A Zcash user recently made a challenge for anyone to tell where his coins came from that went from taddress->zaddress->zaddress->taddress. The winner only had to look at past public transactions and find the same coin amount to find the original t-address.
That is why privacy-by-default is very important, and why right now Monero should be considered more private.
Monero has been "under attack" for a long time now, well before the IRS started giving money out. There are possible attack vectors and subsequent remedies. The Monero people made a series called Breaking Monero where they talk about all of that stuff.