2026-09-23
Should you encrypt the W-9 you just emailed to a new client?
On March 5, 2026, the IRS opened its annual Dirty Dozen list of tax scams (IR-2026-30) the same way it has for several years running — phishing and impersonation at the top — and one entry aims squarely at the exact moment a freelancer is used to handing over a Social Security number without a second thought: "'new client' or 'document request' emails that deliver malicious links or attachments to steal client data or access systems." That's also, word for word, what a real client's first email looks like: a stranger, a first project, and "can you fill out and send back your W-9?" The IRS isn't warning about a rare transaction. Per the Bureau of Labor Statistics' Contingent Worker Supplement, 11.9 million people were independent contractors as of July 2023 — 7.4% of total employment, up from 6.9% in May 2017 — and most of them fill out a fresh W-9 for every new client, often before a single invoice exists.
What a completed W-9 actually bundles together
Form W-9 exists for one purpose: to "provide your correct Taxpayer Identification Number (TIN) to the person who is required to file an information return with the IRS." Filling it in correctly means handing a new contact, in one document, your full legal name and any business name, your entity type, your current address, and — in Part I — either your Social Security number or an EIN, then, per the IRS's own instructions, signing and dating Part II "under penalties of perjury." Almost nothing else a freelancer routinely sends bundles a verified legal name, current address, and government tax ID into one signed, dated file. That's exactly why it works as a tax form. It's also exactly why the saved PDF sitting in your Downloads folder, once it's filled in, is most of what someone needs to open a fraudulent line of credit in your name.
Two different risks, and encryption only touches one
The IRS's March warning targets the first risk: someone impersonating a client purely to get a completed W-9 handed over directly, no breach required. Encryption doesn't help against that one — if you believe the relationship is real enough to send the file, you'd also share a passphrase if one were asked for. The only real defense is verifying a new client through a channel other than the email that made the request, before anything with your SSN on it goes anywhere. The second risk is the mundane one nobody's list covers: a W-9 sent to a genuine client doesn't disappear once the project ends. It sits as a plain, unencrypted attachment in your own Sent folder and in their inbox indefinitely — searchable, backed up, and exposed to whatever eventually happens to either account, years after the work is forgotten. It doesn't even require the payer to ever use it: many collect a W-9 up front, before a single payment, because the 2025 One Big Beautiful Bill Act raises the 1099-NEC and 1099-MISC filing threshold to $2,000 starting tax year 2026 — they may never cross that line with you and never file anything, and the signed form with your SSN on it sits in two inboxes anyway.
What encrypting your own copy actually fixes
The part of this you still control is narrow and specific: the filled-in W-9 that exists on your own device, from the moment you save it as a PDF until the moment it's attached to an email. NearSeal runs entirely in the browser — the file never uploads anywhere — so encrypting that copy with a passphrase costs nothing and removes one plaintext copy of your SSN from your own hard drive, your own backups, and your own cloud-sync folder if you keep one for your records. If you want the client to receive it encrypted too, that only works if you send the passphrase through a different channel than the file — a text message or a phone call, not the same email thread — because a passphrase attached to the same message it's meant to protect protects nothing.
What it honestly can't do
Encryption can't touch either of the two risks above once they've already happened. It doesn't retroactively protect the plaintext copies already sitting in your Sent folder and a client's inbox from every W-9 you've emailed before today — NearSeal has no reach into either mailbox. It doesn't stop the scam the IRS is warning about: encrypting a form you're about to hand to a fake "new client" doesn't help, because if you trust the request enough to send the file, you'd trust it enough to send the passphrase too. And once a real client opens a decrypted copy on their end, it's exactly as exposed as an unencrypted attachment would have been to whatever eventually happens to their account — encryption protects the file in transit and at rest on your side, not forever, on both sides, by default. Like every file NearSeal seals, there's also no passphrase recovery of any kind, so encrypting a document you'll need to reopen for your own tax records is worth doing only if you'll keep the passphrase somewhere as durable as the file itself.
Where NearSeal fits
Eleven million contractors handing over a signed SSN to a new contact isn't a fringe case; it's the routine first step of most freelance relationships, and the IRS's own 2026 warning list shows scammers already treat that routine as an opening. What NearSeal changes is narrow: the completed W-9 doesn't have to sit unencrypted on your own device for even the few minutes between "saved" and "sent." AES-256-GCM, a passphrase-derived key via PBKDF2-SHA256 at 220 iterations, entirely client-side. It's a habit worth building into a form you'll fill out again for the next client, and the one after that — not a fix for a phishing email designed to look exactly like a real one, and not a way to undo what's already sitting, unencrypted, in an inbox you don't control.