Skip to content
Bellator Cyber Guard
Tax38 min readDeep Dive

Online Tax Filing Security Risks: 2025–2026 Guide

Learn the top online tax filing security risks for 2026: phishing, identity theft, credential stuffing. Protect your tax data with expert, IRS-aligned guidance.

By Bellator Cyber Guard Security Team
Online Tax Filing Security Risks: 2025–2026 Guide — online tax filing security risks 2025 2026

Why Online Tax Filing Has Become a Prime Target

Online tax filing security risks are not theoretical. They are active, escalating, and tied directly to the high-value personally identifiable information (PII) that flows through tax returns every filing season. A single federal return contains your Social Security Number (SSN), employer information, bank routing details, and prior-year income data. For an attacker, that combination is the financial equivalent of a skeleton key.

The IRS reported 294,138 identity theft affidavits (Form 14039) submitted by taxpayers in FY2024, and the agency's Criminal Investigation division identified over $5.5 billion in tax fraud schemes that same year. Fraudulent returns can still slip through before legitimate filers act. The window between a data breach and a fraudulent refund claim can be as short as 48 hours.

This guide covers the specific attack vectors targeting individual filers and tax professionals in 2025 and 2026, the regulatory obligations that apply to firms handling taxpayer data, and the concrete steps you can take to protect sensitive financial records. For a broader view of the obligations tax firms carry, see our guide on cybersecurity requirements for tax professionals.

Online Tax Fraud By The Numbers

294K+
Identity Theft Affidavits Filed

IRS Form 14039 submissions in FY2024

$5.5B
Tax Fraud Identified

IRS Criminal Investigation division, FY2024

48 hrs
Breach-to-Fraud Window

Time from data theft to fraudulent refund claim

Tax-Season Phishing: The Most Persistent Attack Vector

Phishing remains the dominant entry point for attacks on tax filers and the firms that serve them. The IRS Dirty Dozen list, published annually, has included tax-related phishing and smishing (SMS phishing) every year since 2015. In the 2025 edition, the IRS warned specifically about a sharp increase in W-2 phishing campaigns targeting HR and payroll personnel, where attackers impersonate executives to request bulk employee wage data before the filing deadline.

From a technical standpoint, these campaigns map to MITRE ATT&CK Technique T1566 (Phishing), with sub-techniques including spearphishing attachments (T1566.001) and spearphishing via service (T1566.003). Threat actors register lookalike domains, use SSL certificates to display the padlock icon, and reference real case numbers to appear credible. Seeing a padlock does not mean a site is safe. It only means the connection is encrypted, not that the destination is legitimate.

Three scenarios account for the majority of tax-season phishing incidents:

  • IRS impersonation emails claiming a refund is pending or that action is required to avoid a penalty, always directing victims to credential-harvesting pages
  • Tax software account takeover attempts that use stolen password lists from prior breaches to access TurboTax, H&R Block, TaxAct, and similar platforms
  • Business Email Compromise (BEC) targeting payroll, where attackers pose as executives requesting W-2 data or direct deposit changes for all employees

Employees who recognize these tactics before clicking are your first and most effective line of defense. Our overview of what phishing is explains the full taxonomy of phishing sub-types and the technical indicators to watch for. For firms dealing with browser-based credential theft, see our analysis of Browser-in-the-Middle phishing attacks.

Tax Identity Theft: How Stolen Data Becomes Fraudulent Refunds

Tax identity theft follows a predictable kill chain. Attackers acquire SSNs through data breaches, phishing, or dark web marketplaces, then file a fraudulent return early in the season before the legitimate taxpayer does. The IRS issues a refund to an attacker-controlled account, often a prepaid debit card or cryptocurrency wallet, and the legitimate filer discovers the fraud only when their return is rejected as a duplicate.

Credential stuffing is one of the primary methods attackers use to gain account access on tax platforms. In a credential stuffing attack, automated tools test username-and-password pairs leaked from unrelated breaches against tax software login pages. Because password reuse remains widespread, these attacks succeed at a measurable rate. Okta's 2024 State of Secure Identity Report found that credential stuffing accounted for 34% of authentication traffic on consumer-facing applications.

The IRS Identity Protection (IP) PIN program is the most direct countermeasure available to individual filers. Once enrolled, a six-digit IP PIN is required on every return filed under your SSN. Without it, the IRS will reject the return. You can enroll at IRS.gov/IPPIN. Enrollment is now open to all taxpayers, not just prior identity theft victims.

For tax professionals, the risk extends beyond individual accounts. A single compromised Electronic Filing Identification Number (EFIN) can be used to submit hundreds of fraudulent returns before detection. This is precisely why the IRS and Security Summit partners require firms to implement the technical and administrative controls detailed in IRS Publication 4557 safeguarding taxpayer data and a Written Information Security Plan (WISP). If your firm has not yet built one, our free WISP template for tax preparers walks through every required element.

How to Secure Your Online Tax Filing in 2026

1

Enroll in the IRS IP PIN Program

Register at IRS.gov/IPPIN to get a six-digit Identity Protection PIN. Once enrolled, this PIN must appear on every federal return filed under your SSN, blocking fraudulent duplicate filings.

2

Enable Multi-Factor Authentication on All Tax Accounts

Turn on MFA for every tax software platform you use: TurboTax, H&R Block, TaxAct, Drake, Lacerte, and IRS e-Services. Use an authenticator app rather than SMS-based codes where possible.

3

Use Unique, Strong Passwords for Every Tax Platform

Password reuse is the primary enabler of credential stuffing attacks. Use a password manager to generate and store distinct credentials for each tax-related account.

4

File Early in the Season

Filing as early as possible reduces the window attackers have to submit a fraudulent return under your SSN before you do. The IRS accepts returns starting in late January each year.

5

Use a Secure, Private Network

Never file taxes or access client data on public Wi-Fi. Use a trusted home or office network, or connect through a verified VPN. See our guide to choosing a VPN for detailed criteria.

6

Audit Browser Extensions Before Filing Season

Remove any browser extensions you did not intentionally install from a verified developer. Malicious extensions can intercept form submissions on tax platforms without triggering antivirus detection.

7

Monitor for Dark Web Exposure

Set up alerts to detect if your SSN, email, or credentials appear on dark web marketplaces. Early detection gives you time to enroll in the IP PIN program and alert affected institutions before a fraudulent return is filed.

What Tax Professionals Are Required to Do Under Federal Rules

Individual filers face personal risk, but tax professionals carry legal exposure too. The Gramm-Leach-Bliley Act (GLBA) and its implementing FTC Safeguards Rule require tax preparers who qualify as financial institutions to maintain a written information security program. Updated in 2023, the Safeguards Rule now mandates specific technical controls: access controls, encryption, multi-factor authentication (MFA), and annual penetration testing for firms handling 5,000 or more customer records. Smaller firms must still implement reasonable safeguards even if the penetration testing threshold does not apply.

Separately, IRS Publication 4557 requires every tax preparer, regardless of firm size, to implement a Written Information Security Plan. The WISP must document how the firm collects, stores, accesses, and destroys taxpayer data. Practitioners who have not yet developed a WISP are out of compliance and face exposure to both IRS sanctions and state-level data privacy penalties. Our detailed breakdown of the FTC Safeguards Rule for tax preparers covers how obligations scale by firm size.

Key technical controls the IRS and FTC expect practitioners to have in place include:

  • Endpoint Detection and Response (EDR) on all workstations and servers that process taxpayer data. Traditional antivirus is not sufficient against modern threats. For a comparison of protection tiers, see our guide to EDR vs. MDR vs. XDR.
  • Encrypted client portals for document exchange. Email attachments containing PII are explicitly discouraged in IRS guidance. Our analysis of tax client portal security covers what encryption standards compliant platforms must meet.
  • Role-based access controls so staff members can only access client files relevant to their assigned work.
  • Incident response procedures with defined IRS notification timelines. IRS Stakeholder Liaison guidance requires notification within 24 hours of confirmed EFIN misuse. A written incident response plan for tax practices is the only way to meet that window reliably.

Practices with multiple preparers should also review our guidance on ransomware protection. Ransomware remains the most financially damaging threat to multi-preparer offices, where a single encrypted server can shut down an entire firm during peak filing season.

2026 Compliance Requirement: WISP Is Mandatory for All Tax Preparers

IRS Publication 4557 requires every tax preparer handling federal returns to have a Written Information Security Plan (WISP) in place. There is no size exemption. Firms without a compliant WISP face IRS sanctions, state data privacy penalties, and potential PTIN suspension. If your firm does not have a current WISPdownload our compliant WISP template to get into compliance before the 2026 filing season.

Online Tax Filing Security Checklist for 2026

  • Enroll in the IRS Identity Protection PIN program at IRS.gov/IPPIN
  • Enable multi-factor authentication on every tax software account
  • Use unique passwords for each tax platform stored in a password manager
  • File your return as early in the season as possible
  • Never access tax accounts or client data on public Wi-Fi
  • Audit and remove unverified browser extensions before filing season
  • Use an encrypted client portal for all taxpayer document exchange
  • Implement role-based access controls on all tax software and file systems
  • Train all staff to recognize W-2 phishing and BEC attempts
  • Document and test your incident response procedures before peak season
  • Review and update your WISP annually

Emerging Threats Targeting Tax Filers in 2026

The environment surrounding online tax filing security risks is shifting in ways that outpace traditional defenses. Three developments deserve specific attention heading into the 2026 filing season.

AI-Generated Phishing at Scale

Large language models have eliminated the grammatical errors and awkward phrasing that once helped users spot phishing emails. Zscaler's 2025 ThreatLabz report documented a 58% year-over-year increase in AI-crafted phishing emails. Tax-themed lures rank among the most-used pretexts because the IRS filing deadline creates urgency that impairs careful judgment. Expect highly personalized emails that reference your specific filing history or the tax software platforms you use. Technical indicators, not writing quality, are now your most reliable detection signal: sender domain mismatches, unexpected links, and requests for credentials or W-2 data via email.

QR Code Phishing in Physical Mail

A newer tactic involves physical letters designed to mimic IRS correspondence that include QR codes directing recipients to credential-harvesting sites. The IRS has formally warned taxpayers that it does not initiate contact via QR codes in mailed correspondence. If you receive a letter with a QR code claiming to be from the IRS, treat it as fraudulent and report it to IRS Criminal Investigation. The IRS only contacts taxpayers by mail for initial outreach, and those letters direct you to IRS.gov or a phone number, not a scannable code.

Credential-Stealing Browser Extensions

Malicious browser extensions disguised as productivity tools or autofill assistants have emerged as a covert method for harvesting tax portal credentials. These extensions are distributed through third-party app stores and can intercept form submissions on tax platforms without triggering antivirus detection. Audit your installed browser extensions before filing season begins and remove anything you did not intentionally install from a verified developer. Enterprise tax firms should consider browser policy controls that restrict extension installation to an approved list.

Staying ahead of these tactics requires understanding what attackers can discover about you before they act. Our primer on security assessments explains how to identify exposure in your own environment and reduce your attack surface before filing season begins.

Bottom Line

Filing early, enrolling in the IRS IP PIN program, and enabling multi-factor authentication are the three highest-impact steps any individual filer can take. For tax professionals, a current WISP and encrypted client portal are not optional best practices. They are regulatory requirements under IRS Publication 4557 and the FTC Safeguards Rule.

Security Capabilities That Protect Taxpayer Data Year-Round

Point-in-time security measures, like changing passwords before tax season, matter. But the threats targeting tax filers and tax professionals operate year-round. Attackers harvest credentials and PII throughout the calendar year, then use that data during the compressed filing window when IRS processing systems are at peak volume.

For individual filers, continuous protection means keeping software and operating systems patched, using a password manager to prevent reuse across accounts, and enabling dark web monitoring to detect when your credentials appear in breach data. Our guide to the best password managers compares options across price and feature tiers.

For tax professionals, year-round protection requires a more structured approach. The IRS Security Summit, a partnership between the IRS, state tax agencies, and private-sector tax software providers, publishes the Security Summit resources annually. These include updated threat intelligence, practitioner checklists, and training materials specifically for the tax professional community.

Managed security services are increasingly practical for small and mid-sized tax firms that do not have dedicated IT staff. A managed Endpoint Detection and Response (EDR) deployment provides continuous monitoring of every endpoint that touches taxpayer data. Combined with a Security Operations Center (SOC) that monitors for anomalous login patterns and data exfiltration attempts, managed security removes the burden of 24/7 monitoring from practitioners who need to focus on client work. Our tax practice security solutions page covers how Bellator Cyber Guard structures this for firms of different sizes.

For firms considering their full compliance posture, our IRS Publication 4557 compliance overview maps every required control to a specific implementation step.

What to Do If Your Tax Data Is Compromised

Speed matters after a breach. The faster you act, the smaller the window attackers have to file a fraudulent return or open accounts in your name.

For individual filers who discover their tax data has been stolen or that a fraudulent return has already been filed in their name, the IRS provides a structured response path. File IRS Form 14039 (Identity Theft Affidavit) immediately. This flags your SSN for enhanced scrutiny and triggers the IRS Identity Theft Victim Assistance process. Concurrently, place a fraud alert or credit freeze with all three major credit bureaus (Equifax, Experian, TransUnion) and notify your financial institutions.

If you used a tax professional whose systems were compromised, you are entitled to know what data was exposed. Federal law under the GLBA requires covered financial institutions, which includes tax preparers, to notify affected customers of a security breach. Our detailed guide on what to do after a data breach covers every notification and remediation step in sequence.

For tax professionals responding to a breach of their own systems, the response timeline is even tighter. IRS guidance requires notification to the IRS within 24 hours of confirmed EFIN misuse. Your incident response plan must be in writing and tested before a breach occurs. A plan you write during an active incident is too late to be useful. Firms that have not yet built out this documentation can start with our WISP template, which includes a basic incident response framework as a required component.

Get a Free Tax Cybersecurity Assessment

Bellator Cyber Guard's tax security specialists will evaluate your current defenses against the top online tax filing security risks and deliver a prioritized action plan at no cost.

Protect Your Tax Practice From Cyber Threats

From WISP development to 24/7 endpoint monitoring, Bellator Cyber Guard gives tax professionals the security infrastructure required by the IRS and FTC Safeguards Rule.

Frequently Asked Questions

The most active threats are phishing emails impersonating the IRS or tax software providers, credential stuffing attacks against tax platform accounts, tax identity theft using stolen SSNs to file fraudulent refund claims, and a newer tactic involving QR codes embedded in physical mail designed to look like IRS correspondence. AI-generated phishing emails are also increasing sharply, with Zscaler's 2025 ThreatLabz report documenting a 58% year-over-year rise in AI-crafted lures.

The IRS does not initiate contact with taxpayers by email, text message, or social media to request personal or financial information. Any email claiming to be from the IRS and asking for your SSN, bank account details, or login credentials is fraudulent. The IRS also does not send QR codes in emails or physical mail. If you receive a suspicious email that appears to be from the IRS, forward it to phishing@irs.gov without clicking any links. Verify any IRS correspondence by calling 1-800-829-1040 directly.

An IRS Identity Protection (IP) PIN is a six-digit number that must appear on your federal tax return before the IRS will process it. It prevents anyone else from filing a return using your SSN, even if they have your Social Security number and date of birth. Enrollment is open to all U.S. taxpayers through the IRS Get an IP PIN tool at IRS.gov/IPPIN. You will need to verify your identity using a valid email address, a financial account number, and a mobile phone number linked to your name. The PIN changes annually and is mailed to enrolled taxpayers each year.

Yes. Major tax software providers are subject to the FTC Safeguards Rule as financial institutions under the Gramm-Leach-Bliley Act. They are required to maintain a written information security program, implement access controls and encryption, and notify users of data breaches. However, your account security also depends on the measures you take: using a unique, strong password and enabling multi-factor authentication significantly reduces the risk of unauthorized account access regardless of the provider's baseline protections.

Act immediately. File IRS Form 14039 (Identity Theft Affidavit) at IRS.gov to flag your SSN for enhanced review. Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion. Notify your bank and any financial institutions where accounts could be opened using your information. If a fraudulent return has already been filed in your name, contact the IRS Identity Theft Victim Assistance line at 1-800-908-4490. Document every step you take, including dates and reference numbers, for follow-up correspondence.

Yes, every tax preparer who handles federal tax returns is required to have a WISP under IRS Publication 4557. There is no minimum firm size or return volume exemption. The WISP must document how your firm collects, stores, accesses, transmits, and destroys taxpayer data, and must include an incident response procedure. Separately, tax preparers who meet the definition of a financial institution under the Gramm-Leach-Bliley Act must also comply with the FTC Safeguards Rule, which has its own written program requirements. Bellator Cyber Guard offers a free WISP template built to IRS Publication 4557 requirements.

The IRS processes returns on a first-come, first-served basis. If an attacker files a fraudulent return under your SSN before you file your legitimate return, the IRS will reject your return as a duplicate and require you to go through an identity verification process that can delay your refund by months. Filing as early as the IRS begins accepting returns, typically late January, minimizes the window during which an attacker can beat you to submission. Combining early filing with IRS IP PIN enrollment provides the strongest protection against duplicate return fraud.

Credential stuffing is an automated attack where threat actors take username-and-password pairs leaked from one data breach and systematically test them against other services. Because many people reuse passwords across accounts, a credential list from a breached retail site can successfully unlock accounts on TurboTax, H&R Block, or other tax platforms. Okta's 2024 State of Secure Identity Report found that credential stuffing accounted for 34% of authentication traffic on consumer-facing applications. The defense is straightforward: use a unique password for every account. A password manager makes this practical at scale.

For individual filers, MFA is strongly recommended and required by most major tax platforms to access certain features, but it is not a federal legal requirement on the individual filer. For tax professionals, the answer is different. The FTC Safeguards Rule, updated in 2023, explicitly requires multi-factor authentication for any staff member accessing customer financial data. IRS Publication 4557 also identifies MFA as a required control for practitioner systems. A firm that does not have MFA enabled on tax software used by its preparers is out of compliance with both requirements.

Both apply to most tax preparers, but they originate from different authorities and have different scopes. The FTC Safeguards Rule under the Gramm-Leach-Bliley Act is enforced by the Federal Trade Commission and applies to financial institutions, a category that includes tax preparers. It requires a written information security program with specific technical safeguards and scales some requirements, like penetration testing, to firms handling 5,000 or more customer records. IRS Publication 4557 is IRS guidance that applies to all tax preparers regardless of size and specifically requires a WISP covering taxpayer data. Both require written programs, access controls, encryption, and employee training. A WISP built to IRS Publication 4557 standards should be reviewed against FTC Safeguards Rule requirements to ensure both are satisfied.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.