Beware of phishy emails during tax-filing season


Associated Press

NEW YORK

It’s tax time, so you’d better think twice before clicking on that link in your email inbox.

What looks like a legitimate communication from your bank, human-resources department or email provider actually may be part of a scheme designed to steal the confidential information stored in your computer, or to gain access to the network it’s attached to.

Experts warn that tax season is a prime time for this brand of fraud known as “phishing,” with hackers out to steal your information in hopes of using it to file a false tax return.

Phishing emails remain one of the top causes of data breaches. Though people are more aware of their danger than ever before, the lures continue to evolve and increase in sophistication, making it tough for the average person to discern which emails are legitimate and which ones aren’t.

Here are a few answers to common questions about phishing:

WHY IS IT SO BAD THIS TIME OF YEAR?

Phishing peaks during tax season, partially because it’s a time of year that many people are accustomed to entering their most-personal information – such as their Social Security number or bank account information – on websites, Satnam Narang, senior security-response manager for security software maker Symantec, says.

Hackers can use that information to file false tax returns and steal a refund

This year is no exception. Earlier this month, the IRS said that it stopped an attack on the e-filing portion of its website. Hackers tried to use a combination of malware and 464,000 Social Security numbers that had been stolen elsewhere to generate PIN numbers that could be used to file fraudulent returns.

No taxpayer data was stolen from the IRS computer systems as a result of the hack.

WHAT are some RED FLAGS?

In an effort to get more people to click on a link before thinking about the possible consequences, many phishing emails will give an impression of scarcity, or include some kind of time limit.

For example, an email made to appear to be from a person’s bank or email provider may state that if that person doesn’t click on the enclosed link within 24 hours, they will be locked out of their account.

And while poor English and long, complex web links previously were sure signs of phishing, they’re not as prevalent anymore.

Meanwhile, it’s become easier to shorten the Web links that direct a people to fake websites, he says.

Narang adds that people should be wary of emails purported to be from banks, or other companies they do business with, but didn’t opt into emails from. He also notes that banks generally don’t include Web links in emails.

IS THERE ANY WAY TO PREVENT A PHISHING-RELATED HACKING?

Basic cyberhygiene can go a long way toward preventing a data breach, even if a link in a phishing email gets accidentally clicked on.

Using different passwords for different accounts, two-factor authentication and changing passwords frequently can be a big help. In addition, companies should test their employees by periodically sending out fake phishing emails to see who falls for them, Narang says.

And companies need to make sure their security keys are up to date, along with their anti-spam filters, so past bad senders don’t keep getting through, says Raj Samani, chief technology officer for Europe, the Middle East and Africa at Intel Security.

He adds that with any email communications, it’s always better to just go straight to the main website of the entity it purports to be from, just to be on the safe side.

By using this site, you agree to our privacy policy and terms of use.

» Accept
» Learn More