When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures
ID: 0fa26c36-e366-5f36-96ac-8fab23deb6b2
STIX ID: report--0fa26c36-e366-5f36-96ac-8fab23deb6b2
Feed Name: Microsoft Security
Date Published: 2026-03-19
Date Updated: 2026-04-28
Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team
Microsoft Threat Intelligence observed multiple coordinated tax‑themed phishing campaigns in early 2026 that targeted U.S. organizations and accounting professionals using personalized lures (W-2s, CPA impersonation, IRS notifications), PhaaS kits (Energy365, SneakyLog), QR codes and attachment-based chains to harvest credentials and deliver remote access malware by abusing legitimate RMM tools (ScreenConnect, SimpleHelp, Datto); the report includes campaign timelines, impacted industries and scales (including a large wave targeting ~29,000 users), IOCs (domains and SHA-256 hashes), and recommended mitigations for detection and prevention.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
