The IRS Just Rebuilt Its Anti-Fraud Playbook Around Your Payroll Provider
IRS Security Summit Anti Fraud Framework 2026: What the IRS actually announced
The Security Summit isn’t new. It’s a public-private group the IRS, state tax agencies, payroll companies, software firms, and the tax-prep community started in 2015 to fight identity-theft refund fraud. What changed on June 8 is the architecture. The IRS (in IR-2026-75) replaced the old working groups with five functions that map to the life of a fraud attempt: pre-filing, forecasting, preventing, detecting and reporting, and responding. Read down that list and you can see the logic. Catch the bad return before it’s filed, predict the next scheme, harden the systems, flag it in real time, then shut it down.
For IRS Security Summit Anti Fraud Framework 2026, the detail that matters for our clients sits inside the “pre-filing” and “preventing” groups. Both call out payroll providers by name. The IRS says it will coordinate more closely with the companies that process payroll because their data has become a primary target — a single breach at a payroll processor hands a criminal thousands of real names, Social Security numbers, and wage figures, which is everything you need to file a convincing fake refund return. The agency is essentially admitting the soft spot isn’t the IRS’s own front door anymore. It’s the vendor your business hired to run payroll, and the new framework is built to watch those systems instead of waiting for the fraudulent return to show up.
Why a business owner should care more than a wage employee
Most coverage of tax identity theft pictures a single taxpayer whose refund got stolen. That happens. But a business is a bigger prize and a softer one. If you own a company, a fraudster who gets into your books can file a fraudulent Form 941, open credit in the company’s EIN, or — the common one — harvest your employees’ W-2 data and file dozens of refund returns at once. The W-2 phishing scam that hits HR and payroll inboxes every January is the same scam the IRS is now reorganizing to catch earlier, before those returns ever reach a processing center.
High earners are a target for a different reason: dollar size. A refund return filed under a name with a big expected refund or a complex return clears more money before anyone notices. The IRS has pushed its Identity Protection PIN program partly for this group, and the new framework’s “detecting” function is built to spot exactly this pattern in real time. If you’re a high-net-worth filer, an IP PIN is the cheapest insurance in the tax code — it’s free, and a return filed without it gets rejected.
What this changes for how you run payroll
If you outsource payroll
Ask your provider one question: what happens to our employees’ data if you’re breached, and what are you doing about the IRS’s new payroll coordination. A serious processor will have an answer. The ones who get quiet are the ones to worry about. The IRS framework leans on these vendors to share fraud signals faster, so a provider that isn’t paying attention to the Security Summit is a provider operating a half-step behind the threat. We help business owner clients vet payroll vendors and read the security language in those service agreements, because “we use bank-level encryption” on a sales page tells you almost nothing.
If you run payroll in-house
You are the payroll provider, which means you carry the duty the IRS is now leaning on the big processors to meet. The IRS has long published a written information security plan requirement for anyone handling taxpayer data, and the practical version for a small employer is unglamorous: lock down the email account that receives W-2 requests, never wire payroll data because someone “from the CEO” asked, and turn on multi-factor authentication everywhere. Our business management and payroll teams build these controls into the back office so the owner isn’t the single point of failure.
The open questions
A reorganization is a promise, not a result. The IRS hasn’t said how the five groups will share data with private payroll companies, what new reporting it will ask of them, or whether any of this reaches small in-house employers in the form of a rule rather than a suggestion. The agency is also doing this while operating under budget pressure that’s been public all year, which raises the fair question of whether a new org chart comes with the staff to run it. We’d watch for two things over the next few months: any new guidance aimed at payroll processors, and whether the IRS expands IP PIN enrollment or W-2 verification in a way that touches how employers file. Until then, the move that protects you doesn’t depend on the IRS finishing its reorganization.
How The Reed Corporation works with clients on fraud defense
We treat payroll security as part of the books, not a separate IT project. For clients on our payroll and business management services, that means controlling who can change direct-deposit information, reconciling payroll filings against the general ledger so a fraudulent 941 would stand out, and getting owners and key employees enrolled in IP PINs before filing season. We also handle the cleanup when something does go wrong — the identity-theft affidavit, the corrected returns, the back-and-forth with the IRS unit that handles these cases — as part of individual and small-business tax work. The IRS rebuilding its fraud framework is a reminder, not a reason to panic. The basics still do most of the work.
Related Services from The Reed Corporation
Helpful Guides You Might Also Like
Sources & References
Frequently Asked Questions
What did the IRS Security Summit actually change on June 8, 2026?
On June 8, 2026 the IRS and its Security Summit partners scrapped the old committee structure and rebuilt the partnership around five work groups that follow the life of a fraud attempt. The five functions are pre.filing, forecasting, preventing, detecting and reporting, and responding. The IRS described the change in its June 8 news release, and the practical takeaway for a business owner sits inside the pre.filing and preventing groups, both of which call for tighter coordination with payroll providers. The Security Summit itself is not new. The IRS, state tax agencies, payroll companies, software firms, and the tax.prep community started it in 2015 to fight identity.theft refund fraud, and you can read its history on the IRS Security Summit page. What shifted in 2026 is the architecture. The old working groups were organized around the participants in the room. The new ones are organized around the stages a criminal moves through. Catch the bad return before it is filed, predict the next scheme, harden the systems, flag fraud in real time, then shut it down. Read down that list and the logic is plain, because each group owns one slice of the attack instead of one type of partner. Here is why that reorganization matters in dollars. Suppose a payroll processor that handles 40 small businesses gets breached, exposing wage and Social Security data for 1,200 employees. Under the old model, the fraudulent refund returns built from that data might not surface until the legitimate employees tried to file in February and got rejected. By then a criminal filing 1,200 returns at an average fake refund of 4,000 dollars has already moved 4.8 million dollars before anyone connects the dots. The new pre.filing group is built to spot the suspicious filing pattern before the returns clear, which is the difference between stopping the theft and chasing it across a dozen states after the money is gone. The detail that matters most for our clients is who the framework names out loud. Both the pre.filing and preventing groups call out payroll providers by name, because a single breach at a processor hands a criminal thousands of real names, Social Security numbers, and wage figures, which is everything needed to file a convincing fake return. The agency is essentially admitting the soft spot is no longer its own front door. It is the vendor your business hired to run payroll. The IRS has paired this with a continued push on the Identity Protection PIN program, which gives individual filers a free way to block fraudulent returns even when the underlying data has leaked. A common mistake business owners make is reading a headline like this and assuming the IRS just fixed the problem on its end. It did not. The framework is a coordination promise, not a shield that now sits in front of your payroll data. The edge case worth flagging is the in.house employer. If you run payroll yourself, you are the payroll provider the IRS is now leaning on, so the announcement points a finger at your own controls rather than at a vendor. If you want help reading what this means for your filings, our tax compliance team tracks Security Summit guidance, identity.theft cleanup runs through our individual tax return service, and you can start a conversation at our new client inquiry page.
Why are payroll providers a target for tax fraud?
Payroll providers are a target because they hold everything a fraudster needs in one place. A payroll processor’s records include real names, Social Security numbers, home addresses, and exact wage figures for entire workforces. One breach can supply the raw material for thousands of convincing fake refund returns, which is why the new IRS framework leans on these vendors to detect and share fraud signals earlier. The IRS spelled out the payroll focus in its June 8 announcement. The mechanics are simple and that is the problem. To file a fraudulent return that passes automated screening, a criminal needs a name, a Social Security number, and a plausible wage and withholding figure. A stolen W.2 hands over all three at once. The IRS has watched criminals shift away from inventing data toward stealing real financial, payroll, and tax information, because a return built from genuine numbers looks legitimate to the systems that screen for fraud. The agency tracks the broader set of scams, including the W.2 phishing schemes that hit HR inboxes every January, through its consumer alerts, and it explains how to recognize phishing on its report phishing page. Consider a concrete example. A 25.employee design firm outsources payroll to a regional processor. In January a fraudster emails the firm’s bookkeeper posing as the owner and asks for a copy of all employee W.2 forms. The bookkeeper, trying to be responsive, sends them. Within a week the criminal files 25 returns claiming refunds that total roughly 90,000 dollars. The firm did nothing wrong with its own accounting software. The data walked out through an email request that felt routine, and every one of those 25 employees now faces a frozen refund and weeks of cleanup. That is exactly the soft spot the IRS framework is built to watch, because the breach happened upstream of any IRS screen. The reason a business is a bigger prize than a single taxpayer comes down to volume. A fraudster who phishes one individual gets one return worth of refund. A fraudster who reaches a payroll processor gets hundreds or thousands at once, all built from verified data, all filed before the real employees have their forms in hand. The new detecting and reporting group is meant to catch that burst of suspicious filings in real time rather than discovering it return by return as rejections trickle in. The common mistake is assuming a big.name payroll vendor is automatically safe. Size is not the same as discipline, and a provider that is not paying attention to the Security Summit is operating a half.step behind the threat. The edge case is the employer who switched providers mid.year. Your old vendor may still hold a full year of wage data, so a breach there exposes you even though you no longer send them payroll. We help business clients vet payroll vendors and read the security language in service agreements through our tax compliance service, because a sales.page promise of bank.level encryption tells you almost nothing. If you want that review, reach us at our inquiry page.
What is an IP PIN and should I get one?
An Identity Protection PIN is a free six.digit number the IRS issues that must appear on your tax return for the return to be accepted. Without it, a return filed in your name gets rejected automatically, which stops the most common form of refund fraud cold. The direct answer is yes, almost everyone who can enroll should, and you can sign up through your IRS online account at the IRS IP PIN page. The mechanics are clean. Once you opt in, the IRS issues a new PIN each year, and any electronically filed return that lacks the current PIN is rejected. A paper return without it gets pulled for extra review. The protection works automatically the moment it is on file, which is rare among tax safeguards. You confirm your identity through the same IRS online account portal you would use for a transcript, described at the IRS online account page. Enrollment takes about fifteen minutes once your identity is verified, and the number changes every year so a leaked PIN from one season does not help a criminal in the next. Here is the worked example that makes the case. Say you are a business owner expecting an 11,000 dollar refund. A criminal who obtained your Social Security number files a fraudulent return in late January claiming a 9,000 dollar refund to a prepaid card. If you have no IP PIN, that return may process, and your legitimate refund stalls for months while you file an affidavit and wait for manual review. With an IP PIN on file, the criminal’s return is rejected at submission because it lacks your current six.digit number. The cost of that protection was zero dollars and about fifteen minutes of enrollment, against months of frozen refund and paperwork on the other side. Why high earners and business owners should move first is a matter of math. A return under a name with a large expected refund or a complex filing clears more money before anyone notices, so criminals chase those names first. The IRS built the new framework’s detecting function partly to spot that pattern, but the IP PIN protects you whether or not the framework catches the attempt, because it blocks the return at the door. The agency walks through the broader recovery process for victims at Identity Theft Central, which is the slow path you avoid by enrolling early. A common mistake is treating the IP PIN as something only past victims need. It is preventive, not reactive. The edge case to plan for is losing the PIN. If you misplace the current year’s number you can retrieve it through your online account, but a return filed without it will bounce, so keep it with your other filing records. We get owners and key employees enrolled before filing season as part of our individual tax return work, and we coordinate it with the rest of your filings through tax compliance. Start at our new client inquiry page if you want help setting it up.
How do I protect my business payroll data right now?
Start with the email account that receives W.2 and direct.deposit requests, because that is where most payroll theft begins. Require multi.factor authentication on it, never act on an emailed request to send wage data or change banking details without confirming by phone, and limit who can change payroll settings. Those few moves block the overwhelming majority of real.world attacks, and they do not depend on the IRS finishing its reorganization. The IRS lays out data.security expectations for anyone handling taxpayer information through its Security Summit resources. The mechanics come down to closing the two doors criminals actually use. The first is the phishing email that asks an employee to send W.2 forms or move a direct deposit. The second is a weak or shared login that lets an outsider into the payroll system itself. Multi.factor authentication shuts the second door because a stolen password alone is not enough to get in. A firm phone.confirmation rule shuts the first because the fraudster is counting on email and urgency, not a voice on the line. The IRS keeps a running list of the exact scams that exploit these gaps at its consumer alerts page, and it accepts reports of W.2 theft and phishing through its report phishing page. Here is a worked example. A 60.person company gets an email that appears to come from its CEO, sent at 4:50 on a Friday, asking the payroll clerk to change the CEO’s direct deposit to a new account before the weekend run. The urgency and the timing are the tell. A clerk who follows a standing rule picks up the phone, reaches the actual CEO, learns the request is fake, and the 9,200 dollar paycheck routes to the right account. A clerk without that rule reroutes the money, and it is gone by Monday. The control that saved 9,200 dollars cost nothing but a habit and a phone call. The same logic protects against the W.2 harvest, which is the higher.dollar version of the same attack. An email that asks for all employee W.2 forms should trigger the same phone.confirmation reflex, because handing over those forms exposes the whole staff at once. Pair that habit with role.based access so that only one or two trained people can pull or send wage data, and the attack surface shrinks to almost nothing. None of this requires new software, which is the point. The common mistake is buying security software and skipping the human process, when the human process stops more theft than any tool. The edge case is the owner who is the single point of failure, approving every payroll change personally from a phone that has no MFA. That owner is the easiest target in the company, because one phished credential opens both doors at once. A simple fix is to route every banking change and every bulk W.2 request through a second trained person who confirms it by phone before anything moves, which removes the single point of failure without adding a dollar of software cost. We build these controls into the back office through our tax compliance and strategy work so a single phished email cannot move money or expose your staff. To set that up, reach us at our new client inquiry page.
What happens if someone files a fraudulent tax return in my name?
If a criminal files a return in your name, you file Form 14039, the Identity Theft Affidavit, and work through the IRS recovery process. Your legitimate return then gets processed manually, which delays any refund, and the IRS assigns you an Identity Protection PIN going forward. It is a fixable problem, but it is slow and it is a hassle, which is the whole argument for getting an IP PIN before it happens. The IRS walks through every step at Identity Theft Central. The mechanics start the moment your e.filed return is rejected as a duplicate, which is usually how victims find out. You submit Form 14039 to flag the account, attach it to a paper copy of your real return, and the case routes to the IRS unit that handles identity theft. That unit untangles the fraudulent filing from yours, releases your correct refund, and flags the account so future returns require your Identity Protection PIN. The agency describes the typical timeline and what to expect on its Identity Theft Central hub, and it warns that manual review can stretch across most of a filing season. Here is the worked example. A taxpayer expecting a 7,500 dollar refund e.files in March and gets a rejection saying a return was already filed under that Social Security number. She files Form 14039, mails her paper return, and waits. The IRS confirms the fraud, but the manual review takes months, so her 7,500 dollar refund that normally arrives in three weeks does not land until late summer. Nothing was permanently lost, but the money was frozen for an entire filing season, and the paperwork ate hours she did not have. Multiply that across a workforce hit by a payroll breach and you see why the IRS reorganized to catch the pattern earlier. What recovery looks like after the immediate fix is also worth knowing. Once the IRS clears your account it issues an IP PIN, so the same attack cannot succeed a second time, and you should monitor your wage and income transcript through your online account to confirm no other fraudulent filings are attached to your number. Identity theft often travels in clusters when it starts from a data breach, so checking the full account rather than just the one rejected return is the careful move, and pulling a wage and income transcript confirms whether a fraudster also filed information returns under your name. The common mistake is waiting to act after the rejection in the hope the IRS sorts it out on its own. It will not move until you file the affidavit, so speed matters. The edge case is the business filer who discovers a fraudulent Form 941 or an EIN.based filing rather than a personal return, which follows a different IRS process and benefits from professional handling. We manage this cleanup for clients, including the affidavit, the corrected returns, and the back.and.forth with the IRS, as part of our individual tax and tax compliance work. If you think a fraudulent return beat you to it, start at our new client inquiry page.
Does this new framework create any obligations for small employers?
Not directly, at least not yet. The June 8, 2026 announcement is an internal IRS reorganization and a tighter relationship with large payroll processors, not a new rule imposed on small businesses. But anyone who handles taxpayer or employee data already carries a duty to safeguard it, and the IRS has long expected even small firms to maintain a written data security plan. The smart read is to treat the announcement as a heads.up about where fraud is heading and to tighten payroll controls before any formal requirement arrives. The framework details sit in the IRS June 8 release. The mechanics of the existing duty are easy to miss because they predate this announcement. The IRS has published guidance for years stating that anyone preparing returns or handling sensitive taxpayer data should maintain a written information security plan, and the broader Security Summit effort, described at the Security Summit page, has pushed that expectation steadily toward smaller players. The 2026 reorganization does not change the letter of that duty. It signals that the IRS is watching payroll data flows more closely, which makes a casual approach riskier than it was a year ago. The agency keeps practical safeguard tips and current scam warnings at its consumer alerts page. Here is a worked example of why the heads.up has value even without a new rule. A 12.person firm that runs payroll in.house spends one afternoon turning on MFA, writing a one.page data security plan, and adding a phone.confirmation rule for banking changes. That afternoon costs maybe 400 dollars in staff time. The alternative, a single successful W.2 theft, can mean 12 fraudulent returns, frozen employee refunds, an angry workforce, and weeks of cleanup that easily exceeds 10,000 dollars in lost time and goodwill. The cheap, voluntary fix beats the expensive, mandatory cleanup every time, and it puts you ahead of any rule the IRS might write later. What might actually change for small employers down the road is worth watching. The IRS has not said how the five groups will share data with private payroll companies, what new reporting it will ask of them, or whether any of this reaches small in.house employers as a rule rather than a suggestion. It is doing this under budget pressure that has been public all year, which raises a fair question about whether a new org chart comes with the staff to run it. The two things to watch are new guidance aimed at payroll processors and any expansion of IP PIN enrollment or W.2 verification that touches how employers file. The common mistake is reading not directly as no obligation and doing nothing. The duty to protect employee data already exists. The edge case is the small employer who also prepares returns or handles client tax data, who faces a clearer written.plan expectation than a pure in.house payroll shop. We help small employers build the plan and the controls through our tax compliance service, layer in residency and entity planning through tax strategy consulting where it matters, and point clients to our broader service offerings, so you are ahead of any rule rather than scrambling after one. Start the conversation at our new client inquiry page.