Blog / Threats
Threats
Tax Season Phishing at CPA Firms: The Fake IRS Notice, the Cloned Portal Link, and the Four Minutes That Cost a Filing Season
Tax season phishing peaks in February at CPA firms. How the fake IRS e-Services notice and the cloned client portal work, and the reply that stops both.
The e-Services notice that lands at 7:40 on a Tuesday
The tax manager at a nine-person CPA firm has sixty-one returns open and three weeks of sleep debt. At 7:40 on a Tuesday in February an email arrives from what says it is IRS e-Services. Subject line: action required, your account has been placed on hold pending identity verification. There is a case number. There is a 48-hour deadline. There is a button that says Verify Now.
She has an EFIN. She knows exactly what losing the use of it in the second week of February would do to the firm. So she clicks, lands on a login page that looks like the one she uses, and types her username, her password and the six-digit code from the app on her phone. The page spins. Verification complete.
Nothing visible happens that day.
Nine days later a client calls to ask why the firm sent him a file-share link he was not expecting. It went out from her mailbox, in her signature, to 340 clients, at 4:12 in the morning. Quoted in the thread underneath: a different client's return from last year, Social Security number sitting in the header.
The six-digit code expired in thirty seconds. It did not matter. During the four minutes the attacker was signed in as her, he added his own authenticator app to the account and never needed her again.
What the heck does this mean
Phishing is a lie delivered by email that asks you to type something into a page you did not go looking for. The tax season variety has two favorite costumes: the IRS or your tax software vendor telling you an account is suspended, and a client, or a fake client, sharing documents through a portal link.
Credential harvesting is what the fake page is for. It records what you type and passes it straight to the real login screen, which is why the code from your phone does not save you. The industry term for that relay is adversary in the middle. Plain version: the attacker is standing between you and the real site, holding the door.
Persistence is the part firms miss. Once inside, an attacker registers a second multi-factor method, or creates a mailbox rule that files replies from your clients into a folder you never open. Your password reset does not remove either of those. You can change the lock and leave his key in the drawer.
Firms that specialize in accounting work are targeted in season for an obvious reason. In February, one mailbox holds a year of W-2s, K-1s and bank details for several hundred households.
The numbers that matter
Credential theft was behind 31% of breaches in professional services in the Verizon 2026 Data Breach Investigations Report. Not exotic malware. A password typed into the wrong box.
The human element, meaning a person doing a normal thing at the wrong moment, featured in 62% of breaches in that same Verizon 2026 report. The tax manager in the story is not careless. She is busy in February, which is the entire plan.
Reported cybercrime losses in the United States reached USD 20.9 billion in the FBI IC3 2025 Internet Crime Report, with business email compromise alone at USD 3.05 billion across 24,768 complaints. Refunds and client wires live in that number too.
What to do this week
- Move the accounts that matter most to phishing-resistant sign-in before 1 March: the e-Services login, the tax software admin account, the firm's email and the portal. Security keys or passkeys, not codes. If a partner refuses, at least turn on number matching and block legacy sign-in protocols. (CIS 6 Access Control Management)
- Ask your IT provider for an alert every time a new multi-factor method is registered on any mailbox, and review the list of registered methods for all staff this week. That single report would have caught the attack above on day one. (CIS 6 Access Control Management)
- Pull the mailbox rules report for the whole firm and block auto-forwarding to outside addresses. Then check who has delegate access to the partners' calendars and mail, which is usually a former assistant nobody removed. (CIS 9 Email and Web Browser Protections)
- Send one plain email to every client before 15 February: the firm sends documents through one portal only, the address is this, bookmark it, and we will never send you a bare file-share link. Half of tax season phishing works because clients have no idea what normal looks like. (CIS 14 Security Awareness and Skills Training)
- Make reporting a suspected email a two-second habit with a button in the mail client, and thank whoever uses it, out loud, even when the message turns out to be real. The firm that punishes false alarms stops hearing about the real ones. (CIS 14 Security Awareness and Skills Training)
- Write the one-page card for the day it happens: who calls the software vendor to lock the EFIN, who resets sessions and removes rogue authenticators, who reviews what the mailbox held, and what your written information security plan already commits you to. Tape it above the printer. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment looks at the things this attack needed: which accounts still sign in with a code, which mailboxes carry forwarding rules, and whether the firm has a written plan it could actually follow at 8am on a February Tuesday. Our phishing and awareness training is customized to your firm and scored, with no per-module charges, and it teaches the report-it habit rather than shaming people. The Cyber Hygiene Test takes three minutes. If the score bothers you, take 15 minutes with an engineer. Our team implements the controls at a reasonable rate, from data loss prevention to scanning to protection of assets.
Questions people ask
How can I tell a fake IRS email from a real one? Do not try. Treat every email claiming to be the IRS as unverified, no matter how correct the case number and the seal look. Never use the link in the message. Open a browser tab yourself, go to the address you already had bookmarked, or call the number printed on a notice you received before this email arrived. If your account really is on hold, you will see it there.
Does multi-factor authentication stop tax season phishing? It stops the cheap version and not the good one. A six-digit code typed into a fake login page can be relayed to the real site by the attacker in the same few seconds, which is what happened to the firm in this post. Phishing-resistant methods, meaning a security key or a passkey tied to the real web address, do not relay, because the browser refuses to hand a credential to a domain it does not recognize.
What does IRS Publication 4557 expect a small tax firm to have? Publication 4557 sets out the Security Six, the basic protections a preparer is expected to run: anti-virus, a firewall, multi-factor authentication, backups, drive encryption and a virtual private network for remote access. It also expects a written information security plan, which you attest to when you renew your PTIN. If your firm handles 500 or more consumers' information, the FTC Safeguards Rule adds its own written program, multi-factor authentication, encryption and vendor oversight, plus notice to the FTC within 30 days of a qualifying event.
Filing season is the one time of year your firm is too busy to think, which is precisely why the email arrives in February and not in August.
Controls this post maps to
CIS Controls v8.1. These are the same controls our assessment scores and the console watches.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
Business Email Compromise: How One Polite Email Moves Your Money to a Stranger's Bank
Business email compromise drove more than half of reported cyber incidents in 2026. How invoice and payroll scams work, and the callback rule that stops them.
ThreatsWire Fraud at a Miami Closing Table: How the Payoff Email Changes Banks
Wire fraud in a Miami real estate closing: how the payoff email changes banks, the three signals that catch it, and the callback rule that ends the argument.
ThreatsAI Cyber Attacks: What Actually Changed for a Small Business, and What Did Not
AI cyber attacks made phishing personal, fluent and cheap. What changed for a small business in 2026, what did not, and the controls that still hold.
