Background with light gradient and lines

A tax practice is one of the richest targets a criminal can find. You hold every client's tax return, Social Security number, bank details, and years of financial data in one place. That is why thieves now go after the tax professional instead of chasing individual taxpayers one at a time. In a single recent year the Internal Revenue Service received more than 250 reports of data breach incidents from tax professionals, affecting roughly 200,000 clients.

If your practice is hit, the hours right after you notice matter more than almost anything else. This guide covers how to spot the signs, how to report the theft to the IRS and the states, how to protect the people whose taxpayer data was exposed, and how to stop it from happening again. If you would rather get ahead of the problem, our data security page covers the controls that keep client data out of the wrong hands.

How do you know your practice has been breached?

Sometimes the signs are loud, like a ransom note on your screen. More often it is quiet, and you learn about it sideways. Clients start getting IRS letters about returns they never filed. E-filed returns bounce back as already submitted. Your software shows logins at odd hours, or your machines slow to a crawl for no clear reason. Any of these can mean cybercriminals are using stolen data to file fraudulent tax returns under your clients' names.

The tricky part is that a data compromise often shows up through a client rather than your own systems, so the early hint is worth treating seriously. Watch for returns you are still preparing, or tax filings that were accepted somewhere before you ever sent them. If two or three clients flag something strange in the same week, do not wait for a fourth. Our breakdown of outsourcing red flags covers a few of the same warning signs that appear when data handling goes wrong.

Step 1: Stop the breach and find its cause and scope

Before you report anything, contain the damage. Disconnect affected machines from the internet so the intruder loses access, and bring in a security expert who can determine the cause and scope of the breach. You need to know what was taken, whose records were involved, and how the attacker got in, because every later step depends on those answers.

A security professional will also help you stop the breach and prevent further breaches from occurring, whether that means closing a remote-access hole, resetting credentials, or rebuilding a compromised system. Following a data breach it is tempting to wipe everything and move on, but resist it. Preserving the stolen tax data and evidence matters when you work with law enforcement and the IRS, and rushed cleanup can destroy the trail that shows what happened. Good data protection during recovery is as important as the security measures that should have prevented the breach.

Step 2: Report the breach to the IRS

This is the step many preparers skip, and it is the one that protects clients fastest. Tax professionals must report a security incident to their local IRS Stakeholder Liaison, the agency's point of contact for exactly this situation. Find your local IRS Stakeholder Liaison by state, then contact the IRS as soon as you have a basic picture of what happened.

Once you report the breach, the liaison will notify IRS Criminal Investigation and others within the agency, and the IRS can take steps to block fraudulent returns tied to your clients' accounts. Speed is everything. A breach reported quickly lets the agency flag those Social Security numbers before refunds go out the door to criminals. The faster you raise an IRS data breach, the more working with the IRS can actually do for your clients. The complete checklist sits on the IRS data theft information for tax professionals page.

Step 3: Notify the states and the FTC

Federal reporting is only half of it. You also need to tell the states where your affected clients file. The fastest route is the Federation of Tax Administrators, which runs a single report a data breach page that points you to the right state tax agencies. Certain states require direct notification on their own state tax timelines too, so check the rules for every state your clients touch, and note that you may also need to contact more than one.

There is a federal layer beyond the agency as well. Tax and accounting firms count as financial institutions, and the FTC Safeguards Rule from the Federal Trade Commission requires you to report an incident when 500 or more individuals are affected, within 30 days. Missing that window turns a security problem into a compliance problem on top of it.

Step 4: Tell your clients and protect them

Your clients trusted you with their most sensitive information, so they deserve to hear about the breach from you, clearly and quickly. Send an individual letter to each affected person to inform them of the breach in plain language: what happened, what data was involved, and what you are doing about it. A vague mass email does not cut it, and in many states a written notice is required.

Then help them defend themselves. Offer credit monitoring and identity theft protection to victims of the breach, and point them to the credit bureaus so they can place a fraud alert or freeze. A paid monitoring service can watch for misuse, and many firms provide guidance on requesting an IRS Identity Protection PIN, which is one of the strongest forms of identity protection a taxpayer can have. Clients may seek their own help too, so give them the facts they need to act. Standing up real credit and identity theft protection for victims of identity theft, rather than just apologizing, is what holds the relationship together. If you need a steady hand keeping client work moving while you manage the fallout, our team can support your tax preparation and planning during the scramble.

Does your insurance policy cover a data breach?

Many firms are surprised by what a breach costs once notification, monitoring, forensics, and legal fees stack up. This is where your insurance company matters. Check whether your insurance policy covers data breach mitigation expenses, because a cyber or professional policy that covers data breach mitigation expenses can absorb a large share of the bill. Knowing in advance what the policy covers, and what it does not, turns a panic into a process. Call your carrier before an incident, not during one.

Step 5: Prevent the next breach with a real security plan

Recovering from one breach is painful enough that it is worth making sure there is never a second. Federal law already requires every tax professional to maintain a written information security plan, and the agency reinforces this through its Security Summit guidance. A good plan names who is responsible, lists your security measures, names a clear safeguard for each risk, and writes down the exact response you just read, so no one has to improvise next time.

The practical safeguards are not complicated. Use multi-factor authentication everywhere, encrypt client files, patch your professional tax software, and limit who can see what. Every tax pro is a line of defense in the wider tax system, and cybercriminals simply look for the weakest link. The same discipline applies to anyone you outsource to. If an offshore team touches client data, their controls become your data security, which is why a partner running on SOC 2 and ISO 27001 with role-based access is the safer choice. We build those steps to protect client information into how we onboard every firm, and our offshore security checklist gives you the questions to ask any provider before you share a single file.

A breach is frightening, but the firms that come through it well are the ones that act fast and report early. If you want help building a setup that keeps client data safe in the first place, our team is happy to talk it through.

Frequently asked questions

1. What should a tax professional do first after a breach? Contain it before anything else. Disconnect affected machines and bring in a security expert to determine the cause and scope of the breach. Once you know what was taken, report the incident to the agency and the states, then notify and protect your clients. Acting in that order keeps you from missing a critical step in the rush.

2. How do I report data theft to the IRS? Contact your local IRS Stakeholder Liaison, who handles security incidents for tax professionals. That contact loops in IRS Criminal Investigation and lets the agency take steps to block fraudulent returns filed with your clients' stolen data. The agency's data theft page for tax professionals lists the full process and the contacts you need.

3. Do I have to notify the states after a breach? Yes. Use the Federation of Tax Administrators report a data breach page to reach the right state tax agencies. Certain states require direct notification on set timelines, so confirm the rules for every state where your affected clients file, not only your own.

4. What is the IRS Stakeholder Liaison? The Stakeholder Liaison is the IRS contact tax professionals use to report data theft and security incidents. There is one assigned to each area, and reaching yours quickly is what allows the agency to act on your clients' accounts before fraudulent returns are processed.

5. Are tax preparers legally required to have a security plan? Yes. Federal law requires every tax preparer to maintain a written information security plan that identifies risks, lists safeguards, and describes how to respond to a breach. The FTC Safeguards Rule and IRS guidance both reinforce this, and a missing plan can create penalties on top of the breach itself.

6. Should I offer clients credit monitoring after a breach? It is strongly recommended and sometimes required. Offering credit monitoring and identity theft protection, along with guidance to contact the credit bureaus, helps clients limit the damage. It also shows them you are taking real responsibility, which matters for keeping their trust after something this serious.

7. Will my insurance policy cover data breach costs? It depends on your coverage. Some cyber and professional policies cover data breach mitigation expenses like forensics, client notification, and credit monitoring. Ask your insurance company exactly what the policy covers before an incident happens, so you are not reading the fine print in the middle of a crisis.

8. How does outsourcing affect my breach risk? Any partner who handles client data becomes part of your security picture. A provider with weak controls raises your risk, while one with SOC 2 and ISO 27001 certification, encryption, and role-based access lowers it. Vet every provider's data security before sharing files, and confirm their breach response lines up with yours.

Table of Contents

Explore More Blogs

Image
Single-Entry vs Double-Entry Bookkeeping: A Simple Guide
Published On:
July 24, 2026

Single-entry vs double-entry bookkeeping made simple: how each accounting system works, the key differences, and which one your small business needs.

Image
CPA vs EA vs Tax Attorney: Which Tax Professional Do You Actually Need?
Published On:
July 24, 2026

CPA vs EA (enrolled agent) vs tax attorney: how each tax professional differs, who can represent you to the IRS, and which fits your tax needs.

Image
Form 1116: How the Foreign Tax Credit Keeps You From Being Taxed Twice
Published On:
July 23, 2026

How the foreign tax credit works on Form 1116: who files, the income baskets, the limitation, carryovers, credit vs deduction, and 2026 changes.

View all posts
Icon
Icon