New IRS Phishing Schemes: The IRS and its Security Summit partners issued a fresh warning on August 4, 2026, telling tax preparers, accountants and enrolled agents across the country to watch for a wave of phishing emails and related scams built to steal sensitive taxpayer data. The alert, released as IR-2026-85, is the second installment in the agency’s five-part “Protect Your Clients; Protect Yourself” summer series, an annual education push run jointly by the IRS, state tax agencies and private-sector tax industry partners since 2015. This year’s warning is notably specific, naming five distinct attack methods, phishing, spear phishing, clone phishing, whaling and fake new-client scams, that criminals are actively using against tax offices right now.
The timing matters. Tax professionals hold some of the most valuable data criminals can steal, Social Security numbers, bank account details, prior-year returns and Employer Identification Numbers for dozens or hundreds of clients at once, all sitting inside a single email inbox or cloud folder. A successful breach at even a small two-person tax practice can expose enough personal data to file dozens of fraudulent returns before anyone notices. We’ll be updating this article monthly as the IRS releases the remaining parts of this summer’s security series and as new scam variations get reported. For now, the agency’s message is blunt: the tactics keep getting more convincing, and the old advice to just “watch for bad grammar” no longer cuts it against scams built to look identical to a real client, a real software vendor, or a real colleague.

Key Highlights: IRS Phishing Warning for Tax Professionals
| Item | Detail |
|---|---|
| Release number | IR-2026-85 |
| Release date | August 4, 2026 |
| Issued by | IRS and Security Summit partners |
| Campaign name | Protect Your Clients; Protect Yourself, week 2 of 5 |
| Scam types named | Phishing/smishing, spear phishing, clone phishing, whaling, new client scams |
| Core protection framework | The Security Six: antivirus, firewalls, multi-factor authentication, backup software, drive encryption, virtual private network |
| Multi-factor authentication requirement | Mandatory under the FTC Safeguards Rule |
| Nationwide Tax Forum dates | Aug. 18-20 New York City, Sept. 1-3 Orlando, Sept. 15-17 San Diego |
| Security Summit partnership active since | 2015 |
| Where to report a breach | IRS Stakeholder Liaison and the Federation of Tax Administrators data breach page |
Latest Update: What the IRS Actually Said on August 4
The August 4 release is part of a coordinated five-week campaign, not a standalone warning, which is worth understanding because it shapes how seriously tax offices should treat it. Week one of the Protect Your Clients; Protect Yourself series, published earlier in July 2026, focused on recognizing viral “tax hack” misinformation and new client scams. Week two, the phishing-focused release covered here, dives specifically into how criminals disguise malicious emails to look like routine business correspondence. Three more installments are scheduled to run through the rest of the summer, with security topics also featured prominently at this year’s Nationwide Tax Forums, three-day continuing education events for tax professionals held in New York City from August 18-20, Orlando from September 1-3, and San Diego from September 15-17.
The IRS’s central point in this release is that phishing has splintered into several distinct attack styles, each requiring a different kind of vigilance. A generic phishing email blasted to thousands of addresses looks very different from a spear phishing message crafted specifically for one firm, and both look different again from a cloned email that copies a real, previously sent message and swaps out the attachment for malware. Treating all suspicious emails the same way, the agency warns, is exactly what lets the more sophisticated versions slip through.
Public Charge Rule Rescinded 2026: New Green Card Eligibility Rules
Federal Funds Rate 3.62% Today: Mortgage and Credit Card Impact
Social Security Spousal Benefit Rule Almost Everyone Gets Wrong, and What It Actually Costs
Canada 50% Tariff 2026: Full List of Products That Could See Price Hikes
Understanding the Five Scam Types Named in the Warning
The IRS release breaks down the current threat landscape into five specific categories, and knowing the difference between them is the fastest way for a tax office to train staff to spot each one.
Phishing and smishing describe the broadest form of the attack, mass emails or text messages sent to as many addresses as possible, hoping a percentage of recipients click a malicious link, hand over login credentials, or download an infected file. Because these are sent in bulk, they tend to be less personalized and slightly easier to catch once staff know what to look for.
Spear phishing narrows the target to a specific person or firm. Instead of a generic message, the criminal builds a more convincing, tailored email, sometimes referencing real client names, real software the firm uses, or a real ongoing engagement. Because these are sent in small numbers to specific targets, they are far harder to catch through automated spam filters alone.
Clone phishing is one of the more deceptive tactics named in the release. It works by copying an email the recipient has genuinely received before, then resending an almost identical version that appears to come from the same trusted sender. The cloned message swaps out a legitimate link or attachment for one containing malware, or redirects the recipient to a fake login page designed to harvest account credentials.
Whaling targets the top of the organization, firm partners, executives, and staff in payroll, human resources or finance roles who have access to the widest range of sensitive data or the authority to approve wire transfers and data requests. Because whaling targets decision-makers, a successful attack can expose far more data, or authorize far more damage, than an attack on a junior staff member’s inbox.
New client scams are aimed squarely at tax preparers. In this version, a criminal poses as a prospective client, emailing a tax office to request services and attaching what looks like tax documents, W-2s, 1099s or prior-year returns. Opening the attachment installs malware or triggers a credential-harvesting page, giving the attacker a foothold inside the firm’s systems. Because soliciting new clients is a routine, welcome part of running a tax practice, this scam specifically exploits the instinct to open attachments from potential business.
Warning Signs Every Tax Office Should Train Staff to Spot
The IRS outlined several concrete red flags that apply across all five scam types. An unexpected email or text claiming to come from a known, trusted source, a colleague, a bank, a cloud storage provider, a tax software company, or even the IRS itself, deserves a second look before any link is clicked. A duplicate copy of an email the recipient has seen before, but with a new attachment or hyperlink swapped in, is one of the clearest signs of clone phishing in action.
Urgency is another consistent tell. Messages pressuring the recipient to act immediately, often built around a false narrative like an expired password that needs updating right now, are designed to short-circuit the normal instinct to pause and verify. The IRS also flagged subtle domain spoofing as a common tactic, an email address, phone number or link that is slightly misspelled or uses a different domain than the real organization, such as a lookalike address instead of the legitimate irs.gov. Hovering the cursor over a sender’s email address, rather than trusting the display name alone, often reveals these small but telling differences.
The Security Six: IRS Baseline Protections for Tax Pros
Alongside the scam breakdown, the IRS reiterated its long-standing Security Six framework, six baseline protections every tax office is expected to have in place. Antivirus software with current updates forms the first line of defense against malware delivered through phishing attachments. Firewalls shield office networks from malicious or unnecessary web traffic before it ever reaches a workstation. Multi-factor authentication, which the release notes is now a requirement under the Federal Trade Commission’s Safeguards Rule, adds a critical layer of protection against cloud-based account takeovers even when a password has already been compromised.
Routine data backups protect against permanent data loss from ransomware, hardware failure or natural disasters, while drive encryption renders sensitive client files unreadable to anyone who manages to access a stolen or lost device. A virtual private network rounds out the list, creating an encrypted tunnel for any data transmitted between a remote worker and the firm’s network, an increasingly important safeguard as more tax offices support hybrid or remote staff.
What Tax Professionals Should Do After a Suspected Breach
The IRS release includes clear guidance for firms that suspect they have already been targeted or compromised. Tax professionals who fall victim to any of these schemes, or who suspect a client’s identity has been stolen, are directed to contact their IRS Stakeholder Liaison immediately and provide full details of the incident. Firms should also notify the relevant state tax agency, which can be done through the Federation of Tax Administrators’ Report a Data Breach page, a centralized resource built specifically for this purpose. Acting quickly matters, since a fast report gives the IRS and state agencies a better chance to flag affected taxpayer accounts before fraudulent returns can be filed using the stolen data.
Firms are also required under the FTC Safeguards Rule to maintain a written information security plan, and the IRS has pointed preparers toward the FTC’s own Data Breach Response guidance as a starting template for building or updating that plan. Given that the Safeguards Rule applies to any business classified as a financial institution under FTC regulations, which includes most paid tax preparation businesses, this is not an optional best practice for many firms but an active legal requirement.
Why This Warning Matters Beyond Tax Season
It is worth noting that this warning arrives in August, well outside the traditional filing season rush. That timing is deliberate. Criminals increasingly target tax offices during the off-season specifically because staff are less vigilant and firms often let their guard down between filing deadlines. A breach discovered in August still exposes the same prior-year data a breach discovered in March would, and stolen credentials harvested now can sit dormant until the next filing season begins, when the payoff for identity thieves is highest. The Security Summit’s decision to run this education campaign every summer, rather than only ahead of the April deadline, reflects a recognition that data theft is now a year-round risk for the tax industry, not a seasonal one.
Fast-Track Deportation Ruling: Could It Affect Indian Immigrants?
2027 COLA Increase for VA Disability: How Much Could Benefits Rise Under the Latest Projection
Official IRS Resources for Tax Professional Security
| Resource | What It’s For | Official Link |
|---|---|---|
| Protect Your Clients; Protect Yourself hub | Full summer security series and past releases | irs.gov/tax-professionals/protect-your-clients-protect-yourself |
| IRS Stakeholder Liaison contacts | Report a data breach or identity theft incident | irs.gov/businesses/small-businesses-self-employed/stakeholder-liaison-contacts |
| Federation of Tax Administrators breach reporting | Notify state tax agencies of a data breach | taxadmin.org/report-a-data-breach |
| Report a fake IRS email or message | Forward suspicious IRS-branded phishing emails | irs.gov/help/report-fraud/report-fake-irs-treasury-or-tax-related-emails-and-messages |
| FTC Safeguards Rule guidance | Written information security plan requirements | ftc.gov/legal-library/browse/rules/safeguards-rule |
| Nationwide Tax Forum registration | Continuing education and security training sessions | irstaxforum.com |
FAQs About the IRS Phishing Warning
What did the IRS warn tax professionals about in August 2026?
On August 4, 2026, the IRS and Security Summit partners warned tax pros about five specific phishing tactics, phishing and smishing, spear phishing, clone phishing, whaling, and fake new-client scams, all designed to steal sensitive taxpayer data.
What is the difference between phishing and spear phishing?
Phishing is sent broadly to many recipients hoping a small percentage respond. Spear phishing targets one specific person or firm with a more personalized, convincing message, making it harder to detect through generic spam filters.
What is a clone phishing attack?
Clone phishing copies a legitimate email the recipient has already received and resends a nearly identical version, replacing a safe link or attachment with one containing malware or a fake login page.
What is the Security Six?
The Security Six is the IRS’s recommended baseline of protections for tax offices: antivirus software, firewalls, multi-factor authentication, backup software or services, drive encryption, and a virtual private network.
Is multi-factor authentication legally required for tax preparers?
Yes, for most paid tax preparation businesses. Multi-factor authentication is required under the Federal Trade Commission’s Safeguards Rule for cloud-based account protection.
What should I do if my tax office experiences a data breach?
Contact your IRS Stakeholder Liaison right away with full details of the incident, and separately report the breach to your state tax agency through the Federation of Tax Administrators’ Report a Data Breach page.
People Also Ask
How do I know if an email claiming to be from the IRS is fake? The IRS does not initiate contact with taxpayers by email, text or social media to request personal or financial information. Any email claiming to be from the IRS asking for this kind of data should be treated as a phishing attempt and reported.
Why are tax professionals a bigger target than individual taxpayers? A single tax office holds concentrated data on dozens or hundreds of clients at once, including Social Security numbers, bank details and prior returns, making a successful breach far more valuable to criminals than targeting one individual taxpayer.
What is a whaling attack in cybersecurity? Whaling is a form of spear phishing that specifically targets senior executives, firm partners, or staff in finance, payroll or HR roles who have access to large amounts of sensitive data or the authority to approve financial transactions.
Can a phishing email really infect a computer just by opening it? Yes, in many cases. Malicious attachments and links can install malware the moment they are opened or clicked, which is why the IRS recommends verifying a sender’s identity before opening any unexpected attachment, even one that appears to come from a known contact.
Where can I report a phishing email pretending to be from the IRS? Suspicious emails claiming to be from the IRS can be reported directly through the IRS’s official fake email and message reporting page, which forwards the details to IRS Criminal Investigation for review.
Conclusion
The IRS phishing warning issued on August 4, 2026 is a reminder that data thieves are not waiting for filing season to target tax professionals, and their tactics have grown far more sophisticated than the obviously fake emails of a few years ago. Phishing, spear phishing, clone phishing, whaling and new client scams each exploit a different weak point in how tax offices communicate and operate, which is exactly why the IRS is urging firms to train staff on all five rather than relying on general caution alone. Pairing that awareness with the Security Six protections, and knowing exactly who to contact if a breach happens, gives tax offices a real chance to stop an attack before client data walks out the door. With three more installments of the Protect Your Clients; Protect Yourself series still to come this summer, and security sessions featured at all three remaining Nationwide Tax Forums, tax professionals have several more opportunities in the coming weeks to shore up their defenses before the next filing season begins.
H-1B FY2027 Cap Reached: What Happens Next for Applicants?
Social Security Payment August 12, 2026: Who Gets Paid Today and When Is Your Next Check?


