CryptoTaxAudit blog graphic. On the left, the headline reads “IRS Data Security Risks for Crypto Holders | 1099-DA,” with text explaining that a TIGTA report found major IRS access-control gaps. On the right, a dark IRS building appears behind a glowing red “Unauthorized Access” warning and a list of taxpayer names with access levels. A red dotted line leads from the IRS data panel to a location pin above a lit suburban home at night, visually representing the risk of sensitive crypto taxpayer data being connected to a person’s home address.

form 1099-da irs data security Sep 17, 2026

IRS Data Security Gaps and the New Physical Risk to Crypto Holders

By Clinton Donnelly, LLM, EA | CEO & Founder, CryptoTaxAudit

In January 2025, kidnappers took Ledger co-founder David Balland and his partner from their home in central France. They severed one of his fingers and demanded a ransom paid in crypto. Police recovered the couple.

French prosecutors have since charged 88 people across a dozen crypto kidnapping and extortion cases. The attackers in these cases did not break encryption. They knew who held crypto and where that person slept.

France is also where two failures at the tax authority have put crypto holder data at risk. One employee of the Direction Generale des Finances Publiques stands charged with selling investor data to criminal networks, a case that has not gone to trial. Separately, the finance ministry confirmed in August 2026 that an attacker breached its systems. No French authority has linked either failure to the kidnappings.

US crypto holders now sit in a version of the same setup. Brokers report digital asset activity to the IRS on Form 1099-DA, with the taxpayer's name and address attached. On August 12, 2026, the Treasury Inspector General for Tax Administration published a report saying the IRS has not been controlling who can access the systems holding that kind of data.

Key Takeaways

  • TIGTA Report 2026-IE-R013 found roughly 17,000 people with unneeded IRS network access: Of the nearly 21,500 IRS employees who accepted a deferred resignation offer, about 17,000 still had network access as of June 2025. More than 14,000 still had access to one or more systems holding sensitive taxpayer information.
  • The cause was a paperwork gap, not a hack: These employees sat on administrative leave without officially separating. The IRS access system revokes entitlements when a separation is recorded, and no separation was recorded.
  • Form 1099-DA lists your name, address, and trading activity in IRS systems. Broker reporting of digital assets began with 2025 transactions. That filing links a crypto holder to a physical address inside a federal database.
  • Tax firms are legally required to meet a security standard the IRS just failed: The Gramm-Leach-Bliley Act and the FTC Safeguards Rule at 16 CFR Part 314 require every paid preparer to maintain a written information security plan with nine specific elements.
  • The Commissioner of Internal Revenue seat has been vacant since March 6, 2026: TIGTA addresses its reports to the Commissioner. There is no Senate-confirmed official in that role to own the response.
  • A virtual mailbox is the practical fix available to individuals: Registering exchange accounts to a virtual mailing address keeps a home address out of 1099 filings and exchange KYC files going forward.
 

What Did the TIGTA Report Actually Find?

On August 12, 2026, the Treasury Inspector General for Tax Administration issued Report 2026-IE-R013, More Controls Could Help Prevent Unauthorized Access to Taxpayer Information. It found that about 17,000 of the nearly 21,500 IRS employees who accepted a deferred resignation offer still had access to the IRS network as of June 2025. More than 14,000 of them still had access to one or more systems holding sensitive taxpayer information.

The mechanism matters more than the headline number. The IRS controls system access through the Business Entitlement Access Request System, known as BEARS. When an employee retires, resigns, or is terminated, the personnel system generates an action that tells BEARS to revoke access automatically.

That never fired here. Employees who took the Deferred Resignation Program were placed on paid administrative leave and stayed coded as active in the personnel system. No separation was recorded, so no revocation was triggered. They were out of the building with their credentials still live.

TIGTA found two more gaps in the same review. Of the nearly 1,200 employees and contractors hired between January and August 2025, more than 550 received sensitive systems access before finishing required security training. Among 91 new contractors, 12 had not taken any of the five cybersecurity courses the Government Accountability Office identified as relevant, and 8 had taken no training at all.

TIGTA also confirmed that some IRS and non-IRS users were granted access to at least one system entirely outside the BEARS approval process, in violation of IRS policy. A separate audit of how far that went is still open.

 

Did the IRS Fix It?

The IRS cut most of the access after TIGTA raised the alarm, but not all of it. TIGTA notified the agency in June 2025. By July 2025, about 13,500 deferred resignation employees still held systems access and about 12,500 still held network access. By August 2025, sensitive systems access had dropped below 8,000 and network access to roughly 1,600.

TIGTA credited the speed of that response. It also said the underlying problem is unchanged. The IRS still has no process that terminates access the moment a business need to see taxpayer information ends.

Two residual findings show why. As of August 2025, TIGTA identified 46 individuals who had fully separated from the IRS and still held active network access. Nine of those 46 also still had access to a sensitive system. Separately, 107 users in IRS Criminal Investigation held sensitive system access with no network access recorded in BEARS, even though they did in fact have network access. TIGTA had flagged more than 1,500 IRS-CI users with the same records gap in its 2024 review, and the IRS had closed that recommendation as complete.

TIGTA issued six recommendations. The IRS agreed with five and partially agreed with one.

 

What the Report Does Not Prove

The TIGTA report documents access, not misuse. It does not establish that any departing employee viewed, copied, downloaded, or sold taxpayer data. That distinction is worth holding onto, because the honest position is that nobody knows yet.

What the record does establish is what unauthorized access looks like when someone acts on it. TIGTA opened its original 2024 review after an IRS contractor accessed an agency database and collected return information on a high-ranking government official and thousands of the wealthiest people in the country. The data was uploaded to a private website to avoid detection, then handed to media organizations. The contractor was sentenced to five years in prison.

One person with legitimate credentials and no oversight produced that outcome. The 2026 report says thousands of people held credentials they had no business reason to hold. Those are different facts, and the second one is not proof of a breach. It is a description of how much room a breach would have had.

 

Why 1099-DA Changes the Risk for Crypto Holders

Form 1099-DA is what turns IRS system security into a crypto safety question. Brokers file it with the IRS for digital asset dispositions beginning with 2025 transactions, and each filing carries the taxpayer's name, address, and transaction detail.

Before 1099-DA, the IRS held crypto information in scattered form. Now it holds a structured, searchable feed of who traded, through which broker, how much, and where that person receives mail.

Consider what someone with database access could do with that. Sort by transaction count. Pull the names at the top. Read off the addresses. No hacking is required at that point, and no tax return needs to be opened. The information return itself is enough.

This is the same shape of exposure that exists at the exchange level. A broker that issues a 1099 already holds the address it printed on the form. The IRS now holds a second copy of it.

 

What the IRS Sees, and What It Does Not

IRS reporting data is transactional, not custodial. It shows how often someone traded and through which broker. It does not show what is sitting in a private wallet.

That has a strange consequence. A high frequency trader moving the same small balance in and out all year looks far busier in IRS data than a holder sitting on a large position in cold storage. Broker reporting is a poor proxy for wealth.

It is an excellent proxy for something else. It identifies who is involved in crypto at all, and it attaches a mailing address to that identification. For a criminal building a target list, that is the harder half of the job already done. Whether the balance turns out to be large is something they can find out in person.

This is why the privacy conversation around crypto reporting is not really about audit exposure. It is about physical exposure.

 

France Is the Case Study

France is where crypto kidnappings and tax authority data failures have run in parallel. French authorities have recorded 135 crypto-related kidnapping or extortion incidents since 2023, including 18 in 2024, 67 in 2025, and 47 by late April 2026. The national anti-organized crime prosecutor's office has charged 88 people across 12 ongoing cases, more than ten of whom are minors.

Two separate data failures sit behind part of that pattern. The first is an individual case. A 32-year-old employee of the Direction Generale des Finances Publiques, the French tax authority, was detained on June 30, 2025 and charged in connection with selling confidential information to criminal networks. Investigators say she used an internal lookup tool called Mira to run searches on crypto specialists and investors that had nothing to do with her job. The case is under judicial investigation. No trial has been held and no verdict has been reached.

The second is a breach. In August 2026, the French finance ministry confirmed that an attacker gained unauthorized access to tax authority systems during June and July by compromising credentials belonging to a tax official and an authorized third party. Reporting on the stolen database put the figure at 678,438 records covering individuals and businesses.

French authorities have not said the breach specifically targeted crypto investors, and they have not established that the stolen records were used in any physical attack. That caveat is real and should be stated plainly. What is not in dispute is that criminals in France have repeatedly identified crypto holders through leaked data rather than through blockchain analysis, and that the attacks followed.

 

Tax Preparers Are Held to a Standard the IRS Is Not Meeting

Every paid tax preparer in the United States is legally required to maintain a written information security plan. The requirement comes from the Gramm-Leach-Bliley Act and the FTC Safeguards Rule at 16 CFR Part 314, which classify tax preparation firms as financial institutions for data security purposes.

This is not a suggestion or a best practice. The plan must cover nine specific elements: a designated qualified individual, a written risk assessment, administrative and technical safeguards, service provider oversight with enforceable contracts, monitoring and testing, documented employee training, an information systems inventory, a written incident response plan, and an annual program review. The IRS publishes the guidance in Publication 4557, Safeguarding Taxpayer Data, with a sample plan in Publication 5708.

Preparers acknowledge the requirement on Form W-12 at PTIN renewal. Failing to have a plan can trigger an FTC investigation.

CryptoTaxAudit maintains that program because federal law requires it. The point of raising it here is the comparison. The agency that imposed the standard on thousands of small firms left 14,000 people with credentials to taxpayer data they had no business reason to hold, and let contractors onto sensitive systems before they had completed security training.

 

The Report Is Addressed to a Commissioner Who Does Not Exist

TIGTA addressed Report 2026-IE-R013 to the Commissioner of Internal Revenue. That office has been vacant since March 6, 2026.

The sequence got there quickly. Billy Long was confirmed as Commissioner on June 12, 2025 and removed on August 8, 2025. Treasury Secretary Scott Bessent then served as acting commissioner, but his authority under the Federal Vacancies Reform Act ran out after 210 days. The IRS confirmed on March 13, 2026 that Bessent had stopped serving in that capacity. Frank J. Bisignano has run the agency as Chief Executive Officer since October 6, 2025, a title that did not previously exist at the IRS and was not created by Congress.

This is why oversight reports on IRS data security keep repeating themselves. TIGTA reported the same class of failure in February 2024, the IRS agreed with the recommendations, marked one of them complete, and the 2026 review found the issue was still there. Findings get accepted. Accountability has nowhere to land.

 

How to Reduce Your Home Address Exposure

The most direct step a crypto holder can take is to register exchange and broker accounts to a virtual mailbox rather than a home address. A virtual mailbox is a commercial mail receiving service with a real street address that accepts mail on your behalf.

Apply it to any platform that will issue a 1099. That address then becomes the address in the exchange's KYC file and the address printed on the 1099-DA that goes to the IRS. Anyone who later pulls that record, whether from inside the exchange or from inside a government system, gets a mail center instead of your front door.

Be clear about what this does and does not do. It is a mailing address change, not a reporting strategy. Every dollar of income still gets reported, the IRS still receives the same transaction data, and using a virtual address to obscure residency for tax purposes creates a separate and worse problem. It also does nothing about records already filed under your home address, or about property records, social media posts, and on-chain activity that point to the same place.

Home invasions targeting crypto holders have occurred in the United States, not only in Europe, and the common thread is that the attacker knew both what the victim held and where to find them. A virtual mailbox breaks one of those two links going forward. That is a small change with a real effect, and there is no reason to wait for a US version of the French case to start using one.

 

Frequently Asked Questions About IRS Data Security and Crypto Privacy

Did the IRS get hacked?

No. TIGTA Report 2026-IE-R013 describes an internal access control failure, not an external intrusion. Roughly 17,000 employees who had accepted a deferred resignation and were sitting on administrative leave retained network access they no longer needed, because the IRS system that revokes access only fires when an official separation is recorded.

Can someone at the IRS see how much crypto I actually own?

Not from broker reporting alone. Form 1099-DA data is transactional, so it shows dispositions through a reporting broker rather than total holdings. Assets held in a private wallet and never sold through a broker do not appear in that data. What the data does show is that you are involved in crypto, and the address you gave the broker.

Should I use a virtual mailbox or a PO box for my exchange accounts?

A virtual mailbox is usually the better fit because it provides a street address, and many exchanges reject PO boxes during KYC verification. Either option keeps your home address off the 1099 and out of the exchange file. Neither changes what you report or how much tax you owe.

I already gave Coinbase my home address years ago. Is it too late?

Changing it now does not erase what was already filed, but it does limit what goes out from this point forward. Update the address on file at every exchange that issues you a 1099, then confirm that the change is reflected on the next form you receive. Prior filings stay as filed.

Has anyone been harmed because of leaked crypto tax data?

In France, a tax authority employee was charged in 2025 with selling data on crypto investors to criminal networks, and the country recorded 67 crypto-related kidnapping or extortion incidents in 2025 alone. That case has not gone to trial. In the United States, an IRS contractor was sentenced to five years in prison for taking return information on thousands of wealthy taxpayers and giving it to the press, which shows the same failure mode without the physical violence.

Does any of this change what I have to report on my tax return?

No. Reporting obligations for digital assets are unchanged, and the arrival of 1099-DA makes accurate reporting more important rather than less, because the IRS now receives an independent copy of your broker activity. Privacy steps like a virtual mailbox operate alongside full reporting, never as a substitute for it.

Want help protecting your crypto tax position and your privacy at the same time?

CryptoTaxAudit handles crypto tax preparation and IRS audit defense for traders in 71 countries, and files under a written information security program required by federal law. Start with a free consultation, or look at the TaxShield membership if you want ongoing IRS account monitoring rather than a one-time filing.

About CryptoTaxAudit: Founded in 2015 by Clinton Donnelly (LLM, EA), CryptoTaxAudit specializes exclusively in cryptocurrency tax preparation and IRS audit defense. Clinton holds an advanced law degree in international financial planning, federal Enrolled Agent status, and the Certified Cryptoasset Anti-Financial Crime Specialist credential from ACAMS. The firm has filed more than 5,000 crypto tax returns, defended clients in over 50 IRS audits, and represented five traders in U.S. Tax Court. CryptoTaxAudit serves clients across 71 countries and maintains a written information security program under the FTC Safeguards Rule for every client file it handles.

 

Related Article: Can Tax Authorities Be Trusted With Your Crypto Data?

Sep 17, 2026

Aug 27, 2026

Jun 25, 2026

Jun 04, 2026