
Why are tax professionals prime targets of spear phishing? Because a tax firm’s email, tax software, and client files can give an attacker complete identity and financial data for many households at once. The practical response is to make stolen passwords less useful, limit access to taxpayer data, train staff to verify unusual requests, and keep a written plan for an incident.
Tax preparers handle Social Security numbers, bank details, income records, dependent information, and prior-year returns. That makes a small practice an attractive target even when it has only a few employees. The IRS Security Summit is a public-private partnership that publishes security guidance for tax professionals and taxpayers.
Quick Answer
Tax professionals are targeted by spear phishing because attackers can use one convincing email to reach tax software, client portals, email accounts, and high-value taxpayer data. Use multi-factor authentication on every account holding client data, give each staff member a separate account, verify payment or credential requests out of band, and maintain a current Written Information Security Plan. These controls reduce risk, but no single control guarantees that an attack will fail.
Why one tax-firm account can expose many clients
A tax return can contain enough information to support tax refund fraud, account takeover, or other identity fraud if it is exposed. Attackers may seek access to a preparer’s mailbox to impersonate the firm, or to tax software and document storage to reach many client records from one login.
According to Verizon’s 2024 Data Breach Investigations Report, 68 percent of breaches involved a human element, including error, misuse, or social engineering. For a tax practice, that makes a rushed email, a reused password, or an unverified client request a security issue, not merely an administrative mistake.
A spear-phishing message is a targeted fraudulent message that uses details about a recipient, firm, client, or vendor to appear credible. It may claim that an e-file was rejected, a portal requires a login, or a client’s bank details need to be updated. Treat an unexpected request for credentials, a payment change, or an attachment as something to verify through a known phone number or a separately opened vendor site.
Tax-firm defenses to put in place before filing season
- Require multi-factor authentication for tax software, email, cloud storage, remote access, and client portals.
- Use separate named accounts and remove access promptly when a worker leaves or changes roles.
- Encrypt laptops and other devices that store or access taxpayer information.
- Test a restore from backups so the firm knows whether files can be recovered.
- Train staff to report suspicious messages and verify unusual requests using a trusted contact method.
- Document who will contain an incident, contact technical help, and handle required notifications.
What the IRS and FTC expect from tax practices
IRS Publication 4557, Safeguarding Taxpayer Data, provides security guidance for tax professionals handling taxpayer information. It recommends a Written Information Security Plan, or WISP, tailored to the firm’s systems, data, staff, vendors, and risks. IRS Publication 5708 provides a sample plan that practices can adapt.
The FTC Safeguards Rule applies to covered financial institutions under the Gramm-Leach-Bliley Act, which can include professional tax preparers. The rule requires a written information security program with safeguards appropriate to the business, including risk assessment, access controls, encryption in relevant circumstances, secure disposal, service-provider oversight, and incident-response planning. The FTC’s Safeguards Rule guidance explains the current requirements. Compliance questions and the applicability of a requirement to your practice should be reviewed with qualified legal counsel.
A plan copied from a template but not matched to your actual software, remote workers, and vendors can create a documentation gap. Start with a current inventory, then use the tax preparer security plan guide and Written Information Security Plan resources to document the controls your firm actually uses.
Key Takeaway
For most small tax firms, the first priorities are MFA, separate staff accounts, tested backups, staff phishing training, and a WISP that reflects the systems and vendors in use today.
How to respond when you suspect taxpayer data was exposed
Act quickly, but preserve evidence. Disconnect a suspected affected device from the network if doing so is safe, avoid wiping it, and contact your security provider or incident-response support. Reset potentially exposed credentials from a known-clean device, review mailbox forwarding rules and login activity, and document what was observed and when.
The IRS advises tax professionals that suspect a data theft to contact their IRS Stakeholder Liaison. Notification duties can also vary by state and by the facts of the incident, so follow your incident plan and obtain legal guidance where needed. The IRS page on data theft information for tax professionals lists its recommended reporting steps.
Do not wait for an incident to decide who has access to client records or whether a backup can restore. Review backup practices for tax firms and use an access-control review to reduce the number of accounts and devices that could expose taxpayer data.
Questions to ask a cybersecurity provider
If you need outside help, ask what is monitored, who responds after an alert, whether the service covers all staff workstations, and how the provider supports recovery after ransomware. Also ask how it documents endpoint coverage, access changes, backup testing, and incident-response responsibilities. A low-cost software license is not necessarily equivalent to a managed security service with monitoring and response.
For firms that need managed endpoint protectionBellator Shield managed EDR is $19 per computer per month. Bellator Core combines managed EDR, remote monitoring, and Ransomware Rollback® for $33 per computer per month. Compare scope and fit on the protection plans page before choosing a service.
Talk with a cybersecurity expert
Discuss the phishing, endpoint, backup, and security-plan gaps that matter most for your tax practice.
Frequently Asked Questions
Spear phishing uses details about a specific firm, person, client, or vendor to make a fraudulent request look credible. A message may reference real tax software, a filing deadline, or a client name. Verify unusual requests through an independent, trusted contact method before opening links, attachments, or changing payment details.
A solo preparer may have fewer systems and users, but still holds sensitive taxpayer data. MFA, encrypted devices, unique passwords, tested backups, a documented security plan, and a clear incident process are practical baseline controls for a practice of any size.
Do not use the message link or phone number to verify it. Open the known vendor site directly, use a previously saved contact number, or ask a supervisor. Report the message internally so others can watch for the same campaign.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.



