February 7th, 2025
Contributor: Aleena Jibin
Multiple phishing campaigns are impersonating legitimate entities like HM Revenue & Customs (HMRC), Intuit (US), and myGov (Australia). These emails mimic official branding and language to appear authentic, tricking recipients into believing they are from trusted organizations.
Typically, these emails contain malicious links or attachments and claim that victim’s tax account requires urgent updates or that a tax form has been rejected. Victims are then directed to fraudulent websites designed to steal credentials. Tax season scams are particularly effective due to their timing and urgency, pressuring recipients to act quickly often without verifying legitimacy.
How to spot the phishing email? - Download
This campaign has impacted thousands of organizations across multiple countries including US, UK, Australia, Switzerland etc. In January 2025, 40,000 Intuit-themed phishing emails were sent in the US alone. Meanwhile, in Switzerland, fraud campaigns impersonated federal tax authorities, requesting bogus payments to adversary-controlled Revolut accounts.
New Malware Campaign Mimic Tax Agencies Attacking Financial Organizations
Reduce human cyber and compliance risks with targeted training.
Get a guided walkthrough — at a time that suits your timezone.
Book a Free Demo