The Internal Revenue Service has issued an urgent warning to tax professionals over a new scam in which cyber-criminals impersonate the IRS over email in an attempt to steal Electronic Filing Identification Numbers (EFINs).

Carrying the subject line “Verifying your EFIN before e-filing,” the scam email purports to be from “IRS Tax E-Filing.”

In the body of the bogus email, targets are asked to send an EFIN acceptance letter dated within the last 12 months and scans of the front and reverse of their driver’s license to a fake email address in order for their EFIN to be verified. 

Thieves who obtained the EFIN and driving license data of a tax professional could use it to impersonate that professional and file fraudulent returns.

“Phishing scams are the most common tool used by identity thieves to trick tax professionals into disclosing sensitive information, and we often see increased activity during filing season,” said IRS commissioner Chuck Rettig. 

“Tax professionals must remain vigilant. The scammers are very active and very creative.”

In an alert jointly issued February 10 by the IRS, state tax agencies, and the tax industry, tax professionals who receive this particular scam email are asked to save it as a file and send it as an attachment to phishing@irs.gov.

Tax professionals were also warned to be on the lookout for other common phishing scams that seek their EFINs, Preparer Tax Identification Numbers (PTINs), or e-Services usernames and passwords.

To Erich Kron, security awareness advocate at KnowBe4, the appearance of tax scams in the first quarter of the year is “as inevitable as paying taxes.”

“These tax-themed email phishing attacks are a powerful tool for cybercriminals to steal sensitive information such as social security numbers or bank account information, redirect payments or steal credentials that will allow them to file fake tax returns,” Kron told Infosecurity Magazine. 

“To defend against these scams, educating people about the types of scams occurring and the red flags, such as links that go to different websites when you hover over them, unexpected requests for sensitive information such as login information or social security numbers, is critical.”

If You Found The Information Here Was Useful Please Consider Sharing This Page!
Refundtalk

Recent Posts

Your Cycle Code Is Your Refund Destiny: Understanding the 2026 Processing Schedule

Why your refund timing depends on a tiny number buried in your transcript Millions of…

8 minutes ago

The Doomsday Code: What TC 420 (Audit) Means for Your Refund and How to React

When the IRS puts your return under a microscope There are dozens of transcript codes…

26 minutes ago

“Where’s My Amended Return” Is a Black Hole: When to Call the TAS Instead

Why the WMAR tracker stops updating — and how to escalate a stalled 1040-X If…

52 minutes ago

The “Three-Column” Check: The #1 Mistake That Gets Your Amended Return Rejected

How to properly complete Columns A, B, and C on Form 1040-X If you are…

1 hour ago

How to Stop a Seized Refund After Filing Form 1040-X for Injured Spouse

Act fast to protect the non-liable spouse’s portion of the refund For married couples filing…

1 hour ago

The “Electronic 1040-X” Lie: Why Your Amended Refund Still Takes 6 Months to Arrive

E-file doesn’t mean fast — and taxpayers deserve the truth The IRS proudly announced that…

1 hour ago