News of the FBI into tax refund fraud using Intuit's TurboTax software did not go unnoticed by cybercriminals, who deployed a phishing campaign to collect personal and financial information.

The emails claim to be from Intuit and have various themes, including: notification of a false security check or a false tax refund notice to notification of account lockout due to a long period of inactivity.
TurboTax app that allows US residents to file their tax returns in an easy way.
The application offers a free version and hundreds of thousands of users rely on it to complete their tax returns, a fact that attracts cybercriminals.
Intuit 's security alerts page has been growing in recent years with new examples of phishing, and more than a dozen alerts have been issued since the beginning of the week. Most of the emails contain fake sender addresses, and some contain TurboTax graphics to increase the recipient's trust level.
In all versions of the deceptive emails, there is a link that the potential victim must access to log in to their account and resolve the problem described in the message.
The URL that is loaded displays a fake log-in that mimics the real one, and all information entered in the provided fields ends up with the scammers.
The ultimate goal of the scammers is to hack into the user's TurboTax and steal their personal information. Addresses, names, and Social Security numbers can be used for identity theft, allowing the scammer to obtain credit from financial institutions in the victim's name.
After entering the fake website, a form may appear requesting personal and financial information. A victim who reaches this stage may ignore the fact that it is a scam, given that the page appears to be real and the verification process completes without problems.
Checking the URL in the browser's address bar to see if it matches a domain associated with Intuit is one way for the user to discover the fraud attempt.
Also, since log-in pages send sensitive information over the Internet, the connection is encrypted and the HTTPS (Secure HTTP) protocol is used. If the connection is not secure, the page is most likely part of a malicious attack.
