Your Employer Identification Number is the key to your business's financial identity — and thieves know it. In 2025, the FTC fielded over 1.35 million identity theft complaints, a nearly 20% jump from the prior year, and business filing fraud remains one of the fastest-growing slices. You could be reconciling your books on a quiet Tuesday when an envelope arrives from Ogden, Utah: Letter 5263C or Letter 6042C. It asks you to verify information about an entity you may not recognize, or to confirm details on a return you never filed. Your first instinct might be to toss it aside as a bureaucratic mix-up. Don't.
That letter is often the earliest signal that someone has used — or attempted to use — your EIN to file a fraudulent tax return, claim a bogus refund, or impersonate your business with lenders and vendors. How quickly and precisely you respond can determine whether you spend weeks untangling the mess or months chasing a still-active fraud.
This guide explains what business identity theft actually looks like, what those IRS letters mean, the exact steps to take within the 30-day window, and the bookkeeping habits that make you a harder target in the first place.
What Business Identity Theft Really Is
Business identity theft happens when someone creates, uses, or attempts to use a business's identifying information without authority to obtain tax benefits. The IRS definition is narrower than the everyday sense of identity theft, but the practical damage is broad.
Typical patterns include:
- Filing a fraudulent business return to claim refundable credits or to generate a bogus K-1 that supports an individual identity theft scheme.
- Hijacking an existing EIN to file payroll or excise returns, open lines of credit, or pass vendor verification checks.
- Creating a shell entity with a stolen responsible-party name and SSN to layer frauds that are harder for automated filters to flag.
Unlike individual identity theft, there is no single consumer credit file that captures the full picture. A business has an EIN, state registration records, Dun & Bradstreet and other business credit files, bank accounts, and tax accounts that don't talk to each other in real time. That fragmentation is what thieves exploit — and why you need monitoring in more than one place.
How Thieves Get Your EIN and Business Details
Your EIN isn't secret in the way an SSN is supposed to be. It appears on W-9s you send to clients, on invoices, on bank paperwork, and in state filings that are often public record. Thieves combine that with other exposed data:
- Phishing and business email compromise. A single employee clicking a fake IRS or vendor email can exfiltrate W-2s, W-9s, and bank letters. The FBI consistently ranks business email compromise among the costliest cybercrimes for small businesses.
- Data breaches at vendors or payroll providers. The Identity Theft Resource Center tracked a record 3,322 data compromises in 2025; the first half of 2026 is already on pace to exceed that. Every breach that includes an EIN, responsible-party SSN, or business address enriches the inventory thieves trade.
- Public records scraping. Secretary of state websites, county filings, and even your own website's team page give thieves officer names, addresses, and formation dates that make a fraudulent SS-4 application look legitimate.
- Stolen mail or unsecured file sharing. Sending a blank W-9 as an unencrypted PDF, storing EIN letters in an unlocked filing cabinet, or leaving mail in an unlocked box are low-tech but common vectors.
The IRS's Security Summit — the joint program of the IRS, state tax agencies, and the tax software industry — has added authentication questions to business return preparation software and back-end filters that flag suspicious filings. Those filters are working: the IRS reported preventing roughly $7 billion in fraudulent refunds across 2024 and 2025. But filtered returns often trigger the very letters this guide covers, which is why legitimate businesses increasingly see them.
The Warning Signs You Should Never Ignore
Business identity theft is more complex than individual identity theft to spot because many of its early indicators also look like routine processing errors. The IRS is explicit that a single red flag does not automatically mean theft — transposed numbers and timing issues can mimic fraud. Watch for a pattern.
Tax-administration red flags
Be alert if you experience any of these:
- You can't e-file because the system says a return with your EIN has already been filed for that period.
- An extension request (Form 7004) is rejected as a duplicate filing — you haven't filed yet, but the IRS thinks you have.
- You receive an unexpected IRS notice or transcript that doesn't correspond to anything you submitted — for example, a notice about employees you never hired, a balance due on a closed or dormant entity, or a CP notice referencing wages you never paid.
- You receive Letter 5263C or Letter 6042C — the two most common business verification letters (more below).
- Routine IRS correspondence stops arriving because the business address on file was changed without your authorization.
- A return is accepted as an amended return when you never filed an original for that year.
Non-tax red flags
Report these to the Federal Trade Commission and your financial institutions immediately, even if no tax issue has surfaced yet:
- Bills for business lines of credit or credit cards you never opened.
- A business credit report showing accounts you didn't authorize.
- Unexplained bank withdrawals or missing expected mail.
- A notice from a company where you do business that your information was compromised.
If any tax and non-tax indicators appear together, escalate quickly — the window in which a thief can exploit a stolen EIN is often just weeks before they move on.
Decoding IRS Letters 5263C, 6042C, and 6217C
These letters come from the IRS's business verification process. They are not scams, but you should still verify any contact using the phone number printed on the letter and not a number from an email or text. The IRS will never initiate contact by email, text, or social media to request personal information, and it will never threaten lawsuits or arrests by phone.
What each letter means
- Letter 6042C — "We need information to validate the return." The IRS has identified a business return that is potentially fraudulent and is asking for additional information before it finishes processing that return. Think: return-level verification.
- Letter 5263C — "We need information to validate the entity." The IRS needs to verify information reported on Form SS-4, the application that created your EIN. This often stems from outdated or incorrect responsible-party information. Think: entity-level verification.
- Letter 6217C is a close cousin, also asking for additional entity information. If the notice says the EIN information on file is incorrect, the fix is the same.
Why the distinction matters: a 6042C usually pauses a specific return and any refund or overpayment application tied to it, while a 5263C signals the IRS's core record of who controls the entity may be wrong — which affects every future filing until corrected. Both require a response within the stated window, typically 30 days from the date on the letter.
Why you might get one even if you weren't attacked
The IRS says data around responsible parties is often outdated or inaccurate across its business master file. If you formed an LLC five years ago, named a partner as responsible party, and later bought that partner out without filing Form 8822-B, the IRS still shows the former partner. A routine cross-check can then generate a 5263C. Similarly, a simple digit transposition on a payroll return can trip a filter that looks exactly like duplicate-entity fraud.
That is why the letter itself asks you to answer affirmatively whether you are associated with the entity — it is designed to distinguish administrative drift from real theft.
What to Do Within 30 Days of Receiving a Letter
Treat the 30-day deadline as firm. Failure to respond delays processing of returns you file, issuance of refunds, or application of overpayments to next year's estimated tax. Fax is fastest; the IRS provides a fax number on the letter. If you fax, don't also mail the same response.
If you are or were affiliated with the entity
- Answer every question on the letter and provide exactly what it requests. Don't add extra narrative; match the checklist.
- For an estate, include a copy of the deceased individual's death certificate.
- For a trust, include a copy of the Certificate of Trust or the title and completed signature pages from the trust documents.
- Fax to the number on the letter using a machine or an online fax service you trust — review that service's privacy and security policy before uploading sensitive documents. Then retain the transmission confirmation.
- If the responsible party has changed since the EIN was issued, also file Form 8822-B, Change of Address or Responsible Party — Business. IRS regulations require EIN holders to update responsible-party information within 60 days of any change. The responsible party must be an individual who controls, manages, or directs the entity and the disposition of its funds and assets — not another entity. If there are multiple qualifying individuals, you may list whichever one you want the IRS to recognize.
If you are not affiliated with the entity or not the responsible party
- Select the statement on the letter indicating no affiliation, provide your name, and return the letter within 30 days.
- File a police report locally and keep a copy — you may need the report number for banks, credit bureaus, and the IRS.
- Notify the IRS immediately using the contact information on the letter if you believe someone fraudulently used your EIN, even if you checked the "no affiliation" box.
After you respond, the IRS will contact you again by mail only if more information is needed. If you hear nothing, no further action is required — but keep monitoring.
The Full Response Checklist Beyond the Letter
A verification letter is often not the only place fraud surfaces. Use it as a trigger to run a broader sweep.
1. Respond to every IRS notice immediately
Use the contact information on the notice itself. Don't call a number found via web search for that notice type — match the letter's header. Keep copies of everything you send and the IRS's reply envelopes.
2. File a report with law enforcement
A police report creates an official record with a case number that banks, card issuers, and the IRS may ask for. Bring the IRS letter, a government-issued ID, and proof you control the business (articles of organization, operating agreement, or EIN confirmation letter CP 575).
3. Review the business registration record
Search your state's secretary of state business entity portal for every active and closed business under your name. Look for unexpected amendments — address changes, new registered agents, or officer additions you didn't authorize. Revert unauthorized changes through the state's correction process and, where available, subscribe to the state's notification service for future filings.
4. Pull and monitor credit reports
- Business credit: Review Dun & Bradstreet, Experian Business, and Equifax Business reports for new tradelines or inquiries.
- Personal credit (for the responsible party): You are entitled to a free weekly report via AnnualCreditReport.com. Consider placing a one-year initial fraud alert by contacting any one of the three nationwide bureaus — the one you contact must notify the other two. You can also request a security freeze from each bureau individually if you want stricter control.
Contact numbers many owners keep on file: Equifax 800-525-6285, Experian 888-397-3742, TransUnion 800-916-8800. Confirm current numbers on the bureaus' official sites before sharing sensitive data.
5. Reconcile every account statement the day it arrives
Open bank, card, payroll, and merchant statements immediately. Match each transaction to source documents and flag unknown payees, duplicate vendor names with slight spelling changes, or small test charges that often precede larger fraud.
6. Close compromised accounts and rotate credentials
Close any account opened or tampered with without permission. Change passwords for email, banking, payroll, and tax software — use a password manager, passphrases, and multi-factor authentication wherever available. Encrypt sensitive files and email attachments and limit access to employees who genuinely need it.
7. File a complaint with the FTC
The FTC's IdentityTheft.gov walks you through a recovery plan and generates pre-filled letters to send to creditors. The IRS also directs non-tax identity theft reports there.
8. Update security software and train the team
Ensure antivirus and anti-malware tools update automatically, enable firewall protections, back up data to a secure external source disconnected from your network, and securely destroy old drives and printers that contain sensitive data. Share IRS Publication 4524 (Security Awareness for Taxpayers) and brief your team on phishing — never open attachments from unknown senders, verify requests by phone using a known number, and keep personal and business email accounts separate.
Keeping Your EIN Current and Safe — A Bookkeeping Habit
The most avoidable cause of a 5263C is stale responsible-party data. Make EIN maintenance part of your regular close process, not a one-time filing.
Keep Form 8822-B on your checklist
File Form 8822-B within 60 days whenever:
- The responsible party changes (sale of the business, partner buyout, new managing member, grantor change for a trust, personal representative change for an estate).
- The business mailing address changes.
- The business location changes, if that is where tax correspondence should go.
Store the filed form and IRS confirmation with your EIN letter (CP 575 or 147C) in a secure, backed-up location. If you no longer need an EIN, formally close the IRS account — an unused EIN that remains active is a standing invitation for misuse.
Harden how you handle W-9s and EIN letters
- Send W-9s only through password-protected, encrypted channels, and confirm receipt by phone.
- Never post your EIN on your website or social media.
- Store CP 575 / 147C letters in an encrypted vault, not in open cloud folders.
- Log every party to whom you disclose the EIN, the date, and the purpose — your future self will thank you when you need to trace a leak.
Build a data security plan you will actually follow
You don't need an enterprise budget. IRS Publication 4557, Safeguarding Taxpayer Data, plus the FTC's Start with Security guide and NIST's Small Business Information Security — The Fundamentals give small businesses a complete framework. At minimum, document who has access to what data, how you encrypt and back up sensitive files, your incident response steps, and your annual review date.
How the IRS Is Trying to Protect Business Filers
Knowing what happens behind the scenes helps you interpret the letters correctly:
- Filters and letters. When the IRS and its Security Summit partners identify a potentially fraudulent business-related return, the IRS pauses processing and issues a verification letter before the return moves forward. That's Letters 6042C and 5263C doing their job.
- Extra authentication in software. Tax preparation software for business returns now asks preparers a series of questions to authenticate the validity of the return. Answer them carefully — inconsistencies can trigger another round of verification.
- No outbound email or text requests. If you get an email or text claiming to be the IRS asking for your IP PIN or business information, forward it to [email protected] and delete it.
What Happens After You Respond
The IRS says that after you provide your response, it will contact you by mail only if more information is needed. Otherwise, no other action is required. In practice:
- Keep the fax transmission sheet or certified mail receipt.
- Calendar 45 days out to check that expected IRS correspondence (refund, notice of account change, or confirmation) arrives as expected.
- If you filed Form 8822-B separately, watch for the IRS confirmation letter and reconcile it to your records.
If a fraudulent return was already processed, resolution takes longer. You may need to work with the IRS's business identity theft affidavit process, substantiate the legitimate return, and coordinate with your state tax agency — keep a single folder with every piece of correspondence, dated and scanned.
A Simple Monitoring Routine That Catches Problems Early
You don't need to become a full-time fraud analyst. A quarterly routine, tied to your existing close, is enough:
Monthly (during your close):
- Reconcile bank and card accounts fully — don't just check the ending balance.
- Review the IRS business tax account for unexpected filings or balance changes.
- Confirm your business address and responsible party on file haven't changed.
Quarterly:
- Pull one business credit report on rotation (D&B, Experian, Equifax).
- Check your secretary of state entity record for amendments.
- Review who has access to accounting software and revoke stale users.
Annually:
- Pull the responsible party's personal credit report cycle.
- Review and update your written data security plan.
- Purge and securely destroy records past their retention period — the less you store, the less there is to steal.
The businesses that recover fastest from identity theft are not the ones with the most sophisticated tools; they are the ones whose books are current, whose EIN records match reality, and whose owners notice when something doesn't reconcile.
Simplify Your Financial Management
Spotting business identity theft early comes down to the same discipline that makes month-end close painless: current records, reconciled accounts, and clear control over who can see and move money. When your books are accurate every week — not just at tax time — an unexpected IRS notice, a changed address, or a charge you didn't authorize stands out immediately instead of hiding in a backlog.
Beancount.io gives you plain-text, version-controlled accounting that keeps every transaction transparent and traceable. No black boxes, no vendor lock-in — just a ledger you fully control and can audit on your own schedule. Get started for free and build a set of books that protects your business as well as it reports on it.