{"id":30395,"date":"2025-04-04T11:37:44","date_gmt":"2025-04-04T11:37:44","guid":{"rendered":"https:\/\/gridinsoft.com\/blogs\/?p=30395"},"modified":"2025-04-04T11:37:44","modified_gmt":"2025-04-04T11:37:44","slug":"urgent-reminder-email-tax-scam","status":"publish","type":"post","link":"https:\/\/gridinsoft.com\/blogs\/urgent-reminder-email-tax-scam\/","title":{"rendered":"Urgent Reminder Tax Scam"},"content":{"rendered":"<p><strong>The &#8220;Urgent reminder&#8221; tax scam is a yearly phishing effort designed to steal Microsoft account details<\/strong> by exploiting tax season urgency. Scammers send emails with attachments titled &#8220;Urgent reminder,&#8221; featuring PDFs with QR codes that lead to phishing sites asking for login information.<\/p>\n<h2>Urgent reminder Tax Scam Targeting Microsoft Credentials<\/h2>\n<p>Tax season, particularly before and around the April 15, 2025, filing deadline, is a peak period for scams, as fraudsters exploit the urgency and stress associated with tax obligations. The &#8220;Urgent reminder&#8221; scam is part of this trend, leveraging <a href=\"https:\/\/gridinsoft.com\/social-engineering\">social engineering tactics<\/a> to deceive users into <strong>compromising their Microsoft account details<\/strong>. Microsoft accounts are valuable targets, providing access to emails, cloud storage (OneDrive), and other services, which can lead to identity theft or data breaches.<\/p>\n<figure id=\"attachment_30410\" aria-describedby=\"caption-attachment-30410\" style=\"width: 1115px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code.webp\" alt=\"Urgent reminder with QR code screenshot\" width=\"1115\" height=\"1261\" class=\"size-full wp-image-30410\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code.webp 1115w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code-265x300.webp 265w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code-905x1024.webp 905w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code-768x869.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/email-qr-code-860x973.webp 860w\" sizes=\"auto, (max-width: 1115px) 100vw, 1115px\" \/><figcaption id=\"caption-attachment-30410\" class=\"wp-caption-text\">Urgent reminder with QR code<\/figcaption><\/figure>\n<p>In brief, these emails, often automated and from the supposed &#8220;Tax Services Department,&#8221; claim users must update tax records by a specific deadline (e.g., March 16) to avoid penalties. <strong>Scanning the QR code redirects to a phishing site<\/strong>, which may use bot protection before prompting for Microsoft credentials, with the email pre-filled to seem legitimate. The stolen credentials could be <a href=\"https:\/\/gridinsoft.com\/darknet\">sold on the dark web<\/a> or used to access email, OneDrive, or other services, posing risks of identity theft or data breaches.<\/p>\n<h2>Urgent Reminder Tax Scam Mechanics<\/h2>\n<p>The scam begins with an email containing an attachment titled &#8220;Urgent reminder,&#8221; which is a PDF file. As I said at the beginning, this is a yearly trend, and we already have <a href=\"https:\/\/gridinsoft.com\/blogs\/tax-season-scams\/\">a similar theme<\/a>, however this time the scammers have gone further. They use <strong>a QR code, which has advantages over a regular link<\/strong>, which I will talk about later. The email is often presented as an automated message with no reply option, giving it an official appearance. It claims to be from the &#8220;Tax Services Department&#8221; and states that a mandatory review and update of tax records is required by a specific date, specifically March 16, 2025, to avoid penalties or account disruptions.<\/p>\n<p>Next, the user is asked to scan the QR code. Scanning the QR code leads to a phishing website, which may use redirects (e.g., via doubleclick.net) <strong>to a domain like fmhjhctk.ru<\/strong>, identified as a russian site. Before prompting for credentials, the site implements bot protection (CAPTCHA), such as &#8220;Verifying encryption before network,&#8221; to appear legitimate. Once past this, it pre-fills the user&#8217;s email and requests Microsoft login details, sending them to the scammer.<\/p>\n<figure id=\"attachment_30416\" aria-describedby=\"caption-attachment-30416\" style=\"width: 450px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/Pre-filled-the-users-email.webp\" alt=\"Pre-filled the user\u2019s email popup\" width=\"880\" height=\"746\" class=\"size-full wp-image-30416\" title=\"\" srcset=\"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/Pre-filled-the-users-email.webp 880w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/Pre-filled-the-users-email-300x254.webp 300w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/Pre-filled-the-users-email-768x651.webp 768w, https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/Pre-filled-the-users-email-860x729.webp 860w\" sizes=\"auto, (max-width: 880px) 100vw, 880px\" \/><figcaption id=\"caption-attachment-30416\" class=\"wp-caption-text\">Pre-filled the user\u2019s email<\/figcaption><\/figure>\n<div class=\"box\">Do you know that con actors can use anti-bot protection as a disguise for their dirty deeds? We have a dedicated article on <a href=\"https:\/\/gridinsoft.com\/blogs\/fake-captcha-sites-malicious-code-lumma-stealer\/\">fake CAPTCHA<\/a> attack campaigns<\/div>\n<p>So, how QR code is better than a link, you ask, and I will answer now. Firstly, QR code better bypasses anti-spam systems, as <strong>it is just a picture, not a link<\/strong>. Secondly, it is impossible to determine where the QR code leads until you scan it. Thirdly, the chances that a person will scan a QR code, at least out of interest, are much higher than that he will follow a link. We also have <a href=\"https:\/\/gridinsoft.com\/blogs\/qr-code-phishing-scams\/\">a separate post<\/a> that explains a lot.<\/p>\n<h2>Risks and Implications<\/h2>\n<p>How about risks, theft of Microsoft credentials poses significant risks, including unauthorized access to personal emails, financial data stored in OneDrive, and potential identity theft. Given that most people have their <a href=\"https:\/\/www.reddit.com\/r\/cybersecurity\/comments\/16uva85\/qr_codes_phishing_emails\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">work linked to their Microsoft account<\/a> in one way or another, an account compromise can have catastrophic consequences. From loss of access, which paralyzes workflow, to the leakage of sensitive corporate data.<\/p>\n<p>In this case, the threat actor is tentatively based in Russia, which is not surprising, so this increasing the likelihood of credentials being sold on dark web markets or used for further attacks. This method, combined with pre-filled email fields, increases the likelihood of success, especially among less tech-savvy users.<\/p>\n<h2>How To Stay Safe?<\/h2>\n<p>Safeguarding yourself from the &#8220;Urgent reminder&#8221; tax scam and similar phishing threats requires a proactive approach, especially during the high-risk tax season. <strong>Never scan QR codes or click links in unsolicited emails<\/strong>, particularly those claiming urgent action. Instead, verify any tax-related communication directly with the IRS through their official website irs.gov or listed phone numbers. Remember, <strong>legitimate agencies won\u2019t demand immediate action via email or text<\/strong>. Additionally, always inspect website URLs before entering credentials; authentic Microsoft login pages will use domains like login.live.com.<\/p>\n<p>Beyond manual checks, deploying robust anti-malware software is non-negotiable in today\u2019s threat landscape, and tools like GridinSoft Anti-Malware stand out for their comprehensive protection. It includes Internet Security features that actively block phishing attempts, malicious redirects, and suspicious domains. Its real-time scanning can detect and neutralize threats from QR code redirects or compromised PDFs before they reach your credentials, offering peace of mind against sophisticated attacks.<\/p>\n<p style=\"padding-top:15px;padding-bottom:15px;\"><a href=\"\/download\/antimalware\" rel=\"nofollow\"><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" src=\"\/blogs\/wp-content\/uploads\/2022\/07\/env02.webp\" alt=\"Urgent Reminder Tax Scam\" width=\"798\" height=\"336\" class=\"aligncenter size-full\" title=\"\"><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;Urgent reminder&#8221; tax scam is a yearly phishing effort designed to steal Microsoft account details by exploiting tax season urgency. Scammers send emails with attachments titled &#8220;Urgent reminder,&#8221; featuring PDFs with QR codes that lead to phishing sites asking for login information. Urgent reminder Tax Scam Targeting Microsoft Credentials Tax season, particularly before and [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":30411,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_sitemap_exclude":false,"_sitemap_priority":"","_sitemap_frequency":"","footnotes":""},"categories":[15,4],"tags":[1223,131],"class_list":{"0":"post-30395","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security-news","8":"category-tips-tricks","9":"tag-email-scam","10":"tag-phishing"},"featured_image_src":"https:\/\/gridinsoft.com\/blogs\/wp-content\/uploads\/2025\/04\/GS_Tax-Season-Alert-New-Urgent-Reminder-Scam-Steals-Microsoft-Credentials-via-QR-Codes_1280x674.webp","author_info":{"display_name":"Stephanie Adlam","author_link":"https:\/\/gridinsoft.com\/blogs\/author\/adlam\/"},"_links":{"self":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/30395","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/comments?post=30395"}],"version-history":[{"count":17,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/30395\/revisions"}],"predecessor-version":[{"id":30407,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/posts\/30395\/revisions\/30407"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media\/30411"}],"wp:attachment":[{"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/media?parent=30395"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/categories?post=30395"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gridinsoft.com\/blogs\/wp-json\/wp\/v2\/tags?post=30395"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}