If something went wrong: the first hour
A first-hour checklist for a tax firm that clicked a phishing link, lost a device or suspects data theft: contain it, secure accounts, keep evidence, and report it quickly.
Speed matters more than a perfect response. The IRS says that if a data theft is reported quickly, it can take steps to block fraudulent returns from being filed with your clients' information. Work through the list below, and write down what you do and when as you go.
This page is general information, not legal advice. Your legal duties after a breach depend on your state, the states your clients live in, and the size and nature of your practice. Talk to an attorney, and to your insurer, early.
Signs you may have a problem
The IRS lists these as common clues that a firm's data has been stolen:
- Clients' e-filed returns reject because a return with their Social Security number was already filed.
- Clients who have not filed receive IRS authentication letters, refunds, or transcripts they did not request.
- More returns are filed under your EFIN or PTIN than you actually filed.
- Clients or colleagues reply to emails you never sent.
- Computers run slowly, turn themselves on, lock you out, or the cursor moves by itself.
The first-hour checklist
1. Contain it
- If a computer connected to the internet is compromised, disconnect it from the internet. The FTC guidance reproduced in the IRS's guide for tax professionals gives this as the first step.
- Do not wipe or rebuild the machine yet. You will want to know how the attacker got in.
2. Secure your accounts
- From a device you trust, change the password on any account that may be exposed, starting with email, since email is used to reset everything else. Then your tax software, cloud storage, bank and Journey.
- Check that multi-factor authentication is still on for each account, and that no unfamiliar forwarding rules or recovery details were added to your email.
- If a staff member's account is involved, or someone has just left the firm, remove their access. The IRS guide advises deactivating a departing employee's usernames and passwords immediately.
3. Preserve evidence
- Keep the files, emails and logs that may show how the breach happened. The same FTC guidance says to preserve and review them.
- Note the time you discovered the problem. Some deadlines run from discovery.
- If you can, bring in a security professional to find the cause and scope and to stop it. The IRS recommends this, and your insurer may provide one.
4. Report it to the IRS
- Contact your local IRS Stakeholder Liaison. The IRS says the liaison notifies IRS Criminal Investigation and others within the agency on your behalf. The IRS notes that its general phone assistors cannot accept third-party reports of identity theft, so go through the liaison. Find yours from the IRS's data theft page for tax professionals.
5. Report it to law enforcement
- The FBI (your local office) and the Secret Service (your local office), if directed.
- Your local police, to file a report.
- For a ransomware attack, the IRS says to contact the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) as well as the IRS.
6. Report it to the states
- Contact the states where you prepare returns. The Federation of Tax Administrators
collects state contact information on its "Report a Data Breach" page, and the IRS
also points to
StateAlert@taxadmin.org. - The IRS notes that most states require the attorney general to be notified of a data breach. Check each state where you prepare returns.
7. Call your insurer
Report the breach and check whether your policy covers the cost of responding.
In the days after
- Tell the FTC if you are required to. Under the FTC Safeguards Rule, a covered business must notify the FTC as soon as possible, and no later than 30 days after discovery, of an event in which unencrypted information of at least 500 consumers was acquired without authorization. The FTC takes these reports through an online form.
- Notify clients as the law requires. Breach notification rules differ from state to state; the IRS tells firms to check whether notification is required under applicable state law. The IRS also suggests individual letters to affected clients, timed in coordination with law enforcement, and notifying the credit bureaus. The FTC publishes a data breach response guide with template letters.
- If employee W-2 data was stolen, the IRS asks businesses to email
dataloss@irs.govwith "W2 Data Loss" in the subject line, giving the business name, EIN, a contact name and phone number, a summary of how the loss occurred and the number of employees affected, and not attaching any employee's personal information. - Fix the cause before you resume. The IRS says to find how the intrusion happened and make the fixes before resuming tax preparation, and to keep your Stakeholder Liaison updated.
Your WISP is your plan for this moment
Tax and accounting firms are required by the FTC Safeguards Rule to keep a Written Information Security Plan (WISP), whatever their size, according to IRS Publication 5708. The IRS's sample plan in that publication includes an attachment for security breach procedures and notifications. If your WISP does not yet say who does what in the list above, add it now, while nothing is on fire.
How Journey helps
- The audit log shows who changed what. Owners and General Managers can open Settings, then Audit log, to review changes to clients, returns and requests, invoices, staff and tasks, with who made each change and when. That helps you work out whether an exposed account was used to change anything in Journey.
- Journey drafts your WISP. In Settings, under the firm's Security section, owners and General Managers can open the Written Information Security Plan. Journey fills in what it knows from your firm's settings, includes a breach procedures section, and lists what your firm still has to write itself.
- Signing in takes more than a password. Signing in to Journey asks staff for a code from their authenticator app as well as the password.
Sources
- IRS, "Data theft information for tax professionals": irs.gov
- IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024), sections "Spot Data Theft", "Report Data Loss to IRS/States", "Respond and Recover from a Data Loss" and "Detecting and Managing System Failures": irs.gov/pub/irs-pdf/p4557.pdf
- IRS Publication 5293, Data Security Resource Guide for Tax Professionals: irs.gov/pub/irs-pdf/p5293.pdf
- IRS Publication 5708, Creating a Written Information Security Plan for your Tax & Accounting Practice (Rev. 8-2024): irs.gov/pub/irs-pdf/p5708.pdf
- IRS, "Form W-2/SSN data theft: Information for businesses and payroll service providers": irs.gov
- FTC, "FTC Safeguards Rule: What your business needs to know": ftc.gov