Think Before You Click: Why Tax-Related Phishing Scams Spike Before Extension Season
As the tax filing deadline fades into the background, it’s easy to assume scam activity slows down as well. Unfortunately, the opposite is often true.
Late summer and early fall are busy months for taxpayers who requested filing extensions, business owners preparing financial information, and accounting firms working toward extension deadlines. Cybercriminals know this, and they use it to their advantage.
Phishing scams become more convincing during this time of year because people are expecting emails about tax documents, electronic signatures, client portals, and financial information. A fraudulent message that might have seemed suspicious in February can appear much more believable in August or September.
Understanding how these scams work is the first step toward avoiding them.
Why Extension Season Creates Opportunity for Scammers
During extension season, communication between taxpayers and their CPA tends to increase. Clients may receive requests for additional documentation, reminders about missing information, or instructions for securely uploading files.
Scammers take advantage of these expectations by sending emails that appear to come from:
- The IRS or state tax agencies
- CPA firms or accounting staff
- Payroll providers
- Banks or financial institutions
- Cloud storage or client portal providers
These emails often create a sense of urgency, encouraging recipients to click a link, download an attachment, or provide sensitive information before taking time to verify the request.
What a Tax-Related Phishing Email Might Look Like
Today’s phishing emails are far more sophisticated than they were just a few years ago. Many contain professional logos, realistic formatting, and language that closely resembles legitimate business communications. Some even use artificial intelligence to mimic writing styles and eliminate the spelling and grammar mistakes that once made fraudulent emails easier to identify.
Common warning signs include:
- Unexpected requests to verify your account or personal information
- Links directing you to log into a tax portal you were not expecting
- Attachments you did not request
- Messages claiming immediate action is required to avoid penalties
- Slightly altered email addresses or website domains that closely resemble legitimate organizations
When in doubt, take a moment to pause before clicking.
The Cost of One Click
A successful phishing attack can have consequences that extend far beyond a compromised email account.
Individuals may become victims of identity theft, fraudulent tax return filings, or stolen financial information. Businesses may experience unauthorized payments, payroll fraud, data breaches, or disruptions to daily operations.
In some cases, attackers gain access to Microsoft 365 or Google Workspace accounts and silently monitor email conversations for weeks, waiting for the right opportunity to strike. They may send a message posing as a vendor notifying you of updated bank account details, when the account is actually controlled by the attacker. Others impersonate a CFO or controller to request an urgent wire transfer. Some intercept invoice attachments, particularly PDFs, and subtly alter payment details before they reach the recipient.
Business Email Compromise remains one of the most common and costly fraud schemes affecting organizations today, and AI-generated emails that perfectly replicate the tone, grammar, and formatting of real executives make these attacks increasingly difficult to detect.
Simple Habits That Can Reduce Your Risk
While phishing scams continue to evolve, a few simple habits can significantly reduce your risk.
Before responding to an unexpected email:
- Verify the sender’s email address carefully, not just the display name.
- Avoid clicking links in unsolicited messages. Instead, visit the organization’s website directly or log into your client portal using a saved bookmark.
- Confirm requests for payment or sensitive information by calling a known phone number, not one listed in the email.
- Be cautious of messages that create unnecessary urgency or pressure you to act immediately.
- Enable multi-factor authentication on financial, tax, and email accounts whenever possible.
These extra steps take only a few minutes but can prevent significant financial loss.
How Nelson & Associates Helps Protect Client Information
At Nelson & Associates, protecting client information is a responsibility we take seriously. If you ever receive an email, payment request, or document request that seems unusual or inconsistent with previous communications, contact our office before responding.
Taking a few moments to verify a request is always preferable to dealing with the financial and administrative burden of recovering from fraud.
Cybercriminals continue to refine their tactics, especially during busy tax periods when legitimate communication increases. By remaining cautious, verifying unexpected requests, and using secure communication practices, individuals and businesses can greatly reduce their risk of becoming the next victim.
Financial planning includes more than preparing tax returns. It also means protecting the financial information that supports them.


