Le Lézard
Classified in: Science and technology, Covid-19 virus
Subjects: Photo/Multimedia, Survey

Valimail Research Finds Public and Private Sectors Susceptible to Tax-Related Phishing Attacks


Valimail, the leading provider of identity-based anti-phishing solutions, today released findings from its 2020 Tax Scam Report. For the report, Valimail analyzed the public DNS records for 200 domains likely to be impersonated for tax fraud, including the 2019 Fortune 100 (some of the largest U.S. employers), U.S. states' departments of revenue, federal tax agencies and well-known tax preparation services. Valimail found the majority of these organizations lack adequate protection against email-based scams including phishing, BEC and W-2/personal information scams.

Valimail's analysis focused on the presence and validity of Domain-based Message Authentication, Reporting and Conformance (DMARC) and Sender Policy Framework (SPF) records. Across all domains analyzed, 78% of the organizations either lack DMARC records or their DMARC policy is not enforced. However, 91% of the domains have SPF records, which indicates a willingness to implement email authentication ? although SPF does not protect domains from phishers spoofing the "From:" field. Without DMARC at enforcement, attackers are able to spoof these organizations' domains and initiate convincing tax-related phishing attacks.

"Threat actors have historically used major events to enhance their phishing attacks, and tax season is no exception," said Alexander García-Tobar, CEO and co-founder, Valimail. "However, we are in a unique position today: Not only is it tax season, but the COVID-19 pandemic has forced U.S. legislators to take aggressive actions to limit social interactions, and as a result many recently out-of-work individuals are facing lost wages. These individuals may be counting on a quick tax return, or they may be confused about the recently changed tax filing deadline. This makes people all the more susceptible to convincing tax scams, and cybercriminals are always willing to take advantage of uncertainty. Unfortunately, organizations that do not have DMARC records at enforcement are an easy target for criminals who use spoofing to launch highly convincing tax-related scams aimed at consumers or these companies' own employees."

Additional key findings from Valimail's Tax Scam Report include:

The low overall rate of DMARC enforcement indicates that there is much work to be done to eliminate tax-related fraud and identity theft caused by domain spoofing and phishing. To download the full report, please visit: https://www.valimail.com/resources/tax-season-vulnerabilities/

About Valimail

Valimail is a pioneering, identity-based, anti-phishing company that has been ensuring the global trustworthiness of digital communications since 2015. Valimail delivers the only complete, cloud-native platform for validating and authenticating sender identity to stop phishing, protect and amplify brands, and ensure compliance. Valimail has won more than a dozen prestigious cybersecurity technology awards and authenticates billions of messages a month for some of the world's biggest companies, including Uber, Splunk, Yelp, Fannie Mae, Mercedes Benz USA, and the U.S. Federal Aviation Administration.


These press releases may also interest you

at 12:39
In an effort to provide the best service possible, enterprise developer Interfuse, has added several important improvements to its Knowledge Base application. Within this update, new pages accessible in the Knowledge Base include Recently Added,...

at 12:16
Amae Health, a trailblazer in delivering patient-centered care for people with severe mental illness, announced today the successful closing of its oversubscribed $15 million Series A funding round. The round was led by Quiet Capital and included...

at 12:05
Kinaxis® Inc. , a global leader in end-to-end supply chain orchestration, today announced it has been named a Leader in the 2024 Gartner® Magic Quadranttm for Supply Chain Planning Solutions. Of the 20 vendors evaluated, Gartner positioned Kinaxis...

at 12:05
Radiance Biopharma ("Radiance" or the "Company"), a biopharmaceutical company specializing in the development of novel Antibody Drug Conjugates (ADCs) and Bispecific ADCs (BsADCs) treatments for cancers, today announced that...

at 12:00
Today, Immutable Games, a global leader in web3 game development and publishing, announced the hiring of Priya Keshyap as Executive Producer for Guild of Guardians, the epic fantasy RPG which comes to mobile on May 15. Keshyap draws on more than a...

at 11:53
Cyberchase, The WNET Group's multiple Emmy-winning math and environmental literacy series for kids ages 6-8, launches its 15th season with an unprecedented digital offering to meet young viewers where they are. An expansive slate of programming...



News published on and distributed by: