Watch for this new cybersecurity scam, IRS warns

The phishing scheme involves cybercriminals posing as individuals looking for help with tax preparation

Jan 13, 2017 @ 12:55 pm

By Liz Skinner

The Internal Revenue Service is warning tax professionals to beware of emails ostensibly penned by prospects — and advisers should heed the same guidance.

A new phishing scheme is making the rounds where cybercriminals pose as an individual who is looking for someone to help them with tax preparation, the IRS said in an alert Wednesday.

Sometimes the notes even appear to come from a friend or colleague, because those individuals' systems already have been hacked, it said.

The attack email is delivered after the professional responds to the sender's first note, and usually has an embedded web address or has a PDF file attached that contains the malicious link.

“The tax professional may think they are downloading a potential client's tax information or accessing a site with the potential client's tax information,” the alert said. “In reality, the cybercriminals are collecting the preparer's email address and password and possibly other information.”

(More: Broker-dealers deploying advanced cybersecurity measures)

Most financial advisers have been warned to be wary of emails purportedly from clients. But cybercriminals are getting more sophisticated in their attempts to steal information and extra care needs to be taken with all unsolicited emails, even those that could lead to new clients, network security experts said.

Advisers have said they often get caught in cyberscams because they are doing so many things at once that they click without thinking.

Such an excuse won't fly with regulators, who have cybersecurity high on their list of examination priorities for 2017.

In October, a Wells Fargo Advisors Financial Network broker was fined $5,000 by the Financial Industry Regulatory Authority Inc. for failing to detect a phishing attack that stole $350,000 from a client. She was fired by Wells Fargo and suspended from the industry for 30 days.

The IRS recommends never clicking on a link or an attachment in an email that came from a source through an unsolicited communication.

0
Comments

What do you think?

View comments

Recommended for you

Featured video

Events

Why blockchain matters to financial advisers

Lex Sokolin, a futurist and entrepreneur focused on the next generation of financial services, explains why every financial adviser should pay attention to blockchain and so-called cryptocurrencies.

Latest news & opinion

Nontraded BDC sales in worst year since 2010

The illiquid product's three-year decline is partially due to new regulations and poor performance.

Tax reform debate sparks fresh interest in donor-advised funds

Schwab reports new accounts up 50% from last year, assets up 33%.

Nontraded REITs to post worst sales since 2002

The industry is on track to raise just $4.4 billion, well off the $19.6 billion it raised just four years ago, as new regulations hinder sales.

Broker protocol for recruiting a boon for clients

New research finds advisers whose firms have joined the agreement take better care of customers.

Meet our 2017 Women to Watch

Introducing 20 female financial advisers and industry executives who are distinguished leaders, advancing the business of providing advice through their creativity and hard work.

X

Subscribe and Save 60%

Premium Access
Print + Digital

Learn more
Subscribe to Print