IRS: New scam email could target Payroll
Give your Payroll team the heads up: There’s a new spear phishing scam email making the rounds that’s attempting to steal their account credentials by trying to convince them to access a fake version of IRS e-Services.
When cybercrooks steal the identity of someone they think is a tax preparer or has access to sensitive employee taxpayer data, they then try to file fraudulent tax returns to get a refund.
The scam email claims to be from IRS e-Services and appears to be legitimate because it includes the IRS logo. Similar, but still bogus, emails can state that they’re from your “tax preparation application provider.”
What the email scam looks like
Subject lines that should raise red flags include:
- “Action Required: Your account has now been put on hold”
- “Your account has been put on hold,” or
- “Unusual activity report.”
The email itself will say that you haven’t applied a critical software update, and that you must restore and update your account immediately within the next 24 hours or else your account will be terminated.
There will be a malicious “solution link” or attachment provided to supposedly restore your IRS account. However, clicking on them either compromises sensitive data or downloads malware onto your computer.
Scam emails that claim to be from your tax software company will have a link that sends the user to a website that shows the logos of several popular tax software providers. Clicking on a logo opens up a popup window that requests your account information. If the info gets entered, that’s how the credentials are stolen.
Stopping the impersonators
The IRS warns Finance pros to avoid following any instructions in emails like these. They should also avoid sending a reply to the email.
If someone on your team gets tricked into clicking on a suspicious link or attachment, your IT team should be alerted ASAP. If necessary, you should contact your tax software provider directly using a trusted phone number not found in an internet search (because a website can be forged by hackers).
Finally, IRS encourages saving scam emails in a file and sending it as an attachment to phishing@irs.gov. The Treasury Inspector General for Tax Administration should also be notified at www.tigta.gov to report the IRS impersonation scam.
Free Training & Resources
White Papers
Provided by UJET
Webinars
Provided by Yooz
White Papers
Provided by Anaplan
Further Reading
The 2024 tables for federal income tax withholding are now available, IRS said during a recent Payroll Industry Call. The Service poste...
Looks like AI won’t be taking the place of all those vacant jobs after all. CEOs at bigger companies — some who laid off a lot ...
A Little Caesars franchisee will pay $409,457 for federal wage and hour violations, the Department of Labor (DOL) recently announced. Th...
Client companies thought they were outsourcing payroll and HR compliance to a vendor. But the tax exposure never really left their books. ...
That familiar voice on the phone? Could be a deepfake. The face you’ve seen a thousand times in meetings? Don’t assume it’...
A beneficial ownership reporting rule that takes effect January 1, 2024 may add another critical item to your compliance to-do list. An ...