Small Business Taxes & ManagementTM--Copyright 2017, A/N Group, Inc.
The IRS, state tax agencies and the tax industry are warning tax professionals to beware of phishing emails purporting to be from a tax software education provider and seeking extensive amounts of sensitive preparer data.
The emailís origin is unknown but likely issued by cybercriminals who could be operating from the U.S. or abroad. The email is unusual for the amount of sensitive preparer data that it seeks. This preparer information will enable the thieves to steal client data and file fraudulent tax returns.
The IRS reminds all tax professionals that legitimate businesses and organizations never ask for usernames, passwords or sensitive data via email. Nor should a preparer ever provide such sensitive information via email if asked.
All tax professionals should be aware that their e-Services credentials, the Electronic Filing Information Number (EFIN), the Preparer Tax Identification Number (PTIN) and their Centralized Authorization File (CAF) number are extremely valuable to identity thieves. Anyone handling taxpayer information has a legal obligation to protect that data.
Because the IRS, state tax agencies and the tax industry, acting in partnership as the Security Summit, are making inroads on individual tax-related identity theft, cybercriminals increasingly target tax professionals. Thieves are looking for real client data so they can better impersonate the taxpayer when filing fraudulent returns for refunds.
The fake email uses the name of a real U.S.-based preparer education firm. Hereís the text as it appears in phishing emails being sent to tax professionals:
In our database, there is a failure, we need your information about your account.
In addition, we need a photo of the driver's license, send all the data to the letter. Please do it as soon as possible, this will help us to revive the account.
*Company Name *
*EServices Username *
*EServices Password *
*EServices Pin *
*Answers to a secret question*
*EIN Number *
*Owner/Principal Name *
*Owner/Principal DOB *
*Owner/Principal SSN *
*Prior Years AGI
Mother's Maiden Name
If you received or fell victim to the scam email, forward a copy to firstname.lastname@example.org. If you disclosed any credential information, contact the e-Services Help Desk to reset your password. If you disclosed information and taxpayer data was stolen, contact your local stakeholder liaison.
Copyright 2017 by A/N Group, Inc. This publication is designed to provide accurate and authoritative information in regard to the subject matter covered. It is distributed with the understanding that the publisher is not engaged in rendering legal, accounting, or other professional service. If legal advice or other expert assistance is required, the services of a competent professional should be sought. The information is not necessarily a complete summary of all materials on the subject. Copyright is not claimed on material from U.S. Government sources.--ISSN 1089-1536
--Last Update 06/26/17