TIGTA Exposes Serious IRS Security Failures

ABUSE OF THE WEEK

ABUSE OF THE WEEK

ABUSE OF THE WEEK ABUSE OF THE WEEK

Taxpayers are expected to comply with the tax code day after day—keeping accurate records and following the rules. They shouldn't have to worry that IRS contractors are failing to do the same by exposing their personal information through preventable security failures. Americans deserve an agency that treats taxpayer data with the same seriousness it demands from everyone else, and TIGTA’s management alert is yet another reminder that IRS accountability is long overdue.

The IRS's Zero Paper Initiative (ZIP) is already raising red flags. A rare management alert from the Treasury Inspector General found serious security weaknesses at private contractor facilities handling taxpayer information. Because these alerts are reserved for urgent problems, the Treasury Inspector General for Tax Administration (TIGTA) warned the risks were too significant to wait for a full audit.

As the IRS begins to modernize through ZIP, TIGTA identified severe systemic security failures, including inadequate safeguards for taxpayer data, unauthorized employee access to taxpayer information, and the use of unauthorized software. Additionally, nearly half of all cybersecurity vulnerabilities were not addressed in a timely manner, prolonging exposure to preventable security risks. These deficiencies increased the risk of taxpayer data being compromised and revealed serious failures in the IRS’s oversight of its contractors.

The Alliance for IRS Accountability is deeply concerned by these failures, deficiencies so urgent that they warranted a management alert. These findings expose fundamental weaknesses in IRS capabilities and raise serious questions about the agency’s ability to safeguard sensitive financial information entrusted to it.

Taxpayers should never have to wonder whether the IRS is adequately protecting their sensitive financial information with the same diligence it demands of Americans when complying with the tax code. Yet, this alert demonstrates that the Agency has failed to oversee and enforce basic security protocols.

AIA calls on the IRS to immediately strengthen oversight of all contractor facilities and implement rigorous security protocols to ensure taxpayer data is protected at every stage of ZIP. Americans deserve confidence that the IRS treats their financial information as a priority rather than an afterthought.

Read the full report here.

If you, or someone you know, have experienced a specific IRS abuse and wish to flag the instance for potential inclusion in our Abuse of the Week series, call our dedicated Abuse Hotline, located in the Resources section of our homepage, or contact us with the details at info@irsaccountability.org