Skip to content
Bellator Cyber Guard
Tax35 min readDeep Dive

Why Hackers Target Tax Preparers and How to Fight Back

Tax preparers hold SSNs, bank details, and financial records for hundreds of clients. Learn why hackers target your firm and how to fight back in 2026.

By Bellator Cyber Guard Security Team
Why Hackers Target Tax Preparers and How to Fight Back - why hackers target tax preparers

Tax Preparers Are Prime Targets for Cybercriminals

Tax preparers are among the most targeted professionals in the country, according to the IRS Security Summit. A single tax firm with 300 clients holds the Social Security numbers, bank routing and account numbers, income history, and employer identification numbers for 300 households. That concentration of financial and identity data makes even a solo practitioner more valuable to a data thief than many larger businesses whose records contain far less actionable information.

Identity thieves use stolen tax data to file fraudulent returns and collect refunds before the legitimate taxpayer ever files. They use that same data to open credit accounts, apply for government benefits, and build synthetic identities that can generate fraudulent income for years. The impact on your clients extends well beyond tax season, and the regulatory consequences for your firm can include fines, PTIN suspension, and civil liability from affected clients.

This article explains exactly why your firm attracts attackers, how the most common attacks unfold, what the IRS and FTC require you to do about it, and the specific steps that block the threats your firm faces most often. These risks apply equally to solo practitioners and large regional firms.

The Threat to Tax Professionals By the Numbers

$4.88M
Avg. Data Breach Cost

IBM Cost of Data Breach Report 2024

68%
Breaches Involve Human Element

Verizon Data Breach Investigations Report 2024

11+
Returns Trigger IRS WISP Requirement

IRS Publication 4557 threshold for all paid preparers

Those breach cost and human-element figures come from the Verizon Data Breach Investigations Report 2024 and the IBM Cost of Data Breach Report 2024. The 68% figure is particularly relevant for tax firms: phishing and social engineering remain the dominant entry points because they bypass technology controls by targeting people directly.

What Makes Tax Preparers Such Valuable Targets

The core issue is data density. A single client's tax return contains nearly everything a cybercriminal needs to commit identity theft: full legal name, date of birth, Social Security number, current address, employer name and Employer Identification Number (EIN), bank account and routing numbers, income sources, and dependent information. No single stolen record from a retailer or healthcare provider provides that level of completeness. A stolen credit card number is disruptive. A stolen tax return is the foundation for years of financial fraud.

For attackers focused on tax refund fraud, the math is straightforward. If they can access a preparer's client database or tax software credentials, they can file fraudulent returns for dozens or hundreds of clients in a single season. The IRS processes millions of returns in a narrow window each February through April. Fraudulent returns filed early, before the legitimate taxpayer files, can result in refunds deposited to criminal-controlled accounts before anyone detects the problem.

Tax preparers also frequently hold power of attorney authorizations, prior-year returns, and financial account information that extends the exploitation window well beyond a single filing season. Some attackers don't monetize stolen data immediately. They stockpile it and sell it on criminal marketplaces, where tax-related records consistently command higher prices than generic stolen credentials because the data is complete and immediately actionable.

The security of your tax client portals is directly tied to this risk. Portals that use weak authentication or unencrypted storage represent exactly the kind of access point attackers probe when targeting a firm.

How Hackers Actually Attack Tax Firms

Understanding the attack methods helps you prioritize your defenses. The IRS Security Summit tracks attack trends against tax professionals each year, and the dominant methods have been consistent across multiple filing seasons.

Phishing and Spear Phishing

Phishing is the entry point for the majority of tax firm breaches. Attackers send emails that appear to come from the IRS, tax software vendors, payroll providers, or even clients. These messages create urgency: a rejected e-file, a software license expiration, a client portal login request, or an IRS notice requiring immediate action. When a staff member clicks the link and enters credentials, the attacker has direct access to your tax software, email, or network.

Spear phishing is a more targeted version. Attackers research your firm using LinkedIn, your website, and public records to craft messages that reference real clients, real software your firm uses, or specific IRS notices. A preparer who works with a particular payroll company might receive a convincing message that appears to come from that company's support team, complete with the firm's logo and a realistic-sounding request.

Ransomware

Ransomware encrypts your files and demands payment to restore access. For a tax firm, an attack during filing season is particularly damaging: you lose access to client files, tax software, and historical returns exactly when clients need you most. Paying the ransom does not guarantee your data is returned intact, and it does not prevent the attackers from publishing or selling your client data separately. Many ransomware operators exfiltrate data before encrypting it, meaning client records are at risk even if you pay and restore operations.

Credential Stuffing and Password Spraying

Many tax professionals reuse passwords across multiple accounts or use weak passwords that can be guessed through automated attacks. Credential stuffing attacks use lists of previously breached username and password combinations, purchased on criminal marketplaces, to attempt login at tax software portals, email providers, and cloud storage. If a staff member uses the same password for their tax software as for a shopping site that was breached years ago, attackers may already have the credentials they need.

Business Email Compromise

Business email compromise (BEC) attacks target financial transactions. After gaining access to a staff email account, attackers monitor correspondence to identify clients expecting refunds or making estimated tax payments. They then send convincing messages from the compromised account redirecting payments to criminal accounts. According to the FBI Internet Crime Complaint Center, BEC losses consistently exceed $2.7 billion annually across all industries, and tax firms are a frequent target because of the volume of financial transactions they facilitate.

IRS Compliance Requirement: WISP Mandatory for All Paid Tax Preparers

Under IRS Publication 4557, all paid tax preparers are required to maintain a Written Information Security Plan (WISP). This applies to every preparer with a Preparer Tax Identification Number (PTIN), including solo practitioners. Separately, tax preparers who qualify as financial institutions under the Gramm-Leach-Bliley Act must also comply with the FTC Safeguards Rule, which carries additional technical requirements. The IRS treats the start of each filing season as the effective compliance checkpoint, and PTIN renewals may be affected by non-compliance.

What the IRS and FTC Actually Require

Tax preparers operate under two overlapping regulatory frameworks that mandate specific cybersecurity practices. Understanding both allows you to build a single security program that satisfies all requirements without duplicating effort.

IRS Publication 4557 and the WISP Requirement

The IRS requires all paid tax preparers to maintain a Written Information Security Plan. A WISP is a documented security policy that identifies the data you collect, the risks to that data, and the specific controls you have in place to address those risks. The WISP must be reviewed and updated annually and whenever you add new technology, hire new staff, or experience a security incident.

The IRS does not prescribe a rigid format, but IRS Publication 5708 provides a sample WISP that firms can adapt to their specific situation. The document must address physical security, employee access controls, data disposal procedures, and incident response. The PTIN and WISP requirements are linked: the IRS expects every preparer holding a PTIN to maintain a compliant, current WISP.

FTC Safeguards Rule

The FTC Safeguards Rule applies to tax preparers because they qualify as financial institutions under the Gramm-Leach-Bliley Act. The 2023 amendments to the Safeguards Rule added technical requirements that go beyond the basic IRS WISP framework. These include:

  • Multi-factor authentication (MFA) on all systems that access customer financial information
  • Encryption of customer data both at rest and in transit
  • Role-based access controls that limit employee access to only the data needed for their specific function
  • Monitoring for unauthorized access attempts or data exfiltration
  • A written incident response plan with defined roles and timelines
  • Annual penetration testing or vulnerability assessments

The FTC has authority to fine firms that fail to implement required controls. Non-compliance also creates civil liability exposure when a breach occurs and the firm cannot demonstrate it had required safeguards in place. For a detailed breakdown of both frameworks, the IRS cybersecurity requirements guide covers the specific controls expected under each standard.

Tax Firm Cybersecurity Checklist

  • Enable multi-factor authentication on all tax software, email, and cloud storage accounts
  • Create or update your Written Information Security Plan (WISP) to reflect current systems and staff
  • Conduct security awareness training for all staff before each filing season
  • Implement separate user accounts with role-based access so staff only see data relevant to their role
  • Encrypt all devices that store client data, including laptops used for remote work
  • Test data backups by actually restoring files, not just confirming the backup completed
  • Review your client portal's authentication settings and session timeout policies
  • Document an incident response plan covering how to notify clients, the IRS, and state regulators
  • Verify that third-party vendors with access to client data maintain their own security programs
  • Conduct or commission an annual vulnerability assessment of all systems

How to Build a Security Program for Your Tax Firm

1

Inventory Your Data and Systems

List every location where client data exists: tax software, cloud drives, email, physical files, USB drives, and backup systems. You cannot protect data you have not identified.

2

Document Your WISP

Create a Written Information Security Plan that maps your risks to your controls. Use the IRS Publication 5708 sample as a starting point, then adapt it to your actual systems and staff size.

3

Implement Multi-Factor Authentication

Enable MFA on every account that accesses client data. This single control blocks the majority of credential-based attacks. Start with tax software, email, and cloud storage accounts.

4

Deploy Endpoint Detection and Response

Install Endpoint Detection and Response (EDR) software on every workstation and laptop used by staff. Signature-based antivirus alone does not detect the behavioral patterns that indicate ransomware or active data exfiltration.

5

Train Your Team Before Filing Season

Conduct phishing simulations and security awareness training at least once before filing season opens. Staff who recognize phishing attempts are your most effective defense against the most common attack method.

6

Write an Incident Response Plan

Document exactly what you will do if a breach occurs: who to contact first, how to contain damage, how to notify affected clients, and what to report to the IRS Stakeholder Liaison and state regulators.

7

Test and Review Annually

Review your WISP and all security controls each year and after any significant change to your systems or staff. Schedule a vulnerability assessment to verify your controls actually work under realistic conditions.

Bottom Line

A tax preparer's client database contains everything a criminal needs to commit identity theft at scale. Multi-factor authentication, Endpoint Detection and Response (EDR) software, and a documented Written Information Security Plan address the three most commonly exploited gaps in small firm security. These are not advanced measures reserved for large firms. They are the baseline for any business holding Social Security numbers and financial account data.

What to Do Immediately After a Data Breach

If you discover or suspect a breach, the first hours determine how much damage occurs. Containment actions taken quickly limit how much data an attacker can access or exfiltrate. Delayed responses allow attackers to move deeper into your systems and increase the number of clients affected.

The IRS requires tax preparers to report data theft to the IRS Stakeholder Liaison immediately. Your state may also require notification to the state attorney general and to affected clients within a defined window, often 30 to 60 days depending on the state. Your incident response plan for your tax practice should specify who you call and in what order, so those decisions are made in advance rather than under pressure after an attack begins.

Key immediate steps: disconnect affected systems from the network without powering them off, which preserves forensic evidence; reset credentials for all accounts that may have been exposed; and contact your cybersecurity provider to begin investigation. If you do not have a cybersecurity provider on retainer, this is typically when firms discover how long finding and engaging one takes.

For clients affected by a breach at your firm, you are responsible for notifying them of the risk to their data. The steps to take after a data breach include placing fraud alerts on client credit files, monitoring for fraudulent returns filed using compromised Social Security numbers, and in confirmed cases, filing IRS Form 14039 on behalf of clients to flag their accounts as potentially compromised. The identity theft prevention resources for tax professionals provide specific guidance on protecting clients after a confirmed incident.

Remote Work and Third-Party Vendor Risks

Remote and hybrid work arrangements have introduced new attack surfaces for tax firms. Staff accessing tax software from home networks, personal devices, or public wi-fi expand the perimeter that needs protection. A secure office network provides no defense when a staff member connects from a shared home network or a coffee shop, and that gap is exactly what attackers look for.

Minimum requirements for remote work include a business-grade VPN for all remote connections, full disk encryption on every device used for client work, and MFA on every remote access point. The remote work security guide for small teams covers the specific controls that translate office-level security to distributed environments without requiring a dedicated IT staff to manage them.

Third-party vendor risk deserves equal attention. If you use a cloud-based document management system, a client portal, a payroll processor, or any software that accesses client data, that vendor's security posture affects your clients directly. The FTC Safeguards Rule explicitly requires covered firms to oversee service providers who access customer financial information. Ask vendors for their SOC 2 Type II reports or other evidence of independent security audits before granting them access to client data.

Password reuse across systems is one of the most common vulnerabilities in small firms. Staff who use the same password for tax software and personal accounts create a risk that extends well beyond your firm's control. A business-grade password manager eliminates credential reuse without placing unrealistic demands on staff to remember dozens of complex, unique passwords for each system they access.

Get a Free 2026 WISP Template for Your Tax Firm

Bellator Cyber Guard provides IRS-compliant WISP templates built specifically for tax professionals. Download the 2026 template and start your security program today at no cost.

Why Security Awareness Training Is a Front-Line Defense

Technology controls stop many attacks automatically. But phishing, spear phishing, and social engineering succeed specifically because they target people rather than systems. A convincing email from what appears to be a trusted source will always have some chance of bypassing even well-configured email security tools.

Security awareness training teaches staff to recognize the signs of phishing: unexpected urgency, mismatched sender domains, requests for credentials or wire transfers outside normal procedures, and links that lead to login pages with slightly wrong URLs. Training also establishes clear procedures for what to do when something seems suspicious, so staff have a defined path that does not involve clicking the link to verify whether it is real.

The IRS Security Summit recommends annual training for all staff who handle taxpayer data, with timing aligned to the start of filing season when attackers ramp up targeting of tax professionals. Phishing simulations, where your firm or security provider sends test phishing emails to staff, measure how well training translates to actual behavior. Firms that run simulations consistently reduce click rates on test phishing emails and, more importantly, identify which staff members need additional coaching before a real attack tests those gaps.

For a detailed overview of how phishing attacks are constructed and the specific indicators that distinguish them from legitimate messages, the guide to phishing attacks and defenses covers the full range of techniques attackers direct at tax professionals each filing season.

Book a Free Tax Cybersecurity Assessment

Our security team works specifically with tax professionals. We will evaluate your current setup, identify your highest-risk gaps, and give you a clear plan for meeting IRS and FTC requirements.

Frequently Asked Questions

Tax preparers hold high-value, complete identity data for every client they serve: Social Security numbers, bank account and routing numbers, income history, employer details, and dependent information. A single breach at a small tax firm can expose hundreds of complete identity profiles. Criminals use this data to file fraudulent tax returns, open credit accounts, and sell records on criminal marketplaces where tax-related data commands premium prices because it is complete and immediately actionable. The data density makes even a solo practitioner a valuable target relative to the perceived difficulty of the attack.

Phishing and spear phishing are the most common entry points. Attackers send emails that appear to come from the IRS, tax software vendors, or clients, tricking staff into entering credentials or opening malicious attachments. Ransomware attacks, often delivered through phishing, encrypt tax files and demand payment for restoration. Credential stuffing uses previously breached username and password combinations to attempt login at tax software portals. Business email compromise (BEC) targets financial transactions by intercepting and redirecting client payments after gaining access to a staff email account.

Yes. The IRS requires all paid tax preparers to maintain a Written Information Security Plan (WISP) under IRS Publication 4557. This applies to every preparer with a PTIN, including solo practitioners working from home. Tax preparers who qualify as financial institutions under the Gramm-Leach-Bliley Act must also comply with the FTC Safeguards Rule, which adds technical requirements including multi-factor authentication, encryption, and annual vulnerability assessments.

A Written Information Security Plan (WISP) is a documented security policy that identifies the data your firm collects, the risks to that data, and the specific controls you have in place to manage those risks. The IRS requires a WISP for every paid tax preparer holding a PTIN, including solo practitioners who work from home and handle a small number of returns. The WISP template for tax preparers provides a starting point that can be adapted to a firm of any size without requiring outside legal or technical expertise to complete.

Contact the IRS Stakeholder Liaison immediately. The IRS has a specific process for tax preparers who experience data theft, and notifying them quickly allows the IRS to flag affected taxpayer accounts before fraudulent returns can be processed. Disconnect affected systems from the network without powering them off to preserve forensic evidence. Reset credentials for all accounts that may have been exposed. Notify your state attorney general and affected clients according to your state's breach notification timeline, typically 30 to 60 days. Your incident response plan should be written and practiced before you need it, not drafted after an attack begins.

The FTC Safeguards Rule sets security requirements under the Gramm-Leach-Bliley Act for financial institutions, a category that includes tax preparers who prepare returns for compensation. The 2023 amendments added specific technical requirements: multi-factor authentication, encryption of customer data at rest and in transit, role-based access controls, monitoring for unauthorized access, a written incident response plan, and annual penetration testing or vulnerability assessments. The FTC can fine firms that fail to implement required controls, and non-compliance creates civil liability exposure if a breach occurs and the firm cannot demonstrate adequate safeguards were in place.

Multi-factor authentication (MFA) requires a second form of verification beyond a password when someone logs into an account. Even if an attacker obtains a staff member's password through phishing or a purchased credential list, they cannot access the account without also having the second factor, typically a code sent to a phone or generated by an authenticator app. The IRS requires MFA for all tax software accounts, and the FTC Safeguards Rule requires it on all systems that access customer financial information. Enabling MFA on tax software, email, and cloud storage eliminates the majority of credential-based attacks at minimal cost and complexity.

Yes. Attackers do not segment their targeting by firm size. A home-based preparer with 50 clients holds 50 complete sets of identity and financial data. The same phishing campaigns, credential stuffing attacks, and ransomware infections that hit large firms reach small ones as well. Small firms often have fewer security controls in place, which can make them easier targets per client record. Both the IRS WISP requirement and the FTC Safeguards Rule apply regardless of firm size, number of employees, or annual revenue.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.