It’s Income Tax Fraud Season Again

Every year about this time, cyber-criminal groups start to ramp up for the annual income tax fraud season.  If you would prefer to receive your own tax refund, as opposed to letting some scam artist get it instead, the basic solution is to file your returns as early as possible.  Here are some things to be watching for.

  • W-2 reports phishing scam – This phishing scan usually targets company HR department personnel, with individually crafted emails that come from the hijacked business email account of a company officer, or sometimes of your tax accountant.  Be wary of any requests for W-2 information that fall outside of the norm for your company.
  • Your accountant is hacked – If your tax preparer’s computer is compromised, or his or her email account hijacked, they your tax information is available to cyber-scammers.
  • Your accountant is NOT hacked – In this scam, you get an email from an accounting professional group that claims your accountant was one of many who were compromised.  The phishing email is a scam designed to get you to click through to a web page that requests your personal information.
  • You filed too late – When you file your taxes electronically, and the tax system says that your taxes have already been filed, then the criminals got there ahead of you, and filed for as big a refund as they could get.  Your tax filings will be wrong, of course.  When this happens you have to open a claim with the IRS, and file an amended report.

Tax Scam Reports from Last  Year

The methods may change slightly, but every year its the same scam.  Here are links to my previous reports on this issue

  • Income Taxes – File Early to Beat the Hacker
    The early bird gets the worm.  The second mouse gets the cheese.  The late tax filer gets nothing.  Why?  April is tax fraud time.  The best way to avoid losing your tax refund to a scammer is to file as early as possible, before the tax fraudster can get it done.  Having said that, this infor…


About the Author:

Cybersecurity analyst, pen-tester, trainer, and speaker. Serving small business owners in the St Paul, Minneapolis, and western Wisconsin area since 2001. Cybersecurity and hacking have been a passion of mine since I entered the computer and networking business in 2000. I hold several cybersecurity certifications including Certified Information Systems Security Professional (CISSP), Certified Advanced Security Pratitioner (CASP), and Certified Ethical Hacker (CEH). Other computer industry certifications include A+, Network+ and Microsoft Certified System Engineer (MCSE). As Cybersecurity Analyst at The WyzCo Group, I help our clients experience high levels of security on their computers, networks, and websites. In addition to consulting on security products and services, we also conduct security audits, vulnerability assessments and full penetration tests. We also work with companies and organizations that need to certify compliance with regulations such as PCI-DSS (credit card processing), HIPAA/HITECH (medical records), and GLBA. We also provide Cybersecurity Awareness Training for clients and their employees. I am a frequent speakers at cybersecurity conferences such as the Minnesota Bloggers Conference, Secure360 Security Conference, the (ISC)2 World Congress, and the ISSA International Conference, and many local community organizations, Chambers of Commerce, SCORE, and several school districts. I have been blogging on cybersecurity since 2008.
  Related Posts

Add a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.