2026-09-27
Should you encrypt your tax documents before emailing them to your accountant before Oct. 15?
The Oct. 15, 2026 deadline applies to one specific group: everyone who filed Form 4868 back in April for more time on a 2025 return. The IRS's own reminder this cycle — IR-2026-101, issued Aug. 26, 2026 — nudges that group to file before the fall rush rather than after it, and notes that IRS Free File stays open through the deadline for anyone with 2025 adjusted gross income of $89,000 or less. What that reminder doesn't mention is what actually happens in the days before Oct. 15 for most of those filers: the packet of documents that finishes a return — W-2s, 1099s, a 1098 for mortgage interest, a 1095 for health coverage, sometimes a signed copy of last year's full return — gets attached to an email and sent to whoever is finishing it, usually a CPA or enrolled agent who wasn't even the one who filed the extension request back in April.
A completed return is not a single form
A single tax form can already bundle a lot into one document — a signed Social Security number here, a bank account number there. A completed return bundles far more, all at once, because that's what finishing one requires: the SSNs of the filer, a spouse, and every dependent claimed; every account number listed on attached 1099-INT, 1099-DIV, and 1099-B forms; whatever a 1098 or 1095 adds about a mortgage or health coverage; and, if the preparer asked for it to speed things along, a signed copy of the prior year's return with most of the same information already in it. None of that is careless on the filer's part — it's the ordinary shape of finishing a return under deadline pressure. It just means the attachment sent on Oct. 10 isn't one person's SSN. It's most of a household's financial identity, gathered into a single file, in roughly the same week that tens of millions of other households are attaching the same kind of file to the same kind of email.
Why a preparer's inbox is a different kind of target
The IRS's own Security Summit — the public-private group that also puts out the deadline reminders — has warned specifically about that concentration effect for years. In a July 2024 report, it said Stakeholder Liaisons had "received reports of nearly 200 tax professional data incidents potentially affecting up to 180,000 clients" in a single spring — an average of roughly 900 people's data per incident, because one preparer's inbox holds many clients' returns, not one. The same pattern was still active this year: an Aug. 4, 2026 Security Summit warning described "new client scams" that "target tax pros with emails from senders who pretend to be potential clients to trick practitioners into opening links or attachments that infect computer systems to steal client information" — aimed at the preparer's system specifically because breaching it exposes everyone who has ever trusted that inbox with a return, not just one client.
What encrypting your own copy actually fixes
NearSeal runs entirely in the browser, so the packet you're about to attach never uploads anywhere to get encrypted — it's sealed on your own device with AES-256-GCM and a passphrase-derived key (PBKDF2-SHA256 at 220 iterations), then attached as ciphertext instead of a readable PDF or ZIP. That removes the file from the one part of this you actually control: your own Sent folder, your own Downloads folder, and any backup or cloud-sync copy of the same attachment sitting on your device. For it to arrive usably encrypted on the preparer's end too, the passphrase has to travel a different way than the file — a phone call or a text, not a reply in the same email thread — because a passphrase sent alongside the file it protects protects nothing.
What it honestly can't do
Encryption doesn't touch the phishing scam the IRS keeps warning about. If a message claiming to be a new client is convincing enough that you'd attach a return to it, you'd hand over a passphrase for it too — the defense there is verifying the request through a channel other than the one it arrived on, not a stronger container around the file. It also doesn't reach the part of this risk that's entirely out of your hands once the file lands: a preparer's own inbox, their own device security, and whatever happens to either between now and the day the return is finished — NearSeal has no presence on a system it never touches. And like every file NearSeal seals, there's no passphrase recovery of any kind, which matters more here than in most cases: tax documents are typically kept for years for audit purposes, so a passphrase that outlives the file only helps if you actually keep it somewhere as durable as the return itself. One more limit worth naming plainly: NearSeal's default container keeps the original filename in a plaintext header field, so "jane_doe_1040_2025_full_return.pdf.nearseal" tells anyone who sees it exactly what's inside even though they can't open it — rename the file to something unremarkable first, or use the opt-in age-encryption.org format, which has no filename field at all.
Where NearSeal fits
Nothing about an extension deadline is unusual — it's the same six-week scramble every fall, whichever six weeks of the calendar Oct. 15 happens to fall into this year. What's changed is how clearly the IRS's own reporting shows that the inbox on the other end of that attachment isn't just one person's risk: a single breached preparer account can expose everyone who has ever trusted it with a return. NearSeal doesn't touch that inbox, and it doesn't stop a convincing phishing email. What it removes is narrower and still worth doing: the packet of W-2s, 1099s, and a full prior return doesn't have to sit as plaintext on your own device for the time it takes to open an email and hit attach.