incident-responsetrade-pressNewsThe Broadside2 min read

IRS still missing 594 devices from departed employees

No policy sets a return deadline or recoups costs, so an employee who walks with a laptop containing taxpayer data faces no consequence.


TL;DR

The Treasury Inspector General for Tax Administration found that 594 IT assets assigned to IRS employees who left during the April, July 2025 separation wave remain unaccounted for as of April 2026. The 22,000 departing staffers held more than 32,000 devices, laptops, smartphones, portable printers. TIGTA flagged that IRS policy requires asset return upon departure but specifies no timeframe and carries no enforcement mechanism; there is no process for recouping costs from employees who don't comply. IRS officials told the watchdog they'd found no evidence of ex-staffers accessing the network, but the hard drives and device memories haven't been wiped and could hold sensitive taxpayer data.

TIGTA laid out a cascading set of process failures. Managers who collected devices from departing staffers didn't return them to the local IT office. Local IT offices didn't ship assets back to headquarters. IT depot workers didn't update inventory statuses once equipment came back in. None of these breakdowns is exotic on its own, but strung together, they produced a 4% loss rate across the separation wave.

The watchdog's core finding is that IRS policy on departing-employee assets is missing the teeth every other federal property-accountability regime has. There's no deadline for return, no financial consequence for non-return, and no reconciliation process that would flag a missing laptop before the employee's departure becomes a stale record. TIGTA wrote flatly: "the lack of guidance contributed to the inaccuracy of the asset inventory."

On the question of whether the missing devices represent a data-loss event, the report is careful but pointed. IRS hardware asset management told the watchdog's investigative arm that some assets were stolen, though the agency provided no documentation to back that up. TIGTA's view: "As these employees have separated from the IRS, we believe these assets should be considered stolen as opposed to missing." The distinction matters because the hard drives and device memories haven't been cleared.

TIGTA made four recommendations: set concrete return timeframes, take steps to locate stolen assets, feed device data into the audit trail repository, and assign audit-trail responsibilities to system administrators. The IRS agreed with all four.

The report lands against a backdrop of repeated IRS access-control findings. TIGTA's August 2026 audit showed roughly 17,000 employees on deferred resignation still had network access as of mid-2025. GAO's 2023 review found 77 unimplemented recommendations on taxpayer-data safeguards going back to 2010. The pattern predates the second Trump administration's workforce reductions, but the speed of the separation wave exposed gaps that slower attrition had let the agency work around.


Published ·Deep Fathom

IRS still missing 594 devices from departed employees — The Broadside