Physical Address
5206 Hwy 5 N Suite 100, Bryant, AR, United States, Arkansas
Physical Address
5206 Hwy 5 N Suite 100, Bryant, AR, United States, Arkansas

The campaign speaks directly to tax professionals, but its warning matters to any AP or finance team that collects sensitive payee information.
| Key point: The IRS announcement did not create a new W-9 or 1099 requirement. It is a timely prompt to review how sensitive tax records are requested, accessed, stored, retained and disposed of. |
On July 7, 2026, the IRS and its Security Summit partners launched the five-week “Protect Your Clients; Protect Yourself” summer campaign. The series is directed primarily at tax professionals and focuses on practical defenses against evolving tax-related identity theft.
That official audience distinction matters. The campaign is not a new security rule for every business. Still, its lessons apply well beyond tax-preparation firms. Businesses routinely collect Forms W-9 from vendors, contractors and other U.S. payees, then use that information when an applicable information return must be prepared. Those records may contain names, addresses and taxpayer identification numbers—data that deserves controlled handling.
The Security Summit brings together the IRS, state tax agencies and members of the tax industry to combat tax-related identity theft. Its 2026 summer series highlights emerging scams, employee training, security basics and the need to verify unusual requests before responding.
For businesses, the correct takeaway is operational rather than regulatory: use the campaign as a midyear security checkpoint. It does not introduce a new form, change a filing deadline or automatically impose a new requirement on accounts payable teams.
Form W-9, Request for Taxpayer Identification Number and Certification, is used to request a U.S. payee’s correct name, taxpayer identification number and required certifications. A W-9 is not limited to independent contractors, and receiving one does not mean the payee will automatically receive a Form 1099.
When a payment meets the applicable reporting requirements, the payer may use the W-9 information to prepare the appropriate information return, such as Form 1099-NEC, for the IRS and the recipient. Because W-9s and 1099s may contain sensitive personal and tax information, scattering them across inboxes, downloads folders and shared drives creates unnecessary exposure.
A stolen taxpayer identification number may be used in fraudulent tax filings or other identity-theft schemes. The business impact can also include incident-response work, disrupted vendor relationships and the cost of determining which records were exposed.
Email is convenient, but a completed W-9 should not be treated like an ordinary vendor document. Use a controlled collection method designed for sensitive information. If email is unavoidable, follow your organization’s approved encryption and data-handling procedures rather than sending an unprotected attachment.
Not everyone who works with a vendor needs access to the vendor’s taxpayer identification number. Assign access according to role, remove access when responsibilities change and review permissions periodically. AP, controller and system-administrator access should be deliberate—not inherited from a broad shared drive.
Store completed forms in an access-controlled system that uses encryption and multi-factor authentication where available. Password protection alone is not a complete safeguard. MFA is especially important for email, cloud storage and any application holding tax records.
A message asking you to resend a W-9, change bank details or open an unexpected document should trigger verification. Contact the vendor using a trusted phone number or contact record already on file. Do not rely on the phone number, link or reply address inside the suspicious message.
The 2026 IRS campaign specifically warns that identity thieves continue to change their tactics. Short, recurring training is more useful than a once-a-year policy acknowledgement. Teach employees to pause when a request is unexpected, urgent or asks for personal, financial or tax information.
Do not delete tax records simply because they look old. The IRS advises businesses to keep an independent contractor’s W-9 in their files for four years in case questions arise from the worker or the IRS. Other retention periods depend on what a record supports and the rules that apply to the business.
Define who owns the retention schedule, how legal or operational holds are handled and how records are securely disposed of after the applicable period expires.
Document who must be contacted, how access will be contained, which systems and records must be reviewed, and how reporting obligations will be evaluated. A response plan built during a calm period is more useful than improvising after suspicious activity is discovered.
Use these questions to test the current process:
If the team cannot answer these questions clearly, the weakness is not just a technology problem. It is a process-ownership problem. Assign an owner, document the workflow and schedule a recurring access review.
A dedicated W-9 collection workflow helps reduce the need to exchange completed forms as ordinary email attachments. GetW9.tax centralizes W-9 requests and records so teams can manage the process in one place instead of relying on disconnected inboxes and spreadsheets.
Software does not replace internal controls. Businesses still need appropriate user access, staff training, retention rules and procedures for verifying suspicious requests. The value of a centralized workflow is that it gives those controls a clearer place to operate.
The IRS’s 2026 summer campaign is aimed at tax professionals, but businesses should not ignore it. Any organization collecting W-9 information is handling data that requires more care than an ordinary vendor file.
Start with the basics: control how forms arrive, restrict who can see them, require MFA, verify unusual requests outside the original message, retain records according to a documented schedule and dispose of them securely when the retention period ends. Those steps will not eliminate every risk, but they will remove avoidable weaknesses before the next 1099 season.