Skip to content
Bellator Cyber Guard
Tax13 min readStandard

IRS Form 14039-B: Data Theft Reporting for Preparers

Learn what IRS Form 14039-B covers, how it differs from a data breach report, and the exact steps tax preparers must take after client data theft.

By Bellator Cyber Guard Security Team

IRS Form 14039-B, the Business Identity Theft Affidavit, is the form a business files when its own Employer Identification Number (EIN) has been used to file a fraudulent business tax return. It is not the form most tax preparers need when a client's Social Security number is stolen from their office systems. That distinction matters, because filing the wrong form, or skipping the actual breach-reporting process, can slow down the IRS response and leave clients exposed longer than necessary.

If your firm has experienced a data breach, ransomware attack, or stolen device containing client tax data, this guide explains which form applies to your situation and what the IRS actually requires you to do first.

Quick Answer

Form 14039-B is for businesses whose own tax identity (EIN) was used to file a fraudulent business return, it is not the primary reporting tool for a tax preparer whose client data was stolen. If your firm suffers a data breach affecting client Social Security numbers, the IRS instead directs you to contact your local IRS Stakeholder Liaison immediately and notify the Federation of Tax Administrators. Affected individual clients, not the firm, generally file Form 14039 if their SSN is later misused on a fraudulent return.

What Form 14039-B Actually Covers

Form 14039-B lets a business report that its EIN was used without authorization to file a fraudulent business tax return, such as a Form 1120, 1120-S, 1065, 1041, or an employment tax return. This is distinct from Form 14039 (the individual Identity Theft Affidavit), which a person files when their SSN is used to file a fraudulent individual return.

For a tax preparation firm, Form 14039-B applies in a narrower scenario than most people assume: it's the correct form if your firm's own EIN was hijacked and used to file a return you didn't submit, or if someone impersonated your business to claim a fraudulent refund or credit under your business tax ID. It is not designed as the reporting channel for a breach where a hacker steals your clients' personal information from your office network.

What to Do When Client Data Is Stolen

The IRS treats a client-data breach as a separate event from business identity theft, with its own reporting sequence outlined in IRS Publication 4557. If your firm discovers unauthorized access to client tax records, from a phishing compromise, stolen laptop, or ransomware incident, the IRS asks preparers to:

  • Contact your local IRS Stakeholder Liaison right away; they coordinate the agency's response and can flag affected taxpayer accounts for extra fraud screening
  • Email the Federation of Tax Administrators at StateAlert@taxadmin.org so state tax agencies where your clients reside can be alerted, since state notification laws vary
  • File a report with local police and, for larger incidents, consider notifying the FBI's Internet Crime Complaint Center
  • Determine which specific clients were affected and notify them so they can watch for signs of misuse

These steps come directly from the IRS's guidance for tax professionals and are separate from, and generally more urgent than, filing Form 14039-B. Reviewing the full form 4557 requirements before an incident happens makes this response much faster when it counts.

Data Theft Response Checklist for Tax Preparers

  • Contain the incident: isolate affected systems and change compromised credentials
  • Contact your IRS Stakeholder Liaison to report the breach
  • Email the Federation of Tax Administrators at StateAlert@taxadmin.org
  • File a report with local law enforcement
  • Identify every client whose data was exposed and notify them directly
  • Only file Form 14039-B if your firm's own EIN was used on a fraudulent business return
  • Advise affected clients they may need to file Form 14039 if their SSN is misused
  • Document the incident and your response for your records and any state reporting obligations

Why the Confusion Happens

Preparers often search for Form 14039-B after a breach because it's the most visible IRS identity-theft form tied to "business" in its name. But the IRS's actual data-theft reporting process for tax professionals runs through the Stakeholder Liaison and state notification channels first, Form 14039-B only becomes relevant in the narrower case where a fraudulent business return was filed under your firm's own EIN, separate from any theft of client information.

Confirming which scenario you're in before you file anything saves time and avoids submitting the wrong paperwork while your clients remain unprotected. If you're unsure, your Stakeholder Liaison can tell you directly whether Form 14039-B applies to your situation.

Preventing the Next Incident

Data theft reporting is a reaction to a problem that a documented security program is meant to prevent. The IRS and FTC require tax preparers to maintain a written information security plan covering access controls, encryption, and incident response. A wisp checklist can help you confirm your plan actually meets the documentation standard examiners expect, and reviewing current irs cybersecurity requirements alongside your ptin renewal security requirements keeps your compliance obligations aligned in one place. Many breaches preparers report each filing season trace back to the same handful of gaps covered in our overview of common tax preparer security threats.

Report Promptly

The IRS asks tax professionals to contact their Stakeholder Liaison as soon as a breach is discovered, not after an internal investigation is complete. Waiting can delay fraud-alert flags on affected client accounts and widen the window for fraudulent returns to be filed.

Book a Free Tax Cybersecurity Assessment

Get plain-language help reviewing your incident response plan and WISP before a breach forces the issue. No pressure.

Frequently Asked Questions

Usually not. Form 14039-B applies when your firm's own EIN was used to file a fraudulent business tax return. A breach involving client Social Security numbers or tax records is reported through the IRS Stakeholder Liaison and the process described in Publication 4557, not Form 14039-B.

Form 14039 is the Identity Theft Affidavit individuals file when their own SSN was used on a fraudulent return. Form 14039-B is the version businesses file when their EIN was used the same way. Preparers file 14039-B only for their own firm's identity, not on behalf of clients.

Yes. IRS guidance directs preparers to identify every client whose information may have been exposed and notify them so they can watch for signs their identity was used to file a fraudulent return. Clients may then need to file Form 14039 themselves if misuse occurs.

The IRS maintains a list of Stakeholder Liaisons by state on IRS.gov, along with instructions for reporting a tax professional data breach. Contact your assigned liaison as soon as you confirm a breach has occurred.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.