17,000 departing IRS staffers kept agency network access
The IRS told watchdogs in 2024 that automated offboarding was "fully implemented"; when 21,500 employees left under the DRP, the response was manual.
TL;DR
TIGTA found roughly 17,000 of the 21,500 IRS employees who took the Deferred Resignation Program retained network access as of June 2025; 14,000 could still reach sensitive systems. The IRS manually removed more than 15,000 by August. The access-removal gap has appeared in GAO and TIGTA reports going back to 2023, and the IRS told watchdogs in 2024 that automated offboarding was "fully implemented."
Roughly 17,000 of the 21,500 IRS employees who signed up for the Deferred Resignation Program still had access to the agency's main network while on administrative leave as of June 2025, according to a TIGTA report released last week. Another 14,000 could reach one or more sensitive IRS systems. "These employees did not have a legitimate business reason to retain this access and posed a potential security risk for unauthorized disclosure of sensitive information," the watchdog wrote. The IRS manually removed more than 15,000 from the network and roughly 6,000 from sensitive systems by August 2025. TIGTA delivered five recommendations, including that the CIO work with the human capital office to revoke departed employees' network access and create procedures to recover PIV cards. The IRS agreed with four and partially agreed with a fifth.
The same gap, four reports
What makes the finding more than a one-off DRP cleanup failure is the lineage. GAO flagged IRS access-control weaknesses in 2023, noting that "continuing weaknesses pose a risk" to taxpayer information. A 2024 TIGTA audit, launched after IRS contractor Charles Littlejohn leaked thousands of wealthy taxpayers' returns to ProPublica and the New York Times, concluded that procedures to remove users who no longer needed access "were not always working as intended." In its FY 2025 audit, GAO found the IRS "did not consistently remove user access to some IT systems for employees who were placed on administrative leave." Now TIGTA's 2026 report finds the same gap, scaled by a workforce that shrank roughly 25% in a single fiscal year.
The IRS told watchdogs in 2024 that it had "fully implemented automated removal of user network access for employees and contractors separated in the IRS personnel system." Yet when the DRP sent more than 21,000 employees toward the exits, the response was manual. The agency "indicated that it was working to manually remove the access of these employees." If the automated system existed, it didn't scale.
For agency CISOs watching this, the control isn't whether you have an offboarding procedure. It's whether the procedure survives a mass departure event. TIGTA's recommendation for the CIO and human capital office to jointly build an "immediate" termination process reads as an acknowledgment that the gap between HR action and system access revocation remains the weak point, at IRS and likely elsewhere.
Published ·Deep Fathom