IRS allowed unauthorized access to VIP taxpayer info

  • Key insight: Learn why the IRS failed to detect employees snooping on high-profile taxpayer accounts.
  • What’s at stake: Taxpayers whose confidential data remains exposed to unauthorized searches by agency employees.
  • Supporting data: 175 taxpayers who did not receive required notifications from the agency.

The Internal Revenue Service’s program for safeguarding against unauthorized access to confidential taxpayer information doesn’t adequately prevent or detect unauthorized access to taxpayer accounts, according to a new report, which found IRS employees had snooped on the taxes of government officials, business leaders and entertainers.

Processing Content

The report, released last week by the Treasury Inspector General for Tax Administration, assessed the effectiveness of the IRS’s unauthorized access, attempted access, or inspection of taxpayer records program, which is designed to prevent unauthorized access and maintain public confidence in the IRS. The program, known as UNAX, was created to implement the requirements of the Taxpayer Browsing Protection Act.

The 1997 law prohibits IRS employees from accessing or attempting to access taxpayer records without a legitimate tax administration purpose. Unauthorized access can result in criminal and civil penalties, as in the case of Charles Littlejohn, an IRS contractor employed by Booz Allen Hamilton who was sentenced to five years in prison after leaking the tax information of President Trump and other billionaires, including Elon Musk and Jeff Bezos, to media outlets including The New York Times and ProPublica. 

TIGTA uncovered deficiencies in a number of controls and processes that are supposed to protect taxpayers and hold IRS employees accountable for their actions. IRS controls mainly restrict employees from accessing accounts of family members or close associates. TIGTA checked the audit logs from the IRS’s Integrated Data Retrieval System from 2022 through 2025 and found 86 irregular accesses involving 30 taxpayers by 52 employees, including records of government officials, business leaders and entertainers. TIGTA referred the 86 suspicious cases to TIGTA’s Office of Investigations for further action. Overall, the report found the IRS lacks sufficient preventative controls to stop unauthorized access and hasn’t effectively identified suspicious unauthorized accesses after such access occurs.

The IRS uses criteria known as the Douglas Factors, named after a 1981 case, Douglas v. Veterans Administration, to determine the appropriate discipline or punishment for misconduct. However, TIGTA identified 22 employees who were not terminated even though they had accessed taxpayer records without consent or authorization. In July 2026, the Office of Personnel Management and the Merit Systems Protection Board proposed a new rule to stop applying the Douglas Factors to improve the accountability of employees for misconduct.

The IRS failed to notify 175 taxpayers about unauthorized access because its employees did not follow the required procedures. Another 101 taxpayers weren’t notified because the IRS requires notification only when disciplinary action is initiated and the responsible employees resigned or retired before that occurred. TIGTA found the IRS doesn’t consistently notify affected taxpayers in a timely way.

“The inability to protect sensitive data may result in unauthorized access, disclosure, misuse, improper modification or destruction of taxpayer information,” said the report. “This burdens affected taxpayers and violates their rights to confidentiality. Unauthorized access or disclosure can also erode public trust in the IRS, which may affect a taxpayer’s decision to voluntarily comply with their tax obligations.”

TIGTA made eight recommendations in the report to improve the IRS’s UNAX program, including studying technologies to implement preventative controls; clarifying guidance on the application of Douglas Factors, and working on a new process to ensure all impacted taxpayers are notified of willful unauthorized employee access. 

IRS officials agreed or partially agreed with seven of the eight recommendations and said they either have or plan to implement corrective actions.

“The Internal Revenue Service (IRS) remains firmly committed to safeguarding taxpayer information and continuously strengthening the Unauthorized Access of Taxpayer Accounts (UNAX) through effective oversight, risk management and process improvements designed to protect taxpayer privacy and maintain trust,” wrote IRS acting chief privacy officer John Walker in response to the report.”

Introductory bullet points created by AI with editorial review.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *