IRS taxpayer data security concerns revealed in TIGTA report
Taxpayers trust the IRS with Social Security numbers, income information and other sensitive financial data. So, when a government watchdog reports that thousands of inactive IRS employees retained access to agency systems, clients may understandably have questions about the security of their tax information.
An August report from the Treasury Inspector General for Tax Administration (TIGTA) identified several weaknesses in the IRS controls for removing access to its network and sensitive systems. TIGTA found that nearly 17,000 employees participating in deferred resignation programs retained access to the IRS network while on administrative leave as of June 2025. More than 14,000 retained access to one or more systems containing sensitive taxpayer information.
The message for concerned clients is straightforward: TIGTA found that inactive employees on administrative leave retained access they did not need while on leave, creating a potential risk to taxpayer information. However, the report did not find that the thousands of employees identified actually accessed or disclosed taxpayer information without authorization. The IRS began removing that access after TIGTA identified the problem.
Why did inactive IRS employees retain system access?
In 2025, as part of a workforce-reduction effort, the IRS reduced its workforce through two deferred resignation programs. Employees who accepted the offers were placed on administrative leave until Sept. 30, 2025.
Although they were no longer working, these employees had not officially separated from the IRS. The IRS manages access to its systems through the Business Entitlement Access Request System (BEARS). Normally, when an employee separates from the IRS, a personnel action is generated and sent to BEARS, triggering removal of the employee's network access.
Employees participating in the deferred resignation programs remained classified as active in IRS personnel records. As a result, the personnel action that would normally deactivate their access was not generated.
What should tax pros tell clients about the risk?
TIGTA found that these employees retained network access. More than 14,000 also retained access privileges to one or more sensitive systems. However, there is an important difference between having the ability to access a system and actually using that access improperly.
TIGTA emphasized the seriousness of the vulnerability because unauthorized access can lead to disclosure of taxpayer information and damage public trust. Some employees posed a greater risk because they retained both sensitive-system entitlements and the network access required to use them.
What did the IRS do about the access problem?
TIGTA alerted the IRS to the issue in June 2025 and recommended that the agency remove network and sensitive-system access for employees on administrative leave.
The IRS agreed and began manually removing access.
TIGTA found that about 13,500 employees participating in the deferred resignation programs still had sensitive system access in July 2025, and approximately 12,500 retained network access. By August, those numbers had fallen to fewer than 8,000 with sensitive-system access and about 1,600 with network access.
The review also identified 46 individuals outside the deferred resignation programs who had separated from the IRS but retained active network access as of August 2025. Nine also retained active access to a sensitive system.
What other IRS data security concerns did TIGTA identify?
TIGTA found additional weaknesses involving personal identity verification (PIV) cards and security training.
The IRS initially lacked a process for collecting PIV cards from employees placed on administrative leave under the deferred resignation programs. These government-issued identification cards can be used to authenticate users on networks and applications and gain access to secure facilities.
The IRS later used participant lists to disable building access and worked with the Treasury Department to terminate the certificates associated with the cards, preventing them from accessing information systems.
TIGTA identified nearly 1,100 new employees who received access to sensitive systems between January and August 2025. Of those individuals, 524 either completed cybersecurity training after receiving access or had not completed all required training at the time of TIGTA's analysis. Additionally, some current contractors maintained system access even though they had not met training requirements.
There was some positive news. TIGTA found that all of the nearly 1,200 new employees and contractors it reviewed had completed required pre-employment checks before receiving sensitive-system access.
What happens next?
TIGTA made six recommendations designed to strengthen IRS taxpayer data security. These included improving access-removal procedures, recovering PIV cards, correcting network access records and ensuring employees and contractors complete required security training before receiving sensitive-system access. The IRS agreed with five recommendations and partially agreed with one.
In this case, practitioners can explain that TIGTA identified a legitimate access-control risk without reporting widespread unauthorized access by the inactive employees involved. Providing that context helps tax pros address client concerns accurately and remain a trusted source of tax information.