IRS Security Summit 2026: Why Payroll Data Is Now a Bigger Security Concern for Small Businesses
07 October, 2026
A payroll file holds far more than paychecks. For each employee, it can include a name, address, Social Security number, wages, and withholding details, which is much of what a criminal needs to file a believable fake tax return. In June 2026, the IRS and its Security Summit partners restructured their anti-fraud program with a sharper focus on payroll partners, which makes payroll data security a practical concern for small businesses.
Why Payroll Data Is a Security Risk
A common reaction is, "We’re too small to be a target." Criminals, though, go where data is useful, not where a company is famous. Payroll and HR records can include employee names, Social Security numbers, wage and tax information, W-2 data, direct deposit details, and employer information. What a given system stores depends on the software and the business, and not every system holds every item.
The IRS has described the logic: as agencies and software providers improve return screening, cybercriminals need more genuine data to impersonate real taxpayers. A ten-person company’s W-2 file contains the same sensitive fields as a larger company’s.
What Is the IRS Security Summit?
The Security Summit is a public-private partnership, formed in 2015, that brings together the IRS, state tax agencies, tax software companies, tax professionals, and other members of the tax community. Its purpose is to combat tax-related identity theft and fraud. It is not a cybersecurity certification, a software standard, or a regulation, and businesses do not enroll in it.
What Changed With the IRS Security Summit in 2026?
On June 8, 2026, the IRS and Security Summit partners announced a restructuring of the partnership. The IRS said the new structure strengthens collaboration with payroll partners, whose wage and withholding data has become an attractive target for cybercriminals. The IRS framed the change as a response to evolving identity theft and fraud, including criminals who go after the underlying tax and financial information.
The work now
sits in five groups:
- Pre-Filing: catches suspicious information returns and unusual behavior in payroll and tax processes before they reach a return.
- Forecasting: anticipates new schemes before they spread.
- Preventing: builds safeguards, including across payroll systems and data exchanges.
- Detecting and Reporting: flags fraud indicators quickly and shares intelligence, payroll industry included.
- Responding: applies technical controls and coordinated action when incidents happen.
In plain terms, payroll providers are now a more central part of the tax-fraud picture, and wage data is watched accordingly. The announcement does not create a new cybersecurity law for small businesses or set required controls for employers. The IRS’s October 1, 2026 Tax Tip recapping the summer series for tax professionals repeated familiar themes: phishing awareness, written security plans, multifactor authentication, and breach reporting.
How Hackers Can Steal Payroll Information
Most payroll data theft starts with a person, not a technical break-in.
Business Email Compromise and W-2 Scams
A criminal posing as an executive emails payroll or HR and asks for employee W-2 data. Because staff believes they are answering the boss, the IRS notes it can take weeks to realize anything was stolen.
Phishing and Spear Phishing
Fake emails, texts, or login pages try to capture credentials. Spear phishing aims at a specific person with a more convincing message. The IRS lists payroll offices and HR departments among likely targets of whaling attacks.
Compromised Accounts
A stolen or reused password can give someone the same access as the real user, without any technical skill.
Weak Internal Access Controls
When many people can see salary and Social Security data, or share one login, there are more places for data to leak and no clear record of who viewed what.
How Small Businesses Can Protect Payroll Data
FTC and NIST small-business guidance both start with knowing what sensitive data you hold, limiting who can reach it, and planning for incidents. In payroll, that looks like this:
- Turn on multifactor authentication for payroll, email, and banking accounts, and use unique passwords kept in a password manager.
- Give every user an individual account, limit access by job role, and review who has access regularly.
- Encrypt laptops and files that hold employee data, install updates promptly, and keep tested backups.
- Train staff to recognize phishing and impersonation.
- Write a short response plan covering who to call, what to preserve, and who must be notified, and report suspected data theft promptly.
How Businesses Can Prevent W-2 Data Theft
The classic scam works because it sounds routine: an "executive" urgently wants every employee’s W-2. Practical controls include:
- Confirm unusual or bulk requests by phone or in person, using a number you already have. The IRS has suggested verbal confirmation before emailing W-2 data.
- Decide in advance who may authorize bulk employee-data requests, and limit access to employee tax records.
- Brief payroll and HR staff on this specific scam.
If data is lost, the IRS asks employers to email dataloss@irs.gov (without attaching employee personal information), contact the Federation of Tax Administrators about state reporting, file a complaint with the FBI’s Internet Crime Complaint Center, and notify employees.
What Security Features Should Payroll Software Have?
When evaluating secure payroll software, treat security as a combination of vendor controls, your own access rules, and employee habits. No single feature makes a system secure, and providers differ, so ask each vendor for current documentation, including its update practices and incident-response procedures.
|
Security Area |
What to Look For |
Why It Matters |
|
MFA |
Multiple verification factors at login |
Helps protect against compromised passwords |
|
Access controls |
Access based on job responsibilities |
Limits exposure of sensitive payroll data |
|
Encryption |
Protection for sensitive data in appropriate situations |
Reduces exposure if data is intercepted or accessed improperly |
|
User accounts |
Individual accounts instead of shared logins |
Improves accountability and access management |
|
Security monitoring |
Activity logs or security alerts, where available |
Can help identify suspicious activity |
Does the IRS Require Businesses to Protect Payroll Data?
It depends on who you are. The Security Summit itself places no mandate on employers. The IRS publishes guidance and recommendations, such as Publication 4557, Safeguarding Taxpayer Data, and the "Security Six" protections, but these are aimed mainly at tax professionals and are not rules for every business.
According to the IRS, tax and accounting professionals are required by law to have a Written Information Security Plan, and multifactor authentication is a requirement for them under the FTC Safeguards Rule. Employers may also face state data-protection and breach-notification laws or contract terms. No blanket IRS rule makes every business use MFA. This is general information, not legal advice.
What Small Businesses Should Do Now
- Review who can access payroll information.
- Turn on MFA wherever it is available.
- Verify unusual W-2 or employee-data requests.
- Review your payroll vendor’s security controls.
- Train payroll and HR staff on phishing and impersonation.
- Create a response process for suspected data theft.
- Keep systems and software updated.
Choosing Payroll Software With Security in Mind
Payroll Made Simple is the idea behind PayProNext, a cloud-based platform for U.S. small businesses that covers payroll processing, federal, state, and local tax filing, W-2 and 1099 management, direct deposit, and contractor payments. Whichever provider you consider, weigh security controls alongside payroll functionality, tax handling, access management, and support, and ask for the provider’s current security documentation.
Frequently Asked Questions
Why is payroll a data security risk?
Payroll is a security risk because it can hold information criminals use for identity theft and fraudulent tax returns. Depending on the system, that may include names, Social Security numbers, wages, W-2 data, and bank details. Risk varies by business and software.
How can small businesses protect payroll data?
Small businesses can protect payroll data by limiting access, using multifactor authentication, giving each person a unique account, and training staff to spot phishing. Keep software updated, back up files, write a simple response plan, and report suspected theft promptly.
What is the IRS Security Summit?
The IRS Security Summit is a public-private partnership, formed in 2015, that unites the IRS, state tax agencies, tax software companies, tax professionals, and others to fight tax-related identity theft and fraud. It is a coordination effort, not a certification or a regulation for businesses.
What changed with the IRS Security Summit in 2026?
In June 2026, the IRS and its partners restructured the Security Summit into five work groups: Pre-Filing, Forecasting, Preventing, Detecting and Reporting, and Responding. The new structure increases collaboration with payroll partners because wage and withholding data has become an attractive target for cybercriminals.
How do hackers steal payroll information?
Most payroll data theft starts with social engineering. Criminals impersonate executives, send phishing messages or fake login pages to capture credentials, or use stolen passwords. Broad internal access can also expose records. Recognizing unusual requests and securing accounts addresses the most common paths.
How can businesses prevent W-2 data theft?
Verify any unusual request for employee W-2 data through a separate channel, such as a call to a known number, before sending anything. Limit who can access tax records, use MFA, and train payroll and HR staff. If data is lost, report it to the IRS at dataloss@irs.gov.
Should payroll software use multifactor authentication?
Yes, MFA is a sound safeguard because it helps protect accounts when a password is stolen. The IRS includes it in its Security Six for tax professionals, and the FTC Safeguards Rule requires it for covered tax professionals. It is not a legal requirement for every employer, and it does not make a system immune.
What security features should payroll software have?
Look for multifactor authentication, individual user accounts, role-based permissions, encryption, activity logging where available, regular updates, and a documented incident-response process. No single feature makes software secure, so ask vendors for current security documentation and compare it with your own access practices.
Does the IRS require businesses to protect payroll data?
Not through the Security Summit, which sets no mandate for employers. The IRS issues guidance, while specific legal duties, such as a Written Information Security Plan, apply to tax professionals. State laws and contracts may also apply to employers, so check the requirements for your situation.