CERT mailing list archives

Current Activity - US Tax Season Phishing Scams and Malware Campaigns


From: Current Activity <us-cert () us-cert gov>
Date: Wed, 8 Feb 2012 11:14:25 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

US-CERT Current Activity

US Tax Season Phishing Scams and Malware Campaigns

Original release date: February 8, 2012 at 11:10 am
Last revised: February 8, 2012 at 11:10 am


In the past, US-CERT has received reports of an increased number of
phishing scams and malware campaigns that take advantage of the United
States tax season. Due to the upcoming tax deadline, US-CERT reminds
users to remain cautious when receiving unsolicited email that could
be part of a potential phishing scam or malware campaign.

These phishing scams and malware campaigns may include, but are not
limited to, the following:
  * information that refers to a tax refund,
  * warnings about unreported or under-reported income,
  * offers to assist in filing for a refund, and
  * details about fake e-file websites.

These messages, which may appear to be from the IRS, may ask users to
submit personal information via email or may instruct the user to
follow a link to a website that requests personal information or
contains malicious code.

US-CERT encourages users and administrators to take the following
measures to protect themselves from these types of phishing scams and
malware campaigns:
  * Do not follow unsolicited web links in email messages.
  * Maintain up-to-date antivirus software.
  * Refer to the IRS website related to phishing, email, and bogus
    website scams for scam samples and reporting information.
  * Refer to the Recognizing and Avoiding Email Scams (pdf) document
    for more information on avoiding email scams.
  * Refer to the Avoiding Social Engineering and Phishing Attacks
    document for more information on social engineering attacks.

Relevant Url(s):
<http://www.us-cert.gov/cas/tips/ST04-014.html>

<http://www.us-cert.gov/reading_room/emailscams_0905.pdf>

<http://www.irs.gov/privacy/article/0,,id=179820,00.html?portlet=5>

====
This entry is available at
http://www.us-cert.gov/current/index.html#us_tax_season_phishing_scams1

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iQEVAwUBTzKfWD/GkGVXE7GMAQKPEQf/Q8U+iKgDegdYbiOO9j9qdPZ6CGu0QpVj
f217/DGZG/ji20FRB4kl1RrRb+NqMBgZrYrUbTh0zKc6FiaZyY2wIr+PoHv6SYAr
t86QF2h86QyjCI5JspIfkPSVenOO5nIytgUpeUc0w6e38JlkRAwfPvkhPLKAqk6c
o83t8BYiTh144R4lA7VnPpAOriq2D84bBF8P1qVDWEdQQFK84sDm58tNKnVMBe5K
iULHh+G8mXGzqjYm3TkQgBn3YkxJZq10YhnhEeydpJd0BbbNC/SEqD8Bqkg/k6UO
fVEdUfHaWKile0EU388/uXVkksbjqTursBhEm9jh92Z0W13df0pv9w==
=bzDg
-----END PGP SIGNATURE-----


Current thread: