Tax and accounting records contain information that can be used for identity theft and financial fraud. Treat every request for documents as something to verify, even when the message appears to come from a familiar person or service.
Verify the person and the channel
Confirm the professional’s identity and contact details independently. Ask what documents are needed, why they are needed, and which secure portal or transfer method should be used. Do not send sensitive files in an initial support conversation.
Strengthen account access
Use unique passwords, a password manager, and multifactor authentication for email, financial, accounting, payroll, and document-storage accounts. Remove former users promptly and review account recovery details.
Share only what is necessary
Redact information when a full identifier is not required, limit access to the engagement team, and avoid public links. Keep a record of what you shared, with whom, for what purpose, and when access should end.
Respond quickly to suspicious activity
If you believe records or credentials were exposed, stop communication, change affected passwords, contact relevant financial institutions, preserve evidence, and follow current reporting and identity-protection guidance from the IRS and other appropriate authorities.