.

Share the Post:

Related Posts

Privacy Statement

The privacy and security of your personal information are important to CrossLink Family of Companies (“CrossLink”). By providing your information above, you consent to CrossLink contacting you and sending information about our products, programs, and services from time to time. You may unsubscribe at any time by using the link provided in our emails or by contacting CrossLink’s Support Team at 800.345.4337. For more details about CrossLink’s privacy practices, please review our Privacy Policy