KMK Ventures

IRS Dirty Dozen Tax Scams 2026: A CPA Firm’s Guide to Staying Protected

IRS Dirty Dozen tax scams

Latest Update: July 2026

The IRS has released its 2026 Dirty Dozen list, highlighting the most common scams targeting taxpayers and tax professionals. As fraud tactics continue to evolve, CPA firms should strengthen internal controls, educate employees, and help clients recognize warning signs before financial or reputational damage occurs.

Answer Snippet

The IRS Dirty Dozen tax scams identify the most significant fraud threats affecting taxpayers, businesses, and tax professionals each year. Understanding these scams helps CPA firms strengthen security, educate clients, and reduce the risk of financial loss, identity theft, and fraudulent tax filings.

Key Facts at a Glance

  • The IRS updates the Dirty Dozen campaign annually.
  • CPA firms remain prime targets because they manage sensitive taxpayer information.
  • Many scams rely on impersonation, identity theft, and social engineering.
  • Employee awareness is one of the strongest fraud prevention tools.
  • A documented incident response plan helps firms react quickly to suspicious activity.

Quick Read

  • Learn the official 2026 Dirty Dozen scams.
  • Understand how fraudsters target CPA firms.
  • Strengthen internal security controls.
  • Educate employees and clients regularly.
  • Develop a proactive fraud response strategy.

Introduction

Every tax season brings new opportunities for cybercriminals to exploit taxpayers and accounting professionals. While many scams still involve phishing emails and fraudulent phone calls, today’s attackers also use artificial intelligence, identity theft, fake tax advice, and sophisticated social engineering techniques to gain access to confidential financial information.

Because CPA firms manage tax returns, payroll records, banking information, and other sensitive client data, they are frequent targets for organized fraud. A single compromised account can expose hundreds of taxpayer records, disrupt operations, and damage client trust.

The IRS Dirty Dozen tax scams campaign serves as an annual warning about the most significant fraud schemes affecting taxpayers and tax professionals. Understanding these threats allows firms to recognize suspicious activity, improve internal controls, and educate clients before fraud occurs.

2026 IRS Dirty Dozen Tax Scams at a Glance

Dirty Dozen ScamPrimary RiskWho Is Most Targeted?
IRS Impersonation Emails & Texts (Phishing/Smishing)Credential theft, malware, financial fraudTaxpayers & CPA firms
AI-Enabled IRS Phone ScamsPayment fraud, disclosure of sensitive informationTaxpayers & Businesses
Fake CharitiesFraudulent donations, identity theftIndividual taxpayers
False Tax Advice on Social MediaInvalid refund claims, penalties, auditsIndividual taxpayers
Identity Theft Targeting IRS Online AccountsUnauthorized account access, refund theftTaxpayers
Abusive Form 2439 (Undistributed Capital Gains) ClaimsImproper tax benefits, IRS examinationTaxpayers & Tax Preparers
Bogus Self-Employment Tax Credit PromotionsFalse refund claims, penaltiesSelf-employed individuals
Ghost Tax PreparersFraudulent tax returns, taxpayer liabilityTaxpayers
Non-Cash Charitable Contribution SchemesInflated deductions, auditsIndividuals & Businesses
Overstated Withholding SchemesFalse refunds, rejected returnsTaxpayers
Offer in Compromise MillsUnnecessary fees, false settlement promisesTaxpayers with tax debt
Misleading Qualified Small Business Stock (QSBS) ClaimsImproper capital gains exclusionInvestors & Business Owners

Understanding the IRS Dirty Dozen Campaign

The IRS Dirty Dozen tax scams campaign is an annual awareness initiative that highlights the most common and dangerous tax-related fraud schemes identified by the IRS. Rather than representing every possible scam, the campaign focuses on the threats that most frequently deceive taxpayers, businesses, and tax professionals.

These scams change as technology evolves. Criminals increasingly use AI-generated content, spoofed phone numbers, fake websites, and convincing emails to impersonate trusted organizations. Others promote fraudulent tax credits, inflated deductions, or misleading tax strategies that can result in penalties and additional IRS scrutiny.

For CPA firms, the campaign reinforces the importance of maintaining professional skepticism. Employees should verify unusual requests, follow established security procedures, and educate clients about emerging fraud risks throughout the year — not only during filing season.

The 2026 IRS Dirty Dozen: 12 Tax Scams Every CPA Firm Should Know

The following scams form the core of IRS tax scams 2026. While they target different audiences, each presents risks that CPA firms should recognize when serving clients.

1. IRS Impersonation Emails and Text Messages (Phishing and Smishing) Fraudsters send messages that appear to come from the IRS, requesting immediate action or promising refunds. Their goal is to steal login credentials, financial information, or taxpayer identities.

2. AI-Enabled IRS Phone Scams Scammers use AI-generated voices, spoofed caller IDs, and convincing scripts to impersonate IRS representatives and pressure victims into making payments or revealing confidential information.

3. Fake Charities Following natural disasters or high-profile events, criminals create fraudulent charitable organizations to collect donations and personal information from well-intentioned taxpayers.

4. False Tax Advice on Social Media Misleading posts and videos encourage individual taxpayers to claim refunds, deductions, or credits they are not legally entitled to receive. Following inaccurate advice can lead to audits, penalties, and delayed refunds.

5. Identity Theft Targeting IRS Online Accounts Cybercriminals attempt to gain unauthorized access to taxpayer online accounts to obtain confidential information, redirect refunds, or commit additional identity fraud.

6. Abusive Undistributed Long-Term Capital Gains Claims Some promoters encourage taxpayers to misuse Form 2439 by claiming tax benefits that are unsupported by their actual investments or tax situation.

7. Bogus Self-Employment Tax Credit Promotions Certain promoters falsely advertise large refunds by encouraging taxpayers to claim self-employment tax credits for which they do not qualify.

8. Ghost Tax Preparers Ghost preparers complete tax returns but refuse to sign them or provide a valid PTIN. They often inflate refunds using unsupported deductions or fabricated tax credits, leaving taxpayers responsible for any errors.

9. Non-Cash Charitable Contribution Schemes These schemes involve artificially inflating the value of donated property to generate excessive charitable deductions that cannot be supported during an examination.

10. Overstated Withholding Schemes Fraudsters encourage taxpayers to report false withholding amounts or fabricate tax documents in an attempt to receive larger refunds than they are entitled to claim.

11. Offer in Compromise Mills Some companies aggressively market debt settlement services by promising that almost anyone qualifies for an Offer in Compromise. Many taxpayers pay substantial fees despite having little or no chance of approval — sound tax planning and advisory guidance can help them evaluate real options first.

12. Misleading Qualified Small Business Stock (QSBS) Claims Promoters encourage taxpayers to improperly claim the Qualified Small Business Stock exclusion even when statutory eligibility requirements have not been met.

Although each scam is different, they all rely on deception, urgency, or misinformation. For CPA firms, recognizing these warning signs is the first step toward effective tax scam prevention. Employee education, secure communication practices, and consistent verification procedures remain essential for protecting both the firm and its clients from evolving tax fraud schemes.

How CPA Firms Can Prevent IRS Dirty Dozen Tax Scams

While fraud techniques continue to evolve, the most effective defense remains a combination of secure technology, well-defined processes, and informed employees. CPA firms that adopt a proactive approach to tax scam prevention are better positioned to protect client information and minimize operational disruptions.

Start by strengthening access controls and data security across all systems that store or process taxpayer information. Multi-factor authentication, strong password policies, and role-based access help reduce the risk of unauthorized access to tax software, document management platforms, and client portals.

Employee training should be an ongoing priority rather than a once-a-year exercise. Team members should know how to identify phishing emails, suspicious phone calls, fake websites, and unusual client requests. Regular security awareness sessions also help employees recognize emerging IRS tax scams 2026 before they become successful attacks.

CPA firms should establish verification procedures for requests involving tax returns, direct deposit changes, banking information, or sensitive client records. Confirming unusual requests through a trusted communication channel can prevent fraud even when a message appears legitimate.

Technology also plays a critical role. Keeping software updated, encrypting confidential files, maintaining secure backups, and monitoring user activity all contribute to stronger CPA cybersecurity. Combined with documented policies and regular quality control reviews, these measures create multiple layers of protection against increasingly sophisticated fraud attempts.

Building a Firm-Wide Fraud Prevention Strategy

Fraud prevention should be embedded into the firm’s daily operations rather than handled only by the IT department. Every employee who works with taxpayer information plays an important role in protecting clients and maintaining regulatory compliance.

Begin by documenting clear policies for collecting, storing, sharing, and disposing of confidential information. Employees should know exactly how to verify client identities, approve sensitive requests, and report suspicious activity.

Regular internal reviews help identify weaknesses before they are exploited. Firms should periodically assess user permissions, review access logs, evaluate vendor security practices, and test incident response procedures. As the firm grows, these reviews ensure that security controls continue to align with operational needs.

Client education is equally valuable. Many tax fraud schemes begin outside the accounting firm, with criminals targeting taxpayers directly through fake emails, text messages, or social media. Encouraging clients to use secure document-sharing methods and verify unexpected requests can reduce the likelihood of successful attacks — part of the broader client accounting advisory relationship firms should maintain.

A strong fraud prevention strategy combines technology, documented processes, employee awareness, and continuous improvement. Firms that regularly evaluate and strengthen these areas are better prepared to respond to emerging threats while maintaining client confidence.

Responding to a Suspected Tax Scam

Even with robust controls in place, no organization is completely immune to fraud. Having a structured response plan helps CPA firms act quickly and limit potential damage.

If suspicious activity is detected, secure the affected systems immediately by changing compromised credentials, restricting access where necessary, and preserving relevant records for review. Prompt action can prevent further unauthorized access and reduce the impact of an incident.

Next, follow the firm’s established incident response procedures. Notify appropriate internal stakeholders, document the event, and determine whether client information may have been exposed. If sensitive data has been compromised, communicate with affected clients promptly and advise them on recommended protective measures.

After the incident has been addressed, conduct a thorough review to identify how the attack occurred and what improvements are needed. Updating verification procedures, enhancing employee training, or strengthening technical controls can help prevent similar incidents in the future.

The objective is not only to recover from an event but also to build a more resilient organization that can adapt to future IRS Dirty Dozen tax scams and other evolving fraud threats.

How KMK Ventures Helps

KMK Ventures partners with CPA firms to deliver reliable accounting support backed by structured processes, strong quality controls, and secure operational practices. Our teams work within documented workflows that promote consistency, confidentiality, and accuracy across every engagement.

As firms respond to evolving IRS Dirty Dozen tax scams, operational discipline becomes just as important as technical security. Clearly defined responsibilities, controlled access to financial information, standardized review procedures, and secure communication practices all contribute to a stronger control environment.

By helping firms streamline accounting operations and reinforce internal processes, KMK Ventures enables CPA practices to focus on serving clients while maintaining high standards of security, compliance, and service quality. Contact us to learn how we can support your firm.

Conclusion

The IRS Dirty Dozen tax scams remind CPA firms that fraud is constantly evolving. From phishing emails and AI-generated phone scams to identity theft and abusive tax schemes, today’s threats require continuous vigilance and a proactive approach to risk management.

Understanding the official 2026 Dirty Dozen list is only the first step. Firms must also invest in employee education, secure technology, documented procedures, and regular process reviews to reduce exposure to fraud.

By combining strong tax scam prevention practices with a culture of security awareness, CPA firms can better protect client information, maintain regulatory compliance, and preserve the trust that is essential to every successful client relationship.

Frequently Asked Questions

The IRS Dirty Dozen tax scams list is an annual awareness campaign that highlights the most significant tax-related fraud schemes affecting taxpayers, businesses, and tax professionals. It helps organizations recognize emerging threats and strengthen fraud prevention efforts. 

CPA firms manage highly sensitive financial and taxpayer information, making them attractive targets for cybercriminals. Understanding IRS tax scams 2026 enables firms to improve security, educate employees, and better protect client data.

 

While risks vary, phishing emails, identity theft, credential theft, and social engineering remain among the most common threats. Effective CPA cybersecurity combines secure technology with employee awareness and documented verification procedures. 

 

Firms should implement multi-factor authentication, maintain updated software, train employees regularly, establish verification protocols, and encourage clients to use secure communication channels. These measures work together to reduce the risk of successful fraud attempts. 

 

The firm should immediately secure affected systems, document the incident, notify appropriate internal stakeholders, assess whether client information has been exposed, and strengthen controls based on lessons learned. A timely and structured response can significantly reduce the impact of tax identity theft and related fraud.

 

What’s Next? 

Fraud prevention is no longer just an IT responsibility. It is a core business function for every CPA firm. KMK Ventures helps firms strengthen accounting operations with secure workflows, standardized processes, and scalable support that complements your internal controls. Connect with our team to learn how we can help your firm operate with greater confidence, security, and efficiency.