IRS Form 14039-B, the Business Identity Theft Affidavit, is the form a business files when its own Employer Identification Number (EIN) has been used to file a fraudulent business tax return. It is not the form most tax preparers need when a client's Social Security number is stolen from their office systems. That distinction matters, because filing the wrong form, or skipping the actual breach-reporting process, can slow down the IRS response and leave clients exposed longer than necessary.
If your firm has experienced a data breach, ransomware attack, or stolen device containing client tax data, this guide explains which form applies to your situation and what the IRS actually requires you to do first.
Quick Answer
Form 14039-B is for businesses whose own tax identity (EIN) was used to file a fraudulent business return, it is not the primary reporting tool for a tax preparer whose client data was stolen. If your firm suffers a data breach affecting client Social Security numbers, the IRS instead directs you to contact your local IRS Stakeholder Liaison immediately and notify the Federation of Tax Administrators. Affected individual clients, not the firm, generally file Form 14039 if their SSN is later misused on a fraudulent return.
What Form 14039-B Actually Covers
Form 14039-B lets a business report that its EIN was used without authorization to file a fraudulent business tax return, such as a Form 1120, 1120-S, 1065, 1041, or an employment tax return. This is distinct from Form 14039 (the individual Identity Theft Affidavit), which a person files when their SSN is used to file a fraudulent individual return.
For a tax preparation firm, Form 14039-B applies in a narrower scenario than most people assume: it's the correct form if your firm's own EIN was hijacked and used to file a return you didn't submit, or if someone impersonated your business to claim a fraudulent refund or credit under your business tax ID. It is not designed as the reporting channel for a breach where a hacker steals your clients' personal information from your office network.
What to Do When Client Data Is Stolen
The IRS treats a client-data breach as a separate event from business identity theft, with its own reporting sequence outlined in IRS Publication 4557. If your firm discovers unauthorized access to client tax records, from a phishing compromise, stolen laptop, or ransomware incident, the IRS asks preparers to:
- Contact your local IRS Stakeholder Liaison right away; they coordinate the agency's response and can flag affected taxpayer accounts for extra fraud screening
- Email the Federation of Tax Administrators at StateAlert@taxadmin.org so state tax agencies where your clients reside can be alerted, since state notification laws vary
- File a report with local police and, for larger incidents, consider notifying the FBI's Internet Crime Complaint Center
- Determine which specific clients were affected and notify them so they can watch for signs of misuse
These steps come directly from the IRS's guidance for tax professionals and are separate from, and generally more urgent than, filing Form 14039-B. Reviewing the full form 4557 requirements before an incident happens makes this response much faster when it counts.
Data Theft Response Checklist for Tax Preparers
- Contain the incident: isolate affected systems and change compromised credentials
- Contact your IRS Stakeholder Liaison to report the breach
- Email the Federation of Tax Administrators at StateAlert@taxadmin.org
- File a report with local law enforcement
- Identify every client whose data was exposed and notify them directly
- Only file Form 14039-B if your firm's own EIN was used on a fraudulent business return
- Advise affected clients they may need to file Form 14039 if their SSN is misused
- Document the incident and your response for your records and any state reporting obligations
Why the Confusion Happens
Preparers often search for Form 14039-B after a breach because it's the most visible IRS identity-theft form tied to "business" in its name. But the IRS's actual data-theft reporting process for tax professionals runs through the Stakeholder Liaison and state notification channels first, Form 14039-B only becomes relevant in the narrower case where a fraudulent business return was filed under your firm's own EIN, separate from any theft of client information.
Confirming which scenario you're in before you file anything saves time and avoids submitting the wrong paperwork while your clients remain unprotected. If you're unsure, your Stakeholder Liaison can tell you directly whether Form 14039-B applies to your situation.
Preventing the Next Incident
Data theft reporting is a reaction to a problem that a documented security program is meant to prevent. The IRS and FTC require tax preparers to maintain a written information security plan covering access controls, encryption, and incident response. A wisp checklist can help you confirm your plan actually meets the documentation standard examiners expect, and reviewing current irs cybersecurity requirements alongside your ptin renewal security requirements keeps your compliance obligations aligned in one place. Many breaches preparers report each filing season trace back to the same handful of gaps covered in our overview of common tax preparer security threats.
Report Promptly
The IRS asks tax professionals to contact their Stakeholder Liaison as soon as a breach is discovered, not after an internal investigation is complete. Waiting can delay fraud-alert flags on affected client accounts and widen the window for fraudulent returns to be filed.
Book a Free Tax Cybersecurity Assessment
Get plain-language help reviewing your incident response plan and WISP before a breach forces the issue. No pressure.
Frequently Asked Questions
Usually not. Form 14039-B applies when your firm's own EIN was used to file a fraudulent business tax return. A breach involving client Social Security numbers or tax records is reported through the IRS Stakeholder Liaison and the process described in Publication 4557, not Form 14039-B.
Form 14039 is the Identity Theft Affidavit individuals file when their own SSN was used on a fraudulent return. Form 14039-B is the version businesses file when their EIN was used the same way. Preparers file 14039-B only for their own firm's identity, not on behalf of clients.
Yes. IRS guidance directs preparers to identify every client whose information may have been exposed and notify them so they can watch for signs their identity was used to file a fraudulent return. Clients may then need to file Form 14039 themselves if misuse occurs.
The IRS maintains a list of Stakeholder Liaisons by state on IRS.gov, along with instructions for reporting a tax professional data breach. Contact your assigned liaison as soon as you confirm a breach has occurred.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.


