logo

From Tax Refund to Total Compromise: IRS-Themed Phishing Email Drives Full-Stack Financial Fraud

ID: 3c56fd2f-3a6c-5efa-ae7b-835b98d7de2c

STIX ID: report--3c56fd2f-3a6c-5efa-ae7b-835b98d7de2c

Feed Name: Cofense Blog

Threat Score
55/100

Date Published: 2026-04-09

Date Updated: 2026-04-27

Author: Cofense

...
...

Cofense Intelligence describes a multi-stage IRS/Elon Musk-themed phishing campaign offering a fake $5,000 tax refund that redirects victims to credential-phishing pages and a fraudulent cryptocurrency marketplace; attackers exfiltrate form data via a Telegram bot and then solicit photo IDs and bank details to enable identity theft and direct theft via ACH and required Bitcoin deposits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.