Skip to main content

IRS reminder: Cybersecurity Awareness Month offers simple steps to protect tax data

October 02, 2026

from the IRS

WASHINGTON — The Internal Revenue Service today encouraged taxpayers to take simple steps to strengthen online security during Cybersecurity Awareness Month.

Cybersecurity Awareness Month highlights the role everyone can play in protecting personal, financial and tax information from identity thieves and scammers. For taxpayers, tax professionals and organizations across the tax community, that starts with everyday actions that help strengthen online security.

“Criminals continue to look for new ways to steal taxpayer information and exploit trusted partnerships,” said IRS Chief Executive Officer Frank J. Bisignano. “Taxpayers and tax professionals can help protect sensitive information and strengthen the security of the tax system by making cybersecurity practices part of their routine year-round.”

The IRS joins the Cybersecurity and Infrastructure Security Agency and Security Summit partners in encouraging taxpayers to make cybersecurity part of their daily routine. The Cybersecurity and Infrastructure Security Agency (CISA) offers cybersecurity resources that individuals, families, businesses and organizations can use to strengthen their online security.

Take simple steps to strengthen cybersecurity

The IRS encourages taxpayers and tax professionals, businesses and other organizations to take these steps:

  • Use strong, unique passwords. Use different passwords for important accounts and consider using a password manager.
  • Turn on multifactor authentication if available, to add an extra layer of protection to online accounts.
  • Update software and devices. Install updates on computers, phones, tablets, apps, browsers and security software. Turn on automatic updates when possible.
  • Recognize and report scams. Be cautious of unexpected emails, text messages, social media messages, phone calls or letters that request personal or financial information or pressure taxpayers to act immediately.
  • Protect tax records. Store digital tax records securely, encrypt sensitive files and back up important information.
  • Use secure networks. Avoid using public Wi-Fi to access financial accounts, tax records or IRS online services.

Watch for tax scams

Scammers continue to use U.S. mail, emails, text messages, social media and phone calls to impersonate the IRS and other trusted organizations. These scams may promise a larger refund, claim a taxpayer’s account is locked, demand immediate payment or direct taxpayers to fake websites.

Businesses, payroll professionals and human resources offices should remain alert for phishing, fake invoices, W-2 and payroll-related schemes designed to steal employee information, credentials or money. Requests to change sensitive employee or payment information should be verified through a trusted channel.

Tax professionals, including enrolled agents, payroll professionals, certified public accountants (CPA), attorneys, or other tax return preparers, should watch for phishing emails and other schemes designed to steal sensitive taxpayer data. Scammers may pose as a prospective client or use a compromised email account to persuade tax professionals to open malicious links or attachments.

IRS tools can help

The IRS offers secure online tools and resources that can help protect accounts and tax information:

  • Get an Identity Protection PIN. An Identity Protection PIN is a six-digit number that helps prevent someone else from filing a federal tax return using a taxpayer’s Social Security number or individual taxpayer identification number.
  • Online Account for Individuals. Taxpayers can securely access personal tax information, view notices, make payments and manage other tax tasks.
  • Business Tax Account. Businesses can securely access available tax information and manage certain tax responsibilities online.
  • Tax Pro Account. Tax professionals can securely manage active client authorizations and submit authorization requests online.
  • Written Information Security Plan. Federal law requires tax and accounting professionals to create and maintain a WISP to protect client information.

How to know it’s the IRS

The IRS normally contacts taxpayers the first time by mail. The IRS sends emails or text messages only when taxpayers opt in and never sends direct messages through social media. The IRS or private collection agencies may call about account matters, but the IRS will never call to demand immediate payment, threaten arrest or tell taxpayers they are due a refund.

Taxpayers should not click links, open attachments or respond to unexpected messages claiming to be from the IRS.

Report scams and suspicious contacts

Taxpayers who receive suspicious tax-related U.S. mail, emails, text messages, or social media messages should visit IRS.gov/SubmitATip to find the appropriate way to report the issue. Taxpayers can also report suspected tax fraud, scams, identity theft, or other tax-related wrongdoing.

Tax professionals who experience a data breach should report it as soon as possible to their stakeholder liaison.

More information

For more information, taxpayers can visit Identity Theft Central, Tax Scams, and CISA's Cybersecurity Awareness Month resources.