Federal Tax Updates
Federal Tax Updates
Roger Harris, EA and Annie Schwab, CPA
38 Minutes of Access: Inside a Real Tax Office Hack
55 minutes Posted Nov 10, 2025 at 3:00 pm.
John Barucci joins the show to break down his real-life data breach. John thought he had all the right safeguards in place: cyber insurance, firewalls, security training, and a written information security plan. But a single click on what appeared to be a Social Security Administration email led to bad actors accessing nine client files, altering returns, and changing bank account information in just 38 minutes.SponsorsPadgett -  Contact Padgett or Email Jeff PhillipsGet NASBA Approved CPE or IRS Approved CELaunch the course on EarmarkCPE to get free CPE/CE for listening to this episode.Chapters
Introduction and Greetings
Current Events and Government Shutdown
PTIN Renewal and Security Measures
Introducing John Bucci's Story
John Bucci's Cybersecurity Breach Experience
Detailed Chronology of the Breach
Immediate Actions Taken Post-Breach
IRS and Software Company Responses
Client Communication and Further Steps
The Weight of Responsibility in Tax Practice
The Importance of Having a Plan
Immediate Actions Post-Breach
Involvement of Thomson Reuters and Stopping the Breach
Forensic Investigation and Legal Steps
Cyber Insurance and Its Benefits
IRS Practitioner Relief Program
Final Reflections and Lessons Learned
Conclusion and Final Thoughts
0:00
55:54
Download MP3
Show notes
John Barucci joins the show to break down his real-life data breach. John thought he had all the right safeguards in place: cyber insurance, firewalls, security training, and a written information security plan. But a single click on what appeared to be a Social Security Administration email led to bad actors accessing nine client files, altering returns, and changing bank account information in just 38 minutes.SponsorsPadgett -  Contact Padgett or Email Jeff PhillipsGet NASBA Approved CPE or IRS Approved CELaunch the course on EarmarkCPE to get free CPE/CE for listening to this episode.Chapters(00:00) - Introduction and Greetings
(
00:41) - Current Events and Government Shutdown
(
01:41) - PTIN Renewal and Security Measures
(
02:44) - Introducing John Bucci's Story
(
04:19) - John Bucci's Cybersecurity Breach Experience
(
06:03) - Detailed Chronology of the Breach
(
18:23) - Immediate Actions Taken Post-Breach
(
21:59) - IRS and Software Company Responses
(
26:00) - Client Communication and Further Steps
(
29:32) - The Weight of Responsibility in Tax Practice
(
30:20) - The Importance of Having a Plan
(
31:26) - Immediate Actions Post-Breach
(
31:51) - Involvement of Thomson Reuters and Stopping the Breach
(
33:19) - Forensic Investigation and Legal Steps
(
34:46) - Cyber Insurance and Its Benefits
(
36:48) - IRS Practitioner Relief Program
(
42:25) - Final Reflections and Lessons Learned
(
49:00) - Conclusion and Final Thoughts
Follow the Federal Tax Updates Podcast on Social Mediatwitter.com/FedTaxPodfacebook.com/FedTaxPodlinkedin.com/showcase/fedtaxpodConnect with John: https://www.linkedin.com/in/johnbarucciConnect with the Hosts on LinkedInRoger HarrisAnnie SchwabReviewLeave a review on Apple Podcasts or PodchaserSubscribeSubscribe to the Federal Tax Updates podcast in your favorite podcast app!This podcast is a production of Earmark MediaThe full transcript for this episode is available by clicking on the Transcript tab at the top of this pageAll content from this podcast by SmallBizPros, Inc. DBA PADGETT BUSINESS SERVICES is intended for informational purposes only.