{"id":8111,"date":"2026-09-10T13:24:17","date_gmt":"2026-09-10T17:24:17","guid":{"rendered":"https:\/\/verito.com\/blog\/?p=8111"},"modified":"2026-09-02T14:08:28","modified_gmt":"2026-09-02T18:08:28","slug":"2026-efin-eservices-phishing-scams","status":"publish","type":"post","link":"https:\/\/verito.com\/blog\/2026-efin-eservices-phishing-scams\/","title":{"rendered":"What Do Fake EFIN and e-Services Phishing Emails Look Like?"},"content":{"rendered":"\n<p><strong>Phishing emails impersonating the IRS are a constant, evolving threat for tax preparers, not a problem that shows up once a year and goes away. One of the best-documented examples, tracked by Microsoft Threat Intelligence, hit more than 29,000 accountants and tax preparers in a single day using 14 rotating sender names and a fake \u201cTranscript Viewer\u201d download that was actually remote-access malware. A separate, longer-running pattern goes straight after your e-Services login instead. Here\u2019s what both actually look like, and what to do about it.<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p>Key takeaways<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Phishing campaigns that impersonate the IRS specifically target accountants and tax preparers, not a broad industry list.<\/li>\n\n\n\n<li>One large, well-documented campaign used a fake EFIN \u201ctranscript review\u201d pretext and a \u201cDownload IRS Transcript View 5.1\u201d button that actually installed a remote-access tool disguised as an IRS application.<\/li>\n\n\n\n<li>A separate, older pattern targets your e-Services login directly, through fake account-revalidation notices or fake \u201cnew user agreement\u201d emails.<\/li>\n\n\n\n<li>Repackaging a legitimate remote-access tool defeats traditional antivirus. Catching it takes a different kind of tool, one that watches behavior instead of matching known bad files.<\/li>\n\n\n\n<li>If you get one, forward it to phishing@irs.gov and delete it. Don\u2019t click, don\u2019t download, don\u2019t reply.<\/li>\n<\/ul>\n<\/blockquote>\n\n\n\n<div class=\"wp-block-rank-math-toc-block\" id=\"rank-math-toc\"><h2 id=\"table-of-contents\">Table of Contents<\/h2><nav><ul><li><a href=\"#what-does-a-fake-efin-transcript-review-email-look-like\">What does a fake EFIN transcript-review email look like?<\/a><\/li><li><a href=\"#what-does-a-fake-e-services-account-notice-look-like\">What does a fake e-Services account notice look like?<\/a><\/li><li><a href=\"#why-are-tax-preparers-targeted-specifically\">Why are tax preparers targeted specifically?<\/a><\/li><li><a href=\"#what-should-you-actually-do-if-one-lands-in-your-inbox\">What should you actually do if one lands in your inbox?<\/a><\/li><li><a href=\"#where-this-fits-with-protecting-your-efin\">Where this fits with protecting your EFIN<\/a><\/li><\/ul><\/nav><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-a-fake-efin-transcript-review-email-look-like\"><strong>What does a fake EFIN transcript-review email look like?<\/strong><\/h2>\n\n\n\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/03\/19\/when-tax-season-becomes-cyberattack-season-phishing-and-malware-campaigns-using-tax-related-lures\/\" target=\"_blank\" rel=\"nofollow noopener\"><strong>Microsoft Threat Intelligence documented one large campaign in detail<\/strong><\/a><strong>:<\/strong><strong> emails claiming that returns filed under your EFIN needed review, sent from addresses rotating across 14 different IRS-themed names, including \u201cIRS EFIN Team,\u201d \u201cIRS e-Services Support,\u201d and \u201cIRS Filing Review.\u201d<\/strong><\/p>\n\n\n\n<p>The subject lines rotated too, most commonly some version of \u201cIRS Request Transcript Review\u201d or \u201cCPA Compliance Review.\u201d The email contained a \u201cDownload IRS Transcript View 5.1\u201d button. Clicking it ran through an Amazon tracking link to a look-alike domain built to mimic SmartVault, a real document-management service accountants actually use, then showed a fake \u201cverification\u201d animation designed to look like the IRS checking the connection before the download started. The file that downloaded, <em>TranscriptViewer5.1.exe<\/em>, wasn\u2019t an IRS tool at all. It was a legitimate remote-access program called ScreenConnect, repackaged to run silently and hand the attacker remote control of the machine once opened, not just a password.<\/p>\n\n\n\n<p>That repackaging is a deliberate choice, not a mistake. Traditional antivirus mostly looks for known bad files, and a legitimate program signed by a real vendor has nothing to flag. What catches it instead is endpoint detection and response, which watches for the behavior, a program suddenly granting an outside party remote control, rather than trying to recognize the file itself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-a-fake-e-services-account-notice-look-like\"><strong>What does a fake e-Services account notice look like?<\/strong><\/h2>\n\n\n\n<p><strong>A separate, longer-running pattern skips the EFIN pretext and goes straight after your e-Services login. The email claims your account needs revalidation, has been closed, or requires you to accept a new user agreement, and sends you to a fake login page built to capture your username and password directly.<\/strong><\/p>\n\n\n\n<p>This one has shown up in a few different costumes over the years: an email claiming your account was closed for failing to revalidate your identity, one asking you to sign a new e-Services user agreement under a subject line like \u201cImportant Update About Your e-Services Account,\u201d and one styled as \u201cSecurity Awareness for Tax Professionals\u201d with a spoofed e-Services logo. All of them lead to the same place, a fake login page built to look like the real thing. The IRS will not email you to reopen a suspended e-Services account. If your account is genuinely closed, the fix runs through the e-Services Help Desk directly, not a link in your inbox.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-1024x576.jpg\" alt=\"Second factor protecting a tax account cinematic visual | Verito\" class=\"wp-image-8125\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-second-factor.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>This lure only works because nothing stands between a stolen password and the account behind it. Multi-factor authentication breaks that chain even after someone has typed a real username and password into the fake page, since the attacker still doesn\u2019t have the second factor.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th><\/th><th>Fake EFIN transcript review<\/th><th>Fake e-Services notice<\/th><\/tr><\/thead><tbody><tr><td>Pretext<\/td><td>Returns filed under your EFIN need review<\/td><td>Your e-Services account needs revalidation, or a new agreement<\/td><\/tr><tr><td>What it asks you to do<\/td><td>Download a \u201cTranscript Viewer\u201d<\/td><td>Log into a page that looks like e-Services<\/td><\/tr><tr><td>What it\u2019s actually after<\/td><td>Remote control of your machine<\/td><td>Your username and password, directly<\/td><\/tr><tr><td>Example wording seen in the wild<\/td><td>\u201cIRS EFIN Team,\u201d \u201cDownload IRS Transcript View 5.1\u201d<\/td><td>\u201cImportant Update About Your e-Services Account\u201d<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"why-are-tax-preparers-targeted-specifically\"><strong>Why are tax preparers targeted specifically?<\/strong><\/h2>\n\n\n\n<p><strong>When Microsoft analyzed who the large EFIN campaign actually reached, it wasn\u2019t concentrated in one industry. It hit financial services, technology, and retail roughly evenly, which pointed to something more specific than an industry list: the campaign was built to find accountants and tax preparers wherever they worked, not just at accounting firms.<\/strong><\/p>\n\n\n\n<p>That kind of role-based targeting lines up with what the IRS itself is warning about. The 2026 Dirty Dozen list names spear-phishing and malware campaigns aimed at tax professionals directly, describing \u201cnew client\u201d or \u201cdocument request\u201d emails built to deliver malicious links and steal client data. The reasoning holds year-round, not just during filing season: a compromised inbox at an accounting firm doesn\u2019t just expose one person\u2019s data, it exposes every client whose return runs through that firm, which makes preparers a consistently higher-value target than almost anyone else a scammer could email. Sender names and subject lines rotate specifically to get past filters trained on last season\u2019s version, and some campaigns borrow a real accountant\u2019s name and logo pulled from public records. Spotting every variation by eye gets harder every season, which is exactly why filtering and monitoring exist as a backstop instead of relying on any one person catching it in time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"what-should-you-actually-do-if-one-lands-in-your-inbox\"><strong>What should you actually do if one lands in your inbox?<\/strong><\/h2>\n\n\n\n<p><strong>Don\u2019t click, don\u2019t download, and don\u2019t reply. Forward the email as an attachment to phishing@irs.gov, then delete it. If you believe you\u2019re specifically being impersonated by the IRS, report it to the Treasury Inspector General for Tax Administration as well.<\/strong><\/p>\n\n\n\n<p>If you\u2019re unsure whether an EFIN or e-Services notice is real, go directly to IRS e-Services or call the e-Services Help Desk yourself rather than using anything in the email. The same applies to messages claiming to be from your tax software vendor: go to the vendor\u2019s own portal directly instead of clicking through. If you already clicked a link or ran a download before realizing it was a scam, disconnect the device from your network, run a full scan, and loop in whoever handles your IT before doing anything else.<\/p>\n\n\n\n<p>Those steps cover the email you actually notice. The harder problem is the one nobody catches in time.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"where-this-fits-with-protecting-your-efin\"><strong>Where this fits with protecting your EFIN<\/strong><\/h2>\n\n\n\n<p><strong>Spotting the lure is half the job. The other half is the ongoing habit of monitoring your EFIN for misuse, which <\/strong><a href=\"https:\/\/verito.com\/blog\/efin-protection-monitoring-tax-professionals\/\" target=\"_blank\" rel=\"dofollow\"><strong>Verito\u2019s guide to protecting your EFIN<\/strong><\/a><strong> covers in detail: checking your weekly return count in e-Services, keeping your e-file application current, and putting MFA on everything the EFIN touches.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-1024x576.jpg\" alt=\"Network cable disconnected after a phishing click cinematic visual | Verito\" class=\"wp-image-8126\" srcset=\"https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-1024x576.jpg 1024w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-300x169.jpg 300w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-768x432.jpg 768w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-1536x864.jpg 1536w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-380x214.jpg 380w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-800x450.jpg 800w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-1160x653.jpg 1160w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect-150x84.jpg 150w, https:\/\/verito.com\/blog\/wp-content\/uploads\/2026\/09\/2026-efin-eservices-phishing-scams-disconnect.jpg 1920w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>Each lure in this piece has a specific control that catches what a person alone might miss:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>What the attacker is counting on<\/th><th>What actually stops it<\/th><\/tr><\/thead><tbody><tr><td>Antivirus won\u2019t flag a repackaged legitimate tool<\/td><td>Endpoint detection and response, which watches behavior instead of matching known files<\/td><\/tr><tr><td>A stolen password alone gets into the account<\/td><td>Multi-factor authentication on every login<\/td><\/tr><tr><td>Generic filters miss a look-alike domain<\/td><td>Email filtering built to catch impersonation and look-alike domains<\/td><\/tr><tr><td>Nobody catches every version by eye<\/td><td>Regular, simulated phishing training<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>VeritGuard bundles all four. Verito\u2019s <a href=\"https:\/\/verito.com\/blog\/defending-cpa-firms-from-phishing-attacks\/\" target=\"_blank\" rel=\"dofollow\">guide to defending firms from phishing attacks<\/a> walks through how those pieces fit together for a firm building this out for the first time.<\/p>\n\n\n\n<p><a href=\"https:\/\/verito.com\/anti-phishing-software\" target=\"_blank\" rel=\"dofollow\"><strong>See what VeritGuard\u2019s anti-phishing protection actually covers \u2192<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"Phishing emails impersonating the IRS are a constant, evolving threat for tax preparers, not a problem that shows&hellip;\n","protected":false},"author":12,"featured_media":8123,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"class_list":{"0":"post-8111","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-knowledge-base"},"acf":[],"_links":{"self":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8111","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/comments?post=8111"}],"version-history":[{"count":4,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8111\/revisions"}],"predecessor-version":[{"id":8127,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/posts\/8111\/revisions\/8127"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media\/8123"}],"wp:attachment":[{"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/media?parent=8111"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/categories?post=8111"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/verito.com\/blog\/wp-json\/wp\/v2\/tags?post=8111"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}