|
Unauthorized access can lead to the disclosure of taxpayer information, which undermines public trust in the IRS’s ability to protect confidential tax information. In our newest report, we made six recommendations to help ensure that IRS employees without a business need do not retain access to the IRS’s network or sensitive systems.
Why did we do this evaluation?
In 2023, an IRS contractor admitted to accessing a database to obtain tax return information for thousands of the nation’s wealthiest individuals. We subsequently reported on the IRS’s controls for granting access to and safeguarding federal tax information stored on its information technology systems.
This time, we assessed whether the IRS has taken appropriate steps to ensure that only authorized employees and contractors can access its network and sensitive data systems.
What did we find?
We found that approximately 17,000 of the nearly 21,500 IRS employees on administrative leave retained access to the IRS network (as of June 2025). These employees were on administrative leave because they accepted the deferred resignation offer. Additionally, over 14,000 of the nearly 21,500 employees kept access to one or more sensitive systems. These employees did not have a legitimate business reason to retain this access and posed a potential security risk for unauthorized disclosure of sensitive information.
Further, some of these individuals could have accessed IRS facilities or systems because the IRS did not initially have a policy to collect or disable Personal Identity Verification (PIV) cards of employees on administrative leave. PIV cards are federal government-issued identification cards that allow access to secure facilities and are used to access information systems and networks.
For more information:
Having trouble viewing this email? View it as a Web page.
|