IRS Couldn't Detect Suspicious Searches of Politicians, CEOs, and Celebrities

Advertisement
IRS Couldn't Detect Suspicious Searches of Politicians, CEOs, and Celebrities
AP Photo/Patrick Semansky, File

The IRS has spent decades warning its employees that curiosity isn’t a legitimate reason to look at somebody’s tax records. Its own watchdog now says the agency still couldn’t reliably detect employees searching the accounts of government officials, business leaders, and entertainers. Investigators reviewed nearly 6 million searches from 2022 through November 2025, and found that 52 IRS employees conducted 86 suspicious accesses involving 30 high-profile taxpayers. Those searches have been referred for investigation, so they shouldn’t yet be described as proven violations.

Advertisement

The technical hole is almost worse than the raw number. Authorized IRS employees use a system called IDRS, but the agency had no systemic control limiting those employees to only the taxpayer accounts assigned to them. Certain “NAMES” search commands let an employee use part of a taxpayer’s last name to retrieve identifying information, and those searches bypassed the IRS monitoring methods used to detect unauthorized browsing. The Treasury Inspector General for Tax Administration (TIGTA) found no preventive or monitoring controls specifically protecting the accounts of celebrities and public officials.

The discipline numbers aren’t much more comforting. In a separate review of 53 confirmed unauthorized-access cases from fiscal years 2023 through 2025, the IRS fired 31 employees but kept 22, although all 22 received some form of discipline. In 13 of those cases, decision-makers cited length of service and a first offense as reasons for not firing the employee. IRS officials noted that federal employment law requires consideration of mitigating factors, but TIGTA pointed out that the agency’s own penalty guide lists removal for unauthorized browsing without the taxpayers’ knowledge or consent.

Then come the people who weren’t told. TIGTA examined 122 closed unauthorized-access cases, and found that 276 affected taxpayers went without notification. Employees failed to follow procedures involving 175 of them, while another 101 weren’t notified, because the IRS employees involved had retired or resigned before discipline was proposed. The IRS has since reviewed cases and said 182 taxpayers were notified, but TIGTA also found some notices arrived hundreds of days late, with 11 taxpayers waiting between 1,001 and 1,423 days.

Advertisement

Nothing in this audit establishes that the 86 suspicious searches resulted in leaked tax returns. Americans already know, however, what can happen when IRS access control fails. Former contractor Charles Littlejohn stole and disclosed thousands of tax returns, including President Donald Trump’s information and records involving some of America’s wealthiest taxpayers. He pleaded guilty and received a five-year federal prison sentence.

From the Department of Justice:

Littlejohn accessed tax returns associated with Public Official A (and related individuals and entities) on an IRS database after using broad search parameters designed to conceal the true purpose of his queries. He then uploaded the tax returns to a private website in order to avoid IRS protocols established to detect and prevent large downloads or uploads from IRS devices or systems. 

Littlejohn then saved the tax returns to multiple personal storage devices, including an iPod, before contacting News Organization 1. Between around August 2019 and October 2019, Littlejohn provided News Organization 1 with the tax return information associated with Public Official A. 

Littlejohn subsequently stole additional tax return information related to Public Official A and provided it to News Organization 1. Beginning in September 2020, News Organization 1 published a series of articles about Public Official A’s tax returns using the tax return information obtained from Littlejohn.

Advertisement

The IRS agreed or partially agreed with seven of TIGTA’s eight recommendations, and says it will strengthen access controls, monitoring, discipline guidance, and oversight. Those fixes are welcome, but they arrive after inspectors discovered searches the IRS itself hadn’t detected and taxpayers the agency hadn’t informed. 

The inability to protect sensitive data may result in unauthorized access, disclosure, misuse, improper modification, or destruction of taxpayer information. This burdens affected taxpayers and violates their rights to confidentiality. Unauthorized access or disclosure can also erode public trust in the IRS, which may affect a taxpayer’s decision to voluntarily comply with their tax obligations. We found the IRS’s UNAX program is not adequately addressing the risk of unauthorized access to taxpayers’ accounts. 

Specifically: 

  • Additional controls to prevent and detect unauthorized access violations need to be implemented.
  • Disciplinary actions on UNAX violations need to be consistent and emphasize zero-tolerance.
  • Victim notification letters were not always provided to impacted taxpayers.
  • The IRS has not established executive oversight of the UNAX program.
  • The IRS should improve the performance metrics for the UNAX program.

Americans are legally required to hand over extraordinarily private financial information to the government. Requiring the government to know who is looking at it, why they’re looking, and whether they belong there seems to be a very modest expectation.

Advertisement

Government agencies have enormous power over your money, privacy, and daily life. PJ Media keeps digging into the watchdog reports and government records that too often disappear beneath the daily noise. Join PJ Media VIP today and save 60% with promo code FIGHT.

Comments

VIP

Join the Conversation

VIP members get the ability to comment on articles.

Recommended

Trending on PJ Media Videos