Phishing emails impersonating the IRS are a constant, evolving threat for tax preparers, not a problem that shows up once a year and goes away. One of the best-documented examples, tracked by Microsoft Threat Intelligence, hit more than 29,000 accountants and tax preparers in a single day using 14 rotating sender names and a fake “Transcript Viewer” download that was actually remote-access malware. A separate, longer-running pattern goes straight after your e-Services login instead. Here’s what both actually look like, and what to do about it.
Key takeaways
- Phishing campaigns that impersonate the IRS specifically target accountants and tax preparers, not a broad industry list.
- One large, well-documented campaign used a fake EFIN “transcript review” pretext and a “Download IRS Transcript View 5.1” button that actually installed a remote-access tool disguised as an IRS application.
- A separate, older pattern targets your e-Services login directly, through fake account-revalidation notices or fake “new user agreement” emails.
- Repackaging a legitimate remote-access tool defeats traditional antivirus. Catching it takes a different kind of tool, one that watches behavior instead of matching known bad files.
- If you get one, forward it to [email protected] and delete it. Don’t click, don’t download, don’t reply.
Table of Contents
What does a fake EFIN transcript-review email look like?
Microsoft Threat Intelligence documented one large campaign in detail: emails claiming that returns filed under your EFIN needed review, sent from addresses rotating across 14 different IRS-themed names, including “IRS EFIN Team,” “IRS e-Services Support,” and “IRS Filing Review.”
The subject lines rotated too, most commonly some version of “IRS Request Transcript Review” or “CPA Compliance Review.” The email contained a “Download IRS Transcript View 5.1” button. Clicking it ran through an Amazon tracking link to a look-alike domain built to mimic SmartVault, a real document-management service accountants actually use, then showed a fake “verification” animation designed to look like the IRS checking the connection before the download started. The file that downloaded, TranscriptViewer5.1.exe, wasn’t an IRS tool at all. It was a legitimate remote-access program called ScreenConnect, repackaged to run silently and hand the attacker remote control of the machine once opened, not just a password.
That repackaging is a deliberate choice, not a mistake. Traditional antivirus mostly looks for known bad files, and a legitimate program signed by a real vendor has nothing to flag. What catches it instead is endpoint detection and response, which watches for the behavior, a program suddenly granting an outside party remote control, rather than trying to recognize the file itself.
What does a fake e-Services account notice look like?
A separate, longer-running pattern skips the EFIN pretext and goes straight after your e-Services login. The email claims your account needs revalidation, has been closed, or requires you to accept a new user agreement, and sends you to a fake login page built to capture your username and password directly.
This one has shown up in a few different costumes over the years: an email claiming your account was closed for failing to revalidate your identity, one asking you to sign a new e-Services user agreement under a subject line like “Important Update About Your e-Services Account,” and one styled as “Security Awareness for Tax Professionals” with a spoofed e-Services logo. All of them lead to the same place, a fake login page built to look like the real thing. The IRS will not email you to reopen a suspended e-Services account. If your account is genuinely closed, the fix runs through the e-Services Help Desk directly, not a link in your inbox.

This lure only works because nothing stands between a stolen password and the account behind it. Multi-factor authentication breaks that chain even after someone has typed a real username and password into the fake page, since the attacker still doesn’t have the second factor.
| Fake EFIN transcript review | Fake e-Services notice | |
|---|---|---|
| Pretext | Returns filed under your EFIN need review | Your e-Services account needs revalidation, or a new agreement |
| What it asks you to do | Download a “Transcript Viewer” | Log into a page that looks like e-Services |
| What it’s actually after | Remote control of your machine | Your username and password, directly |
| Example wording seen in the wild | “IRS EFIN Team,” “Download IRS Transcript View 5.1” | “Important Update About Your e-Services Account” |
Why are tax preparers targeted specifically?
When Microsoft analyzed who the large EFIN campaign actually reached, it wasn’t concentrated in one industry. It hit financial services, technology, and retail roughly evenly, which pointed to something more specific than an industry list: the campaign was built to find accountants and tax preparers wherever they worked, not just at accounting firms.
That kind of role-based targeting lines up with what the IRS itself is warning about. The 2026 Dirty Dozen list names spear-phishing and malware campaigns aimed at tax professionals directly, describing “new client” or “document request” emails built to deliver malicious links and steal client data. The reasoning holds year-round, not just during filing season: a compromised inbox at an accounting firm doesn’t just expose one person’s data, it exposes every client whose return runs through that firm, which makes preparers a consistently higher-value target than almost anyone else a scammer could email. Sender names and subject lines rotate specifically to get past filters trained on last season’s version, and some campaigns borrow a real accountant’s name and logo pulled from public records. Spotting every variation by eye gets harder every season, which is exactly why filtering and monitoring exist as a backstop instead of relying on any one person catching it in time.
What should you actually do if one lands in your inbox?
Don’t click, don’t download, and don’t reply. Forward the email as an attachment to [email protected], then delete it. If you believe you’re specifically being impersonated by the IRS, report it to the Treasury Inspector General for Tax Administration as well.
If you’re unsure whether an EFIN or e-Services notice is real, go directly to IRS e-Services or call the e-Services Help Desk yourself rather than using anything in the email. The same applies to messages claiming to be from your tax software vendor: go to the vendor’s own portal directly instead of clicking through. If you already clicked a link or ran a download before realizing it was a scam, disconnect the device from your network, run a full scan, and loop in whoever handles your IT before doing anything else.
Those steps cover the email you actually notice. The harder problem is the one nobody catches in time.
Where this fits with protecting your EFIN
Spotting the lure is half the job. The other half is the ongoing habit of monitoring your EFIN for misuse, which Verito’s guide to protecting your EFIN covers in detail: checking your weekly return count in e-Services, keeping your e-file application current, and putting MFA on everything the EFIN touches.

Each lure in this piece has a specific control that catches what a person alone might miss:
| What the attacker is counting on | What actually stops it |
|---|---|
| Antivirus won’t flag a repackaged legitimate tool | Endpoint detection and response, which watches behavior instead of matching known files |
| A stolen password alone gets into the account | Multi-factor authentication on every login |
| Generic filters miss a look-alike domain | Email filtering built to catch impersonation and look-alike domains |
| Nobody catches every version by eye | Regular, simulated phishing training |
VeritGuard bundles all four. Verito’s guide to defending firms from phishing attacks walks through how those pieces fit together for a firm building this out for the first time.
See what VeritGuard’s anti-phishing protection actually covers →