Hackers are also trying to take advantage of this year's tax season by sending phishing emails that claim to be from the IRS, but which are actually designed to infect victims' computers with malware or trick users into handing over personal data, such as banking information, usernames, passwords and other sensitive information.
See also: BEC scams cost victims more than ransomware

Fortinet cybersecurity researchers say the scams aren't particularly sophisticated, but they're being sent out en masse at a time when people are pressed for time with tax deadlines — and even if a small portion of those who receive the phishing emails are duped, hackers can steal a lot of data.
One of the phishing campaigns is based on an email purporting to come from the US Internal Revenue Service (IRS) and is designed to infect the victim with Emotet malware, a powerful trojan used to steal passwords that also creates a backdoor on the infected computer.
See also: Which ransomware encrypts data the fastest? (comparison of 10 variants)
Claiming to be from “IRS Online,” the email with the subject line 'Incorrect Form Selection' asks victims to open an attachment called “W-9 form.zip” – providing the target with a plain text password required to open the file. The lure is designed to resemble Form W-9, which is a Request for Taxpayer Identification Number and Certification from the IRS.
If the user opens the Zip file, they are prompted to enable macros – a common tactic used by hackers to deliver malware. Once the macros are enabled, the malicious document then retrieves and downloads the Emotet malware, which attackers can use to steal usernames and passwords on the compromised Windows machine.
Emotet is a popular backdoor for delivering other forms of malware to infected systems, including ransomware.
Another tax season-themed phishing scam uses slightly different tactics, but has the same goal of tricking people into giving up sensitive information. This phishing email, with the subject line “NEW YEAR-NON-RESIDENT ALIEN TAX EXEMPTION UPDATE,” contains a PDF document titled “W8-ENFORM.PDF.”.
While the PDF itself is not malicious – since it does not provide malware – the scam asks the user to fill out the document and send it back. Some of the information requested is name, address, tax ID number, email, passport number and mother’s maiden name, as well as bank account details.

See also: Hackers steal cryptos from other hackers by promoting fake malware
All of this sensitive information can be used to compromise the victim's online accounts, including their bank account. The information can also be used to commit fraud in the victim's name.
Researchers note that the IRS never asks for information from taxpayers via email and uses the postal service to send letters. However, the social-engineering tactics and the fact that these emails are sent during tax season may convince some users.
Information source: zdnet.com
