Cybercrooks Digging for Tax Data
It’s tax season, which means cyber-thieves are trawling the Web and sending counterfeit email in the hopes of snaring your personal tax data. And they’ve created websites with reasonable-seeming addresses and legitimate-seeming emails in order to lure unsuspecting citizens into clicking on the wrong link or downloading a virus-laden PDF.
They’ve been working on this particular scam for many months. Jeff Horne, director of threat research for anti-virus vendor Webroot, says an email account he set up to attract and study these types of email has received over one million phony tax-related messages since November.
These cyber-crooks also begin publishing malicious sites early in the tax season, with pages that allow people to download IRS forms for filing. “They automatically deliver the malware without you even realizing it,” said Horne. Whether delivered via email or a visit to a malicious site, the viruses lurk on your hard drive looking for keywords related to tax filing, such as social security numbers, street addresses, employer names and income, and then sends it back to the cyber-crooks.