The Internal Revenue Service and its Security Summit partners issued a fresh warning on September 4 telling tax professionals and taxpayers to lock down their accounts against identity theft, and the agency’s own data explains why the timing matters: taxpayers whose identities are stolen and used to file a fraudulent return currently wait close to two years for the IRS to sort out the resulting mess and release their refund. The warning centers on three defenses — multifactor authentication, secure IRS online accounts, and a six-digit Identity Protection PIN that blocks a thief from filing a return under a stolen Social Security number in the first place.
A Fourth Warning in a Five-Part Security Summit Campaign
The push arrived as IR-2026-106 on September 4, the fourth installment in the IRS and Security Summit’s five-part “Protect Your Clients; Protect Yourself” summer campaign aimed at tax professionals and the taxpayers whose data they hold. The release leans hardest on multifactor authentication, which the Federal Trade Commission’s Safeguards Rule already requires tax preparation firms to use to protect client data unless a qualified individual signs off in writing on an equivalent control. IRS Chief Executive Officer Frank Bisignano framed the message as a call to use tools already available rather than wait on new legislation or technology.
Multifactor authentication works by requiring at least two independent ways to confirm a person’s identity — a password paired with a code sent to a device, or a password paired with biometric data — which blocks the phishing and credential-theft attacks that let criminals into tax software and client files in the first place. The IRS is also steering both preparers and individual filers toward IRS Online Account and Tax Pro Account, secure portals that let a taxpayer view their own records and, just as importantly, prevent a fraudster from registering an account under someone else’s name before the real taxpayer does.
The timing lines up with the final stop on the 2026 IRS Nationwide Tax Forum circuit, running September 15 through 17 in San Diego, where practitioner security has been a headline topic all year. The Security Summit — a public-private partnership between the IRS, state tax agencies, and the tax preparation industry that has run since 2015 — uses the forum circuit and the summer release series together to reach both professionals and the clients who trust them with Social Security numbers.
Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.
The Refund Delay an IP PIN Is Built to Prevent
The warning’s urgency is easier to understand against the backdrop of the National Taxpayer Advocate’s 2026 mid-year report to Congress, released in June, which found that identity theft victim assistance cases are taking about 20 months to resolve — nearly two years before an affected filer gets a refund the fraud held hostage. More than half a million such cases were still sitting in IRS inventory at the end of the 2026 filing season, according to the report, a backlog large enough that the National Taxpayer Advocate named cutting it a formal priority for the fiscal year ahead.
National Taxpayer Advocate Erin Collins wrote that for many taxpayers, “waiting nearly two years for a refund is not merely an inconvenience” but a genuine financial hardship, particularly for lower- and middle-income filers who depend on that money. The same report flagged that the Taxpayer Protection Program telephone line — which taxpayers call specifically to clear up suspected identity theft holds on their returns — answered only 19% of the 2.4 million calls it received during the filing season.
Substantially reducing those identity-theft resolution delays is now one of eleven advocacy objectives the Taxpayer Advocate Service has set for fiscal year 2027, alongside separate goals for clearing paper-check backlogs and improving how the IRS communicates when a return gets frozen for review. None of those fixes reach the underlying cause the September 4 warning targets: a return can only get flagged for an identity-theft hold after a thief has already tried to file one.
How the IP PIN Actually Blocks a Fraudulent Filing
An Identity Protection PIN is a six-digit number known only to a taxpayer and the IRS, valid for a single calendar year before a new one is generated, and the agency uses it to verify a filer’s identity the moment an electronic return carrying that Social Security number arrives. A thief who has stolen a name, birth date, and Social Security number still cannot e-file a return without also supplying the correct PIN for that year, which closes off the exact filing method identity thieves rely on most.
Enrollment happens only through the taxpayer directly; a tax professional cannot request or retrieve an IP PIN on a client’s behalf, so a filer has to complete the identity verification process on IRS.gov to opt in. Anyone already confirmed by the IRS as a victim of tax-related identity theft is treated differently — the agency automatically issues that person a new IP PIN every year going forward without a fresh application, a standing protection built specifically around cases that have already happened once.
The gap between prevention and resolution is the real story behind the September 4 warning: an IP PIN can stop a thief from filing a fraudulent return in the first place, but for a filer whose identity has already been used against them, the agency’s own numbers show the fix takes closer to two years than two months. Until the Taxpayer Advocate’s stated priority of shrinking that resolution time shows up in next year’s report, the PIN remains the strongest tool a filer controls before the theft happens, not after.
This article was drafted with AI assistance and edited for accuracy.
More Financial Reading