← Blog

IRS Data Breaches: Full Timeline Through 2026

Share on X

People search IRS data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 4 IRS-linked incidents, with headline counts up to 28.2M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.

Why IRS breach history matters

IRS operates in Government. Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.

Full timeline through 2026

2017 — 100,000 records

Cataloged incident. Apr 2017. Up to 100,000 taxpayers had personal data compromised via IRS Data Retrieval Tool used for FAFSA. Identity thieves used stolen PII to initiate FAFSA applications and retrieve adjusted gross income. Unauthorized access detected since Sep 2016. IRS shut down tool in Mar 2017; restored Oct 2017 with enhanced encryption. Exposed categories include Names, AGI, tax information. BreachHistory cites approximately 100K+ affected records in this row. See the irs2017 and canonical BreachHistory entry.

2016 — — IRS: A recent report from the Treasury Inspector General…

Cataloged incident. A recent report from the Treasury Inspector General for Tax Administration (TIGTA) found that IRS employees sent unencrypted emails which contained 8,031 different taxpayers’ personally identifiable information. According to the report, TIGTA found 326 unencrypted emails containing taxpayer data. 275 of the emails were sent internally within IRS, while 51 emails were sent outside of the agency’s network to non-IRS email accounts. Of those emails sent externally, 20 were sent to six IRS employees Exposed categories include Personal information. BreachHistory cites approximately 28.2M+ affected records in this row. See the irs2016 and canonical BreachHistory entry.

2015 — — IRS: An unnamed cybermafia used an IRS app to download…

Unverified claim — treat actor counts cautiously. An unnamed cybermafia used an IRS app to download forms full of personal information. They posed as legitimate taxpayers, and tried to download forms on 200,000 people between February and May. They got away with half of them, the IRS said. The crooks used about 15,000 of them to claim tax refunds in other people's names. BreachHistory cites approximately 100K+ affected records in this row. See the irsu and canonical BreachHistory entry.

2014 — — IRS: A former emloyee of the IRS took home a computer…

Cataloged incident. A former emloyee of the IRS took home a computer thumb drive that contained personal information on 20,000 current and former employees and contractors. The information included Social Security numbers, names and addresses. The thumb drive was plugged into the employees unsecured network, which could have left the information vulnerable. This incidence dates back to 2007 before the IRS stared using automatic encryption. The IRS will not comment why they did not discover this breach until now, or Exposed categories include Personal information. BreachHistory cites approximately 20K+ affected records in this row. See the irs2014 and canonical BreachHistory entry.

Patterns and analysis

  • Mixed intrusion and disclosure events — appears across multiple IRS catalog entries; prioritize controls that address this class of failure.
  • Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
  • 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.

What to do if you may be affected

  1. Step 1: Enable phishing-resistant MFA on every account tied to this brand.
  2. Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
  3. Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
  4. Step 4: Bookmark the IRS company page for new 2026+ disclosures.

Canonical BreachHistory hub

Explore every indexed row: breachhistory.com/irs · Latest: irs2017.

Sources: BreachHistory catalog (4 rows for IRS), company and regulator disclosures cited in individual breach records.