Security researchers are warning of an active phishing wave timed around tax filing periods and directed at both consumers and finance teams.
Observed tactics include:
- High-fidelity domain impersonation and cloned login workflows.
- SMS and email lures that pressure users with fake deadlines.
- Real-time relay pages that capture one-time passcodes.
Organizations should refresh anti-phishing guidance, update mailbox filtering rules, and monitor for lookalike domain registrations.
