Security Summit Fires the Starting Gun on Its 2026 Summer Series: Week One Puts New Scams Aimed at Your Firm on Notice

The IRS and Security Summit partners kicked off the 2026 “Protect Your Clients; Protect Yourself” campaign on July 7, 2026. The five week summer series is now in its 11th year and remains one of the few consistent public private touchpoints between the IRS, state tax agencies, and the tax industry on tax related identity theft. This year’s series runs concurrent with the 2026 IRS Nationwide Tax Forums, which continue August 4 through 6 in New Orleans, August 18 through 20 in New York City, September 1 through 3 in Orlando, and September 15 through 17 in San Diego. Several forums are expected to sell out.

Week one focuses on new and emerging scams aimed squarely at tax professionals.

The four scams the IRS is calling out this year

Four categories are on the front of the list:

IRS impersonation across every channel. Scammers are using email, text, direct messages on social platforms, spoofed caller ID, and computer generated voice calls to push targets toward malicious links, malware attachments, or the disclosure of sensitive financial information. The tell is almost always the same: a request that manufactures urgency and asks the recipient to click, download, or verify something on a channel the IRS does not actually use.

Misleading tax advice on social media. Viral “tax hacks” continue to push taxpayers toward filing returns with false information or claiming credits they do not qualify for. For preparers, the downstream risk is real. A client who insists on a position they picked up on TikTok is a client who can turn a routine engagement into a preparer penalty exposure. Circular 230 due diligence obligations do not bend for viral content.

“New client” spear phishing. Fraudsters pose as prospective clients and send messages carrying malicious links or attachments dressed up as tax documents. The window between initial contact and the click is where most firms lose control. Every unfamiliar sender with an attached “W-2” or “prior year return” should be treated as suspect until verified through a channel the sender did not choose.

EFIN, PTIN, and CAF theft. Phishing schemes specifically targeting the practitioner identifiers that unlock the highest value fraud, including your Electronic Filing Identification Number, EFIN documents, your Preparer Tax Identification Number, and your Centralized Authorization File number. A compromised EFIN in the wrong hands can send thousands of fraudulent returns through your firm’s e file account before the pattern is caught.

Why this matters for tax pros

Five practice level takeaways.

First, treat the Written Information Security Plan (WISP) as a legal requirement, not a formality. Every paid tax return preparer is required under the FTC Safeguards Rule and IRC Section 7216 to have a written data security plan in place. Publication 5708 provides a template. Counsel and firm owners should confirm the plan exists, is current, is signed, is trained on annually, and reflects the firm’s actual systems (not a template dropped into a folder three years ago). If a data breach occurs and no WISP is in place, both regulatory exposure and civil liability multiply.

Second, tighten intake for prospective clients. New client spear phishing works because most firms accept a first contact through email or a website form and open attachments to prepare a quote. Build a protocol: no attachments opened until identity is verified by phone using a number the firm sourced independently, and no client data accepted through an unencrypted channel. If your website intake form does not sit behind SSL and route to encrypted storage, fix that this month.

Third, build EFIN and PTIN monitoring into your operational calendar. Check the number of returns filed under your EFIN in your IRS e Services account weekly during filing season and monthly year round. Reconcile against your actual filings. A discrepancy is the earliest signal of EFIN compromise, and early reporting is what allows the IRS to freeze fraudulent returns before refunds pay out.

Fourth, know the reporting playbook cold, before you need it. If a data breach occurs, three parallel channels open simultaneously: (a) the local IRS Stakeholder Liaison, who alerts the appropriate IRS offices and coordinates blocking fraudulent client returns, (b) the state tax agency through the Federation of Tax Administrators Report a Data Breach portal, and (c) the FTC Data Breach Response requirements, which should already be reflected in your written response plan. Speed matters. The IRS’s ability to block fraudulent filings in your clients’ names depends on getting the report in early.

Fifth, front load your response plan documentation. Have the Stakeholder Liaison contact information, the state reporting portal link, your cyber insurance carrier’s 24 hour incident line, and your outside counsel’s contact in one document that lives outside the firm’s compromised systems. In a real breach, the systems used to hunt for that information are often the systems the attacker is inside.

What is coming in weeks two through five

The remaining series releases will cover: phishing, spear phishing, whaling, and the “Security Six” core protections (week two); the WISP itself and Publication 5708 (week three); tools including multi factor authentication, Identity Protection PINs, IRS Online Accounts, and Tax Pro Accounts (week four); and signs of identity theft with reporting mechanics (week five). Practitioners running firm training should calendar the release cycle now and build the internal cybersecurity refresher around it.

A closing note on the legal posture. The Security Summit’s public education campaign is not itself a regulatory action. The obligations that matter (the FTC Safeguards Rule, IRC Section 7216, Circular 230 due diligence, state data breach notification statutes, and any professional licensure obligations) predate this campaign and continue to apply. Treat the summer series as free operational guidance layered on top of the compliance floor your firm is already required to meet.


THE TTR TAKE
Every year the Security Summit tells tax pros where the scammers are aiming next, and every year the firms that ignore it are the ones writing breach notification letters in January. Pull your WISP off the shelf this month, run an EFIN reconciliation, and make sure your intake process for new clients is not the front door for spear phishing.


The Tax Room: For Tax Professionals. Real updates. Real strategy. Real conversations behind the work. Got a story worth sharing? Submit your story today.

Read Full Release on IRS.gov →

Direct link to the official Internal Revenue Service announcement.

← Back to The Tax Room
Scroll to Top