Criminals are running IRS impersonation scams during tax filing season, using phone calls, emails, and texts to pressure victims into paying alleged tax debts or “fines,” or to trick them into disclosing sensitive personal and financial information. Common tactics include spoofed caller ID/sender details, use of official-looking IRS branding, and urgent threats (e.g., arrest or penalties) designed to short-circuit normal verification steps.
Guidance highlighted for defenders and end users includes treating unsolicited IRS outreach as suspicious (the IRS typically initiates contact via mailed letters), refusing demands for immediate payment, and recognizing that requests for payment via gift cards or cryptocurrency are strong indicators of fraud. One reported lure centers on the phone number 833-727-9955 being used in “IRS scam calls,” consistent with broader IRS-themed social engineering that may be further amplified by AI-enabled voice/text techniques to increase credibility and scale.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
A warning was issued about unsolicited calls and voicemails offering fake 'tax abatement' or 'verification' help while impersonating the IRS or tax-related agencies. The scam sought to pressure targets into disclosing sensitive information or paying fraudulent upfront fees for bogus tax-debt relief.
A community scam alert reported that phone number 833-727-9955 was being used in IRS impersonation calls. Callers allegedly claimed to represent the Internal Revenue Service and threatened victims over tax filings and collections.
During the 2026 tax-filing season, security researchers warned that scammers were exploiting the period by impersonating the IRS, tax preparers, and tax software companies through email, text messages, and phone calls. The scams included phishing, smishing, vishing, refund-theft schemes, fake refund verification sites, bogus tax-credit offers, and fraudulent tax preparers diverting refunds.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
onlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourcewelivesecurity.com
Open sourceirs.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.