Breaking News
Communities

The IRS warns tax professionals to be aware of phishing scams

4 min read

WASHINGTON -- In the second installment of a special series, the Internal Revenue Service and Security Summit partners warned tax professionals to be aware of evolving phishing scams and cloud-based schemes designed to steal sensitive taxpayer information.

The IRS and Security Summit partners -- representing state tax agencies and the nation's tax industry -- continue to see a steady stream of e-mail and related attacks aimed at the nation's tax professional community. These are designed to steal sensitive tax and financial information from clients.

The variants of these email attacks routinely number in the hundreds and can target tax professionals whether it's tax season or not.

"We continue to see a barrage of email and related attacks designed to trick tax professionals and gain access to their sensitive information," said IRS Commissioner Danny Werfel. "These attempts can be elaborate, multi-layered efforts that look convincing and can easily fool people. Tax professionals need to be wary and educate their employees to use extra caution to protect their clients and their businesses."

This is the second release in an eight-part "Protect Your Clients; Protect Yourself" summer series, part of an annual education effort by the Security Summit, a group that includes tax professionals, industry partners, state tax agencies and the IRS. The public-private partnership has worked since 2015 to protect the tax system against tax-related identity theft and fraud.

These security tips will be a key focus of the Nationwide Tax Forum, which will be in five cities this summer throughout the U.S. In addition to the series of eight news releases, the tax professional security component will be featured at the forums, which are three-day continuing education events. The remaining forums begin July 30 in Orlando, Aug. 13 in Baltimore, Aug. 20 in Dallas and September 10 in San Diego.

The IRS reminds tax pros that registration deadlines are quickly approaching for several of the forums, and Orlando is already sold out.

Phishing, spear phishing, clone phishing and whaling

One of the most common threats facing tax pros are phishing and related scams. These are designed to trick the recipient into disclosing personal information such as passwords, bank account numbers, credit card numbers or Social Security numbers.

Tax professionals and taxpayers should be aware of different phishing terms and what the email scams might look like:

Phishing/Smishing --Phishing emails or SMS/texts (known as "smishing") attempt to trick the recipient into clicking a suspicious link, filling out information or downloading a malware file. Often phishing attempts are sent to multiple email addresses at a business or agency increasing the chance someone will fall for the trick.

Spear phishing -- A specific type of phishing scam that bypasses emailing large groups at an organization, but instead identifies potential victims and delivers a more realistic email known as a "lure." These types of scams can be trickier to identify since they don't occur in large numbers. They single out individuals, can be specialized and make the email seem more legitimate. Scammers can pose as a potential client for a tax professional, luring the practitioner into sharing sensitive information.

Clone phishing -- A newer type of phishing scam that clones a real email message and resends it to the original recipient pretending to be the original sender. The new message will have either an attachment that contains malware or link that tries to steal information from the tax professional or recipient.

Whaling -- Whaling attacks are very similar to spear phishing, except these attacks are generally targeted to leaders or other executives with access to secure large amounts of information at an organization or business. Whaling attacks can also target people in payroll offices, human resource personnel and financial offices.

Security Summit partners continue to see instances in which tax professionals have been particularly vulnerable to emails posing as potential clients. In the "new client" scam, the criminals use this technique to trick practitioners into opening email links or attachments that infect computer systems with the potential to steal client information.

Starting at /week.