Consumer-facing warnings described a surge of taxpayer-targeting impersonation scams using fake entities such as the “National Tax Executive Office” and “Tax Resolution Oversight Department,” alongside broader IRS-themed phishing via calls, emails, and SMS. Reported lures include urgent claims of tax debts or refunds, links to spoofed “official” sites, and AI-enabled impersonation (voice mimicry and deepfake-style video calls) to pressure victims into immediate payment. Common indicators include threats of arrest or license revocation and demands for nonstandard payment methods such as gift cards, wire transfers, prepaid debit cards, cryptocurrency, or P2P apps; guidance emphasized that the IRS generally initiates contact via postal mail and that suspected scams should be reported through official IRS/TIGTA channels.
Separately, the IRS leadership told Congress it is conducting a thorough cybersecurity review as lawmakers scrutinize the agency’s taxpayer data protections and a contested data-sharing agreement with Immigration and Customs Enforcement (ICE). Congressional questioning cited multiple privacy controversies, including litigation over the ICE agreement, allegations of inappropriate access to personally identifiable information, and historical disclosures (including a prior contractor leak affecting high-profile taxpayers). A federal judge’s opinion was also referenced alleging the IRS violated federal law tens of thousands of times by improperly sharing taxpayer addresses with the Department of Homeland Security via a flawed matching process; IRS leadership acknowledged responsibility for improving controls while declining detailed comment due to ongoing litigation.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Public scam guidance described a surge in taxpayer-targeting fraud using fake agencies such as the 'National Tax Executive Office' and 'Tax Resolution Oversight Department.' The notice also referenced the IRS 2026 'Dirty Dozen' scam themes and advised victims to verify contacts through official IRS channels and report phishing or impersonation attempts.
The IRS warned about widespread tax-related scams delivered by text, email, and phone calls, including AI-enabled voice mimicry and deepfake-style impersonation. The agency reiterated that it does not initiate contact through email, text, or social media, and does not demand payment via gift cards, wire transfers, cryptocurrency, or payment apps.
IRS CEO Frank Bisignano told the House Ways & Means Committee that the agency is conducting a thorough cybersecurity review and broader evaluations of taxpayer-data protections. The review comes amid scrutiny over IRS data-sharing with ICE, reported access to personally identifiable information, and other privacy controversies.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
foxbusiness.com
Open sourceonlinethreatalerts.com
Open sourceonlinethreatalerts.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.