
The government’s own watchdog says IRS systems let employees quietly peek at famous taxpayers’ files, and the agency often missed it.
Story Snapshot
- Inspectors found 86 suspicious accesses to 30 high-profile taxpayers by 52 IRS employees from 2022–2025.
- The audit says IRS lacked a mechanism to prevent or reliably detect browsing of celebrities and public officials.
- Rules make snooping a crime, yet monitoring and taxpayer notifications were inconsistent.
- IRS reports some security fixes, but gaps remain in access controls and case handling.
What Inspectors Found Inside IRS Access Logs
The Treasury Inspector General for Tax Administration reviewed Internal Revenue Service audit logs from 2022 through November 2025. Investigators identified 86 suspicious lookups tied to 30 high-profile taxpayers and linked them to 52 employees. The report states the Internal Revenue Service did not have a mechanism to prevent or systemically detect browsing of celebrities and public officials. That weakness left famous names exposed to curiosity searches that had no clear tax purpose.
The audit focused on the Integrated Data Retrieval System, which staff use to view taxpayer accounts. Inspectors said the Internal Revenue Service lacked extra access controls for sensitive accounts and relied on weak monitoring. That approach made it hard to catch misuse in real time. The finding lands after years of warnings about access control gaps across tax systems that hold sensitive personal and financial data for nearly every household.
What The Rules Say And Why Enforcement Lags
Federal law and Internal Revenue Service policy are clear. Willful unauthorized access or inspection of taxpayer data is illegal. The Internal Revenue Manual directs that the Treasury Inspector General investigates potential cases, and confirmed violations can be referred for discipline or prosecution. Yet the Government Accountability Office found only about one-quarter of investigated cases over a decade were substantiated, showing a large volume of allegations but uneven proof and follow-through.
The audit also flags breakdowns in notifying victims. Inspectors reported that in 2025 the Internal Revenue Service closed 122 unauthorized access cases but properly notified only 64 taxpayers in 39 cases, roughly one-third. People whose records may have been viewed without cause often did not learn what happened or how to protect themselves. That erodes trust across the board, for everyday filers and for high-profile targets alike.
How The IRS Says It Is Responding
The Internal Revenue Service told inspectors it has started to tighten safeguards since earlier data leaks made headlines. Steps include classifying sensitive data, limiting internal sharing, improving audit logging, disabling external storage, and strengthening encryption. The watchdog agrees progress exists but says more work is needed to shore up access controls and integrate monitoring so that improper searches trigger alerts and swift action, not after-the-fact surprises.
For taxpayers, the stakes are simple. The agency asks for deep personal details and has the power to audit, fine, and seize. That power demands strong walls and fast alarms. When staff can browse famous names without automatic checks, it feeds a larger fear shared by both left and right: rules seem to bind citizens more than the government itself. Solid guardrails and consistent notices are not politics; they are the price of public trust.
Sources:
pjmedia.com, tigta.gov, dailycaller.com, gao.gov, home.treasury.gov, irs.gov



