In today’s threat landscape, phishing attacks, like death and taxes, are inevitable. For financially motivated threat actors, the deadline pressure and frantic exchange of forms and documents that occurs during tax season creates an appealing opportunity to deploy phishing campaigns targeting high-risk data from millions of stressed and distracted individuals and businesses.
Although everyone can be a target of tax-season phishing, certain groups of people are more vulnerable than others. Prime targets include individuals who may be less informed about IRS methods of engagement—Green Card holders, small business owners, new taxpayers under the age of 25, and older taxpayers over 60.
This special tax season threat intelligence report surveys the tactics, techniques, and procedures (TTPs) threat actors use most in the following sections:
- Microsoft Threat Intelligence uncovers a 2024 tax season phishing campaign, where details of a new tax-season phishing technique using lures masquerading as tax-related documents provided by employers are described.
- Threat actors impersonate tax payment processors in phishing emails, which describes how Microsoft Threat Intelligence has observed threat actors using third-party federal tax payment processor logos.
- What cybercriminals want at tax time, where we identify the different types of high-risk data commonly targeted at tax time.
- How cybercriminals get your data, where we describe the tax season–themed social engineering techniques threat actors use most.
- Tax season cybersecurity best practices, where we provide best practices and actionable advice for staying vigilant against social engineering attacks.
Follow Microsoft Security