Skip to content
Back to Kworia

IRS Cybersecurity Awareness Month 2026: Year-Round Habits to Combat Tax Fraud

The IRS's annual Cybersecurity Awareness Month campaign in October 2026 emphasizes year-round cybersecurity practices for the entire tax ecosystem, including scam recognition, reporting mechanisms, and identity-protection tools. While not a regulatory update, the guidance references the newly effective FTC Safeguards Rule MFA requirement for tax professionals.

Kworia 3 min read AI-generated content — How this site is made

Key takeaways

  • The IRS's Cybersecurity Awareness Month campaign emphasizes year-round cybersecurity practices for the entire tax ecosystem.
  • Scammers impersonate the IRS through various channels, and taxpayers should report suspicious activities at IRS.gov/SubmitATip.
  • The FTC Safeguards Rule MFA requirement, effective from September 19, 2026, mandates multifactor authentication for tax professionals.
  • Tax and accounting professionals must maintain a Written Information Security Plan (WISP) to protect client information.
  • Baseline hygiene practices include strong unique passwords, MFA, software updates, secure tax record storage, and avoiding public Wi-Fi for financial accounts.

Context

Cybersecurity Awareness Month 2026 is part of the IRS's ongoing effort to educate taxpayers and professionals about emerging cyber threats. The campaign targets a broad audience: individual taxpayers, payroll professionals, HR offices, enrolled agents, CPAs, and attorneys. IRS CEO Frank J. Bisignano framed cybersecurity as a routine discipline, stating that "Criminals continue to look for new ways to steal taxpayer information and exploit trusted partnerships." The guidance is timely, as the FTC Safeguards Rule's multifactor authentication (MFA) requirement came into effect on September 19, 2026, binding tax and accounting professionals to adopt stricter security measures.

The IRS's emphasis on year-round cybersecurity practices reflects the evolving landscape of tax-related fraud. Scammers increasingly target taxpayers and professionals through various channels, making it critical to adopt robust security measures beyond the month of October.

Scam Recognition and Reporting

Scammers impersonate the IRS through mail, email, text, social media, and phone calls. Common tactics include promising larger refunds, claiming locked accounts, demanding immediate payment, or directing victims to fake websites. The IRS's official contact protocol is first-contact by mail only; it never uses social media direct messages and will not call to demand immediate payment, threaten arrest, or claim a refund is owed.

Taxpayers and professionals should report suspicious tax-related communications through the IRS's dedicated reporting channel at IRS.gov/SubmitATip. This platform ensures that suspicious activities are flagged and investigated, helping to mitigate potential fraud.

The IRS offers several identity-protection tools to enhance security:

  • Identity Protection PIN (IP PIN): A six-digit code that provides an additional layer of protection for taxpayers' accounts.
  • Online Account for Individuals: A secure portal allowing individuals to manage their tax information and communications with the IRS.
  • Business Tax Account: A dedicated platform for businesses to handle their tax obligations and communications with the IRS.
  • Tax Pro Account: A secure account for tax professionals to manage client information and interactions with the IRS.

Professional Obligations and Baseline Hygiene

Federal law requires tax and accounting professionals to maintain a Written Information Security Plan (WISP) to protect client information. This obligation underscores the importance of robust security measures in handling sensitive taxpayer data.

The IRS recommends several baseline hygiene practices to enhance cybersecurity:

  • Strong Unique Passwords: Ensuring that passwords are complex and unique for each account.
  • Multifactor Authentication (MFA): Implementing MFA to add an extra layer of security beyond passwords.
  • Software Updates: Regularly updating software to protect against known vulnerabilities.
  • Secure Tax Record Storage: Ensuring that tax records are stored securely to prevent unauthorized access.
  • Avoidance of Public Wi-Fi for Financial Accounts: Refraining from using public Wi-Fi networks to access financial accounts, as these can be less secure.

Implications for Tax and Accounting Professionals

The IRS's guidance is particularly relevant to tax and accounting professionals, who handle sensitive taxpayer data daily. The FTC Safeguards Rule MFA requirement, effective from September 19, 2026, mandates that professionals adopt multifactor authentication to protect client information. This requirement aligns with the IRS's broader emphasis on robust security measures.

Professionals must also ensure compliance with federal law by maintaining a WISP. This plan should outline the steps taken to protect client information and mitigate potential security risks. Adhering to these guidelines is crucial for maintaining client trust and ensuring the integrity of tax-related data.

Outlook and What to Watch

Looking ahead, the IRS's emphasis on year-round cybersecurity practices is likely to become a permanent fixture in tax and accounting professions. The evolving nature of cyber threats necessitates continuous vigilance and adaptation.

Key milestones to watch include:

  • Enforcement of MFA Requirements: Monitoring how the FTC Safeguards Rule MFA requirement is enforced and its impact on tax professionals.
  • Emerging Scam Tactics: Staying informed about new scam tactics and adapting security measures accordingly.
  • IRS Guidance Updates: Keeping abreast of any updates or additional guidance issued by the IRS regarding cybersecurity best practices.

Frequently asked questions

What are the common tactics used by scammers impersonating the IRS?
Scammers use various tactics, including promising larger refunds, claiming locked accounts, demanding immediate payment, or directing victims to fake websites. The IRS never uses social media direct messages and will not call to demand immediate payment, threaten arrest, or claim a refund is owed.
How can taxpayers report suspicious tax-related communications?
Taxpayers should report suspicious tax-related communications through the IRS's dedicated reporting channel at IRS.gov/SubmitATip.
What identity-protection tools does the IRS offer?
The IRS offers several identity-protection tools, including an Identity Protection PIN (IP PIN), Online Account for Individuals, Business Tax Account, and Tax Pro Account.
What are the professional obligations of tax and accounting professionals regarding cybersecurity?
Federal law requires tax and accounting professionals to maintain a Written Information Security Plan (WISP) to protect client information. Additionally, the FTC Safeguards Rule MFA requirement mandates multifactor authentication for tax professionals.
What baseline hygiene practices does the IRS recommend?
The IRS recommends strong unique passwords, multifactor authentication (MFA), software updates, secure tax record storage, and avoiding public Wi-Fi for financial accounts.
Share: X LinkedIn Email

Related articles

The IRS has published Notice 2026-53, the first substantive guidance on Section 45Z following amendments under the Working Families Tax Cuts (WFTC) law, affecting biofuel producers and agricultural stakeholders. The notice updates emissions rate tables, excludes indirect land use change (ILUC) emissions from calculations, and restricts eligible feedstocks to those produced in the U.S., Mexico, or Canada.

IRS Issues Updated Guidance on Section 45Z Clean Fuels Production Tax Credit

The IRS has published Notice 2026-53 with updated guidance on Section 45Z Clean Fuels Production Tax Credit, excluding ILUC emissions from calculations and restricting eligible feedstocks to those produced in the U.S., Mexico, or Canada. The notice provides compliance flexibility for biofuel producers while final regulations remain under development.

4 min read