Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Security brief: tax scams aim to steal funds from taxpayers

ab11a32f0d617e50eb0c710d63128f79

TLP:CLEAR
Active

MD5 Hash

Description

Threat actors are exploiting tax season with numerous campaigns leveraging tax themes to deliver malware, remote monitoring tools, fraud attempts, and credential phishing. Over a hundred campaigns have been observed in 2026, with a notable increase in remote monitoring and management (RMM) payloads. Tactics include impersonating tax agencies, claiming expired documents, and requesting tax filing support. While primarily targeting the United States, campaigns have also been observed in Canada, Australia, Switzerland, and Japan. Notable actors include TA4922, a newly designated threat group delivering malware from the Winos4.0 ecosystem, and TA2730, focusing on credential phishing for financial institutions. Business email compromise actors are also using tax form lures to steal financial and personal data. These campaigns demonstrate the ongoing exploitation of timely and topical themes by cybercriminals to deceive users.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Security brief: tax scams aim to steal funds from taxpayers
Pattern Type
STIX
Confidence
75%
Valid From
May 3, 2026 16:06
Total Sightings
0
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of ab11a32f0d617e50eb0c710d63128f79

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.