Guide

What to do if your tax office has a data breach

Maybe it's ransomware on the office server. Maybe a staffer's email was phished, or returns are being filed in your clients' names. Whatever form it takes, the first 48 hours shape everything that follows. Here's the sequence, in plain English.

First: stop the bleeding, don't destroy the evidence

  • Disconnect affected machines from the network (pull the network cable or Wi-Fi), but don't wipe or reinstall anything yet. You may need those systems intact for investigators and insurers.
  • Change passwords from a known-clean device, starting with email, tax software, and anything with remote access. Turn on multi-factor authentication anywhere it's missing.
  • Start a written timeline now. What you noticed, when, and what you did. Every later conversation (IRS, insurer, attorney, clients) goes better with a contemporaneous record.

Call the IRS quickly: they can actually help

The IRS asks tax professionals who experience data theft to contact their IRS Stakeholder Liaison promptly, ideally within days, not weeks. This isn't just a reporting formality: the IRS can flag affected client accounts to watch for fraudulent returns, which directly limits the damage to your clients. Also notify your state tax agency; states process fraudulent refunds too.

Then work the rest of the list

  1. Your cyber insurance carrier (if you have coverage). Early notice is often a policy condition, and many policies bring their own forensics and legal help.
  2. An attorney familiar with breach response. State breach-notification laws (potentially in every state where you have clients) dictate who must be told and how fast.
  3. The FTC, if the incident is large enough. Under the Safeguards Rule, security events involving the unencrypted information of 500 or more consumers must be reported to the FTC within 30 days of discovery.
  4. Law enforcement: local police for a report, and the FBI's IC3 for cybercrime.
  5. Your clients. Honest, prompt notification hurts less than clients discovering it via a rejected e-file. Point them to an IRS Identity Protection PIN (IP PIN), one of the strongest protections an individual taxpayer can add.

Afterward: turn the incident into a program

Once the dust settles, the question every reviewer, insurer, and client will ask is: what's different now? A real written information security plan, with the safeguards actually implemented, is both the answer to that question and the thing that makes a repeat far less likely. IRS Publication 4557 is the reference point; our free checklist is a faster first look.

This guide is a general educational overview, not legal advice, and notification obligations vary by state and situation. In an actual incident, engage qualified legal counsel early, and get current contact procedures directly from irs.gov.

Rather never need this page?

Prevention is cheaper than response, every single time. We help firms put the plan and the protections in place before anything goes wrong.

Get WISP-ready