Phishing Emails Claiming to be Software Update Notices from Tax Software Firms Being Sent to Preparers
The IRS issued a warning regarding attempts to trick tax professionals to install malware on their systems by clicking on an “update” link for their tax software. [IR-2016-103] Once clicked, the “update” will install a keystroke logger that will send all of the preparer’s keystrokes (which will likely include important client information) to a third party—and we can presume that party is planning to use that information for various nefarious purposes.
The use of email to trick users into installing malware is very common—because it’s very effective. If the email fits the general context that users expect (email from the software provider we use for tax software that is formatted as expected) and the message itself seems reasonable (there’s an important software update—perhaps even an extremely important one to avoid having your systems compromised) we will often click through on the email and follow its instructions without a second thought.
Image Copyright pixelbrat / 123RF Stock Photo
Read More