Skip to main content

IRS Contractor Data Security Failures: What the 2026 TIGTA Report Found — and How to Protect Your Tax Data

8 min readMike ThriftMike Thrift
IRS Contractor Data Security Failures: What the 2026 TIGTA Report Found — and How to Protect Your Tax Data

Fourteen employees walked into restricted rooms full of taxpayer tax returns 1,375 times over eight months, without the access they were supposed to have. At the same facilities, computer systems flagged as "critical" security risks sat unpatched for an average of 223 days — nearly eight times longer than the 30-day fix window the IRS itself requires. If you filed a paper tax return in the past year, there's a real chance your Social Security number, income details, and bank account information passed through one of these buildings.

This isn't a hypothetical. It's the finding of a federal watchdog report released in mid-2026, and it's worth understanding — both because of what it reveals about how your tax data is actually handled, and because of what it should prompt you to do next.

What the Watchdog Actually Found

The Treasury Inspector General for Tax Administration (TIGTA) — the independent office that audits the IRS — inspected two facilities run by private contractors under the IRS's "Zero Paper Initiative." That initiative exists for a reasonable reason: the IRS still receives millions of paper tax returns every year, and instead of manually keying in the data, it now ships stacks of paper returns to outside contractors who scan the documents and extract the data electronically. It's a sensible modernization effort. The problem TIGTA found is in how it's being run.

At the two sites TIGTA visited during 2025, the findings broke down into three categories.

Unauthorized physical access. Fourteen contractor employees who did not have proper clearance entered restricted areas containing sensitive taxpayer documents. Combined, they made 1,375 unauthorized entries between May and December 2025. TIGTA found no direct evidence that anyone improperly accessed or copied a document — but the sheer volume of entries shows the access controls meant to prevent exactly that kind of exposure simply weren't working. One site's loading dock, which connects directly to the taxpayer document storage area, was found unsecured and unguarded. The facility's perimeter fence also lacked adequate security controls.

Unresolved computer vulnerabilities. This is the part that should concern anyone who thinks about data security. At one site, auditors identified 269 security vulnerabilities in the systems that process taxpayer information. Of those, 128 — 48% — had not been fixed within the deadlines set by IRS policy. Twenty of those unresolved vulnerabilities were rated "critical," the highest severity tier, and they'd been sitting open for an average of 223 days against a 30-day remediation requirement. Another 84 "high" severity vulnerabilities averaged 231 days unresolved, against a 60-day requirement. TIGTA specifically flagged one critical flaw tied to unsupported software still in use, and another involving a database configuration that could let an attacker bypass authentication entirely.

Weak oversight of contractor tools. At the second site, the contractor was using vulnerability-scanning software that had never been validated against the government's required security standard. TIGTA's report noted that IRS cybersecurity staff knew the contractor was using unauthorized scanning tools and didn't act on it. At the first site, IRS policy calls for monthly security scans of every device handling taxpayer data — but in August 2025, the contractor scanned just one out of 203 devices.

Why This Matters Even If Nothing Was "Stolen"

TIGTA was careful to say it found no confirmed evidence that a bad actor accessed taxpayer data through these gaps. That's a genuinely important distinction, and it's not spin — an unlocked door is not the same as a burglary.

But it's also not the reassurance it might sound like. Security failures like these matter regardless of whether they were exploited, for three reasons:

  1. A tax return is one of the most complete identity-theft toolkits that exists. It contains a Social Security number, full name and address, employer information, bank account and routing numbers for direct deposit, investment account details, and often information about spouses and dependents. A single exposed return can fuel identity theft, fraudulent refund filing, and account-takeover attempts for years.
  2. Unpatched critical vulnerabilities are a standing risk, not a one-time event. A flaw that lets someone bypass authentication doesn't need to be "used" the day it's discovered to be dangerous — it sits there as a door that stays unlocked until someone closes it. 223 days is more than seven months of exposure window.
  3. This follows a pattern of documented IRS data-security concerns. TIGTA's report lands against a backdrop of prior high-profile incidents involving IRS taxpayer data (including the 2023 case in which a contractor employee leaked tax records of thousands of high-income filers to news organizations). Watchdog findings like this one are part of why that history keeps getting cited — the underlying institutional controls are still catching up.

What the IRS Says It's Doing About It

To its credit, the IRS agreed with TIGTA's findings and committed to specific fixes rather than disputing the report. Its stated remediation steps include:

  • Updating its internal security guidance (Publication 4812) to require monthly reviews of physical access logs at contractor sites, instead of the current annual review cycle.
  • Building a monthly process to flag aging, unresolved vulnerabilities so procurement officials and contractor management can act on them faster.
  • Strengthening how it vets and monitors contractor cybersecurity practices going forward.

Those are reasonable commitments, and it's worth acknowledging when an agency responds to a watchdog report constructively. But "committed to fixing" and "fixed" are different states, and TIGTA's own numbers show how much can slip between an annual review cycle and a real problem sitting unaddressed for months.

What You Can Actually Do About It

You can't control how a third-party contractor secures its facility. But you're not powerless here — there are concrete steps that reduce your exposure regardless of what caused it.

Get an IRS Identity Protection PIN (IP PIN). This is the single most effective free tool available to individual taxpayers. It's a six-digit code that changes annually and must be included on any tax return filed under your Social Security number — without it, the IRS will reject an e-filed return and flag a paper one for extra scrutiny. That means even if someone has your SSN, they can't successfully file a fraudulent return in your name. You can enroll through your IRS online account, and once enrolled, the IRS automatically issues you a new PIN each filing season. If your information has been involved in any breach — this one or otherwise — this is worth doing today, not next tax season.

File early next year. Fraudulent-refund schemes rely on beating the real taxpayer to the punch. The earlier you file, the smaller the window a criminal has to file first using stolen information.

Watch your IRS transcript and account, not just your bank statements. Most people monitor their bank and credit card accounts for fraud but never check their IRS online account. Tax-related identity theft often shows up first as a rejected e-file (because someone already filed under your SSN) or an unexpected notice about a return you didn't file. Checking periodically catches problems before they compound.

Consider whether you need to file on paper at all. If you're currently filing paper returns by choice or habit, this is a reasonable moment to reconsider. E-filed returns go through IRS-controlled electronic pipelines rather than being physically shipped to a third-party scanning facility. For most individual filers, e-file is faster, has a lower error rate, and — per this report — currently has a narrower attack surface than the paper pathway.

If you use a preparer or accountant, ask how they transmit your data. The same principle that applies to the IRS's contractors applies to any third party that handles your financial records: physical security and patch cadence aren't abstract IT concerns, they're the actual mechanism protecting your Social Security number.

The Bigger Lesson: Data Custody Chains Are Longer Than You Think

The uncomfortable takeaway from this report isn't really about the IRS specifically — it's a reminder of how many hands your financial data passes through before it's "processed." A paper tax return doesn't go straight from your mailbox to a government database. It goes to a private contractor's warehouse, gets handled by staff whose access needs auditing, sits on systems that need patching on a schedule, and only then reaches the agency you actually filed with. Every link in that chain is a place where controls can lapse.

That's true for individuals filing 1040s, and it's just as true for small businesses and freelancers managing their own books. The fewer intermediaries that touch your raw financial data, and the more visibility you have into exactly where your records live and how they move, the smaller your exposure. This is part of the case for tools that keep your financial records in a format you control directly, rather than trusting them entirely to opaque third-party systems and hoping the audit findings stay clean.

Keep Your Financial Records Under Your Own Control

Watchdog reports like this one are a useful reminder that financial data security isn't only about strong passwords — it's about how many hands your records pass through and how much visibility you have into each one. Beancount.io offers plain-text accounting that keeps your financial data transparent and version-controlled on your own terms, with no black-box vendor storage in between. Get started for free and see why developers and finance-conscious individuals are moving toward accounting systems they can actually audit themselves.

Share this article