
Scott E. Vincent is the founding member of Vincent Law, LLC in Kansas City.
Labeled “Protect your clients, protect yourself,” this year’s annual campaign included forums and several news releases by the IRS.1
The news releases focus on the concern that tax and legal professionals are prime targets of criminal syndicates that either trick or hack their way into professionals’ computer systems to access client data. Even when client data is stored in a secure platform, such as the cloud, lack of strong authentication can make information vulnerable. For example, in the tax system context, identity thieves use stolen data with real financial information to file fraudulent tax returns that are then difficult for the IRS and the states to detect.
The IRS emphasizes tax and legal professionals need to focus on data security fundamentals and watch for emerging vulnerabilities, as well as new updates involving multi-factor authentication and the latest requirements for a Written Information Security Plan. The campaign highlights a series of actions that tax and legal professionals can take to better protect their clients and themselves from data theft.
Create a security plan
The Written Information Security Plan, or WISP, is an “easy-to-understand document developed by and for tax and industry professionals to keep customer and business information safe and secure.”2 IRS Publication 5708 provides guidance and sample language for creating a WISP. The IRS also notes that the Federal Trade Commission requires a WISP to keep customer data safe. See IR-2024-208 for more details.
Understand the different phishing scams
Tax and legal professionals are “common, everyday target[s] of phishing scams designed to trick the recipient into disclosing personal information such as passwords, bank account numbers, credit card numbers, or Social Security numbers.”3
Phishing/Smishing
“Phishing emails or SMS/texts (known as ‘smishing’) attempt to trick the recipient into clicking a suspicious link, filling out information, or downloading a malware file. Often phishing attempts are sent to multiple email addresses at a business or agency increasing the chance someone will fall for the trick.”4
Spear phishing
In some phishing scams, potential scammers identify potential victims and deliver more realistic emails, commonly referred to as a “lure.” “These types of scams can be trickier to identify since they don’t occur in large numbers. They single out individuals, can be specialized, and make the email seem more legitimate.”5
For example, “fraudsters pretend to be real taxpayers [or clients] seeking tax [or legal] help. They use emails to try to get sensitive information or gain access to a practitioner’s client data. In these fake ‘new client’ schemes, the fraudster can send a malicious attachment or include a link to a site that the tax [or legal] professional thinks they need to access to obtain the supposed new client’s [… sensitive] information. But in reality, the site is collecting information from the [… professional], such as their email and password, or loading [malicious software] onto the [… professional’s] computer to gain access to their computer or system.”6
Clone phishing
A newer type of phishing scam “clones a real email message and resends it to the original recipient pretending to be the original sender. The new message will have either an attachment that contains malware or [a] link that tries to steal information from the tax [or legal] professional or recipient.”7
Whaling
“Whaling attacks are very similar to spear phishing, except these attacks are generally targeted to leaders or other executives with access to secure large amounts of information at an organization or business. Whaling attacks can also target people in payroll offices, human resource personnel, and financial offices.”8
Know the tell-tale signs of identity theft
Many “professionals who report data theft to the IRS also say they were unaware of signs that a theft had already occurred.”9 Signs tax and legal professionals should watch for include “multiple clients suddenly receiving suspicious IRS letters requesting confirmation that they filed a tax return; tax professionals seeing e-file acknowledgements for far more tax returns than they filed; and tax pros’ computer cursors moving seemingly on their own.”10 See IR-2024-193 for more details.
Utilize multi-factor authentication
Lawyers and tax professionals should use multi-factor authentication, or MFA, to even better protect their clients’ information. The FTC even requires all tax professionals use MFA to protect clients’ sensitive information. “The June 2023 change mandates MFA to strengthen account security by requiring more than just a username and password to confirm an identity when accessing any system, application, or device.”11
“The extra layers of different authentication factors include something only a user knows, like a username and password; something they have, like a token or random number sequence sent to their cell phone; or something unique, like biometric information. These provide extra assurance that a […] client, not an impostor, is gaining access.”12
Understand the “Security Six” protections
Here are six important security basics that form a critical defense against identity thieves and hackers:
1. “Anti-virus software scans computer files or memory for certain patterns that may indicate there’s […] malware – on the device. Anti-virus vendors find new issues and update malware daily. This is why it’s important for users to install the latest updates of the software.”13
2. “Firewalls provide protection against outside attackers. The firewall shields computers and networks from malicious or unnecessary web traffic. This helps prevents malicious software from accessing the user’s system.”14
3. “Multi-factor authentication adds an extra layer of protection beyond a password. The returning user enters credentials like a username and password. Then, there’s another step, such as entering a security code, token or a biometric like a fingerprint.”15
4. “Backup software or services should be routinely used by tax [and legal professionals] to back up critical files on their computers and hard drives to external sources. This is helpful not just to protect against a cyber-attack but is also helpful in case of device failure or a natural disaster.”16
5. Drive encryption software, also known as disk encryption, “transforms data on the computer into protected files that are unreadable to outsiders. This means only people who are authorized to access the data can do so.”17
6. Virtual Private Network, or VPN, is important since many firms’ employees occasionally connect to unknown networks or work from home. “This allows for a more secure connection. A VPN provides a secure, encrypted tunnel to transmit data between a remote user over the internet and the company network.”18
Conclusion
The “Protect your clients, protect yourself ” campaign highlights several important concerns for professionals relating to client and firm data security. Importantly, the current series also identifies some key federal requirements, including multi-factor authentication and
implementation of a WISP, that may apply to your legal practice.
Endnotes
1 Protect Your Clients; Protect Yourself — Summer 2024, INTERNAL REVENUE SERVICE (Aug. 27, 2024), https://www.irs.gov/tax-professionals/protect-your-clients-protect-yourself-summer-2024.
2 IR-2024-180.
3 Id.
4 IR-2024-188.
5 Id.
6 IR-2024-183.
7 Id.
8 Id.
9 IR-2024-180.
10 Id.
11 IR-2024-201.
12 Id.
13 IR-2024-218.
14 Id.
15 Id.
16 Id.
17 Id.
18 Id.