{"id":44885,"date":"2022-02-16T10:41:31","date_gmt":"2022-02-16T18:41:31","guid":{"rendered":"https:\/\/lapost.us\/?p=44885"},"modified":"2022-02-16T10:41:31","modified_gmt":"2022-02-16T18:41:31","slug":"latest-spearphishing-scams-target-tax-professionals","status":"publish","type":"post","link":"https:\/\/lapost.us\/?p=44885","title":{"rendered":"Latest spearphishing scams target tax professionals"},"content":{"rendered":"<p>Feb. 16, 2022,\u00a0WASHINGTON \u2013 With tax season in full swing, the Internal Revenue Service, state tax agencies and tax industry today warned tax professionals of new email scams that attempt to steal their tax software preparation credentials.<\/p>\n<p>&nbsp;<\/p>\n<p>The Security Summit partners warned these \u00a0scams serve as a reminder that <a href=\"https:\/\/www.irs.gov\/tax-professionals\/protect-your-clients-protect-yourself\">tax professionals<\/a> remain prime targets for thieves. These thieves try to steal client data and tax preparers&#8217; identities in an attempt to file fraudulent tax returns for refunds.<\/p>\n<p>&nbsp;<\/p>\n<p>The latest phishing email uses the IRS logo and a variety of subject lines such as &#8220;Action Required: Your account has now been put on hold.\u201d The IRS has observed similar bogus emails that claim to be from a \u201ctax preparation application provider.\u201d One such variation offers an \u201cunusual activity report\u201d and a solution link for the recipient to restore their account.<\/p>\n<p>&nbsp;<\/p>\n<p>\u201cScams continue to evolve, and this one is especially sinister since it threatens tax professional\u2019s accounts,\u201d said IRS Commissioner Chuck Rettig. \u201cTax professionals must remain vigilant in identifying and staying clear of these IRS impersonation emails. A little extra care can protect the tax professionals and their clients.\u201d<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Emails claiming \u201cYour account has been put on hold\u201d are scams<\/strong><\/p>\n<p>The IRS has observed similar bogus emails that claim to be from tax software providers. The scam email will send users to a website that shows the logos of several popular tax software preparation providers. Clicking on one of these logos requests tax preparer account credentials.<\/p>\n<p>&nbsp;<\/p>\n<p>The IRS warns tax pros not to respond or take any of the steps outlined in the email. Similar emails include malicious links or attachments that are set up to <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p5293.pdf\">steal information<\/a> or to download malware onto the tax professional&#8217;s computer.<\/p>\n<p>&nbsp;<\/p>\n<p>In this case, if recipients enter their credentials into the pop up window, thieves can use this information to file fraudulent returns by using credentials that were provided by the tax professional.<\/p>\n<p>&nbsp;<\/p>\n<p>An example of this type of bogus email states:<\/p>\n<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/p>\n<p><strong><em>Your account has now been put on hold<\/em><\/strong><\/p>\n<p><strong><em>\u00a0<\/em><\/strong><\/p>\n<p><em>ALL preparers are required to apply security feature to their Tax Pro account towards 2021 Tax Returns processing.<\/em><\/p>\n<p><em>You have failed to apply new update before expiry date<\/em><\/p>\n<p><em>You are restore and update your acc|ount immediately.<\/em><\/p>\n<p><em>Please Click Here to update your acc|ount now.<\/em><\/p>\n<p><em>Important<\/em><\/p>\n<p><em>Failure to update your account within the next 24hours will lead to you account being terminated and be barred from filing tax returns\u00a0 claims for 2021 tax season Your access will be restored once you have updated your details.<\/em><\/p>\n<p><em>\u00a0<\/em><\/p>\n<p><em>Sincerely,<\/em><\/p>\n<p><em>IRS.gov eServices<\/em><\/p>\n<p><em>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<\/em><\/p>\n<p>&nbsp;<\/p>\n<p>Tax professionals who clicked on one of the URLs and then entered in their account information should contact their tax software preparation provider\u2019s support hotline.<\/p>\n<p>&nbsp;<\/p>\n<p>Tax professionals who get a <a href=\"https:\/\/www.irs.gov\/privacy-disclosure\/report-phishing\">scam email<\/a> should save the email as a file and then send it as an attachment to <a href=\"mailto:phishing@irs.gov\">phishing@irs.gov<\/a>. They should also notify the Treasury Inspector General for Tax Administration at <a href=\"https:\/\/www.treasury.gov\/tigta\/\">www.tigta.gov<\/a> to report the IRS impersonation scam. Both TIGTA and the <a href=\"https:\/\/www.irs.gov\/compliance\/criminal-investigation\">IRS Criminal Investigation division<\/a> are aware of this scam.<\/p>\n<p>&nbsp;<\/p>\n<p>The IRS, state tax agencies and the nation\u2019s tax industry \u2013 working together in the Security Summit initiative \u2013 have taken numerous steps since 2015 to protect taxpayers, businesses and the tax system from identity thieves. Summit partners continue to warn people to watch out for common scams and schemes this tax season.<\/p>\n<p>&nbsp;<\/p>\n<p>For additional information and help, tax professionals should review <a href=\"https:\/\/www.irs.gov\/pub\/irs-pdf\/p4557.pdf\">Publication 4557, Safeguarding Taxpayer Data<\/a> and <a href=\"https:\/\/www.irs.gov\/identity-theft-fraud-scams\/identity-theft-information-for-tax-professionals\">Identity Theft Information for Tax Professionals<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<p>-30-<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Feb. 16, 2022,\u00a0WASHINGTON \u2013 With tax&#46;&#46;&#46;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[],"class_list":["post-44885","post","type-post","status-publish","format-standard","hentry","category-u-s-a"],"_links":{"self":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/44885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=44885"}],"version-history":[{"count":1,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/44885\/revisions"}],"predecessor-version":[{"id":44886,"href":"https:\/\/lapost.us\/index.php?rest_route=\/wp\/v2\/posts\/44885\/revisions\/44886"}],"wp:attachment":[{"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=44885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=44885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lapost.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=44885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}