The 15-second answer: don't reply to the email. Call the firm on a number you already had — a previous invoice, your own contacts, their website typed in yourself — and ask which secure channel they want you to use. Most firms run a client portal, and they are required by federal law to have a plan for handling your data.
If you already emailed it, skip to the last section. The two things worth doing are both free and neither of them is panicking.
First: is the request actually from your accountant?
This is the question the situation buries, and it is the one worth answering first, because if the answer is no then nothing else matters.
An email asking a client for a Social Security number at tax time is completely ordinary. That is exactly what makes it useful to someone else. A sender name is display text and can say anything. A lookalike domain — one letter changed, .co instead of .com — costs a few dollars and reads correctly at a glance. And if the firm's own mailbox has been compromised, the message really does come from the real address, in the real thread, under the real signature.
A genuine request and a convincing imitation are indistinguishable from inside the email. Every signal you can check without leaving your inbox — the name, the address, the thread history, the tone — is a signal the sender controls. Confirming has to happen somewhere else.
Somewhere else means a channel you chose. Call the number on last year's invoice, or the one already in your phone. Don't call the number in the email signature, and don't reply to the email to ask "is this you?" — whoever sent it will happily confirm that it is.
Worth knowing: this runs in both directions. The IRS Security Summit — the IRS working with state agencies and the tax industry — has repeatedly warned tax professionals about spear-phishing that impersonates clients, including a "new client" scam where criminals pose as prospective customers to get a preparer to open an attachment. The Summit's own advice to preparers is to know their customers and use the phone to confirm identities. Your accountant is being told to check that you are you. It is entirely reasonable for you to check the same thing in reverse, and a good firm will not find the question odd.
Second: why email is a poor container for this
The usual framing is that email might be intercepted in transit. That is the weaker half of the argument — connections between major mail providers are typically encrypted now.
The real issue is that email is built to keep things. Send your SSN and it exists in your Sent folder, in your accountant's inbox, in whatever their firm archives for retention, in both providers' backups, and in the search index of every device either of you has ever linked to those accounts. If a file was attached, it is sitting in an attachment store somewhere too.
Nothing has gone wrong at that point. But you have converted a one-time disclosure into a permanent one, spread across systems neither of you can inventory. If any one of those mailboxes is compromised in three years, the number is exposed then, and you will probably never learn it happened. That is the actual weakness, stated plainly rather than dramatically: it is not that email is intercepted, it is that email does not forget.
Your accountant is required to have a better channel
Here is the part most advice on this leaves out, and it changes the tone of the conversation.
Under the Gramm-Leach-Bliley Act, tax and accounting professionals are treated as financial institutions. The FTC's Safeguards Rule therefore applies to them, and it requires a written information security plan covering how client data is collected, stored and protected — scaled to the size of the firm, but required even of a sole practitioner. The IRS publishes guidance to help preparers meet it, including Publication 4557 (Safeguarding Taxpayer Data) and Publication 5708, which walks a small practice through writing the plan.
So "how would you like me to send this securely?" is not an awkward or distrustful question. It is a question your preparer is expected to have a documented answer to. In practice most firms do: a client portal from their tax software provider, which you sign into rather than email into. If a firm's answer is "just email it over," that is worth a follow-up, kindly phrased.
The free ways to send it
In rough order of how well they work:
- The firm's client portal. Best option and free to you. It is already inside their workflow, which means it is also the one they will actually check.
- Read it aloud on a call you placed. Slightly old-fashioned and completely reasonable for nine digits. The important word is placed — you dial, on a number you sourced yourself.
- A one-time expiring link from a password manager. Bitwarden, 1Password and others all offer this. Put the number in the link, send the link one way, and if it has a password send that a different way — a link and its password in the same email is one channel, not two.
- In person, if you happen to be going in anyway. Hard to beat, rarely convenient.
One method to be honest about: splitting the number across two emails. It beats a single email, but both halves still live forever in the same two mailboxes, so it helps less than it feels like it does.
If you already sent it, do this
Most people reading this have already replied. That is a recoverable position, and the two steps that matter most are free, take about twenty minutes together, and are worth doing whether or not anything was ever actually at risk.
- Request an IRS Identity Protection PIN. An IP PIN is a six-digit number that prevents anyone else from filing a tax return using your SSN or ITIN. It is free and voluntary, it lasts one calendar year, and anyone with an SSN or ITIN who can verify their identity can enrol — you no longer have to be a confirmed victim first. The fastest route is your IRS online account. This is the single highest-value step here, because it targets precisely the fraud that a leaked SSN enables at tax time.
- Freeze your credit at all three bureaus. Equifax, Experian and TransUnion, separately. Federal law made freezes free in September 2018, and a freeze does not affect your credit score. Requested online or by phone, it must be placed within one business day. You lift it temporarily when you actually apply for something.
- Clean up what you can, without overrating it. Delete the message from your Sent folder and ask the firm to delete their copy. This is partial — backups and archives are not covered — but it shortens the list of places the number sits.
- Know the tripwire. Don't file an identity theft affidavit pre-emptively; there is nothing to report yet. The signal to watch for is an e-filed return rejected because one was already filed under your SSN. If that happens, you file a paper return along with Form 14039, the Identity Theft Affidavit.
- If something does go wrong, the FTC runs IdentityTheft.gov, which produces a free personalised recovery plan and pre-fills the letters and forms you would otherwise have to write yourself. Start there rather than with a paid recovery service.
If you only do one: get the IP PIN. A credit freeze protects against new accounts being opened in your name; the IP PIN protects against the specific thing an SSN in a mailbox is most useful for, which is someone filing a return in your name to collect your refund before you do.
For next year
The exchange that starts this every year is the same one: your preparer needs documents, you need to get them there, and email is what is in front of both of you. Agreeing on the channel before tax season — portal, and here is the number I'll call to check anything unexpected — removes the improvised decision under time pressure, which is where these things actually go wrong.
If the two of you exchange sensitive details regularly, it is also worth having a way to confirm identity that doesn't depend on recognising a voice or an email address. SimplyAuth does that with a phrase both sides see on screen at the same moment, and sends the information itself end-to-end encrypted, with an expiry, so it isn't left sitting anywhere afterwards. The call-back method is free and covers the same ground for one-off situations — use that first if it fits.
I'm Kevin — I build SimplyAuth, so I have an obvious interest in you deciding email isn't the right place for this. I've tried to write the page I'd want to find: the portal your accountant already has is free and is usually the right answer, the IP PIN and the credit freeze cost nothing and matter more than any app, and none of that needs me. Nothing here is tax or legal advice, and SimplyAuth doesn't make anyone's firm compliant with anything — that is your preparer's obligation, not a feature you can install.
How the identity check works is covered in the FAQ.