Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

400% Spike in Tax-Themed Phishing Attacks Targeting US Employees

Hoxhunt
06/09/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Welcome in everyone. And today we are discussing a finding from the Hawks Hunt Threat Analyst Team that is hot off the presses. This is some data that we discovered. There was a big spike in a new tax themed phishing campaign circulating through the United States, especially. It was targeting US employees. And once we saw this, we decided to take a little bit of a different approach to the webinar this week. And that we wanted to publish these findings immediately to give everyone the opportunity to get ahead of this attack, because we think that it probably isn't going to be confined just to the spring 2026 tax filing season. Moreover, it probably won't be confined to the United States. So I'm pleased to have David Bedanes and Petri Cuivilla discussing what's going on with this campaign, why it matters to you and what you can do about it. So David and Petri, great to have you here today. Good to be with you. Uh, Elliot, thank you so much. You know, Ben Franklin said there's only two certainties in life, death and taxes. With all respect to Mr. Franklin, I think we have to add a third, which is AI powered phishing attacks. Yes, sir. I'm happy to be here again. So let's start off. I will just read off some of these statistics and we will then launch into David and Petri's insights into what they mean and what you can do about it. So Hawks Hunt analysts detected a 400% increase in U.S. tax authority impersonation campaigns targeting U.S. employees. That is part of an overall 147% spike in U.S. phishing volume. This is from the Hawks Hunt threat analyst data pool, which is tens of millions of threat reports from 4 million users. And the threat reports that they issue are automatically analyzed by Hawks Hunt's native AI platform. And then our analysts go over that analysis to discover spikes, anomalies, and trends. So this spike that we're seeing in 2026, there was no comparable spike in the previous spring periods. This also comes on the heels of what we reported in March with a 14 X spike in AI generated phishing attacks. And it's possible that this phishing campaigns at scale personalization and targeting of emails was enabled by AI tooling. This is also concerning because with taxing phishing attacks that have been personalized and contextualized, there is a fourfold elevated risk of a malicious click. So there is a fourfold elevated risk of malicious clicks with these personalized, contextualized phishing attacks. And that is four times the risk compared to the global baseline. And that is from Hawks Hunt phishing simulation data. So where normally there would be about a four to 6% click rate on a typical phishing attack in our, in our simulation data. And that's across all bands of employee skill level. Uh, this is a 16% failure rate and that's including well-trained users. So first of all, um, David, what stands out to you about the findings of this phishing campaign? Yeah, thanks Elliot. I mean, it's clear that this is not a blip, right? This is a trend that is here, right? The Hawks Hunt is sitting on the 4 million different, uh, users globally. So able to sort of see that rise that you're talking about. The 400% increase is real. It's also incredibly effective as well. Right. Um, and we're seeing the increase in failure rate. And I don't need to tell you as a, um, as you get a message from the IRS, it raises your, your pulse, right? There's always that sense of dread. It plays onto sort of all of the things that, uh, really good phishing email campaigns can do. And, and I think that it really should be getting security leaders attention, right? You need to be absolutely training your users to be aware that these, that these trends are coming to be on heightened alert, uh, and to know the proper ways that as an organization, you should be handling these types of threats. I agree on that and let me do add something on top of that. I think that there is one, or actually two words that is a very, very meaningful. AI as it always is nowadays. But the second is the word context that Elliot already mentioned. Uh, David said that it's all about the emotional hours where something comes from the IRS. Uh, we are more likely of being a bit more stressed. Yeah, that's true. But what makes it so damn difficult now is that it's also timely, correct. It is something that is, you are expecting to do. And that's something that I'm a bit afraid actually in here, that how do we train the people, uh, to be able to actually withstand against something that is contextually even correct. It doesn't need to be contextually correct, a hundred percent time. It just needs to be contextually correct for multiple people. And then the other side is capable of actually taking advantage of it. Yeah, Petri, just piggybacking on that for a second, uh, we always tell our people to be looking for things that are out of the ordinary. And the challenge with this, as you said so well, is that this is not out of the ordinary. It's a neutral message that they, uh, it root, most of them read like routine government notices. It's something that you probably were expecting, right? And so that makes it even more difficult to learn how to, to handle it. So speaking of context, I think that's a really good point. So speaking of expecting some kind of a notification or message from the tax authority, which is a seasonal activity. We all go through the ritual of getting these, uh, scary, uh, letters from the IRS or from whatever your tax authority is, wherever you live and, uh, need them to puzzle through those and go through the stress of that. But, uh, the question is, is this going to be confined to the spring of 2026? Uh, David, you live in the United States. What are your thoughts about this being confined to the spring or potentially going beyond the spring? Well, as far as tax campaigns, I think that is in the spring, but we also have to understand that many American tax players do quarterly taxes, right? They, they file quarterly. They also file extensions, which are due in October, which conveniently is also cybersecurity awareness month. So I think that the nature of when these things happen, it's just becoming clear that the attackers are knowing kind of the, the business calendar, for lack of a better words, they know that tax season is in April and on the 15th of each quarter and in October for those filing extensions, they know that open enrollment for benefits happens around Thanksgiving or December. They know that bonus season, you know, for most companies that do a fiscal year is maybe in, in February. So the bigger news is that they are highly in tune with what normal looks like. And they're figuring out the right way to adapt it as that. And that's exactly the scary part of this whole thing. I have been telling for multiple years now that don't look anymore into the kind of spelling mistakes that's gone. That was gone a few years ago when AI was going to introduce. Now, obviously AI is used to ideate that what is actually fitting to the likes of the normal people. And that's the context that David just were highlighting. That's going to be damn difficult. That's going to be damn difficult. I'm just saying. And that of course leads me to think that now more than ever, it is important that we will kind of form a group of people. It's a collective brain of all of ours. When David and Elliot actually jumped into the bandwagon and clicking the stuff and failing with the real life attack, hopefully I'm alert today. So a message that I had been saying so many times earlier, it has always been important, but the more the context is coming to the plate, the more people will kind of fall to these ones and the more important it is that we form a collective where some folks always save the asses of the ones who are falling. But you, what do you mean by that? Forming a collective where one person. So if, uh, if me and David fail and you understand it, how would you save us in that kind of a collective? What does that look like? Yeah, there, there is two sides to the game of numbers in here. The other kids are using the game of numbers by using actually something that they send to the millions of people. Uh, they try to of course make it better and better and better all the time as they are now doing it with the context to all, uh, uh, uh, uh, uh, uh, uh, court of attacks or so. So their numbers are increasing. So on the other side, if you train your people, uh, not only for the telling mistakes, but also to kind of spot the abnormal things, some of us always will be saying that, Hey, this is actually still busy in some sense. And then when you are kind of having that sensation, you're reporting the stuff and our backend is, is, uh, uh, verifying that he has, this actually wasn't an attack, this was not from the, from the IRS, uh, that will then actually feed into the system. And the system will be saving the ones who are kind of falling. There are multiple things. There are the filtering technologies, obviously that we are feeding to, but then there is the local, uh, security operating center, and then there's our own AI that is capable of actually doing the, uh, pre and post, uh, uh, attack kind of cleaning stuff. So it's multiple layers. Uh, so it continues to be the whack them all game as security has so long been. Yeah, I like that. So that sounds like a closed loop system. A threat comes in the system, the threat is analyzed. And after the threat is analyzed, the threat is fed back into your training, other forms of defenses, filtering systems. So that's a very critical point about that. Uh, what we need to do to prepare for this new age of AI enabled threats here. What do you guys think about in general, the concept of seasonality in phishing attacks? We hear a lot in popular media about, uh, big threats coming from, let's say Black Friday, uh, surges or travel themed attacks during Christmas or Thanksgiving or Easter, or whatever your country's main travel holiday is. Is seasonality a thing in phishing campaigns in your experience? It's one of the easiest things to predict from the outside what is If you are getting a phishing attack related to DHL packets, it's a huge guess in a numbers game that yes, Elliot is actually nowadays receiving a packet from the DHL, but most of us are not. So most of us are feeling that, Hey, this is out of the context. It is not fitting to me. But Christmas is Christmas for all of us at the same time. Or is it Thanksgiving or is it taxation season? So that is something that is going to be, I believe, I predict that that's going to be the trick that will stay with this industry for a long time. If not forever. Yeah. And I'll just add is that this just makes the incredible case for, uh, ensuring that you have a phishing program that, that is automated and gamified and personalized because most security awareness programs today are actually built on a really a fixed annual calendar that has nothing to do with the threat calendar and they can't be dynamic with new intelligence, like what we're seeing of the fork, uh, the, the, the increase that we're seeing of the IRS attack. So it's important to, you know, to be nimble, uh, in all things and be able to adjust, um, what you're training your users, uh, to measure with what you're seeing actually in the wild. Uh, let me actually build on top of that one a bit, uh, exactly that sort of program, but also the program that really engages people. Uh, if you have a hundred percent people engaging and 70% of your people are reporting about the phishing issues, your likelihood of getting this sort of kind of report to your back-end SOCA and so on is so much more higher than if you have 5% of your people engaged and only 20% of those are reporting something. The numbers are then not on your side. I have a few more characteristics about this campaign, and we'll talk a bit more about the campaign and then broaden the conversation out to, uh, other types of campaigns that this one does resemble. So consistent, consistent structural patterns were observed across the tax-themed phishing campaigns. Among the tax-themed phishing emails analyzed by Hawks Hunt analysts in the spring 2026 period, 66% included malicious links, 15% included attachments, and 12% requested replies, uh, including what the new trend that we're seeing here at Hawks Hunt is a big surge in callback phishing, which is made more dangerous through deepfake, uh, voice capabilities. The attachment-based messages frequently referenced tax return The attachment-based messages frequently referenced tax return reviews, supporting documentation, and verification requirements. The tax phishing campaign actually has similar characteristics to other tax designed to blend into administrative workflows. And this is something that Petra, you and I talked a little bit offline that I want to go into here in a moment. Uh, the fact that when you can blend something from a personal life that does contain, as you've already, uh, you and David have both described as being kind of like a perfect breeding ground for social engineering, where just from, just from looking at a sender field, you already feel a sense of urgency and fear. Uh, then you are, the attacker already has a leg up on the, uh, potential victim. Now, I also want to go into the tone of this, speaking of social, uh, social engineering is that contrary to the highly charged emotional tone that is typical of social engineering, many of these tax theme messages did not rely on the dialed up urgency or the dialed up explicit financial incentives that you might see in a, uh, in an attack directed at a private individual. And instead they typically used formal administrative language, a neutral tone and procedural framing. And the examples included in the messages that we have are return, review, notifications, document confirmation requests, and portal login instructions. So overall, this campaign is quite formal. And when I look at the, uh, the message I see in here, they do look very similar to what I've seen from legitimate requests from a tax authority, whether that's in the United States, the department of treasury, or whether that's the IRS, uh, in Finland, it's called something else in Germany is called something else. But, but these attacks are also, again, not confined to the United States. We have seen very similar campaigns localized to other countries, tax authorities and language. Uh, they just have not, we have not seen the big rise in actual campaign volume yet. So talking about that, how important is tone and context when you are trying to trick an employee and clicking on something, uh, let's say compared to a private individual? Well, I think the, the tone here is that the, the attackers are doing a great job mimicking the tone that is, that they're already seeing from typical messages like this, right, there is no need to, um, to do, to use a superfluous language by saying, you know, you owe this amount of money right away. No, it's, we are reviewing your return. Um, you know, we believe that there could be an opportunity to, um, to, to amend your filing, would you, you know, please click here to, to learn more or to confirm that we have your information correct. It's, it's, it's mimicking what, that, what we're actually seeing in the threat environment and we need to teach, treat our people to, uh, be ready for that. And, and even more so when it's coming from internal style business communications, it heightens the importance of being very, very context aware of what you're seeing and being very suspicious and having that skepticism of, uh, of what you're seeing. Yeah. Yeah. Not, not, not much to add to that one. Uh, it's, it's, uh, actually contextually correct language as well. You, that's what you expect from the order. Uh, the other thing that I started to think about when I saw the numbers, there was actually the technological type of things. What is the attacker actually trying to achieve here? Is it so that the IRS doesn't actually have the 2FA or MFA solution in place? And then I started to ask from the AI that, how is it, and then, uh, in, in US the IRS actually has pretty wide coverage, if not actually all the online solutions are already 2FA. So then it leads me to think that it is actually something where they are maybe, and most probably trying to fish, of course, the, uh, authentication details related to the other services. They, uh, might be actually misusing the weaker parts of the 2FA implementations. If you have the SMS solution in place, or if you have other kind of weaker solutions in place, uh, they might, might be able to bypass those. And, and in a previous report, we have also seen that some of the best criminal minds are already nowadays dealing on the session cookies. So, so they don't actually necessarily need to acquire your password. They can actually bypass that whole authentication process if they are just stealing your, uh, genuine session cookie that tells to the IRS that, yes, that's me. That's them. Yeah. It's a great point, Petri. What are they trying to accomplish and how are they able to accomplish that nowadays with adversary in the middle attacks, anything they can do to steal your cookies so all of a sudden they really can be you and access your most, uh, sensitive data. I want to talk about the context part. So also part of the context and contextualizing these attacks is that they are sometimes posing as a actual work department, like your finance department or your HR department. They will issue some kinds of tax-related messages to you. So it's not entirely out of the realm of possibility that you will get a tax related message from your company about something, uh, W-2 forms in America, what have you elsewhere. Uh, so thinking about that and also that there are cyclical events in the, uh, corporate workflows where you're going to be used to exchanging sensitive information, I don't think that's confined to taxes, uh, Petri, what are some other things that you've seen as a CISO over the years where you've seen a cyclical nature of attack that tries to tap into this, uh, this, this to tap into this virtual exchange of sensitive information that happens every quarter or every year, what types of exchanges are those trying to piggyback off of? Yeah, they said it already a few minutes ago, but, uh, good to highlight that yes, of course, the pay raise, uh, bonuses, uh, other HR type of things, uh, they would be the ones that will be for sure targeted. What I'm now currently actually thinking here is that why they are using the tax association or Kris Motiv and so on, they're, they can, uh, throw the net so wide, they can throw it to everyone. Whereas actually the pay raises and bonuses and so on, they may vary a bit between the companies. So you need to be a bit more targeted. And, and that, this actually leads me to think that Elliot, we need to ask from our analyst team also to look into the interesting, small details. Do we have actually in our 4 million reported kind of database information about cases where someone is actually lured to do something interesting, uh, with, uh, for example, M&A focused or stock option focused, or something that is very, very company specific, something that you have most probably read from the online or newspapers, if anyone is anymore reading paper, but, uh, kind of, something that is only targeted to one company. How much do we see that? We don't have currently the answers obviously here, but that's actually something that I think that we need to take an action point about. Yeah. And I'll add to that. I mean, tax season and working with your company's HR group is it's a time when you are knowingly, um, it's a risky time that you're knowingly providing, you know, your social security number, sensitive information about your salary, your benefits, maybe sensitive medical things, and you're providing those, you know, oftentimes over the internet, right. And, um, you know, it's, it's something that everybody's guard should be a little bit up, um, but that is, um, especially in this time, right, what we're seeing from this report is that these attacks are increasing, um, it attackers have just figured out that this is a time when, uh, that we are vulnerable and they are standing in line to hopefully take advantage of that moment and to collect as much of that information as they can. Yeah. Actually, let me actually guys ask something from you. I'm not a US citizen, so I don't know the stuff. Uh, but I, I've read online that actually, if you are filing your kind of, uh, tax return, uh, request in advance, uh, you don't actually need to use the 2FA at all, but it is more like, like that if you know the social security numbers, if you know the, uh, kind of exact details of someone you're capable of possibly misusing the process. Yeah, Petri, this is, I mean, this is a scam. This, this even dates before the idea of a cyber attacks and scams, but there are a number of people who actually file tax returns on behalf of other individuals. Right. So you can, and this was actually, you know, you could, if you know someone's social security number, you can log in and you can make a tax return, claim a refund, cash that check, and then when someone else, and people will do this in January, right, late January, early February, when those of us who go around and we're April 14th, April 15th, uh, and we're actually going around to file our taxes, you find out that, oh my goodness, somebody has already, already fall, uh, filed on your behalf. And then there's a process to go around that. But, um, it does show how you should protect things like your social security number and the like as well. Right. Thanks. And speaking of filing on someone's behalf, Petri, uh, this is not the case for every country in Europe, but in America, you can't have a personal tax accountant who files on your behalf. And some of the messages we're seeing are people who are, who are, uh, they're being imposters of actual accountants or people who would file on your behalf. They, the messages read something like, Hey, uh, here's the refund that we filed for you. You have to log into this portal or something. So it does add another layer. I mean, the more we talk about, the more I realized like how attractive of an audience that the U S tax filer is for a social engineer compared to a lot of the different countries I see in Europe and in Asia, where it's a bit of a different system and it can be a little bit more, uh, balkanized as far as like what system is in which country and, and the, uh, different kind of workflows with that. Uh, it is quite complicated in America too. So oftentimes, even those of us who think we have a pretty good handle of how to file our taxes, where we are, there's always a little bit of a sense of being overwhelmed by it because of the complexity to it. Elliot, I think about those moments in time for the average person's American in this context where large amount of money are going to move around. Right. And you think about it as tax time. I also am particularly thinking about kind of the home buying, the realtor process, right? Then people impersonating your realtor and impersonating your settlement agent. Um, you know, when you are wiring funds to buy a house or receiving the funds from the sale of a house, those are all things that cyber threat actors are trying to get in those, into those workflows, those business cadences that we talked about earlier to extract value from, uh, from a situations. And that's when we need to be particularly aware. Great point. So again, for the audience, this campaign is targeting employees. All the data that we have on the threats at Hoxton are employee reported threats. So as Petri and David has said, when people are looking at a, uh, taxing phishing email, they're probably giving some kind of an access that the social engineers are going to use to access your systems. So this is a corporate facing risk. So the question is, what do we do about this? How do you turn this disadvantage that they have with these emotionally charged seasons into an advantage? So I think the most important thing is to start with the threats and not the content calendar. You know, a lot of times cyber awareness programs are built backwards. At the beginning of the year, you say to yourself, okay, we're going to do topic A in January, topic B in February, topic C in, in March. And, and they run it on the cadence of, regardless of what happens, you have to be adaptive, adaptable. You have to be nimble. Um, you know, and, and this, what we're seeing in the Hoxton threat intelligence is a great example of why we need to double down on this in this month, right? And organizations that adapt the fastest are the ones that are able to translate this threat intelligence into actual insights for their people as soon as possible. Yeah, exactly where you started with the real life. When we, and our threat intel team is collecting this data next to its AI capabilities, they harvest about 1,500 kind of simulations a year, which are immediately taken into production, which are kind of fed to the people, which are contextually correct locally out there, language out there, even the, even the season out there. So you need to get this into the faces of the people in a place where it's actually free of kind of training it. But it's not only about the training. It's, it's something that you need to do it in a very positive tone to engage the people and, and, and, and, uh, conditionalizing their brain of reporting this stuff when the stuff actually happens. If you don't do that, uh, training or knowledge is nothing. It is not actually making any differences here. Maybe only from the kind of regulation point of view, but that's not going to save your date. Your day is going to be saved by the people who are reporting it, reporting it in, in less than one minute or so. Uh, the AI is also bringing not only the more sophisticated contextual phishing messages, but much more faster cycles of taking advantage of your foothold that you have in a company. There are latest reports that are telling that the time to take advantage of those footholds is shrinking to less than a few minutes or so. So you just need to prepare yourself as well of being minute by minute actions instead of kind of reacting to something in a few hours. Let me also just throw out an idea as well, as I think it's very important for, um, for cybersecurity leaders to think and enable the business. So what does that mean in this context? I think it's very important to understand sort of the regular business cadence of your organization. Get close with HR, get close to investor reporting. Um, get close to your, your, your regulatory teams and know what their cycles are like. Know when they're going to be sending out the open enrollment emails. Know when they're going to be sending out the opportunity to change your withholding, um, a part of your, your paycheck, uh, know when, uh, deferments come for, uh, for, for your, for your bonuses, right. The, to with, with payroll. Um, because in doing so you are going to be better prepared. If somebody flags emails as I think this is a fish that you are closer to that team and you can let them know that it is, it either is legitimate or it is a fish. And, and that can be really important. Excellent points. Very good points. Uh, from the flat feed, you can get amazing training curriculum. So it's absolute, absolutely vital to use that and have a threat first to people first approach. The security awareness campaign is David kicked off this part of the conversation saying. So here's a question that I have for both of you. And the reason I'm asking this is that sometimes we can kind of get blinded to the processes and the methodology of Hawks Hunt, I think a lot of our audience here, they are looking for new ways to approach a security awareness training program, to approach a fishing training program, and you say it as if everyone does this, each people to report. I want you to kind of go further into what is the actual outcome that you are hoping to get from a security awareness program? Is it to get a better simulation? Is it to get a better open rate? And when we talk reporting rates, what are we talking about? That's excellent question, Elliot. I see that we are all here to make sure that our business is something that is much more safe and predictable. Security is there only for the sake of business predictability. If we are not building these programs so that we constantly increase the resilience of our company, we are doing something wrong. We should not be in a past where we are trying to satisfy the needs of the regulations and so on. We are there to actually contribute to the resilience of the company. You were asking about the kind of reporting rates, reporting rate and engagement rates. Those are the kind of raw materials, raw materials to increase the likelihood that your organization, not the individual, but your organization actually knows when they are attracted for. And then when they know they have the capability of actually stopping that immediately or before it comes to something meaningful at all. The issue have, for example, 50% likelihood of one message being kind of reported by the people, it means that if it's a targeted attack to Elliot only, there's a 50-50 chance that it's kind of reported, but if you have five recipients and there is this 50% likelihood, the overall likelihood actually increases into that 96.88% already. If you have 10 people attack or so, it increases even more. So it's as I said a few times, it's a game of numbers here. Yeah, I think Petri hit the nail on the head talking about building a resilient program. And that's not about building a workforce that never clicks. It's about building one that recovers fast, right? You know, I've given talks about athletic training and elite athletes. They don't avoid mistakes, but what they do is they try to reset and recover for them faster than anybody else. And that's what a really great nimble phishing program does. It rewards those people who are reporting messages. Who are reporting messages. And that's the difference between being more on the brittle end to be candid and being more resilient. And the fact is, is that our resilience can fade between threats and these big campaigns that are, you know, just point in time, like that's, and by October it comes around, like the tax phishing conditions maybe have changed and the vigilance that you put in place in spring has weakened and a truly resilient program, it plans for, you know, that decay and it reinforces the trends that they're seeing when the next window opens, not when the moment has passed. If people are reporting, then that shows that you are actually reducing the risk, right? And also if people are failing, that shows you that there is a risk. That shows you that you have an area that needs to be improved. And then you just get the right training in there to improve that performance there. We've seen this multiple times with the simulations that are sent out based on these new threats, including these tax themed phishing, sometimes there are certain kinds of new tactics, sometimes new technologies involved too, that are particularly dangerous. And that's because people haven't seen them before. And then they need some help. And if you scare them off with very punishment-based consequence-based training, where they get this big red flashing message saying you failed and now you're in trouble, well, you're not really helping them. You're not really going to turn that fail into a report, which is what you want. At best, you might get a miss. What we call a miss, which is where you just sort of pass on the actual simulation, but that just means that someone else is going to get it if they don't report it. And that also means that this person is not learning. So I think that we typically get this question quite often from the audience is that, are you looking at reporting rates or failure rates or open rates? And I think we all agree that reporting rates is the most important thing to look at because that is a clear evidence of a skill being demonstrated and recognizing and doing something about a threat and protecting your fellow coworkers. And failure, while of course it's not ideal, it's really not the worst thing. At least someone is participating. At least someone is learning if you have a good program in place. Absolutely. And what you are starting to talk about there actually is the security culture. For the last few days, actually, I've been engaging more like a kind of hobbyist project at this stage, but it may turn to something for auction as well. So I've been reading actually quite a lot about the aviation industry and how that safety culture actually really developed in that area. And without spouting all the beans already about something that I'm still developing, the core of the whole thing is that they have a really focused, you know, from regulations, starting from the regulation and ending up where the people, or into the operation where people are kind of doing their daily work. They are highlighting that if you report something, there's never going to be kind of anything that is penalized. There is no plain culture totally. That encourages the people to kind of learn and learn and learn better and better and better. That doesn't actually mean that you would never be penalized. So-called just culture that they actually have there has also a kind of very clear accountability features when people are doing something stupid that they knew that it was stupid or even careless or so. So there needs to be a kind of correct balance between that sort of aspects in culture, but let's take another kind of webinar for explaining that a bit deeper. I like that a lot. Yeah. Cybersecurity is not the only place far from it where reporting is absolutely vital for broader safety concerns. All right, gentlemen, I think that brings us to a natural ending here. Any closing thoughts about the tax themed phishing and what to do about it? Any closing thoughts about what our audience should do when planning ahead for October awareness month, which incredibly, even though it's, it's only April, but it's right around the corner for all of you, all those of you who are starting to look at it. Calendars for what we call the Superbowl security awareness that happens in October. Closing thought on the only things that are kind of shit and taxes that, and the development of cybersecurity in this. There you go. Mr. Franklin said it best, I guess. Right. Yeah, it was pretty good. Well, we can't really one-up Benjamin Franklin, can't we? So, uh, I think that's a good place to leave it off. Thank you, gentlemen. Thank you, Elliot. Really appreciate it. Thank you. Thank you. And thank you all for joining us.

TL;DR

  • Hoxhunt detected a 400% increase in US tax authority impersonation attacks during spring 2026, with a 16% failure rate among trained users—four times the normal phishing baseline—likely enabled by AI-powered personalization and contextual targeting.
  • The campaign uses formal administrative language and neutral tones that mirror legitimate government communications, with 66% containing malicious links, 15% attachments, and 12% callback phishing attempts enhanced by deepfake capabilities.
  • Attackers are exploiting cyclical business workflows beyond just tax season, including quarterly filings, benefits enrollment, and payroll changes, making contextually appropriate phishing increasingly difficult to detect.
  • Organizational resilience depends on collective reporting rather than individual perfection—with 50% individual reporting rates, detection probability reaches 96.88% when five employees receive the same attack.
  • Security leaders should align with HR and finance teams to understand regular communication cycles, implement threat-first training using real attack data, and foster a 'just culture' that encourages reporting without punishment.

Unprecedented Tax Phishing Campaign Surge

Hoxhunt threat analysts detected a dramatic 400% increase in US tax authority impersonation campaigns targeting American employees during spring 2026, part of an overall 147% spike in US phishing volume. This surge represents a significant departure from previous tax seasons, with no comparable spikes observed in prior years. The campaign's sophistication is evident in its 16% failure rate among well-trained users—four times higher than the typical 4-6% baseline for phishing simulations. Analysts attribute this effectiveness to AI-enabled personalization and contextual targeting that exploits the natural stress and urgency associated with tax-related communications. The timing coincides with Hoxhunt's March 2026 report documenting a 14X increase in AI-generated phishing attacks, suggesting these tax campaigns may leverage similar AI tooling for scale and personalization.

Attack Characteristics and Technical Tactics

Analysis of the tax-themed phishing emails reveals a sophisticated multi-vector approach: 66% contained malicious links, 15% included attachments, and 12% requested replies including callback phishing attempts enhanced by deepfake voice capabilities. Unlike traditional phishing that relies on emotional urgency, these messages employ formal administrative language and neutral tones that mirror legitimate government communications. The attacks reference routine processes like return reviews, document confirmations, and portal login instructions—making them exceptionally difficult to distinguish from authentic correspondence. Technical analysis suggests attackers may be targeting authentication credentials for services beyond tax portals, exploiting weaker 2FA implementations like SMS-based verification, or attempting to steal session cookies to bypass authentication entirely through adversary-in-the-middle techniques.

Organizational Defense Through Collective Resilience

The webinar emphasizes that effective defense requires shifting from individual failure prevention to organizational resilience through collective reporting. With a 50% individual reporting rate, the probability of detection increases to 96.88% when five employees receive the same attack—demonstrating the power of the 'numbers game' working in defenders' favor. Security leaders are advised to align closely with HR, payroll, and investor relations teams to understand regular business cycles when employees expect sensitive communications, enabling faster validation of suspicious messages. The speakers advocate for a 'just culture' approach borrowed from aviation safety—encouraging reporting without punishment while maintaining accountability for genuinely reckless behavior. This cultural shift, combined with threat-first training that uses real attack data to educate users on emerging tactics, creates resilient programs that recover quickly from inevitable failures rather than attempting to achieve zero-click perfection.

Chapters

0:00 - Introduction and Campaign Overview
3:43 - Key Findings and Statistics
6:32 - Seasonal and Cyclical Attack Patterns
13:08 - Attack Characteristics and Technical Tactics
19:19 - Contextual Targeting Beyond Tax Season
26:53 - Building Organizational Resilience
28:59 - Reporting Rates vs Failure Rates
33:51 - Security Culture and Just Culture
35:21 - Closing Thoughts

Key Quotes

1:33 "With all respect to Mr. Franklin, I think we have to add a third, which is AI powered phishing attacks."
5:10 "What makes it so damn difficult now is that it's also timely, correct. It is something that is, you are expecting to do."
7:13 "The bigger news is that they are highly in tune with what normal looks like. And they're figuring out the right way to adapt it as that."
8:32 "Some folks always save the asses of the ones who are falling."
27:22 "The AI is also bringing not only the more sophisticated contextual phishing messages, but much more faster cycles of taking advantage of your foothold that you have in a company."
31:17 "That's not about building a workforce that never clicks. It's about building one that recovers fast, right? ..."
Categories:
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Email Security
  • Security Operations
  • Best Practices
  • Webinar
  • Tax-themed phishing campaigns
  • AI-powered social engineering
  • Contextual phishing attacks
  • Security awareness training
  • Collective defense strategies
  • Threat intelligence analysis
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: 400% Spike in Tax-Themed Phishing Attacks Targeting US Employees

              XStreaminars (watch here)

              • Jul
                28

                Illumio + Netskope: Zero Trust in the Age of AI Autonomy

                07/28/202601:00 PM ET
                • Jul
                  29

                  Ask Your Cloud Anything: Unlocking Governance Silos in your Environments

                  07/29/202601:00 PM ET
                  More events

                  Industry Events (watch there)

                  • Aug
                    06

                    Mitigating Risks of Sensitive Data Exposure in AI Platforms

                    08/06/202604:00 AM ET
                    • Aug
                      06

                      Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks

                      08/06/202602:00 PM ET
                      • Aug
                        07

                        Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift

                        08/07/202611:00 AM ET
                        More events

                        Upcoming Webinar Calendar

                        • 07/28/2026
                          01:00 PM
                          07/28/2026
                          Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                          https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
                        • 07/29/2026
                          04:00 AM
                          07/29/2026
                          Real-Time Strategies for Safeguarding Against Prompt Injections
                          https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
                        • 07/29/2026
                          01:00 PM
                          07/29/2026
                          Ask Your Cloud Anything: Unlocking Governance Silos in your Environments
                          https://www.truthinit.com/index.php/channel/2048/ask-your-cloud-anything-unlocking-governance-silos-in-your-environments/
                        • 08/06/2026
                          04:00 AM
                          08/06/2026
                          Mitigating Risks of Sensitive Data Exposure in AI Platforms
                          https://www.truthinit.com/index.php/channel/2058/mitigating-risks-of-sensitive-data-exposure-in-ai-platforms/
                        • 08/06/2026
                          02:00 PM
                          08/06/2026
                          Same Tactics, Enhanced Velocity: The Impact of AI Agents on Identity Attacks
                          https://www.truthinit.com/index.php/channel/2064/same-tactics-enhanced-velocity-the-impact-of-ai-agents-on-identity-attacks/
                        • 08/07/2026
                          11:00 AM
                          08/07/2026
                          Discover DLP Memories: The Evolving Triage Agent That Learns Each Shift
                          https://www.truthinit.com/index.php/channel/2062/discover-dlp-memories-the-evolving-triage-agent-that-learns-each-shift/
                        • 08/07/2026
                          11:30 AM
                          08/07/2026
                          Refreshing Beverage Ideas Paired with Essential Cybersecurity Insights
                          https://www.truthinit.com/index.php/channel/2063/refreshing-beverage-ideas-paired-with-essential-cybersecurity-insights/
                        • 08/13/2026
                          12:00 PM
                          08/13/2026
                          Harnessing AI for Secure Innovation in the Enterprise with Netskope & Omada
                          https://www.truthinit.com/index.php/channel/2065/harnessing-ai-for-secure-innovation-in-the-enterprise-with-netskope-omada/
                        • 08/19/2026
                          12:00 PM
                          08/19/2026
                          Becoming Agent Ready: Insights and Strategies with Cyera
                          https://www.truthinit.com/index.php/channel/2036/becoming-agent-ready-insights-and-strategies-with-cyera/
                        • 09/02/2026
                          12:00 PM
                          09/02/2026
                          Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                          https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                        • 09/30/2026
                          04:00 AM
                          09/30/2026
                          AI Command Center: Optimizing Visibility and Control in Your Operations
                          https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version