Intaxion
Operations

A Practical Suspicious-Email Handoff for Small Tax Offices

Published September 3, 2026
6 min read
Two small-office professionals pause at a laptop while transferring a blank handoff sheet and folder for follow-up.

An unexpected email arrives with an urgent request. The sender’s domain is off by one character, or a follow-up message contains a different attachment. These details call for caution, but they do not prove that malware was installed, an account was compromised, or client data was stolen.

The IRS Security Summit has warned tax professionals about phishing emails and related attacks. Small offices can make their response more consistent with a straightforward internal handoff: pause interaction, document what was observed, preserve the message, assign an owner, and choose the reporting path that fits the known facts.

This is a suggested office workflow, not a universal sequence required by the IRS.

Record warning signs without turning them into conclusions

Warning signs may include unexpected contact, unusual urgency, a slightly altered sender address or domain, or a duplicate message with a different link or attachment. The IRS Security Summit warning and IRS Publication 4557 provide more information about recognizing phishing.

Describe only what can be observed. For example, record “the displayed domain differed by one character from the expected domain,” rather than “the account was breached.” The first statement documents an observation; the second makes a determination that the available evidence may not support.

1. Pause interaction

Do not reply, click a link, or open an attachment while the message moves through the office’s designated process. If someone already interacted with it, record exactly what happened without speculating about the result.

2. Create a short internal record

Useful fields may include:

  • Date and time received
  • Person who noticed the message
  • Displayed sender and apparent domain
  • Action requested by the sender
  • Urgent or pressuring language
  • Links or attachments seen but not opened
  • Any reply, click, download, or other interaction that already occurred
  • Questions that remain unresolved

This record is a suggested internal tool. It is not an IRS form and does not replace professional guidance that may apply to the office.

Workflow diagram showing the office steps described in the English article.

3. Preserve the message

Keep the original message available for the person assigned to handle it. The IRS instructions for reporting fake IRS, Treasury, or tax-related messages explain that saving or forwarding an email as an attachment, or providing its header, may preserve more identifying information than an ordinary forward.

Staff should not attempt unfamiliar technical procedures without appropriate support. The internal record can note how the message was preserved and who can access it.

4. Assign an owner

Send the record and preserved message to the person designated by the office. That person takes responsibility for the next procedural decision, including whether more information is needed and which reporting path matches the facts.

For this suggested workflow, the office would need to identify who fills this role. The responsibility may appear in an internal plan, but this handoff is not an IRS-mandated structure. It also may not cover every legal, contractual, insurance, state, or professional obligation that could apply.

Decision matrix comparing the workflow choices described in the English article.

5. Match the reporting path to the situation

A suspicious message by itself does not establish that client data was stolen. Targeted phishing and an actual security or data breach have distinct IRS instructions. If the facts remain unresolved, keep the internal classification provisional rather than treating the situation as confirmed theft.

Targeted phishing aimed at a tax professional

For targeted phishing, the IRS instructs tax professionals not to reply, click links, or open attachments. Submit the message to phishing@irs.gov with the subject “Spearphishing”. When feasible, preserve identifying information by sending the email as an attachment or providing its header. Check the current conditions on the IRS reporting page.

An actual security or data breach or data theft

If an office has had a security or data breach, or a tax professional is a victim of data theft, the IRS directs the tax professional to contact the local IRS Stakeholder Liaison immediately. The IRS page on identity-theft information for tax professionals describes this response path. This statement does not imply that these are the only circumstances in which liaison contact may be appropriate.

An unconfirmed warning sign or suspected theft does not, by itself, establish that a breach or data theft occurred. Keep unresolved cases provisional while the office determines the facts with appropriate support. Depending on the facts and jurisdiction, state channels or other obligations may also apply. This article does not determine whether a breach or theft occurred and does not provide legal, tax, cybersecurity, or compliance advice.

A compact handoff template

  • Observer:
  • Date and time:
  • Observable warning signs:
  • Interaction status: No interaction / reply sent / link clicked / attachment opened / other
  • Preservation method:
  • Assigned owner:
  • Current classification: Suspicious message / targeted phishing / actual security or data breach / unresolved
  • Reporting action:
  • Unresolved questions:

Keep the classification provisional while facts remain uncertain. Add verified information as it becomes available instead of rewriting earlier observations as conclusions.

Operational checklist summarizing the readiness steps in the English article.

Where Intaxion fits

Intaxion may complement this process as a workflow and documentation layer for defining office responsibilities and recurring procedures. It does not inspect email, provide incident-response services, replace IRS instructions, or establish compliance or a security outcome.

Explore the Intaxion WISP generator as a resource for documenting office responsibilities and workflows. Any resulting material remains subject to the office’s review and applicable professional guidance.

Official sources

Get our free Tax Preparer Compliance Checklist

A practical checklist to help you review whether your process addresses IRS due-diligence requirements. Your office remains responsible for applying the rules. Download instantly.

We respect your privacy. Unsubscribe at any time.