Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-19 and was added to the RWP archive on 2026-09-07.

Daily Top · Identity

2026 tax-season phishing was an accountant-targeting RMM problem, not just refund-QR spam

Microsoft mapped overlapping US tax-themed campaigns — including a 10 February blast over 29,000 users at 10,000 organizations — splitting credential kits and ScreenConnect-class RMM.

RWP Ventures · 2026-09-07 · event 2026-02-10 · 2 min read · priority 7.6

Bottom line up front

CONFIRMED Microsoft's 19 March 2026 tax-season brief documented the annual US April-15 surge, with a qualitative change: accountants and tax preparers as the intended inbox, not only consumers. A 10 February 2026 operation reached more than 29,000 users across 10,000 organizations, ~95% US. Parallel threads: Energy365 PhaaS with CPA lures, 1099-themed domains, QR credential pages, and tax mail that installed RMM (ScreenConnect/Datto-class) instead of a stealer. One March CPA-targeted wave was about 1,000 US emails with a Datto payload in secondary summaries of the same Microsoft post.

Seasonal lure is infrastructure. Historical backfill of 19 March 2026 reporting; added 7 September 2026.

What happened

W-2, refund, EFIN, IRS IR-number subject lines, Eventbrite-styled IRS branding, crypto 1099 lures at higher ed. Some kits harvest. Some drop legitimate remote-support software so the SOC sees a signed RMM, not "malware.exe."

Why it mattered

Accounting firms are concentrating nodes for W-2s and client portals. RMM on a CPA laptop is a quiet path into every client's data. Blocking "IRS.zip" is not the control; blocking unexpected ScreenConnect is.

Who / what was affected

US finance, tech, retail as volume shares; intended roles clustered on accountants. OT not claimed.

Technical context

Allow-list RMM publishers. Alert on new ScreenConnect/AnyDesk/Datto from mail-origin processes. QR-in-PDF still bypasses some attachment sandboxing — treat images in tax mail as links.

Exploitation / threat status at the time

CONFIRMED Microsoft campaign metrics and lure types.

REPORTED 29k/10k on 10 February as the flagship blast.

What defenders should have done

  1. Accounting tenants: no RMM except the firm's named tool.
  2. Extra scrutiny on tax-themed mail to finance DL from 1 February–30 April, every year.
  3. If RMM landed: isolate, rotate client credentials, notify.

RWP assessment

Confidence: High on Microsoft's scale numbers as vendor telemetry.

Defensive actions

  1. Calendar the tax-season detection pack; do not invent it in April.
  2. RMM allow-list.
  3. Partner-firm questionnaire: how do you stop ScreenConnect-from-mail.

Sources

  1. Microsoft Threat Intelligence — When tax season becomes cyberattack season
  2. The Hacker News / Threat Beat — Microsoft warns IRS phishing hits 29,000 users, deploys RMM
  3. GBlock — Tax season phishing hit 29,000 users in a single day