The TIGTA outlined the results of its probe in a report released on Sept. 29, identifying 86 suspicious instances involving 52 IRS employees [2]. Investigators reviewed nearly six million searches during that period and determined that the employees conducted the 86 suspicious accesses involving 30 high-profile taxpayers [3]. TIGTA concluded that the IRS does not have effective ways to prevent employees from peeking at celebrities' tax records or detect that access after it happens [1].
Investigators identified 22 employees who were not terminated despite improperly accessing taxpayer information without authorization or consent, according to the watchdog report [4]. The report stated that the IRS UNAX unauthorized access program is not adequately addressing the risk of unauthorized access to taxpayer accounts.
The IRS failed to inform 175 taxpayers that employees had improperly accessed their records because agency personnel did not follow established procedures, the report stated [5]. Another 101 taxpayers were never notified because the responsible employees resigned or retired before disciplinary action was proposed [5].
The findings raise fresh concerns about taxpayer privacy, government accountability and the IRS' ability to safeguard Americans' sensitive financial information. The watchdog found that 91,661 individuals had credentials for IRS systems with sensitive taxpayer information, and while most were IRS employees, more than 5,000 others also had access [6].
TIGTA issued eight recommendations, including strengthening security systems, restricting employee access to sensitive database functions and reinforcing the legal consequences of intentionally accessing taxpayer records without authorization [5]. The IRS agreed or partially agreed with seven recommendations, with corrective measures planned for December 2026, according to the report [7].
However, the agency rejected a recommendation to establish overall timeliness standards for notifying victims, arguing such standards already exist [7]. The watchdog maintained that the IRS unauthorized access program is not adequately addressing the risk of unauthorized access to taxpayers' accounts [7].
Federal and state officials (including former officials) who make disclosures of taxpayer information not authorized by statute can be punished by imprisonment of up to five years and a fine of up to $5,000, according to legal reference materials on taxpayer privacy [8].
President Donald Trump previously filed a lawsuit against the IRS and the Department of the Treasury, alleging the government failed to protect his confidential tax records from unauthorized inspection and disclosure [9]. Trump and the Department of Justice later settled the lawsuit with the IRS, and Trump's attorneys filed a motion to dismiss the case, according to Politico [10].
Former IRS contractor Charles Littlejohn was sentenced to five years in federal prison in January 2024 after leaking confidential tax information belonging to Trump and other wealthy Americans [11]. Littlejohn pleaded guilty in October 2023 to unauthorized disclosure of tax returns and return information [11]. The IRS ultimately determined that approximately 406,000 taxpayers were affected by that breach [11].
The findings come amid longstanding concerns about the IRS's handling of politically sensitive taxpayer information. A federal judge ruled in February 2026 that the IRS violated federal law by disclosing confidential taxpayer information to Immigration and Customs Enforcement approximately 42,695 times, calling the breach a significant failure of legal safeguards [12].
TIGTA concluded that the IRS unauthorized access program is not adequately addressing the risk of unauthorized access to taxpayers' accounts [7][2]. The IRS has planned corrective measures for December 2026, while rejecting victim notification timeliness standards [7].
The findings add to longstanding concerns about taxpayer privacy, government accountability and the IRS's ability to safeguard sensitive financial information. The report follows decades of similar incidents in which IRS employees improperly accessed records of public figures without authorization, including past cases involving celebrities and elected officials [13].
The internal investigation underscores the need for stronger safeguards to protect Americans' confidential financial data from unauthorized access by government employees. The IRS has not announced specific timetables for implementing the seven agreed-upon recommendations beyond the December 2026 target date.