IRS warns tax professionals about phishing and related schemes
On August 4, 2026, the IRS and Security Summit partners issued IR-2026-85 describing phishing, spear phishing, clone phishing, whaling, and fake new-client emails used against tax preparers. This is official guidance, not a new rule.
- Official source
- Internal Revenue Service ↗
- Jurisdiction
- United States
- Publication date
- August 4, 2026
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax
Summary
On August 4, 2026, the IRS and Security Summit partners issued IR-2026-85 describing phishing, spear phishing, clone phishing, whaling, and fake new-client emails used against tax preparers. This is official guidance, not a new rule.
Why it matters
Tax and accounting practices hold concentrated client Social Security and financial data, and the named tactics match how small firms are actually targeted. The IRS also states that multi-factor authentication is a requirement under the FTC Safeguards Rule for covered firms; coverage still depends on the practice.
Recommended action
Read the IRS release. Ask your IT owner or managed service provider whether the Security Six items are in place, and keep a written note of the answer. Confirm with qualified counsel whether the Safeguards Rule applies to your practice.