Thursday, January 12, 2017

New Two-Stage E-mail Scheme


The Internal Revenue Service, state tax agencies and tax industry leaders today warned tax professionals to be alert to an email scam from cybercriminals posing as clients soliciting their services.

A new variation of this phishing scheme is targeting accounting and tax preparation firms nationwide. The scheme's objective is to collect sensitive information that will allow fraudsters to prepare fraudulent tax returns.

These latest phishing emails come in typically two stages. The first email is the solicitation, which asks tax professionals questions such as "I need a preparer to file my taxes." If the tax professional responds, the cybercriminal sends a second email. This second email typically has either an embedded web address or contains a PDF attachment that has an embedded web address.

In some cases, the phishing emails may appear to come from a legitimate sender or organization (perhaps even a friend or colleague) because they also have been victimized. Fraudsters have taken over their accounts to send phishing emails.

The tax professional may think they are downloading a potential client's tax information or accessing a site with the potential client's tax information. In reality, the cybercriminals are collecting the preparer's email address and password and possibly other information.

The IRS urges tax professionals and tax preparation firms to consider creating internal policies or obtain security experts' recommendations on how to address unsolicited emails seeking their services.

Courtesy of IRS

For more information contact Neikirk Mahoney and Smith at 502-896-2999

No comments:

Post a Comment