logo

When tax season becomes cyberattack season: Phishing and malware campaigns using tax-related lures

ID: 0fa26c36-e366-5f36-96ac-8fab23deb6b2

STIX ID: report--0fa26c36-e366-5f36-96ac-8fab23deb6b2

Feed Name: Microsoft Security

Threat Score
72/100

Date Published: 2026-03-19

Date Updated: 2026-04-28

Author: Microsoft Threat Intelligence and Microsoft Defender Security Research Team

...
...

Microsoft Threat Intelligence observed multiple coordinated tax‑themed phishing campaigns in early 2026 that targeted U.S. organizations and accounting professionals using personalized lures (W-2s, CPA impersonation, IRS notifications), PhaaS kits (Energy365, SneakyLog), QR codes and attachment-based chains to harvest credentials and deliver remote access malware by abusing legitimate RMM tools (ScreenConnect, SimpleHelp, Datto); the report includes campaign timelines, impacted industries and scales (including a large wave targeting ~29,000 users), IOCs (domains and SHA-256 hashes), and recommended mitigations for detection and prevention.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.