Confirm sensitive instructions separately whenever the message comes from an accountant, tax software provider, bank, or other financial contact and asks for action involving money or identity data. The safest approach is to verify the request by phone or by logging directly into the official system, not by using links or contact details in the message.
Why a Separate Channel Matters for Tax Filing and Refund Requests
Tax filing and refund instructions are high-trust messages because they can redirect money, expose identity data, or change filing details at the exact point where people expect routine communication. The danger is not just phishing in the abstract, but a convincing message that borrows the credibility of an accountant, tax platform, or bank to trigger a fast, unverified action.
A separate channel breaks that trust shortcut. If the instruction is legitimate, it should still withstand a call-back to a known number, a fresh login to the official portal, or another independent verification path. If it fails that test, the message is not trustworthy enough to act on.
What Should Be Verified Before Acting on the Request?
The key question is whether the request changes where money goes, who receives a refund, or which identity details are being used. Those are the moments when attackers most often try to substitute their own instructions for a real one. Verification should use contact details or access paths you already trust, not the ones embedded in the message itself.
That means checking the sender relationship, the exact payment destination, and any request to update banking details, tax software credentials, or personal identifiers. A message can look professional and still be fraudulent, especially if it creates urgency, warns of a penalty, or asks for secrecy. The safest assumption is that the message content is untrusted until confirmed elsewhere.
- Use a known phone number or official portal already saved or bookmarked.
- Confirm the request text against prior filings or account history.
- Recheck any change to refund routing, bank details, or account recovery information.
- Treat urgency or pressure to move quickly as a reason to slow down, not speed up.
When Is Separate Verification Most Important?
Separate verification is most important when the message asks for a one-time action that is hard to reverse, such as changing refund instructions, approving a tax payment, sharing an identity document, or resetting access to a tax portal. These are exactly the kinds of requests where a single mistaken click can produce immediate financial loss or expose enough personal data to enable broader fraud.
It also matters when the message arrives through a channel that can be imitated easily, including email, text, or messaging apps. In those channels, the appearance of legitimacy is cheap to fake, so the decision should rest on independent verification rather than tone, branding, or attachment quality.
Risk and Threat Considerations
Tax-related impersonation works because it compresses decision time and exploits the expectation that a financial professional or platform is already trusted. The main risk is misdirected payment or fraudulent redirection of a refund, but identity data exposure can also support later account takeover, tax fraud, or broader financial impersonation.
Failure mechanism: The attacker forges or hijacks a trusted-looking message, then pushes the target to act through the same message thread, link, or reply path. If the recipient uses that path instead of a separate one, the attacker controls the verification loop and can substitute their own instructions.
Impact: A successful bypass can change refund destination details, divert funds, expose sensitive identity records, or create a follow-on fraud case that is harder to unwind once the filing or payment has already been processed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Tax account access depends on verifying who is making the request. |
| IA-8 — Identification and Authentication (Non-Organizational Users) | External tax preparer and provider interactions rely on confirming outside parties. | |
| IA-5 — Authenticator Management | Refund and filing changes often hinge on protecting credentials and access paths. | |
| Recommendation — Require verified authentication before accepting changes to tax filing or refund instructions. Use verified identity checks for external contacts before acting on sensitive instructions. Protect and rotate access credentials used for tax portals and payment systems. | ||
| NIST SP 800-63 | Digital Identity Guidelines | Supports phishing-resistant verification when confirming account-sensitive tax actions. |
| Recommendation — Use phishing-resistant account recovery and login methods for sensitive tax changes. | ||
Practitioner Guidance
What to verify: Confirm any request that changes payment routing, refund instructions, or identity data through a separate, pre-established channel. If the request only feels legitimate because it arrived from a known name or branded message, it has not been sufficiently verified.
Decision rule: If the request involves money movement or personal/tax identity data, verify it outside the message before acting. If the request cannot be confirmed quickly through a known number or the official account, treat it as unsafe until proven otherwise.
Common mistake: Replying to the message, calling a number inside it, or clicking its link to “verify” the instruction. That keeps the verification process inside the same trust boundary the attacker may have already compromised.
Practitioner takeaway: For tax and refund changes, the control is not skepticism alone, it is independent confirmation. Separate-channel verification is the difference between a routine administrative request and a fraud path that can move money or identity data without resistance.
Related resources from NHI Mgmt Group
- What breaks when an AI system cannot separate instructions from data?
- How should organisations secure online tax filing against phishing and impersonation?
- Why do tax and filing workflows create identity verification risk?
- How should organisations use digital signature certificates for tax filing workflows without creating approval bottlenecks?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org