Social engineering at a tax firm
How criminals trick tax firm staff into handing over client data, passwords or money: phishing, fake new clients, fake IRS contacts, W-2 requests and hijacked email.
Social engineering is the manipulation of people into breaking normal security practice or giving away confidential information. The IRS defines it that way in its guide for tax professionals, and it is the front door for most data thefts at firms. Software can block a lot, but it cannot stop a person from being persuaded to click, type or send.
The tactics tax firms see most
Phishing and spear phishing
A phishing email is made to look like it came from someone you know or a company you use. The IRS describes the usual shape: an urgent subject line ("Update Your Account Now"), and either a link to a fake page that asks for your username and password, or an attachment that installs malware such as a keystroke logger. Spear phishing is the same thing aimed at you personally, perhaps using an address found on your firm's website, and it works better because it is tailored.
Pretending to be someone you trust
According to the IRS, the thief may pose as your tax software provider, your data storage provider, the IRS, a prospective client, your bank, or a colleague whose email account has been taken over. Criminals who break into a firm's email may also send messages under the firm's name to trick colleagues and clients.
The "new client" email
A stranger emails asking for help with their taxes, and attaches their "tax documents" or sends a link to them. The IRS warns that opening the link or attachment can hand the scammer your email address and password, and can load malware that reaches your clients' data. It peaks during filing season, and the IRS's 2026 "Dirty Dozen" list still names "new client" and "document request" emails as a threat to tax professionals.
Fake IRS contacts
The IRS says it normally contacts people first by mail. It emails or texts only people who have opted in, and a direct message on social media is never from the IRS. A phone call, email or text message is not from the IRS if it is unexpected, rushes you, threatens you, asks for personal or financial information, or demands payment now. For tax professionals in particular, the IRS says it never starts contact by email about returns, refunds or requests for sensitive financial or password information.
Requests for W-2s and payroll data
The IRS describes a scheme it calls business email compromise: an email disguised to look like it comes from an executive is sent to someone in payroll or HR, asking for a list of all employees and their Forms W-2. The data is then used to file fraudulent returns. Firms that run payroll for clients hold exactly this kind of data.
Changed bank or refund details
A message asks you to change where a client's refund is deposited, or where the firm sends a payment. It may come from a real but hijacked account, so the address can look right. The IRS advises a final review of return information before e-filing, especially direct deposit details. Treat any change of bank details as something to confirm by phone first; see Verifying a request.
Fake "support" calls and pop-ups
A pop-up says your computer is infected and gives a number to call, or someone phones claiming to be from your software vendor and asks for remote access. The IRS tells tax professionals never to call a number from a pop-up claiming your computer has a virus, and never to pick "security software" from a pop-up advertisement. If a caller says they are support, hang up and call the vendor on a number you already have.
Red flags
- It is unexpected, even if it seems to come from someone you know.
- It is urgent, or leans on authority ("the partner needs this before noon").
- It asks for passwords, sign-in codes, Social Security numbers, W-2s or bank details.
- The sender's address is slightly off, or the reply-to address differs from the sender.
- It wants you to open an attachment or follow a link to see something.
- It asks to change where money goes.
- Clients mention emails from you that you never sent. The IRS lists this as a sign of data theft.
What to do
- Do not click, open or reply. The IRS advises never opening attachments from unknown senders, including potential clients, and making contact by phone first.
- Check it through a channel you already have, such as the number in the client's file. See Verifying a request.
- Report it. Forward IRS-related phishing emails to
phishing@irs.gov. For a W-2 scam email you did not fall for, the IRS asks for more: save the scam email as a file, then attach that file to a new email tophishing@irs.govwith the subject "W2 Scam", because a plain forward loses the email headers the IRS needs. Do not attach employee Social Security numbers or W-2s. Then file a complaint with the FBI's Internet Crime Complaint Center at ic3.gov. - Tell the person who runs security at your firm, so others can be warned.
- If you already clicked, opened, or typed a password, go straight to If something went wrong.
How Journey helps
- Signing in takes more than a password. Staff accounts have to set up an authenticator app, and signing in to Journey asks for a code from that app as well as the password.
- Clients send documents through the portal. When your clients upload files to their portal rather than emailing attachments, an emailed "here are my tax documents" attachment stands out as something to question. See Client portal.
Sources
- IRS Publication 4557, Safeguarding Taxpayer Data (Rev. 6-2024), sections "Recognize Phishing Scams", "Guard Against Phishing Emails", "Be Safe on the Internet" and the glossary: irs.gov/pub/irs-pdf/p4557.pdf
- IRS Publication 5293, Data Security Resource Guide for Tax Professionals: irs.gov/pub/irs-pdf/p5293.pdf
- IRS, "Tax professionals: Watch out for 'new client' email scam" (February 2024): irs.gov
- IRS, "Dirty Dozen tax scams for 2026" (March 2026): irs.gov
- IRS, "How to know it's the IRS": irs.gov/help/how-to-know-its-the-irs
- IRS, "Form W-2/SSN data theft: Information for businesses and payroll service providers": irs.gov