Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

Spam and phishing targeting taxpayers | Kaspersky official blog

0
Medium
Phishing
Published: Thu Apr 23 2026 (04/23/2026, 16:02:57 UTC)
Source: Kaspersky Security Blog

Description

This threat involves widespread phishing campaigns targeting taxpayers globally during tax season. Attackers create fake tax authority websites and fraudulent services to steal personal data, credentials, credit card information, and cryptocurrency wallet seed phrases. The scams include malicious file downloads disguised as official tax documents and fake AI tax assistance tools that harvest sensitive data. These phishing attempts have been observed targeting multiple countries including Germany, France, Austria, Switzerland, Brazil, Chile, and Colombia. The campaigns aim to steal money directly, hijack crypto wallets, and collect data for further fraud or resale. Users are advised to avoid unofficial sites, not share sensitive data with AI tools, and use official channels for tax matters.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 04/23/2026, 16:06:19 UTC

Technical Analysis

During tax season, cybercriminals deploy phishing campaigns impersonating tax authorities and related services across various countries. They use fake government portals to harvest credentials and credit card details, often charging fees for fraudulent tax deductions. Malicious files disguised as tax documents are distributed to infect victims' devices. Cryptocurrency holders are specifically targeted with fake tax compliance sites demanding wallet verification and seed phrases, enabling attackers to drain wallets. Additionally, fake AI-based tax assistance websites collect personal and tax data for malicious use. The threat exploits the urgency and complexity of tax filing to trick victims into divulging sensitive information.

Potential Impact

Victims risk financial loss through stolen credit card information and drained cryptocurrency wallets. Personal data such as taxpayer identification numbers, employment history, and bank details are harvested, enabling identity theft, fraudulent loan applications, account hijacking, and further social engineering attacks. Malware infections from malicious tax documents can compromise devices. Data collected by fake AI tax tools can be sold on the dark web or used for extortion. The overall impact includes financial theft, privacy breaches, and long-term fraud risks.

Mitigation Recommendations

No official patch applies as this is a phishing threat. Users should file taxes themselves or use trusted, verified services. Avoid interacting with unsolicited tax-related emails or websites, especially those requesting sensitive information or downloads. Use reliable security solutions that block phishing sites and malicious downloads. Do not share personal or financial data with AI tools, especially online services; if AI is used, run it locally without uploading sensitive documents. Always verify communications through official tax authority channels and be wary of slight deviations in sender details. Encrypt sensitive tax documents and store them securely.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/income-tax-phishing-bait/55637/","fetched":true,"fetchedAt":"2026-04-23T16:06:11.129Z","wordCount":2085}

Threat ID: 69ea437387115cfb682da704

Added to database: 4/23/2026, 4:06:11 PM

Last enriched: 4/23/2026, 4:06:19 PM

Last updated: 4/24/2026, 6:07:29 AM

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses