Join our Newsletter — 33% off our NHI Course
Home› FAQ› Authentication, Authorisation & Trust› When should taxpayers confirm tax filing or refund…
Authentication, Authorisation & Trust

When should taxpayers confirm tax filing or refund instructions by a separate channel?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 28, 2026 Domain: Authentication, Authorisation & Trust

Confirm sensitive instructions separately whenever the message comes from an accountant, tax software provider, bank, or other financial contact and asks for action involving money or identity data. The safest approach is to verify the request by phone or by logging directly into the official system, not by using links or contact details in the message.

Why a Separate Channel Matters for Tax Filing and Refund Requests

Tax filing and refund instructions are high-trust messages because they can redirect money, expose identity data, or change filing details at the exact point where people expect routine communication. The danger is not just phishing in the abstract, but a convincing message that borrows the credibility of an accountant, tax platform, or bank to trigger a fast, unverified action.

A separate channel breaks that trust shortcut. If the instruction is legitimate, it should still withstand a call-back to a known number, a fresh login to the official portal, or another independent verification path. If it fails that test, the message is not trustworthy enough to act on.

What Should Be Verified Before Acting on the Request?

The key question is whether the request changes where money goes, who receives a refund, or which identity details are being used. Those are the moments when attackers most often try to substitute their own instructions for a real one. Verification should use contact details or access paths you already trust, not the ones embedded in the message itself.

That means checking the sender relationship, the exact payment destination, and any request to update banking details, tax software credentials, or personal identifiers. A message can look professional and still be fraudulent, especially if it creates urgency, warns of a penalty, or asks for secrecy. The safest assumption is that the message content is untrusted until confirmed elsewhere.

  • Use a known phone number or official portal already saved or bookmarked.
  • Confirm the request text against prior filings or account history.
  • Recheck any change to refund routing, bank details, or account recovery information.
  • Treat urgency or pressure to move quickly as a reason to slow down, not speed up.

When Is Separate Verification Most Important?

Separate verification is most important when the message asks for a one-time action that is hard to reverse, such as changing refund instructions, approving a tax payment, sharing an identity document, or resetting access to a tax portal. These are exactly the kinds of requests where a single mistaken click can produce immediate financial loss or expose enough personal data to enable broader fraud.

It also matters when the message arrives through a channel that can be imitated easily, including email, text, or messaging apps. In those channels, the appearance of legitimacy is cheap to fake, so the decision should rest on independent verification rather than tone, branding, or attachment quality.

Risk and Threat Considerations

Tax-related impersonation works because it compresses decision time and exploits the expectation that a financial professional or platform is already trusted. The main risk is misdirected payment or fraudulent redirection of a refund, but identity data exposure can also support later account takeover, tax fraud, or broader financial impersonation.

Failure mechanism: The attacker forges or hijacks a trusted-looking message, then pushes the target to act through the same message thread, link, or reply path. If the recipient uses that path instead of a separate one, the attacker controls the verification loop and can substitute their own instructions.

Impact: A successful bypass can change refund destination details, divert funds, expose sensitive identity records, or create a follow-on fraud case that is harder to unwind once the filing or payment has already been processed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-2 — Identification and Authentication (Organizational Users)Tax account access depends on verifying who is making the request.
IA-8 — Identification and Authentication (Non-Organizational Users)External tax preparer and provider interactions rely on confirming outside parties.
IA-5 — Authenticator ManagementRefund and filing changes often hinge on protecting credentials and access paths.
Recommendation — Require verified authentication before accepting changes to tax filing or refund instructions. Use verified identity checks for external contacts before acting on sensitive instructions. Protect and rotate access credentials used for tax portals and payment systems.
NIST SP 800-63Digital Identity GuidelinesSupports phishing-resistant verification when confirming account-sensitive tax actions.
Recommendation — Use phishing-resistant account recovery and login methods for sensitive tax changes.

Practitioner Guidance

What to verify: Confirm any request that changes payment routing, refund instructions, or identity data through a separate, pre-established channel. If the request only feels legitimate because it arrived from a known name or branded message, it has not been sufficiently verified.

Decision rule: If the request involves money movement or personal/tax identity data, verify it outside the message before acting. If the request cannot be confirmed quickly through a known number or the official account, treat it as unsafe until proven otherwise.

Common mistake: Replying to the message, calling a number inside it, or clicking its link to “verify” the instruction. That keeps the verification process inside the same trust boundary the attacker may have already compromised.

Practitioner takeaway: For tax and refund changes, the control is not skepticism alone, it is independent confirmation. Separate-channel verification is the difference between a routine administrative request and a fraud path that can move money or identity data without resistance.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org