Share

Related Links

Related Stories

  • IRS phishing scam targets corporate email
    Security firm eSoft is warning clients about an IRS phishing con that is specifically targeting businesses and corporate email accounts.
  • All is not OK in Oklahoma: State tax website victim of hack
    The website of the Oklahoma Tax Commission was the apparent victim of a hack yesterday, one in which visitors to the website were prompted to accept an Adobe license agreement and download software. The hack could not come a worse time for the Commission, whose site is undoubtedly experiencing an uptick in visitors as tax season approaches.

Top 5 Stories

News

Record season for tax, IRS phishing scams

30 March 2010

Data from McAfee show that the number of fake IRS domains is already at a record level when compared with last year’s numbers, as the security vendor warns last-minute filers not to fall prey to the various methods of identity and data theft that capitalize on tax season.

A recent McAfee security blog posting reveals data that scammers attempting to pull off phishing schemes based on the IRS and tax time are off to an early and record-setting start. In fact, stats from McAfee Labs show that more than 1500 domains hosted IRS phishing scams this past February, which eclipsed the high-water mark of more than 800 seen in April of 2009.

McAfee warns that this cluster of “fake IRS URLs” can be arrived at from many avenues: phishing emails, posting of URLs on various forums, and black-hat SEO manipulation, just to name a few. According to the company’s data, the volume of malicious sites hosting IRS and tax scams has already eclipsed that of 2009, this with more than two weeks left until the April 15 IRS deadline.

The IRS does provide a Consumer Alerts page that reviews some of the latest and most notorious tax season flimflam. The site lists a number of scams that the IRS has encountered, and acknowledges that many of the bogus communications – especially emails – can look very official, especially when they make use of the IRS logo. However, the IRS warns users that there is only one official IRS website, IRS.gov, and that the service will never initiate contact with taxpayers via email.

This article is featured in:
Data Loss  •  Internet and Network Security  •  Malware and Hardware Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.

We use cookies to operate this website and to improve its usability. Full details of what cookies are, why we use them and how you can manage them can be found by reading our Privacy & Cookies page. Please note that by using this site you are consenting to the use of cookies. ×