Tax Season Is a Brand Impersonation Event

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Tax document folders labeled IRS Notices, W-2 Forms, CPA Records, and Payroll Documents with a highlighted “Verification Required” folder being selected

    Every year, the security industry frames tax season as a phishing problem. It’s more accurately understood as the largest coordinated brand impersonation campaign on the calendar.

    The IRS released its annual Dirty Dozen scam list in early March, and the contents were familiar: phishing emails impersonating the agency, smishing campaigns using alarming language and QR codes to redirect taxpayers to fake websites, AI-generated voice calls spoofing caller ID, and spear-phishing targeting tax professionals with “new client” lures. The IRS reported over 600 social media impersonators during fiscal year 2025 alone. None of this is new. What has changed is the scale of the infrastructure behind it and the breadth of brands being abused.

    In February, Microsoft documented a campaign that targeted over 29,000 users across 10,000 organizations, almost exclusively in the United States, by impersonating the IRS and claiming that potentially irregular tax returns had been filed under recipients’ identification numbers. A separate campaign impersonated real, named CPAs, complete with their logos and professional branding, to deliver the Energy365 phishing-as-a-service kit through Excel attachments and OneNote files hosted on OneDrive. Check Point Research found that one in every ten new tax-related domains registered in March 2026 was flagged as malicious or suspicious, with infrastructure preparation beginning as early as September 2025.

    The pattern that makes tax season distinct from other seasonal fraud surges is the sheer number of trusted brands being impersonated simultaneously. This isn’t just about the IRS. Tax software companies, accounting firms, payroll platforms, identity verification services, financial institutions, and document-signing tools are all being spoofed as part of the same ecosystem of attacks, often within the same campaign chain.

    Why this Is a brand protection problem

    The conventional framing of tax season threats focuses on consumer awareness: don’t click suspicious links, verify communications through official channels, report phishing to the IRS. That guidance is necessary but insufficient, because it places the entire burden of defense on the individual and ignores the organizational exposure.

    For companies whose brands are being impersonated in tax-themed campaigns, the damage extends beyond the immediate phishing event. When a CPA firm’s name and logo appear in a credential harvesting campaign, that firm’s professional reputation absorbs the impact regardless of whether it was involved. When payroll platforms and HR systems are spoofed to harvest W-2 data, the impersonation costs fall on the companies whose brands were borrowed. Tax professionals are now reporting that clients arrive suspicious of legitimate communications because they’ve been trained by the volume of fakes to distrust everything that looks official.

    The seasonal concentration also creates a detection challenge. Tax-related lookalike domains surge in registration months before April 15, and Check Point’s finding that one in ten March registrations was flagged as risky suggests the infrastructure is scaling faster than monitoring can track. For brand protection teams, the window between domain registration and campaign activation is the critical detection opportunity, and for many organizations, that window is passing without visibility.

    Trusted platforms as phishing infrastructure

    The most significant development in this year’s tax campaigns is the degree to which attackers are embedding phishing infrastructure inside platforms that victims already use and trust. Microsoft’s research documented campaigns delivering phishing kits through OneNote files hosted on OneDrive, using real accountants’ names and logos as lure material. Separately, researchers have identified IRS impersonation campaigns running through Docusign, Netlify, Vercel, and Cloudflare Pages, services whose domains pass through email security filters because the sending infrastructure is legitimate. Victims interact with a real platform interface before encountering anything malicious.

    This is the same Living Off Trusted Sites pattern that has reshaped phishing across other categories. ID.me is being spoofed because the IRS uses it as its official identity verification provider, and taxpayers who have completed legitimate ID.me verification in previous years are conditioned to do it again without hesitation. The lure works not because the impersonation is technically sophisticated, but because the trust relationship is already established.

    Microsoft’s research revealed a parallel technique: tax-themed domains registered in January and February 2026 used keywords like “tax” and “1099form” while also impersonating specific legitimate companies in the tax filing, accounting, and investing sectors. The brand impersonation extends well beyond the IRS itself. CPA firms, tax preparation software, and financial platforms are all being weaponized as lure material, and the infrastructure is being prepared months before filing season begins.

    The Bottom Line

    Tax season will always attract fraud because it combines urgency, financial stakes, and a population conditioned to expect official-looking communications from institutions they trust. What has changed is the operational maturity of the campaigns: infrastructure prepared months in advance, trusted platforms used as delivery mechanisms, multiple brands impersonated within single campaign chains, and AI-generated content that eliminates the linguistic tells that once helped users distinguish real from fake. For organizations whose brands intersect with tax workflows, the exposure is not hypothetical. It’s seasonal, predictable, and, with the right monitoring, detectable before customers are impacted.

    Key Takeaways

    • Tax season is the largest coordinated brand impersonation event on the annual calendar, with the IRS, CPA firms, tax software, payroll platforms, and identity verification services all spoofed simultaneously.

    • Microsoft documented a February campaign impersonating the IRS that hit 29,000+ users across 10,000 organizations, while a separate campaign impersonated real, named CPAs to deliver phishing-as-a-service kits.

    • Attackers are hosting tax-themed phishing inside trusted platforms including Docusign, Netlify, and Vercel, where email security filters pass the traffic through because the sending infrastructure is legitimate.

    • Check Point found one in ten new tax-related domains registered in March 2026 was flagged as malicious, with infrastructure preparation beginning as early as September 2025.
    Categories:

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.