The New IRS App. What the Individual Online Account Migration Means for Client Data Security and Practitioner Practice
The IRS announced on September 25, 2026, that it is replacing IRS2Go with a new IRS mobile app, extending secure mobile access to a subset of Individual Online Account services. [1] For tax practitioners, the announcement is less a technology story than a data-security and client-advisory one — the app now provides an additional authenticated channel through which a taxpayer’s account information, some of it plainly protected under § 6103, can be accessed, and an additional vector through which that access could be spoofed or abused.
What the App Actually Does
Per the IRS’s announcement, the new app allows a taxpayer who securely signs in to access:
- Refund and amended-return status
- Available balance information
- Payment activity, and the ability to make payments
- Select notices and letters
- Available tax records and transcripts
- Certain profile and communication preferences
- An Identity Protection PIN (IP PIN) [1]
The IRS was explicit that this is an extension of the existing Individual Online Account infrastructure, not a replacement for it: “The IRS app expands secure mobile access to selected IRS Individual Online Account services. It does not replace IRS.gov or the IRS online accounts.” [1] Business Tax Account and Tax Pro Account access remain confined to IRS.gov for now, with the app “initially extending selected Individual Online Account features only.” [1] Practitioners managing client accounts through Tax Pro Account should note that this rollout does not currently extend that access to the mobile app.
The Confidentiality Dimension. Section 6103 in a New Channel
Every category of information the app makes accessible — return status, balance information, notices, transcripts — is “return information” within the meaning of I.R.C. § 6103(b)(2), which generally restricts IRS disclosure of such information except to the taxpayer or a properly authorized representative. [FLAG — confirm current scope of § 6103(b)(2) and any amendments; stating from settled general understanding of the provision, not independently verified against current text for this piece] Section 6103 governs the IRS’s disclosure obligations and restrictions; it does not itself impose a security standard on the app’s authentication architecture, but it is the reason authentication matters so much here — a channel that allows unauthorized access to this information functions, in substance, as an unauthorized disclosure, even though the IRS itself did not affirmatively disclose anything.
The practical question for practitioners advising clients is authentication integrity, not disclosure doctrine: the app extends account access to a new device-based channel, which is functionally a new attack surface for account takeover, regardless of § 6103’s disclosure rules operating exactly as they did before. This is a security-practice concern for client advisory purposes, not a change in the statutory landscape.
Identity Protection PINs and Authentication Risk
Notably, IP PIN access is now available through the app. [1] The IP PIN program, administered by the IRS to prevent identity thieves from filing fraudulent returns using a legitimate taxpayer’s SSN, is itself a security-additive measure — but making the IP PIN retrievable through a new mobile channel means the security of that channel’s authentication now bears directly on the integrity of a program specifically designed to prevent tax-related identity theft. [FLAG — confirm current IP PIN program authority/citation (this is generally administered under IRS procedures rather than a specific Code section establishing the program by name); do not cite a specific Code section for the IP PIN program without confirming it]
Advisors with clients who have been victims of identity theft, or who are enrolled in the IP PIN program for that reason, should specifically confirm the authentication method (multi-factor, biometric, or otherwise) the new app requires before advising clients to rely on it as their IP PIN retrieval method.
The Impersonation and Phishing Risk the IRS Itself Flagged
The IRS’s own release devotes meaningful space to warning taxpayers about look-alike apps and phishing attempts exploiting the transition: “Taxpayers should use verified IRS links or the official IRS app listings … and be cautious of look-alike apps, advertisements and unsolicited messages claiming to provide access to IRS accounts. The IRS will not ask taxpayers to provide sensitive personal or financial information through an unsolicited text, email, or pop-up message.” [1]
This warning is not boilerplate — it reflects a real and recurring enforcement problem. Individuals who impersonate IRS officials or fraudulently solicit taxpayer information under color of IRS authority can face criminal exposure under statutes such as 18 U.S.C. § 912 (impersonating a federal officer or employee) and the various wire fraud and identity theft provisions typically charged alongside IRS-impersonation schemes. [FLAG — confirm whether § 912 or another specific statute is the one typically charged in IRS-impersonation phishing prosecutions; stated here as a general illustrative reference, not a confirmed citation for this specific context] Any client-facing communication about the app transition should include the same caution the IRS itself is issuing: a name-brand-adjacent app launch is a predictable moment for phishing campaigns to spike, and clients should be advised to locate the app only through the official Apple App Store / Google Play listings or the verified IRS.gov link. [1]
Practical Guidance for Practitioners
A few concrete points worth relaying to clients during this transition:
- No action is required for most existing IRS2Go users. The IRS states that current IRS2Go users with automatic updates enabled will receive the new app through the normal update process, without needing to separately locate and download it. [1]
- The app does not extend to Tax Pro Account or Business Tax Account services at this time, so practitioners managing client matters through those channels should continue to rely on IRS.gov directly. [1]
- Clients should be specifically warned that the transition period is a predictable window for phishing and look-alike-app schemes, consistent with the IRS’s own advisory. [1]
- Telephone and in-person assistance remain available and are unaffected by this rollout, which may be relevant for clients whose issues cannot be resolved through self-service channels. [1]
Takeaway
This announcement is administrative rather than doctrinal — there is no new statute, regulation, or case interpreting it. Its legal relevance to practitioners lies almost entirely in client-advisory terms: a new authenticated channel for accessing § 6103-protected return information means client guidance on device security and phishing awareness is more, not less, important during the transition, and the IRS’s own release effectively concedes that risk by devoting a substantial portion of the announcement to it.
Source
- IRS, IR-2026-114, “IRS2Go becomes IRS app, adding secure mobile access to selected Individual Online Account services,” Sept. 25, 2026, https://www.irs.gov/help/app