IRS Security Summit Warns Tax Pros About Phishing and Email Scams
The IRS Security Summit is urging tax professionals to stay vigilant against phishing emails and other schemes that can compromise client data and QuickBooks files.

Tax professionals who rely on QuickBooks to manage client books and payroll are being urged to sharpen their defenses against a rising tide of phishing emails and related cyberattacks. A recent alert from the IRS Security Summit underscores how attackers are increasingly targeting accounting practices — businesses that handle sensitive financial data and are therefore especially valuable to criminals.
Why Tax and Bookkeeping Practices Are in the Crosshairs
Accounting firms, bookkeeping services, and independent tax preparers sit on a concentrated pool of sensitive information: client Social Security numbers, employer identification numbers, bank account details, and full financial histories. For a criminal, compromising a single tax professional’s system can unlock data on dozens or hundreds of clients at once. That makes these practices disproportionately attractive targets compared with the clients themselves.
The QuickBooks company file itself is a trove of this information. A .qbw file typically contains customer and vendor details, payroll data, bank account and routing numbers, and enough identity information to fuel tax-fraud schemes. If an attacker gains access to the machine hosting that file — or to a cloud-based QuickBooks environment — the exposure can be immediate and severe.
How the Attacks Typically Work
The phishing campaigns described in the IRS alert generally follow familiar patterns, though they are growing more sophisticated. A common approach involves an email that appears to come from the IRS itself, from a state tax agency, or from a recognized software provider. These messages often claim that there is a problem with a recent filing, a refund issue, or an account that needs immediate verification.
Some variants impersonate clients, sending what looks like an ordinary email with an attachment — an invoice, a W-2, or a document that purports to be related to an ongoing engagement. When the recipient opens the attachment or clicks a link, malware is deployed. In more targeted attacks, criminals use spear-phishing tailored to a specific firm, referencing real client names or ongoing matters to lower the recipient’s guard.
The objective is usually one of the following: install keylogging software to capture passwords, deploy ransomware to lock the firm out of its own systems, or steal credentials that allow the attacker to file fraudulent tax returns using stolen client identities.
Practical Steps to Reduce Risk
The Security Summit guidance, consistent with longstanding IRS recommendations, points tax professionals toward several concrete measures. Multi-factor authentication should be enabled on every account that supports it — email, QuickBooks, payroll services, tax-preparation software, and any portal used to exchange documents with clients. A password alone is no longer adequate protection for systems holding this level of sensitive data.
Email attachments and links deserve scrutiny even when they appear to come from known senders. A quick phone call or text to a client to confirm they actually sent a document costs seconds and can prevent a catastrophic breach. The IRS itself notes that it does not initiate contact with taxpayers or tax professionals by email to request personal or financial information, so any message claiming to do so should be treated with suspicion.
Firms should also ensure that their QuickBooks company files and all related backups are protected. If ransomware does get through, having a clean, offline backup is the difference between a temporary disruption and a total loss of client records. For practices that have already experienced a corrupted or locked company file, professional QuickBooks data recovery services can sometimes recover data from damaged or encrypted files, though prevention remains far less costly.
What to Do If a Compromise Occurs
If a firm suspects that its systems have been breached, speed matters. The IRS recommends reporting the incident promptly — there are established channels for tax professionals to notify the agency of data losses, which can help protect affected clients from fraudulent filings filed in their names. State tax authorities may have their own notification requirements.
Internally, the affected machines should be taken offline immediately, credentials should be changed from a known-clean device, and a qualified IT professional should assess the scope of the intrusion. The QuickBooks company file should be examined for integrity — a breach that involved malware does not always damage the file itself, but ransomware certainly can, and the file should be verified before being trusted for ongoing use.
The broader takeaway for the QuickBooks community is straightforward: the software that makes a practice efficient also concentrates risk. The same company file that lets a bookkeeper serve dozens of clients seamlessly can, in the wrong hands, expose all of them at once. Treating email as the primary threat vector — and building habits around verification rather than trust — is the most practical defense available.