Intaxion
Operations

Post-Filing Document Quarantine: Stopping Phishing Before It Becomes a Breach

Published June 18, 2026
7 min read
By Intaxion Team
Form 8821 provides access to specified tax information. Form 2848 permits representation within the authorization and in specified IRS matters.

Versión en español

The attachment did not fool your office because it looked convincing. It fooled your office because no one owned quarantine at first contact.

For many small tax offices, midsummer can look deceptively quiet: filing pressure has eased, and the phone may ring less than it did in March. In that lull, imagine a prospect email asking for help with, say, an attached zip file or a portal link — the kind of message that could get treated as routine intake instead of a request that needs verification first. That general pattern — a fraudulent message posing as a new client — is the kind of risk the IRS is flagging in its current 2026 Security Summit summer campaign.

This is workflow guidance for small tax offices, not tax advice, legal advice, or a promise that any single checklist stops every attack. The IRS's current summer release says identity thieves keep adapting their tactics and tells tax professionals to review security basics, train staff, and verify unusual requests before responding. It lists several scam patterns to watch for now: IRS impersonation by email, text, and phone; misleading tax advice on social media; so-called new client schemes; and phishing aimed at EFIN, PTIN, and CAF credentials. The IRS describes new client schemes as spear phishing, where fraudsters pose as prospective clients and send malicious links or attachments disguised as tax documents. Its phishing-reporting page adds the practical response: if a message looks like a new client scam or an EFIN scam, do not reply, click links, or open attachments. Forward it to phishing@irs.gov with the subject line "Spearphishing," report it to TIGTA, and contact your stakeholder liaison if a breach occurred. That phishing@irs.gov and TIGTA reporting path is scoped to emails that look like targeted new-client or EFIN phishing — it is not a single procedure covering every channel above, such as phone calls, text messages, or social media posts, which can call for a different response.

Those are the security facts. The office problem is what happens in the five minutes before anyone decides whether a message is real.

A policy binder alone doesn't close this gap. One likely failure point is informal intake — a front-desk inbox, a preparer's personal email, a bilingual text thread, and a habit of opening a file to see what it is. That's the kind of gap a fake prospect email is designed to exploit.

Many offices already run a disciplined first-touch process for real clients: who the taxpayer is, what service they need, which language the household prefers, what documents are missing, and who owns the follow-up. The risk starts when prospect intake skips that same discipline because the message carries urgency and a plausible story, and someone opens the attachment before the office has decided the sender can be trusted.

Authorization workflow visual for tax offices.

A workable quarantine lane for a small bilingual office needs six controls:

1. One first-touch inbox or route for new prospect documents.

2. One named reviewer for attachment and link triage before anything is opened.

3. One status label separating "awaiting verification" from "ready for review."

4. One note field recording how the sender was verified.

5. One escalation rule for suspicious phishing emails specifically, including forwarding to phishing@irs.gov and reporting to TIGTA when applicable — phone and text scams may need a different response.

Authorization workflow visual for tax offices.

6. One record of whether the prospect continues in English or Spanish once cleared.

That is ordinary queue control, not enterprise security theater.

Three habits tend to break it. First, offices sometimes confuse speed with service: answering instantly by opening an unverified attachment trades a small delay for real risk. Second, suspicion gets stored outside the case record: someone says a message "looked weird" in a text or a Slack thread, and a teammate later sees the same sender name, assumes it was cleared, and opens the file anyway. Bilingual offices feel this acutely, since a fraudulent message may arrive in English while the callback happens in Spanish, or the reverse — the risk isn't the language, it's that verification status never made it into the shared record. Third, offices treat every suspicious message as either harmless or catastrophic, when it is usually a triage item that belongs behind a visible status: suspect, escalated, or cleared.

Quarantine in a small office is not a security appliance. It means an attachment, link, or portal invite does not enter the normal workstream until a named reviewer checks the sender's path, domain, story, and request — and clears it, redirects it to a safer intake method, or reports it. Verification first, review second, follow-up third.

Consider a scenario many offices will recognize: known-client extension questions, prior-year clean-up requests, and transcript pulls arrive in the same inbox as messages from new prospects. If that mix occurs and the office hasn't separated known-client follow-up from new-sender intake, a bad message could travel the same well-worn path as a routine document chase.

The metric worth tracking isn't how many phishing emails arrived — it's how many new-sender documents were opened before verification. As an internal operating target we'd recommend (this is an editorial suggestion, not an IRS standard), that number should be zero. A second useful number is how many prospect messages sit without a named owner, since unowned intake tends to get opened just to move the queue. A short weekly check can answer it: how many new prospect messages carried links or attachments, how many were verified before anything opened, how many moved to a safer route, how many were escalated, and how many now have an owner, a language path, and a next step.

The supporting visual should stay operational: a simple flow from new sender to quarantine review to either safe intake or phishing escalation, a four-state status board (unverified, verified safe route, escalated, intake-ready), and a short list of what belongs in the record — sender verified, method changed, report sent, owner assigned.

Authorization workflow visual for tax offices.

Most clients are unlikely to see or use the term "spear phishing." What they notice is whether an office looks careful with documents. Saying "first-time files move through one controlled intake route before anything opens" reads as operational maturity, not marketing.

Intaxion's role here is narrow: it is an intake-and-document workflow layer, not a security guarantee. According to Intaxion's own product page, for signed-in users it supports bilingual intake, document upload, intake status tracking, missing-item follow-up, and preparer review readiness. The sender-verification and quarantine steps described in this article are an office-recommended process, not an Intaxion product feature.

A quick audit for this week: pull the last ten new-sender messages your office received and check whether anyone opened a file before verifying the sender, whether one visible record shows who cleared each intake, whether the next staff member can see the prospect's language path, and whether suspicious or legitimate messages both left a trace — an escalation report or a move into the normal document checklist. A "no" on any of those points is a first-touch control gap, not bad luck.

Intaxion's free Document Checklist is a bilingual checklist builder — a starting point for organizing what you request from new and existing clients, not a substitute for your office's own sender-verification and quarantine process: https://www.intaxion.com/tools/document-checklist

Question for owners: if a new prospect sent a tax file in the next five minutes, who on your team is actually allowed to open it first?

#TaxProfessionals #BilingualTax #TaxOfficeOps #DocumentWorkflow #Intaxion

Sources

  • https://www.irs.gov/newsroom/irs-security-summit-launch-summer-series-to-help-tax-pros-protect-clients-from-identity-theft
  • https://www.irs.gov/tax-professionals/protect-your-clients-protect-yourself-summer-2026
  • https://www.irs.gov/help/report-fraud/report-fake-irs-treasury-or-tax-related-emails-and-messages
  • https://www.irs.gov/tax-professionals/tax-security-2-point-0-the-taxes-security-together-checklist

Open related Intaxion tool

Get our free Tax Preparer Compliance Checklist

A practical checklist to ensure you're meeting all IRS due diligence requirements. Download instantly.

We respect your privacy. Unsubscribe at any time.