Stress and worry are emotions that are often linked with the period between the beginning of a new year and mid-April, the federal tax filing deadline. Modern technology has brought with it techniques and applications that reduce this burden by making it easier for consumers to prepare a tax return. Unfortunately the age of e-filing has come with increased risk of tax fraud due to cybercrime. According to IRS statistics, investigations, prosecutions, and convictions for tax crimes, including those involving identity theft, have been on the decline over the last three years.
However, last year the agency announced a “surge in phishing email” schemes designed to harvest employee W-2 information used to file fraudulent returns. Around the same time, security researcher Brian Krebs wrote a blog post about commercial operations that monetize the data appropriated by successful phishing schemes. Both reports note that employees working in payroll and human resources are commonly targeted in these types of attacks.
With tax season upon us, Bitsight researchers investigated the frequency of reported phishing incidents by sourcing data from state Freedom of Information Act requests and cybersecurity news. It is important to note that these are only the phishing events that have been identified and reported publicly rather than a complete accounting of every event that has occurred. They found that in Fiscal Year 2016, reports of phishing dramatically increased between the months of February and May when compared with the rest of the year. The majority of these incidents involve human resource employees being tricked into sharing company W-2 information with an attacker via email, or slight variants of that attack pattern. Cybercriminals coerce HR into complying with these phony requests by impersonating an executive officer’s email address and hoping that the employee is not suspicious enough to closely screen emails from their boss. As recently as February of this year a municipality, a travel agency, and a school district found themselves embroiled in phishing scams with very familiar fact patterns.
