EFIN Protection: Guard Your E-File Number
Your EFIN is one of your most valuable business assets. Criminals who steal it can file thousands of fraudulent returns in your name.
By the Numbers
What EFIN Protection Guide Covers
Credential Security
Secure your EFIN, PTIN, and e-Services login with strong passwords and MFA.
Filing Activity Monitoring
Monitor your EFIN for unauthorized filing activity throughout the year.
Application Security
Secure the IRS e-Services application and restrict access to authorized personnel only.
Employee Access Controls
Limit who can access filing credentials and maintain an access log.
Renewal Security
Protect the annual EFIN renewal process from social engineering attacks.
Theft Response Plan
Know exactly what to do if your EFIN is compromised or used fraudulently.
How to Get Started
Audit Current Access
Identify everyone who has access to your EFIN and e-Services credentials.
Implement MFA
Enable multi-factor authentication on all IRS e-Services and tax software accounts.
Monitor Filing Activity
Regularly review your filing statistics for unexpected spikes or unusual patterns.
Secure & Document
Store credentials securely, document access policies, and train staff on EFIN security.
Frequently Asked Questions
An Electronic Filing Identification Number (EFIN) is assigned by the IRS to authorized e-file providers. Criminals can use stolen EFINs to submit fraudulent returns and steal refunds, making it extremely valuable on the dark web.
Through phishing emails impersonating the IRS, malware on tax preparation computers, social engineering of firm employees, and compromised e-Services login credentials.
Watch for unexpected rejection of returns, IRS notices about returns you did not file, unusual changes to your e-Services account, or communications from the IRS about suspicious filing activity under your EFIN.
Immediately contact the IRS e-Help desk, file a complaint with the Treasury Inspector General, report to local law enforcement, change all credentials, and notify your professional liability insurance carrier.
From requirement to defensible practice
Turn IRS and FTC expectations into a WISP your office can follow
A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.
- Know what applies
- Document the evidence
- Make the safeguard operational
A defensible path
- 01
Confirm the requirement
Separate what is required from recommendations and vendor language.
- 02
Map it to your environment
Connect the rule to people, devices, data, vendors, and current procedures.
- 03
Close and document the gaps
Prioritize changes and keep evidence that the process is being followed.
People also look for
Keep exploring Tax security & WISP
Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.
- Common question: free WISP templateStart with a written information security planUse a practical WISP framework built around the safeguards tax practices need.
- Common question: IRS Publication 4557 requirementsRead the Publication 4557 guideSee how the IRS expects tax professionals to safeguard taxpayer data.
- Common question: IRS WISP requirementsReview the WISP requirementsWork through the required sections and the evidence your practice should retain.
- Common question: FTC Safeguards Rule checklistUse the FTC Safeguards checklistTranslate the rule into a clear list of security and documentation tasks.
- Common question: tax practice incident response planPrepare a tax-office incident planKnow who to contact, what to preserve, and how to respond to a client-data incident.
