Insights / IRS & compliance

IRS Security Summit (IR-2026-111): Protect Your Clients—What Cary/RTP Taxpayers Should Do Now

IRS IR-2026-111 closes Week 5 of “Protect Your Clients; Protect Yourself.” Cary/RTP taxpayers and tax pros should know phishing red flags, IP PIN, Pub 5708, Security Six, and Form 14039 reporting paths.

Published By YCL CPA
IRS Security Summit IR-2026-111 protecting Cary/RTP taxpayers and tax professionals

Bottom line in one breath

On September 16, 2026, the IRS issued IR-2026-111 closing Week 5 of the Security Summit series “Protect Your Clients; Protect Yourself.” The message is for tax professionals and taxpayers: identity thieves still target preparer credentials (EFIN / PTIN / CAF), “new client” malware, IRS impersonation, and social-media tax “hacks.” Know the red flags—client e-file rejects when an SSN was already used, unexpected IRS Online Account activity, and authentication letters such as 5071C / 4883C / 5747C when no return was filed. Use the tools the IRS highlights (Pub 5708 WISP, Security Six, IP PIN Opt-In) and report breaches promptly (local IRS Stakeholder Liaison, FTA data-breach channel, and Form 14039 when appropriate). This article is compliance planning for Cary/RTP (and other) households and firms—it is not a promise of any outcome.

Background

The Security Summit is a public-private partnership of tax professionals, industry partners, state tax agencies, and the IRS that has worked since 2015 to protect the tax system from identity theft and fraud. IR-2026-111 is the fifth and final week of the 2026 summer awareness series. IRS Chief Executive Officer Frank J. Bisignano emphasized that protecting taxpayer information is fundamental to confidence in the tax system, and that continued vigilance and partnership remain essential as threats evolve. Tax professionals remain prime targets because millions of taxpayers entrust them with highly sensitive data—making security basics and prompt breach reporting part of professional duty, not optional extras. For Chinese-American families and business owners in Cary / RTP, phishing often arrives in English and Chinese channels (email, SMS, WeChat, social apps), so bilingual awareness matters as much as the technical checklist.

Old habits vs. Security Summit guidance

1. Old habit: treat unsolicited “new client” PDFs or portal links as routine intake. Guidance: assume “new client” attachments/links can be malware until verified out-of-band.

2. Old habit: share EFIN / PTIN / CAF numbers or related documents after a casual email request. Guidance: treat requests for those identifiers as high-risk phishing.

3. Old habit: click links in emails/texts that look like “IRS” because caller ID or branding looks familiar. Guidance: IRS impersonation uses email, text, DMs, spoofed caller ID, and computer-generated calls—verify through known IRS channels, not the message itself.

4. Old habit: follow viral social-media “tax hacks” that promise fast refunds or unusual credits. Guidance: false positions can mean refund delays, exams, and penalties.

5. Old habit: ignore odd system slowdowns or a one-off e-file reject. Guidance: unusual computer activity, lockouts, SSN-already-used rejects, unexpected authentication letters, or IRS notices for clients you do not represent are warning signs.

6. Tools named in IR-2026-111: Pub 5708 (written information security plan / WISP), Security Six, and IP PIN Opt-In; breach reporting via Stakeholder Liaison, FTA state channel, client notice, and Form 14039 when appropriate.

Self-check: does this affect you?

1. You are a Cary/RTP taxpayer (or own a small business) and work with a tax preparer—or you self-prepare and use IRS Online Account.

2. You received letter 5071C, 4883C, or 5747C even though you did not file a return.

3. You got a notice that an IRS Online Account was created in your name without your authorization—or saw a transcript/refund you did not request.

4. Your e-filed return was rejected because your SSN was already used.

5. You are a tax pro / firm owner and were asked for EFIN, PTIN, or CAF materials by an unexpected “client,” vendor, or “IRS” message.

6. Your office saw lockouts, unusual computer activity, or IRS notices for clients you do not represent.

Simplified example (illustration only—not a recommended path or promised outcome)

Assume Ms. Li, a Cary professional, receives Letter 5071C asking her to verify identity, even though she has not filed yet this season. Separately, her friend’s preparer received a “new client” email with a ZIP of “prior-year returns”:

1. Scenario A — taxpayer letter, no return filed: do not click links in unexpected emails that claim to “resolve” the letter; confirm letter authenticity through known IRS contact patterns; discuss Online Account status and whether an IP PIN or Form 14039 path fits the facts—no outcome is promised.

2. Scenario B — e-file reject, SSN already used: treat as a possible identity-theft indicator; work with a licensed professional on next steps and documentation—blogs cannot choose the path for you.

3. Scenario C — preparer “new client” malware lure: do not open the attachment; isolate the machine if already opened; review Security Six controls and Pub 5708 plan; if a breach is suspected, report promptly to the local IRS Stakeholder Liaison and the FTA state breach channel, and notify affected clients.

Different facts → different moves; a blog cannot choose for you.

Action timeline

1. This week: inventory recent IRS letters (especially 5071C / 4883C / 5747C), Online Account alerts, and any e-file rejects tied to SSN reuse.

2. Before the next filing season push: taxpayers should consider whether IP PIN Opt-In fits their risk profile; firms should refresh Pub 5708 WISP and Security Six controls (antivirus, firewall, backups, encryption, MFA, VPN).

3. If phishing or a breach is suspected now: stop interacting with the lure; preserve evidence; contact the local IRS Stakeholder Liaison; use the FTA Report a Data Breach path for state agencies; inform affected clients.

4. When identity theft is indicated: evaluate Form 14039 with a professional when appropriate; monitor for unexpected refunds or transcripts.

5. Ongoing: treat social-media tax “hacks” and unsolicited EFIN/PTIN/CAF requests as high-risk until independently verified. Delay usually worsens posture when notices arrive.

What YCL can do

1. Help Cary/RTP clients interpret identity-theft indicators (unexpected authentication letters, Online Account alerts, SSN-already-used rejects) in a compliance-focused review.

2. Discuss IP PIN Opt-In and documentation habits that reduce unauthorized filing risk—no promised refund or exam outcome.

3. Support firms and owner-operators reviewing security hygiene aligned with Security Six / Pub 5708 themes (process checklist, not a cybersecurity product sale).

4. Bilingual (EN/ZH) explanation for Chinese-American households who receive mixed-language phishing or IRS letters.

5. Cary (RTP) + Shanghai offices with CPA Chenchen Liu and Gloria; Free Consultation.

FAQ

Q: What is IR-2026-111 about?

A: It is the IRS Security Summit reminder closing Week 5 of “Protect Your Clients; Protect Yourself” (Sept. 16, 2026). It highlights ongoing threats to tax pros and taxpayers and points to Pub 5708, Security Six, IP PIN Opt-In, and breach-reporting steps.

Q: I got a 5071C (or 4883C / 5747C) but I did not file—what should I do?

A: Treat it as a warning sign listed in IR-2026-111. Avoid links in unexpected emails claiming to “fix” the letter. Confirm next steps through trusted IRS patterns and a licensed professional; IP PIN or Form 14039 may be discussed depending on facts—no outcome is promised here.

Q: What are the “Security Six”?

A: Per the IRS Security Summit materials referenced in IR-2026-111: antivirus software, firewalls, backup software or services, encrypted drives, multifactor authentication, and virtual private networks.

Q: How should a tax firm report a data theft?

A: IR-2026-111 says report promptly to a local IRS Stakeholder Liaison, report through the Federation of Tax Administrators’ Report a Data Breach page to the state agency, inform affected clients, and recommend protective steps such as an IP PIN or Form 14039 when appropriate.

Book a consult

YCL Tax, Accounting & Advisory

Web: yclcpa.com | Email: info@yclcpa.com

Phone: 919-802-8376 / 980-202-0666 | WeChat: YCLUSA

U.S. office: 1140 Kildaire Farm Rd. STE 208, Cary, NC 27511

Shanghai office: 2-516, Zhongye Xiangteng Plaza, Lane 31, Jiatong Road, Shanghai

Free Consultation available by appointment.

Disclaimer

This article is general tax information only and is not tax, legal, or investment advice for any person or business, and it is not a promise of any penalty, refund, or exam outcome. Application depends on your facts, filings, and current IRS procedures. Consult a licensed professional for advice specific to you.

Ready to talk? The first 30 minutes are on us.

Book online, or send us a few details and we will come back with a written quote within one business day.

Book free callRequest a quote