惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
Blog — PlanetScale
Blog — PlanetScale
B
Blog
GbyAI
GbyAI
爱范儿
爱范儿
月光博客
月光博客
N
Netflix TechBlog - Medium
T
Tailwind CSS Blog
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
Vercel News
Vercel News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
WordPress大学
WordPress大学
The GitHub Blog
The GitHub Blog
Recent Announcements
Recent Announcements
腾讯CDC
MyScale Blog
MyScale Blog
V
Visual Studio Blog
The Cloudflare Blog
Microsoft Security Blog
Microsoft Security Blog
A
About on SuperTechFans
Google DeepMind News
Google DeepMind News
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻

Check Point Blog

Reading the Signals in the OWASP LLM Top 10 2026 - Check Point Blog Ransomware Didn't Slow Down in Q2 2026. It Just Spread Out. - Check Point Blog July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure Widens - Check Point Blog State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit - Check Point Blog Lazarus Hackers Exploit Windows Zero-Day in Fake Job Scam Native AI Security Comes to Claude: Why Anthropic's Inference Hooks Matter - Check Point Blog Claude AI Security: How Anthropic Inference Hooks Enable Real-Time Protection The Top Exposure Management Questions Security Leaders Ask (Part 1) - Check Point Blog Black Hat 2026: Check Point Research Takes the Stage - Check Point Blog Check Point Joins the Open Secure AI Alliance to Advance Open, Measurable and Enterprise-Ready AI Security - Check Point Blog Three AI security disclosures, fourteen days: what the warnings signs are telling us - Check Point Blog When Data Becomes Instructions: AI Agents Need a Chain of Custody for Context - Check Point Blog Your VLAN Isn’t an Air Gap: Six Hard Truths From the New CI Fortify Guidance - Check Point Blog Check Point Named a Visionary Leader in the 2026 Frost Radar™ for Enterprise Risk Mitigation and Management Platforms - Check Point Blog AI Escaped a Sandbox. That is Not What Should Worry You - Check Point Blog Introducing the Industry's First AI Network Firewall - Check Point Blog Attackers Are Turning Microsoft's Trusted Login System Into Their Latest Phishing Weapon - Check Point Blog AI Agent Security Just Had Its Catalyst Moment - Check Point Blog Your AI Governance Policy Should Survive Your Next Model Change - Check Point Blog The Branding and Attribution Behind Cybercrime - Check Point Blog Which Brands Are Impersonated Most? Inside the Q2 2026 Brand Phishing Report - Check Point Blog Security Advisory - Action Required - July 2026 Security Update - Check Point Blog What the 2026 Exposure Gap Report Reveals About Remediation - Check Point Blog Inline Email Security and Microsoft 365: A Practical View of Mail Routing, Risk, and Prevention - Check Point Blog The State of Hybrid SASE: Built-In vs. Bolted-On - Check Point Blog AI Appreciation Day: Let's Be Honest About What We're Appreciating - Check Point Blog AI Security Is Never Finished: Building the Continuous Red Teaming Loop  - Check Point Blog AI Security Threats in 2026: Annual Insights from Check Point Research - Check Point Blog AI Agents are Only As Effective as Their Harness - Check Point Blog Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security - Check Point Blog How Check Point Email Security Stopped a Student Job Scam Before It Reached the Inbox - Check Point Blog Redefining the CISO Contract: From Securing the Business to Securely Doing Business - Check Point Blog
Tax Season 2026: How Cyber Criminals Are Preparing Their ...
rohann@checkpoint.com · 2026-04-02 · via Check Point Blog

Tax season remains one of the most attractive periods of the year for cyber criminals. As individuals and organizations exchange sensitive financial and identity data online, attackers take advantage of increased tax‑related activity to launch phishing campaigns, fraudulent websites, and malware attacks.

Check Point Research shows that these campaigns are not opportunistic.  Threat actors begin preparing their infrastructure months in advance.

A Surge in Malicious Tax‑Related Domains

Between September 2025 and February 2026, hundreds of new domains containing tax‑related keywords or tax authority names were registered each month. This activity steadily increased toward the end of 2025 and intensified from November onward, indicating deliberate preparation ahead of tax‑season campaigns.

Notably, one in every 15 newly registered tax‑related domains has already been classified as malicious or suspicious, highlighting the widespread abuse of tax‑related themes.

In March 2026, both volume and risk increased further. The number of newly registered domains grew compared to earlier months in 2026, while the proportion of malicious and suspicious domains reached its highest level so far this year — one in every 10 new domains registered in March was flagged as risky.

IRS Impersonation Campaigns

Supporting this trend, Check Point Research identified multiple phishing domains impersonating the US Internal Revenue Service (IRS) in January 2026, including 2025irswebsiteislive[.]live and irstax-refund[.]xyz. These domains appear to be part of the same coordinated campaign, sharing nearly identical content and functionality.

The websites lure victims with fake “tax refund” offers, promising unusually high payouts such as weekly payments of $1,400 or a one‑time payment of $38,700. Victims are then prompted to submit sensitive personal information — including full name, Social Security number, phone number, and email address — followed by an identity verification process, strongly suggesting large‑scale data harvesting.

2025irswebsiteislive[.]live

irstax-refund[.]xyz

Malicious Tax Emails Targeting Spanish Organizations

Tax‑related attacks are not limited to fraudulent websites. In February 2026, Check Point Research identified a malicious email campaign impersonating the Spanish tax authority, Agencia Tributaria (AEAT).

In February 2026, an email was sent from a spoofed address [email protected], masquerading as a legitimate sender, to a Spanish industrial company, using the subject “AEAT – Notification Notice 2026” (translated from Spanish).

The email contained a malicious executable attachment (hash: bda5cc053c4d9eb09f6dd1c45892fb4c) classified as Trojan.Downloader / Trojan.Minix (NSIS) and operates as a loader, designed to download and execute additional malicious payloads.

Once executed, the malware enables the delivery of secondary threats, such as credential stealers or keyloggers, potentially leading to further compromise of the victim’s system and sensitive data.

Date 24-Feb-2026
Sender [email protected]
Subject AEAT – Notification Notice 2026
(aeat – aviso de notificación 2026)
File Execution
Staying Vigilant During Tax Season

Tax season creates ideal conditions for cyber crime: high volumes of sensitive data, expected official communications, and pressure to act quickly. As these findings show, cyber criminals continue to refine their tactics and expand their reach.

As tax deadlines approach, organizations and individuals should remain alert. Monitoring newly registered domains, identifying phishing attempts early, and preventing malicious files from executing are critical steps in reducing risk. Proactive security and informed users remain the strongest defense against tax‑related cyber threats.