PolicyExplainer
IRS Employees Accessed Tax Records of Officials and Business Leaders With Little Oversight
A Treasury Inspector General report found 52 IRS employees made 86 suspicious accesses to high-profile taxpayers' records, exploiting system gaps that let search functions bypass monitoring.

A Treasury Inspector General for Tax Administration report released in late September 2026 found that 52 Internal Revenue Service employees conducted 86 suspicious accesses to the tax records of 30 high-profile taxpayers—including government officials, business leaders and entertainers—between 2022 and 2025. The report exposed critical gaps in the agency's systems for preventing and detecting unauthorized browsing, revealing that certain search functions let employees bypass IRS monitoring methods entirely.
For business leaders and officers of public companies, the findings underscore vulnerabilities in how the IRS protects sensitive financial data. Among 53 confirmed unauthorized-access cases from fiscal years 2023 through 2025, the IRS terminated 31 employees but retained 22 others, despite agency policy requiring removal for such violations. The findings emerge within a pattern of oversight gaps documented over more than a decade: investigators identified 1,694 cases of unauthorized employee access to taxpayer data between 2012 and 2021, with approximately 27 percent substantiated as violations.
How the UNAX Monitoring Program Failed
The IRS maintains a formal program called UNAX—Unauthorized Access—designed to address the risk of employees browsing taxpayer accounts without legitimate tax administration purpose. IRS employees are permitted to access taxpayer information only when required for their official duties, and unauthorized access or disclosure violations can carry criminal penalties, including imprisonment or fines.
Yet TIGTA's review of approximately 6 million searches across the IRS's systems nearly four years found critical deficiencies. The IRS's internal account-access system includes certain NAMES search commands that allow employees to retrieve identifying information using only part of a taxpayer's last name. These searches bypassed the monitoring methods the agency uses to detect suspicious browsing patterns. An employee could search for a surname without triggering the same alert systems designed to catch other forms of unauthorized access. Additionally, the agency had no preventive or monitoring controls specifically protecting the accounts of celebrities and public officials.
Disciplinary Guidelines Undermined by Implementation
IRS policy is explicit: removal of the employee is to be proposed for all unauthorized access violations under the UNAX program. However, the disciplinary guidelines allow the deciding official to mitigate penalties based on factors surrounding individual cases, such as tenure or whether the violation was a first offense. This discretion, TIGTA found, has resulted in inconsistent enforcement that may undermine the agency's stated zero-tolerance approach.
Among the 53 confirmed unauthorized-access cases from fiscal years 2023 through 2025, the IRS terminated 31 employees, or 58 percent of those found to have violated policy. The remaining 22 received reduced discipline. This stands in contrast to historical outcomes: an earlier Government Accountability Office report documented that more than 82 percent of confirmed unauthorized-access violations between 2012 and 2021 resulted in employee suspension, resignation or removal. The gap between stated policy and disciplinary action in the current cases raises questions about how consistently the IRS enforces its own rules.
Notification Failures Affecting Hundreds of Taxpayers
Notification of affected taxpayers proceeded unevenly and incompletely. TIGTA examined 122 closed cases and found that the IRS failed to notify 276 taxpayers of unauthorized access. Of those, 175 taxpayers were not notified because IRS personnel did not follow established notification procedures in 42 of the cases. The remaining 101 taxpayers were not notified because the responsible employees had already resigned or retired before the IRS could propose disciplinary action.
Some taxpayers experienced extraordinary delays in learning their records had been accessed. Eleven victims learned of the breach between 1,001 and 1,423 days after the unauthorized access occurred—roughly three to four years after their records were viewed. The IRS and TIGTA disputed whether the agency should establish specific timeliness standards for victim notification. TIGTA recommended formal time limits to ensure prompt notification. The IRS disagreed, claiming that adequate notification procedures already existed.
Regulatory Demands and Uncertain Outcomes
TIGTA issued eight recommendations aimed at closing the gaps that enabled the unauthorized access. The recommendations include studying technological and systemic changes capable of preventing unauthorized access, reducing or more closely controlling the number of employees able to use certain taxpayer-search functions, and strengthening monitoring of suspicious activity. The inspector general also called for issuing guidance emphasizing the legal weight of intentional UNAX violations to reinforce consequences for employees.
Acting IRS Chief Privacy Officer John Walker responded that the agency agreed or partially agreed with seven of the eight recommendations, with corrective actions planned for December 2026. The contested recommendation again involved notification standards. For business executives and officers, the report signals awareness of monitoring deficiencies and regulatory pressure for reform, but raises questions about implementation speed and enforcement consistency. The findings also follow the 2024 prison sentence of Charles Littlejohn, a former IRS contractor convicted for disclosing thousands of tax returns to the public, underscoring broader institutional risks in protecting sensitive taxpayer information.






