Cybersecurity specialists have uncovered an advanced phishing operation specifically targeting taxpayers via their mobile phones.
These attacks exploit the stress of last-minute tax filers, offering cybercriminals the perfect opportunity to steal sensitive financial and personal information.
Since early February, these attacks have surged nearly fourfold, with a notable increase as the tax deadline nears and individuals scramble to file their returns.
The primary method of attack is SMS messages, where scammers use alarming language about tax refunds being delayed or threats of legal action for unpaid taxes.
These scam texts often contain links that appear to lead to the legitimate IRS website (Source – McAfee). However, clicking these links directs victims to convincing but fraudulent IRS-like sites designed to steal personal data such as Social Security numbers and financial details.

With nearly 50% of all taxpayers filing their returns between mid-March and April 15, this period becomes a prime opportunity for these attacks.
McAfee researchers have identified that these scams use domain spoofing techniques, inserting “irs.gov” into deceptive URLs to create a false sense of authenticity.
Examples include domains like “irs.gov.entes-tax[dot]com” and “irs.gov.tax-pleas[dot]com,” which at first glance seem legitimate but actually lead to fake sites controlled by the attackers. Link shorteners, such as bit.ly or custom versions, are commonly used to further disguise these malicious links.
The sophistication of the attacks is evident in how closely the fake websites mimic the official IRS infrastructure.
Researchers have found that these fraudulent sites use advanced visual copying techniques, replicating the official IRS logos, color schemes, and layouts so closely that they are nearly indistinguishable from the real thing.

Fake IRS claim website (Source – McAfee)
The attackers have created a custom framework that adapts seamlessly to different mobile devices, ensuring that phishing pages display correctly on any screen size or operating system.
The attack begins with a text message containing a shortened URL, often via services like bit.ly, which redirects victims through multiple stages before landing on the fake site. This multi-stage process makes it harder for traditional URL filters to detect these links.
The phishing sites use HTTPS certificates with names that incorporate terms such as “irs,” “tax,” or “refund,” further convincing victims that they are visiting legitimate IRS pages.
Once users submit their personal information, it is immediately sent to servers controlled by the attackers, often in countries where U.S. law enforcement has little authority.
To protect themselves, taxpayers should always verify any communication by visiting the official IRS website directly and remain alert to signs of these increasingly complex scams.




