Microsoft is warning of new phishing campaigns that are taking advantage of the U.S. tax filing season to steal credentials and install malware. IRS phishing attacks are targeting thousands of users with fake emails that mimic official Internal Revenue Service, taking advantage of the urgent nature of tax obligations.
See also: Microsoft: OAuth phishing attacks are evolving

Email campaigns exploit the urgent and time-sensitive nature of messages to send phishing* messages that masquerade as tax refund notifications, payroll forms, filing reminders, and requests from tax professionals. The attacks trick recipients into opening malicious attachments, scanning QR codes, or interacting with suspicious links.
According to Microsoft Threat Intelligence and Microsoft Defender Security Research teams, many campaigns target individuals to steal personal and financial data, while others specifically target accountants and other professionals handling sensitive documents and having access to financial data. These professionals are accustomed to receiving tax emails during this period, making them ideal targets.
While some of these attempts direct users to suspicious pages designed through Phishing-as-a-Service (PhaaS) platforms, others lead to the installation of legitimate remote monitoring and management (RMM) tools, such as ConnectWise ScreenConnect, Datto , and SimpleHelp. These tools allow attackers to gain permanent access to compromised devices.
Microsoft reports that it observed a large-scale IRS phishing campaign on February 10, 2026, which affected more than 29,000 users in 10,000 organizations. Approximately 95% of the targets were located in the United States, covering sectors such as financial services, technology and software, retail, and consumer goods.
See also: Phishing campaign targets Bitpanda users

The emails masqueraded as the IRS, claiming that potentially fraudulent tax returns had been filed under the Electronic Filing Identification Number (EFIN) . Recipients were encouraged to review these returns by downloading a supposedly legitimate “IRS Transcript Viewer.” The emails, sent via Amazon Simple Email Service (SES), contained a “Download IRS Transcript View 5.1” button that redirected users to smartvault[.]im, a domain masquerading as SmartVault.
The phishing site relied on Cloudflare to keep bots and automated scanners away, ensuring that only human users are served with the main payload: a maliciously packaged ScreenConnect that provides attackers with remote access to their systems and facilitates data theft, credential harvesting, and further activity after exploitation.
The attackers use various techniques to deceive victims. One campaign uses Certified Public Accountant (CPA) lures to deliver phishing pages that are linked to the Energy365 PhaaS kit to capture the victims' emails and passwords. The Energy365 phishing kit is estimated to send hundreds of thousands of malicious emails daily.
Protection Measures and Security Recommendations
To remain safe from these attacks, organizations are advised to enforce 2FA for all users, implement conditional access policies, monitor and scan incoming emails and visited websites, and block users from accessing malicious domains. Training employees on social engineering techniques and recognizing phishing emails is also critical, especially for accountants and tax professionals who are primary targets.
See also: Microsoft: Incorrect email routing enables internal domain phishing

Microsoft emphasizes that organizations must be especially careful during the tax season and verify all communications that appear to originate from the IRS through official channels.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
