A Treasury watchdog flagged 86 suspicious accesses involving 52 IRS employees and 30 high-profile taxpayers — and found the agency still has major gaps in how it detects and prevents unauthorized browsing.
The IRS has a very simple rule for its employees: just because you can look at someone’s tax return does not mean you get to look at someone’s tax return. A new watchdog report suggests dozens of employees needed that lesson repeated.
The Treasury Inspector General for Tax Administration identified 86 suspicious accesses involving 52 IRS employees and 30 high-profile taxpayers between 2022 and 2025. The taxpayers included government officials, business leaders and entertainers, according to the report. The watchdog did not publicly identify the individuals whose records were accessed.
That distinction matters because tax records are among the most tightly protected documents the federal government holds. They can reveal income, business interests, investments, deductions, addresses and other financial details. IRS employees need access to taxpayer information to do their jobs, but federal law sharply restricts them from browsing records without a legitimate business purpose.
The report found the agency’s controls were not good enough to reliably stop or detect unauthorized snooping. Investigators reviewed millions of system queries and found certain searches could slip around ordinary monitoring tools, including commands that allowed employees to search using part of a taxpayer’s name.
Which means that, in an era when your streaming service can detect that you logged in from a different sofa, the federal tax system was still struggling to reliably flag employees poking around celebrity accounts out of curiosity.
The inspector general also found problems after suspicious access was discovered. In a separate set of confirmed unauthorized-access cases, some employees were fired while others received lesser discipline. The IRS said federal employment rules require managers to consider mitigating factors, including prior service and whether the conduct was a first offense.
The victim-notification process was messy too. The watchdog found that hundreds of taxpayers were not notified in cases where employees had improperly accessed records. Some missed notifications happened because procedures were not followed; others involved employees who retired or resigned before formal discipline was proposed.
That is not a small administrative detail. If someone inside the IRS improperly looks at your records, knowing that it happened gives you at least some chance to watch for financial misuse, identity theft or other fallout. Finding out years later because an audit finally connected the dots is less helpful.
The IRS says it takes taxpayer privacy seriously and agreed or partially agreed with most of the watchdog’s recommendations. Planned fixes include examining stronger system controls, tightening access to certain search commands and improving the way potential violations are detected.
The report arrives with unusually bad timing for an agency already haunted by one of the biggest tax-data scandals in recent history. Former IRS contractor Charles Littlejohn stole and leaked confidential tax information involving Donald Trump and thousands of wealthy Americans. He later pleaded guilty and received a five-year federal prison sentence.
The new watchdog findings are not the same as the Littlejohn case. There is no public evidence that the 86 suspicious accesses resulted in leaked returns or that every flagged employee committed a crime. The report is about suspicious and unauthorized access, weak controls and the IRS’s ability to police its own systems.
But that is still an uncomfortable problem for an agency whose entire operating model depends on Americans handing over extraordinarily sensitive information. The IRS can require taxpayers to disclose almost everything about their finances. In exchange, taxpayers are entitled to assume the employee processing their account is not opening it because they recognize the name.
There is a difference between an auditor reviewing your return and somebody treating the IRS database like Celebrity Net Worth with better documentation.
The real question is whether the latest fixes will make unauthorized browsing materially harder, or whether the government is still relying too heavily on catching employees after curiosity has already turned into a privacy violation.





