Phishing Scams Targeting Tax Professionals: How to Spot and Stop Them
The IRS's 2026 Dirty Dozen warns that tax professionals are targeted by fake 'new client' and 'document request' emails. How these scams work, the warning signs and the defenses every firm should have.
Quick answer: Tax professionals are a prime target for phishing because they hold large amounts of sensitive client data and have access to tax filing systems. The IRS's 2026 Dirty Dozen list specifically warns that tax professionals and businesses remain targets of "new client" or "document request" emails that deliver malicious links or attachments to steal client data or access systems. The best defenses are multi-factor authentication, verification by phone, staff training and a single secure channel for client documents.
Key takeaways
- Spear phishing against tax professionals is on the IRS's 2026 Dirty Dozen list.
- The most common lure is a fake prospective client who sends a "document" containing malware.
- Fake document requests and IRS impersonation by email and text are also common.
- Multi-factor authentication is required for tax professionals under the FTC Safeguards Rule, and it blunts many attacks.
- Report suspected IRS-related phishing to phishing@irs.gov.
Why tax professionals are targeted
A single compromised tax practice can give criminals hundreds of clients' Social Security numbers, income details and bank accounts, plus access to tax software that can be used to file fraudulent returns. That's why the IRS and its Security Summit partners repeatedly warn practitioners about targeted attacks.
Common scams aimed at firms
The "new client" scam
Someone emails asking for help with their taxes. After you reply, they send a link or attachment, supposedly their tax documents, that installs malware or leads to a fake login page. Because responding to prospective clients is normal work, this scam is effective. Accounting Today's coverage of the 2026 list notes scammers pose as new clients or request documents specifically to target practitioners.
Fake document requests
Emails that look like they come from a colleague, a client or a vendor asking you to open a shared document, often with an urgent tone and a login prompt.
IRS impersonation
Phishing and smishing messages that appear to come from the IRS, sometimes with links or QR codes leading to fake websites, are at the top of the IRS's list.
Software and account credential theft
Messages claiming your tax software, e-Services or email account needs urgent verification.
Warning signs
- A prospective client who's vague about their situation but quick to send attachments or links
- Attachments in unusual formats, or files that ask you to enable macros or content
- Links that lead to login pages, especially for email or cloud storage
- Urgency, secrecy or pressure to act before checking
- Sender addresses that are slightly off from the real domain
- Requests to change bank details or send data to a new address
How to protect your firm
- Turn on multi-factor authentication for email, tax software, cloud storage and remote access. The FTC Safeguards Rule requires MFA for anyone accessing customer information.
- Never open unexpected attachments from new contacts. Ask new prospects to use your secure upload channel instead of emailing files.
- Verify by phone, using a number you already have, before acting on any request to change payment details or send data.
- Train staff at least annually and before busy season, and run practice exercises.
- Keep software patched and use reputable security software.
- Limit access so each person can reach only the data they need.
- Document it in your written information security plan.
Why a single document channel helps
When clients routinely email attachments, a malicious attachment looks normal. When your firm only accepts documents through one secure upload channel, an emailed "tax document" from an unknown sender stands out immediately. It also trains clients to be suspicious of any message asking them to email their documents, which protects them from scams impersonating your firm. Read more in our guide to sending tax documents securely. Correctdocs gives each client one secure request link for uploads, so documents don't need to arrive as email attachments.
If you think you've been compromised
- Disconnect affected devices and contact your IT provider
- Change passwords from a clean device
- Follow your data breach response plan
- Contact your IRS Stakeholder Liaison so the IRS can help protect affected clients
- Report IRS-related phishing to phishing@irs.gov
Correctdocs is in early access. The first 10 US accounting, bookkeeping and tax firms get a free 30-day pilot on real client requests. Request early access.
Frequently asked questions
What is the "new client" phishing scam?
A criminal poses as a prospective tax client, then sends a malicious link or attachment disguised as tax documents to steal data or access the firm's systems.
Where do I report IRS phishing emails?
The IRS asks people to send suspected IRS-related phishing emails or messages to phishing@irs.gov.
Is multi-factor authentication required for tax preparers?
Yes. The FTC Safeguards Rule requires multi-factor authentication for anyone accessing customer information on a covered firm's systems.