Security Summit Week Two: Phishing Gets a Vocabulary Lesson and MFA Is Officially Not Optional

The IRS and Security Summit partners released week two of the 2026 “Protect Your Clients; Protect Yourself” summer series on August 4, 2026. Week two puts the phishing threat landscape into named categories and pairs each with the Security Six baseline countermeasures. For any firm that has not audited its cybersecurity posture since last filing season, this release doubles as a compliance checklist.

The remaining 2026 IRS Nationwide Tax Forums continue August 18 through 20 in New York City, September 1 through 3 in Orlando, and September 15 through 17 in San Diego. Registration deadlines are approaching and forums historically sell out.

The phishing typology, in plain language

Not every attempted intrusion is a “phishing email.” The IRS is asking practitioners to distinguish among five variants because the defense against each is slightly different.

Phishing and smishing. Mass distributed emails or SMS messages designed to trick recipients into clicking a link, sharing credentials, or downloading malware. Volume is the strategy. If the same lure hits five people in your firm, one click is enough.

Spear phishing. A targeted lure aimed at a specific person or firm. The email looks personalized because it is. The threat actor did homework, and the message may reference your firm name, a real client, a recent event, or a colleague. Spear phishing is materially harder to detect than mass phishing because it does not trigger the volume based filters most firms rely on.

Clone phishing. A near identical copy of a legitimate email that the recipient has already received. The safe link or attachment in the original is swapped for a malicious one. The message appears to come from the same trusted sender. This is the attack that punishes teams for saying “I already got that email from them yesterday, so it must be fine.”

Whaling. Spear phishing aimed specifically at leadership, executives, payroll staff, HR, and finance functions. The premise is that decision maker access unlocks more damage per compromised account. For firm owners and managing partners, this is the category with your name on it.

New client scam. A prospective client email carrying a malicious link or attachment (often disguised as a prior year return, a W-2, or a “please review” document). The attack exploits the firm’s business development posture. Every unfamiliar sender with a tax document attachment during intake season should be treated as suspect until independently verified.

Warning signs the IRS wants tax pros to memorize

Four indicators, together or separately, should trigger a hold on the email:

An unexpected message claiming to come from a known source such as a colleague, bank, cloud provider, tax software vendor, the IRS, or another government agency.

A duplicate email from a trusted source that includes a new attachment or hyperlink not present in the original.

An urgent tone pressuring the recipient to act, particularly when the pressure is tied to a password reset, account expiration, or “verify to continue” narrative.

An email address, sender name, or URL with a subtle misspelling or a different top level domain. The IRS specifically calls out irs.com (fake) versus IRS.gov (real). Hovering the cursor over the sender address will often expose the mismatch.

The Security Six as a compliance floor

The Security Six is the IRS’s baseline framework for tax pro cybersecurity. Every one of these belongs in every firm, and one of them is a Federal Trade Commission Safeguards Rule requirement, not a best practice:

Anti virus software. Installed, maintained, and updated on every device that touches client data.

Firewalls. Both perimeter and endpoint level, protecting the firm’s network from unwanted inbound and outbound traffic.

Multi factor authentication. Required under the FTC Safeguards Rule. This is the item the IRS is highlighting most heavily in the current release. A firm without MFA on every system that stores or accesses client tax information is not just underprotected. It is out of compliance with a federal regulation, and the exposure runs through the FTC’s enforcement authority as well as through state data breach notification statutes and civil liability.

Backup software or services. Routine backups of critical files, tested for restore. A backup that has never been tested is a hope, not a control.

Drive encryption. Full disk encryption on every laptop, desktop, and mobile device that touches client data. If a firm laptop is lost or stolen with encryption enabled and configured properly, the data theft loss analysis is materially different than if the drive is unencrypted.

Virtual Private Network (VPN). A secure encrypted tunnel for remote users to access the firm network. Any staff working from home, from a coffee shop, or from a hotel is a candidate.

Why this matters for tax pros

Six practice level takeaways.

First, MFA is a regulatory requirement, not a preference. The FTC Safeguards Rule applies to every “financial institution” as defined in the regulation, and paid tax return preparers are covered. Failure to implement MFA is not just poor hygiene; it is a documented control gap that surfaces in any post breach investigation. Firm owners who have been putting this off should treat it as this month’s compliance project.

Second, train staff on the phishing typology by name. It is one thing to tell a paralegal to be careful. It is another to walk through what clone phishing actually looks like, why the “same email from yesterday” is not automatically safe, and why the CFO is a whaling target. Named training builds pattern recognition. Vague training does not.

Third, audit the new client intake pathway. New client scams work because most firms have an open front door for prospective business. Confirm the intake pipeline: how do new prospects reach the firm, what channels accept documents, and what verification runs before an attachment is opened. If the answer is “our email,” that is the front door the attacker uses.

Fourth, treat duplicate emails as a red flag, not a convenience signal. The IRS specifically calls out duplicate messages that contain a new attachment or hyperlink. That is the clone phishing signature. Firm policy should require independent verification of any “same sender, new attachment” pattern before the attachment is opened.

Fifth, keep the incident response playbook accessible offline. The current release again reminds practitioners to contact the IRS Stakeholder Liaison after a breach and to report to the state tax agency through the Federation of Tax Administrators Report a Data Breach page. Both are useless if the contact information lives only inside the compromised email system. Keep the numbers, portal links, cyber insurance carrier’s 24 hour incident line, and outside counsel contact in a printed document in the firm’s physical office.

Sixth, calendar the tax forum security programming. Security is a featured track at the remaining Nationwide Tax Forums in New York, Orlando, and San Diego. For firm owners who have delegated cybersecurity to whichever staff member seemed most technical, sending that person to a forum with a mandate to bring back a written action plan is a defensible use of continuing education budget.

A note on the legal posture

The Security Summit’s guidance is educational. The obligations that bind the firm are elsewhere: the FTC Safeguards Rule, IRC Section 7216, Circular 230 due diligence and confidentiality obligations, state data breach notification statutes, and (for firms with attorney owners) state bar rules on client confidentiality and technology competence. This release should be read as a helpful clarification of what “reasonable safeguards” look like in the current threat environment, not as an exhaustive statement of legal obligation. Counsel and firm owners should still map their controls against the actual regulatory text.


THE TTR TAKE
Week two of this series turns the phishing threat into a named vocabulary and puts MFA on the compliance side of the line, not the aspirational side. If your firm still treats multi factor authentication as optional, this is the week to fix it before the next breach notification letter drafts itself.


The Tax Room: For Tax Professionals. Real updates. Real strategy. Real conversations behind the work. Got a story worth sharing? Submit your story today.


Read Full Release on IRS.gov →

Direct link to the official Internal Revenue Service announcement.

← Back to The Tax Room
Scroll to Top