IRS Warning on Phishing Emails Demands Attention

Recently, the IRS issued a warning that internet hackers have stepped up their phishing campaigns. Specifically, the hackers are increasing the usage of business email spoofing and business email compromise phishing campaigns. A common variation of this type is known as CEO Fraud or Gift Card Fraud (which HBK Risk Advisory services warned clients and colleagues earlier this month – Don’t Fall for the Phish(ing) Bait).

The warning from the IRS highlights two versions of the phishing scam:
  1. Emails impersonating company employees to Human Resources staff members requesting changes to the “employees'” payroll direct deposit bank accounts.
  2. Emails impersonating company executives to the staff members responsible for wire transfers requesting a wire transfer to a specific bank account on the “CEO’s” behalf.
Tips for Identifying Phishing Emails:
  1. Look for clues such as poor spelling or grammar, these are common in phishing messages.
  2. Don’t fall victim to the “urgent request” prompt. Unexpected messages that requires “your immediate attention” or are earmarked as “emergency” emails are often phishing scams.
  3. Be VERY skeptical! Place a phone call to the requesting employee or executive to verify the request of payroll or banking account changes.
Reminders of How to Keep Your Company’s Electronic Messaging Cyber Safe:
  1. Implement a formal Cyber Awareness Campaign. It should include regular educational updates about the red flags of phishing email campaigns.
  2. Establish an inventory of your Information Technology (IT) assets (including data mapping).
  3. Implement or update IT Security Policies (including data classification).
HBK can assist with any of the above action items, as well as advise on additional cyber security topics. Contact Bill Heaven at wheaven@hbkcpa.com for details or to schedule a business consultation.

Speak to one of our professionals about your organizational needs

"*" indicates required fields

hbkcpa.com needs the contact information you provide to us to contact you about our products and services. You may unsubscribe from these communications at anytime. For information on how to unsubscribe, as well as our privacy practices and commitment to protecting your privacy, check out our Privacy Policy.