The agency that demands every detail of your financial life can’t keep its own employees out of other people’s tax records. That is the takeaway from a new report by the Treasury Inspector General for Tax Administration, the IRS’s independent watchdog.
The inspector general found 86 suspicious accesses by 52 IRS employees into the tax records of 30 high-profile taxpayers between 2022 and late 2025, according to the Daily Caller. The records belonged to “United States government officials, business leaders, and entertainers,” the report said.
The report was released September 29, Just the News reported, and drew wider coverage over the weekend.
Snooping without the firing
IRS employees are only allowed to open a taxpayer’s file when their job requires it. Looking without a business reason is called unauthorized access, or “UNAX” in IRS shorthand.
IRS guidance says firing “is to be proposed for UNAX violations,” though a deciding official can reduce the penalty, according to International Business Times. Yet the watchdog found that 22 employees who accessed records without authorization were not terminated, the Daily Caller and IBTimes reported.
The watchdog’s conclusion was blunt: “The IRS’s UNAX program is not adequately addressing the risk of unauthorized access to taxpayers’ accounts.”
Victims left in the dark
When the IRS confirms that someone snooped on a return, its procedures call for telling the taxpayer. Often, that didn’t happen.
According to the report, as described by IBTimes and the Daily Caller:
- 175 taxpayers were never notified because IRS staff didn’t follow procedures.
- 101 more taxpayers weren’t notified because the employees involved resigned or retired before discipline was proposed.
- That’s 276 taxpayers in all who never learned their records had been viewed without authorization.
In other words, an employee could peek at a file, retire, and the victim would never know.
What the watchdog wants fixed
The inspector general made eight recommendations, IBTimes reported. They include studying system improvements to catch suspicious searches, limiting which employees can use certain account commands, and issuing guidance that stresses the legal consequences of intentional snooping.
The IRS’s acting chief privacy officer, John Walker, responded that the agency agreed or partially agreed with seven of the eight recommendations and planned corrective actions by December 2026. The IRS disagreed with one: setting timeliness standards for notifying victims. The agency said such standards already exist.
We’ve seen this before
Americans have good reason to worry. In January 2024, former IRS contractor Charles Littlejohn was sentenced to five years in prison for leaking President Trump’s tax returns and the tax information of other wealthy Americans to the media, Fox News reported. The judge called the leak “an intolerable attack on our constitutional democracy.”
President Trump later sued the IRS and Treasury over that failure, then dropped the $10 billion lawsuit in May 2026, Just the News reported.
The new report shows the problem didn’t end with one rogue contractor. It describes a system that can’t reliably spot snooping, doesn’t consistently punish it and doesn’t consistently tell victims about it.
The bottom line
The IRS holds more private information about Americans than almost any other institution: income, debts, medical deductions, charitable gifts, business deals. Taxpayers have no choice but to hand it over. The least the agency owes them is a guarantee that bored or politically motivated employees won’t go browsing.
This report shows the IRS can’t make that guarantee. When dozens of employees open the files of public officials and celebrities, and 22 of them are never fired, the message inside the agency is that the rules are optional. When hundreds of victims are never told, the public can’t hold anyone accountable.
Congress should demand that the IRS adopt every one of the watchdog’s recommendations, make firing the real default for willful snooping, and notify every victim. A government that can’t protect our private records has no business asking for more of them, or for more agents to go through them.
