Microsoft: IRS Phishing Hit 29,000 Users in Single Day

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Microsoft warned that a February 10, 2026 IRS-impersonating phishing campaign hit 29,000 users across 10,000 organizations, with 95% of targets in the U.S. and financial services (19%) the top-hit sector, followed by tech/software (18%) and retail (15%).
- RMM tools like ConnectWise ScreenConnect, Datto, and SimpleHelp are being weaponized for persistent access, with abuse of such tools surging 277% year-over-year per Huntress.
- The February 10 campaign used emails sent via Amazon SES claiming irregular returns under recipients' EFIN, redirecting to smartvault[.]im — a fake SmartVault page protected by Cloudflare to block bots — to drop a malicious ScreenConnect installer granting remote access.
- Phishing kits Energy365 and SneakyLog (Kratos) power CPA- and W2-themed credential-harvesting pages, with Energy365 alone estimated to send hundreds of thousands of malicious emails daily across roughly 100 organizations in manufacturing, retail, and healthcare.
- Attackers impersonated the IRS with a cryptocurrency tax-form lure targeting the U.S. higher-education sector, directing victims to irs-doc[.]com or gov-irs216[.]net to deliver ScreenConnect or SimpleHelp.
- Threat actors are chaining URL rewriting services from Avanan, Barracuda, Bitdefender, Cisco, INKY, Mimecast, Proofpoint, Sophos, and Trend Micro to nest redirects and evade detection, per LevelBlue — a shift from single-vendor rewrites to multi-layer nesting.
- Elastic Security Labs researchers Daniel Stepanic and Salim Bitam warned that because RMM tools are used by legitimate IT departments, they are typically trusted and overlooked in most corporate environments.
Why it matters: The 277% year-over-year surge in RMM tool abuse means attackers are hiding in plain sight using IT-trusted software, converting a single tax-season click into persistent remote access. With 95% of 29,000 victims in the U.S. and financial services the top-hit sector, the credential and document theft feeds directly into wire-fraud and tax-fraud pipelines, while the multi-vendor URL-rewriting chain frustrates standard email gateway detection.



