IRS cyber weaknesses put taxpayer data at risk again, TIGTA says
September 24, 2026
For the second consecutive year, a watchdog has labeled the IRS’s cybersecurity program so ineffective that taxpayer data could be at risk if the agency fails to address security weaknesses.
For the 2026 fiscal year, a report from the Treasury Inspector General for Tax Administration found that 86%, or six of seven, sampled information systems had critical vulnerabilities that were not fixed within the IRS’s required 30-day time frame.
The report also said the agency could not provide an inventory of its critical software. “If the IRS does not take steps to mitigate these deficiencies, taxpayer data could be vulnerable to inappropriate and undetected use, modification or disclosure,” TIGTA said in the report.
Among other findings, TIGTA reported that 841 privileged service accounts spanning 313 systems remain outside the IRS’s privileged account management system. Learn more.