Identity Theft Is Rampant at Tax Time. Here's How to Avoid It

Yasuhide Fumoto | Digital Vision | Getty Images

Identity-thieving tax schemers are proliferating like never before, so it's important to know how to avoid them.

In 2011, there were fewer than 300 Internal Revenue Service criminal investigations into identity theft. That number more than tripled in 2012 to almost 900, and it's on track to double again this year.

The scammers are busy and their schemes are varied.

According to court records, one husband-and-wife team with a tax-prep business in Roanoke, Va., had clients sign returns without reviewing their contents—which the couple would falsify—and then had the inflated refunds deposited directly into their own accounts. Then they'd cut checks to their clients for a fraction of the refund received.

(Read More: Tax Refund: What Are You Doing With Yours?)

A Pittsburgh man had the nerve to steal Uncle Sam's identity: He opened a shell company under the name Uncle Sam's Tax Service in Buckeye, Ariz., through which he defrauded the government of nearly $300,000 using the identities of deceased Californians.

Others are buying and selling identities like baseball cards. (They go for about $10 apiece, judging by the case of an Alabama woman who stole them from the medical records office where she worked. She sold 800 for about $8,000.)

In all, of 109 million returns claiming refunds, the Treasury Department says some 1.5 million are filed under stolen identities. Those are just the detected ones.

Ed Brown, a partner in the Atlanta law office of Burr & Forman, offered these pointers to avoid being among the scammed:

  • Never answer emails from the IRS. In all likelihood, such emails are fake and "phishing" for your personal information. If you feel you need to check if one is real (it very probably isn't), call the IRS and ask: (800) 829-1040.
  • If you have personal information on your computer, guard it closely. Ideally, a computer with your banking information, Social Security number, etc. is one you shouldn't use for travel or connecting to a public or unprotected network.
  • Passwords are important. Invent passwords that are extremely hard to guess ones (not "password," or "1234567," or your birth date). Then change them frequently.
  • Use common sense. Check your credit report annually for irregularities at Don't toss old tax returns or bank statement in the trash without shredding them. And don't click on suspicious-looking links in your email inbox.
  • File early. You can beat a crook whose gotten his hands on your info to the IRS's door.
  • Check your withholding: You can not only stop lending the government your money interest-free, you can reduce what's at risk from a stolen-identity return.

Tiffany Washington, owner of Washington Accounting Services in Waldorf, Md., also urged taxpayers to think about the chain of custody of their tax returns.

"If you are sending it by U.S. mail, never leave it in an unlocked home or business mailbox," she said. "Always use registered or certified mail, which not only provides you with a record of who accepted it, but serves as a deterrent to anyone with malicious intent who comes in contact with your materials."

For e-filers, she said: "Don't use a public computer. Make certain you are on a secure network. Check your computer for any viruses or malware prior to filing."

And err on the side of caution when it comes to any links or emails offering assistance, she advised. Use only trusted sources.

Attorney Brown said it's really no different from other forms of identity theft, like credit card fraud. The bad guys are most likely to try to get your digits by persuading you to give them up through "phishing"—that is, masquerading as a trustworthy person or organization online or in an email.

It's not easy to be ever vigilant, but it is necessary.

Brown admitted that after looking over his own list, he realized he had let his own diligence slip. "I changed two passwords last night," he said.

By CNBC's Matt Twomey; Follow him on Twitter @Matt_Twomey