
Most of us know we should protect our personal information online. But it’s worth considering just how much sensitive information is contained in the financial documents we routinely access, store, and share.
A tax return alone may contain Social Security numbers, income information, addresses, banking details, information about dependents, business interests, investments, and other data that could be extremely valuable in the wrong hands.
For business owners, the stakes can be even higher. Payroll information, employee data, financial statements, tax identification numbers, account information, and other records can create opportunities for criminals when they aren’t adequately protected.
October is Cybersecurity Awareness Month, making it a good time to look at the everyday habits that can help protect your financial information.
And increasingly, one of the most important habits is simply knowing when to stop and verify.
Scams Are Becoming More Convincing
Many of us have learned to recognize the classic scam email filled with misspellings, strange formatting, and an obviously suspicious sender.
Unfortunately, today’s scams aren’t always that easy to spot.
The IRS's 2026 Dirty Dozen list of tax scams includes IRS impersonation through email and text, as well as AI-enabled impersonation by phone. Criminals can use technology to make messages, voices, caller identification, and other communications appear increasingly legitimate. (IRS)
That means we can no longer rely solely on whether something “looks real.”
Instead, pay attention to what the communication is asking you to do.
The IRS identifies several common warning signs, including unexpected communications, pressure to act quickly, threats, requests for personal or financial information, and demands for immediate payment. (IRS)
If something feels unusual, slowing down may be one of the best things you can do.
Before You Click, Take 30 Seconds
When you receive an unexpected email, text, or other message involving your taxes or finances, ask yourself a few questions before responding:
Was I expecting this message?
Is it asking me to provide sensitive personal or financial information?
Is there pressure to act immediately?
Does the sender's address, phone number, wording, or link look even slightly unusual?
Can I verify this request another way?
If a message appears to come from a bank, financial institution, government agency, CPA, or other trusted organization, you can independently contact that organization using a phone number or website you already know to be legitimate.
Avoid using the contact information or links provided in the suspicious message itself.
That extra minute can be worth far more than the time it takes.
Treat Unexpected IRS Messages With Caution
Scammers frequently use the IRS name because taxes naturally create a sense of urgency.
An unexpected message might claim that you owe money, have an unclaimed refund, need to verify your account, or must provide information immediately to avoid a penalty.
The IRS advises taxpayers not to reply to suspicious IRS-related emails or click links or open attachments contained in them. Suspicious communications can also be reported to the agency. (IRS)
If you receive something and aren't sure whether it's legitimate, don't let urgency make the decision for you.
Verify first.
Use Multifactor Authentication
A strong password is important, but passwords can be compromised.
Multifactor authentication adds another layer of protection by requiring additional verification before someone can access an account. The IRS recommends using it wherever available, particularly for accounts containing sensitive financial or tax information. (IRS)
Consider enabling multifactor authentication for your:
• Banking and investment accounts
• Accounting software
• Cloud storage
• Payroll systems
• Tax-related accounts
• Other services containing sensitive personal or business information
It may add a few seconds to the login process. Those few seconds can make unauthorized access significantly more difficult.
Your Email Account Deserves Extra Attention
Your email account can be a gateway to a tremendous amount of personal and financial information.
Think about what passes through your inbox over the course of a year: invoices, financial statements, password resets, account notifications, business documents, tax information, payroll conversations, and communications with financial professionals.
If someone gains access to your email, they may be able to gather information about you, impersonate you, or use legitimate past conversations to make a fraudulent request appear more convincing.
Use a strong, unique password for your email account, enable multifactor authentication, and be cautious about accessing sensitive information while using unsecured networks or shared devices.
Be Thoughtful About How You Share Financial Documents
Sometimes protecting financial information is less about sophisticated technology and more about everyday behavior.
Before sending a document containing Social Security numbers, banking information, tax identification numbers, payroll records, or other sensitive data, consider how you're sending it and who will have access to it.
When a secure portal or other protected method is available for exchanging sensitive documents, use it rather than defaulting to ordinary email.
And if you receive an unexpected request for sensitive financial information, even from someone whose name you recognize, verify the request separately before sending anything.
Business Owners Should Think Beyond Their Own Accounts
For business owners, cybersecurity isn't only about protecting personal information.
Your company may hold sensitive information belonging to employees, customers, vendors, or other individuals. A compromised email account, payroll system, or financial platform can therefore affect far more people than the person whose password was stolen.
The IRS advises businesses to remain vigilant about phishing and other cyberattacks and recommends measures including strong passwords, multifactor authentication, updated security software, and caution around unexpected requests for sensitive information. (IRS)
Cybersecurity should be treated as part of normal business risk management, not simply an IT issue.
If Something Doesn't Look Right, Say Something
One of the simplest ways to prevent fraud is to create a habit of verification.
If you receive an unusual request involving a payment, banking information, tax documents, payroll records, or other sensitive financial information, don't be embarrassed to double-check it.
Call the person or organization using contact information you trust.
Ask whether they actually sent the request.
If you're uncertain about something that appears to involve your taxes, contact your CPA before responding.
A legitimate request can withstand a few extra minutes of verification.
Small Habits Can Protect Valuable Information
Cybersecurity can sound highly technical, but many of the most important protections come down to simple habits.
Use strong, unique passwords. Turn on multifactor authentication. Keep devices and security software updated. Be careful with sensitive documents. Question unexpected requests. Avoid clicking unfamiliar links. And when something creates a sense of urgency, give yourself a moment to verify before acting.
If you believe your tax identity or personal information has been compromised, act quickly. The IRS recommends stopping communication with the suspected scammer, contacting affected financial institutions, reporting identity theft when appropriate, and taking steps to protect your tax account. (IRS)
At Waters Hardy, protecting our clients' financial information and helping them navigate an increasingly complex financial environment are responsibilities we take seriously.
If you receive a suspicious tax-related communication or aren't sure whether something involving your financial information is legitimate, reach out to our team. Sometimes the smartest thing you can do is ask before you act.