The Internal Revenue Service's effort to reduce the amount of paper it deals with may be exposing taxpayer data to unwanted security vulnerabilities.
The Treasury Inspector General for Tax Administration released a
However, TIGTA inspectors identified deficiencies in physical security controls designed to safeguard taxpayer data, security vulnerabilities in the information systems used to process taxpayer information, and weaknesses in information system configuration controls.
During the inspectors' site visits, they found that 14 employees accessed areas with taxpayer information without being authorized by the IRS. The employees accessed areas where taxpayer documents were scanned, digitized or stored on 1,375 occasions last year at the two sites.
The perimeter fence and loading dock used to receive taxpayer information were
open and not properly secured at one of the sites. "The loading dock allows entry into the facility's document storage area that contains taxpayer information," said the memo. "In addition, there were no guards controlling access to the area."
During TIGTA's discussions with representatives of the contractor, they said the loading dock is left open during the day and locked at night and claimed their contract didn't require the use of guards within the facility. But TIGTA disagreed, saying the contractors are responsible
for safeguarding taxpayer data and need to implement security controls in accordance with IRS policies. The IRS plans to update its Publication 4812 for 2027 to require contractors to review access logs monthly or more frequently at the discretion of the IRS.
The inspectors also found problems with cybersecurity. They identified 128 (48 percent) of 269 security vulnerabilities in information systems that process taxpayer information were not resolved on a timely basis. It said the IRS Cybersecurity function's limited review during the contractor security assessments would not have identified overdue vulnerabilities. Examples of such vulnerabilities included systems using a software version that was no longer
supported by the vendor with security updates, or when the software was still supported by the vendor, the available security updates not being installed. One site used unauthorized software to scan its information systems for vulnerabilities. TIGTA found the contractor was using open-source software that was not validated to use Security Content Automation Protocol standards.
After TIGTA provided the memorandum to the IRS for review and response, the IRS indicated that it has taken or would take corrective actions to address TIGTA's concerns. TIGTA plans to visit the other contractors' facilities as they start scanning paper tax returns and will include those results, and any actions the IRS takes to address those concerns, in a future audit report.







