On July 7, 2026, the IRS and its Security Summit partners launched a five week campaign called “Protect Your Clients; Protect Yourself.” It targets tax professionals squarely, and it makes the case for identity theft protection for tax professionals plainly: small tax and accounting firms are a preferred target for identity thieves, not an afterthought.
Last Updated: July 2026 | Reading time: ~10 minutes
If you run a small tax prep shop, bookkeeping firm, or accounting practice, this campaign is about you. Here is what it covers, why your firm faces exposure, and what to do about it before the next filing season, not during it.
Table of Contents
- Why Tax and Accounting Firms Are a Preferred Target
- What the IRS Summer Campaign Actually Covers
- The Scams Making the Rounds Right Now
- What Smart Firm Owners Are Doing Differently
- What to Look for in Identity Protection Coverage for Your Staff
- Frequently Asked Questions
Why Tax and Accounting Firms Are a Preferred Target
A ten person tax prep firm can hold more concentrated identity data than a mid sized retailer. Names, Social Security numbers, dates of birth, W-2 and 1099 records, bank routing numbers, dependents’ information, sometimes years of returns going back a decade. It is a single, dense target, and most small firms protect it with a shared office password and whatever antivirus came with the computer.
The Security Summit has run this awareness campaign for eleven years for a reason. Tax professionals keep getting hit, and the fallout does not stay contained to the firm. A single breached preparer can hand a criminal ring the raw material to file fraudulent returns in hundreds of clients’ names, each one a multi month recovery process for the victim and a reputational hit for the firm that lost the data.
Small firms also face structural exposure in ways large firms do not. Fewer dedicated IT staff. No formal incident response plan. Client documents moving over email instead of a secure portal. Seasonal staff get a login in January and are gone by May, sometimes with nobody ever revoking their access.
What the IRS Summer Campaign Actually Covers
The 2026 “Protect Your Clients; Protect Yourself” series runs five weekly releases, timed to coincide with the IRS Nationwide Tax Forums running through September (Chicago, then New Orleans August 4 to 6, New York City August 18 to 20, Orlando September 1 to 3, and San Diego September 15 to 17). Here is what each week covers, according to the IRS:
- Week one, new and emerging scams. IRS impersonation by email, text, and spoofed calls. Misleading “tax hack” advice circulating on social media. Fake prospective clients sending malware disguised as tax documents. Phishing attempts targeting a preparer’s EFIN, PTIN, or CAF number specifically.
- Week two, phishing, spear phishing, and whaling. How targeted attacks differ from generic phishing, and the “Security Six” protections the IRS recommends every firm put in place.
- Week three, the written security plan. Federal law requires paid preparers to maintain a Written Information Security Plan. The IRS is using this week to push firms that do not have one, or have not updated it, to fix that.
- Week four, tools that actually help. Multi factor authentication, Identity Protection PINs, IRS Online Accounts, and Tax Pro Accounts.
- Week five, recognizing and reporting theft. What the early signs of a breach look like and the reporting steps that limit the damage, including contacting your local IRS Stakeholder Liaison and your state tax agency through the Federation of Tax Administrators.
The “Security Six,” Explained
Week two is worth pausing on, because the “Security Six” gets referenced constantly in tax industry guidance without much explanation of what it actually requires. Under IRS Publication 4557, the six baseline protections are:
- Anti-virus and anti-malware software, kept on automatic updates so it catches newly identified threats daily.
- Firewalls, both hardware and software, to block unwanted traffic before it reaches a workstation or server.
- Multi factor authentication, on every system that touches client data, not just email.
- Backup software or services, with critical files routinely copied to an external or cloud source.
- Drive encryption, so a stolen or lost laptop does not hand over readable client files.
- A virtual private network, for any connection made outside the office, including a preparer’s home Wi-Fi during a slow afternoon.
None of this is new advice, exactly. What is new is the IRS spelling out, in public, that tax professionals remain a soft and valuable target heading into the back half of 2026.
The Scams Making the Rounds Right Now
Per the IRS’s week one release, four patterns account for most of the current activity against tax professionals:
- IRS impersonation. Scammers use email, text, direct messages, and spoofed caller ID, sometimes with computer generated voices, to push preparers or their staff toward a malicious link or a request for sensitive information.
- “New client” phishing. A fraudster poses as a prospective client and sends an attachment disguised as a tax document. Opening it hands over firm and client data at once.
- EFIN, PTIN, and CAF number theft. These are the credentials that let a preparer file on a client’s behalf. Once stolen, they let a criminal file fraudulent returns that look, on paper, like they came from a legitimate practice.
- Viral tax misinformation. Social media “hacks” convince taxpayers to claim credits they do not qualify for or file with false information, which then lands on the preparer’s desk as a compliance headache, and sometimes as an accusation that the preparer enabled fraud.
What Smart Firm Owners Are Doing Differently
The firms that stay off next year’s breach notification list treat this as an operating requirement, not a once a year training video.
Write the security plan and actually follow it. A Written Information Security Plan is a federal requirement for paid preparers, not a nice to have. If your firm does not have a current one, the IRS publishes a template. If you have one from three years ago, assume it is out of date.
Turn on multi factor authentication everywhere client data lives. Tax software, email, cloud storage, the works. This single step stops the majority of credential based break ins.
Verify before you trust a “new client.” A legitimate prospective client will tolerate a phone call to confirm identity before you open their attachment. A fraudster will not.
Lock down access the day someone leaves. Seasonal and part time staff need offboarding discipline as much as full time employees. Revoke logins the day the engagement ends, not whenever someone gets around to it.
Protect the people who handle the data, not just the data itself. Your staff’s own identities are a target too. A preparer or bookkeeper whose personal Social Security number ends up on the dark web is one incident away from a very bad month, and a distracted employee is a bigger risk to your clients’ data. Offering identity theft protection as a benefit is not just goodwill. It is a control that keeps your team focused and your firm out of a second, unrelated breach story.
What to Look for in Identity Protection Coverage for Your Staff
If you are evaluating identity protection as a benefit for your firm, whether it is three employees or thirty, the features that matter are the same ones that matter for any small business:
- Dark web monitoring, so you find out if an employee’s credentials or Social Security number are circulating before a criminal uses them.
- SSN and credit file monitoring, which flags new accounts or inquiries early, the first sign something is wrong.
- Fully managed recovery, meaning a dedicated advocate handles the calls, disputes, and paperwork if a criminal compromises an employee’s identity, rather than handing them a checklist during your firm’s busiest season.
- Family plan coverage, since a compromised household member’s finances can distract an employee just as much as their own.
- U.S. based support with real response times, measured by how fast someone picks up, not by a features list.
Frequently Asked Questions
Does my small tax practice really need a Written Information Security Plan?
Yes. It is a federal requirement for any paid tax return preparer, regardless of firm size. The IRS publishes a template (Publication 5708) that firms can adapt rather than build from scratch.
What is an EFIN, and why do criminals want it?
An Electronic Filing Identification Number is what the IRS issues to authorize a preparer to e-file returns. A stolen EFIN lets a criminal file fraudulent returns that appear to come from a legitimate firm, which is why this year’s campaign calls out phishing attempts targeting EFINs, PTINs, and CAF numbers specifically.
What should I do if I think my firm has been breached?
Contact your local IRS Stakeholder Liaison immediately so the IRS can move to block fraudulent returns filed under your clients’ names. Also report the incident to your state tax agency through the Federation of Tax Administrators’ data breach reporting page, and follow the FTC’s data breach response guidance for businesses.
Is offering identity theft protection to my employees actually useful, or just a nice-to-have benefit?
Both. For a firm handling client SSNs and financial data all day, a compromised employee identity creates both a distraction and a risk vector at the same time. Coverage that includes dark web monitoring and managed recovery limits how much of your busiest season gets eaten up by one employee’s personal identity theft crisis.
What exactly are the IRS’s “Security Six” protections?
Six baseline controls defined in IRS Publication 4557: anti-virus and anti-malware software, firewalls, multi factor authentication, regular data backups, drive encryption, and a VPN for remote connections. The IRS treats these as the minimum, not a finish line.
How should I handle security for seasonal or part-time tax prep staff?
Treat their offboarding with the same discipline as a full time employee’s. Revoke login credentials, tax software access, and shared drive permissions the day the engagement ends, not weeks later when someone remembers to do it. A seasonal preparer’s forgotten login is one of the more common ways firm data stays exposed long after filing season closes.
The Window to Fix This Is Now, Not January
Tax season is when firms discover their security gaps. Summer is when firms actually have time to close them. The IRS is using its five week campaign to make that case publicly. Use the slow season to write or update your security plan, turn on multi factor authentication, and decide whether your team has the identity protection coverage they need before next filing season puts everyone back under pressure.
If you are evaluating identity theft protection as a benefit for your practice’s employees, defend-id works with small businesses to provide identity theft protection and recovery services for employees and their families. A dedicated, U.S. based recovery advocate is what matters most when something actually goes wrong.
Articles related to protecting tax and accounting firms
- Tax Fraud Prevention in 2026: How to Protect Yourself
- Small Business Identity Theft Protection: The 2026 Guide
- Business Data Protection Practices: Six Pillars for 2025
- Identity Theft Protection Employee Benefit: 2026 HR Guide