Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-19 and was added to the RWP archive on 2026-09-07.
2026 tax-season phishing was an accountant-targeting RMM problem, not just refund-QR spam
Microsoft mapped overlapping US tax-themed campaigns — including a 10 February blast over 29,000 users at 10,000 organizations — splitting credential kits and ScreenConnect-class RMM.
Bottom line up front
CONFIRMED Microsoft's 19 March 2026 tax-season brief documented the annual US April-15 surge, with a qualitative change: accountants and tax preparers as the intended inbox, not only consumers. A 10 February 2026 operation reached more than 29,000 users across 10,000 organizations, ~95% US. Parallel threads: Energy365 PhaaS with CPA lures, 1099-themed domains, QR credential pages, and tax mail that installed RMM (ScreenConnect/Datto-class) instead of a stealer. One March CPA-targeted wave was about 1,000 US emails with a Datto payload in secondary summaries of the same Microsoft post.
Seasonal lure is infrastructure. Historical backfill of 19 March 2026 reporting; added 7 September 2026.
What happened
W-2, refund, EFIN, IRS IR-number subject lines, Eventbrite-styled IRS branding, crypto 1099 lures at higher ed. Some kits harvest. Some drop legitimate remote-support software so the SOC sees a signed RMM, not "malware.exe."
Why it mattered
Accounting firms are concentrating nodes for W-2s and client portals. RMM on a CPA laptop is a quiet path into every client's data. Blocking "IRS.zip" is not the control; blocking unexpected ScreenConnect is.
Who / what was affected
US finance, tech, retail as volume shares; intended roles clustered on accountants. OT not claimed.
Technical context
Allow-list RMM publishers. Alert on new ScreenConnect/AnyDesk/Datto from mail-origin processes. QR-in-PDF still bypasses some attachment sandboxing — treat images in tax mail as links.
Exploitation / threat status at the time
CONFIRMED Microsoft campaign metrics and lure types.
REPORTED 29k/10k on 10 February as the flagship blast.
What defenders should have done
- Accounting tenants: no RMM except the firm's named tool.
- Extra scrutiny on tax-themed mail to finance DL from 1 February–30 April, every year.
- If RMM landed: isolate, rotate client credentials, notify.
RWP assessment
Confidence: High on Microsoft's scale numbers as vendor telemetry.
Defensive actions
- Calendar the tax-season detection pack; do not invent it in April.
- RMM allow-list.
- Partner-firm questionnaire: how do you stop ScreenConnect-from-mail.
Sources
- Microsoft Threat Intelligence — When tax season becomes cyberattack season
- The Hacker News / Threat Beat — Microsoft warns IRS phishing hits 29,000 users, deploys RMM
- GBlock — Tax season phishing hit 29,000 users in a single day