They work because they exploit expectation, urgency, and authority. During filing season, many people expect messages about payments, forms, or account updates, so a convincing lure can feel routine rather than suspicious. Attackers also add penalties, deadlines, and brand impersonation to reduce scrutiny. That combination makes recipients more likely to click, enter credentials, or follow a fraudulent payment path.
Why these emails keep bypassing routine scepticism
Tax agency impersonation works because it fits a believable work pattern. Employees are used to seasonal notices, payment prompts, document requests, and account alerts, so the message does not arrive as an obvious anomaly. The strongest lures do not look novel, they look administratively normal, which makes the recipient rely on recognition instead of verification.
The attacker’s advantage is not just the topic, but the timing and framing. A filing deadline, penalty notice, or refund update compresses the decision window and pushes the reader toward fast action. Once the email seems to match an expected business event, scrutiny drops and the path to either credential capture or fraudulent payment becomes much easier.
- Routine subject matter lowers suspicion.
- Urgency reduces checking time.
- Official-looking branding increases perceived legitimacy.
- Payment or account language nudges action before confirmation.
That is why these campaigns remain effective even when employees know phishing exists. The question is rarely whether the email is technically sophisticated; it is whether it can borrow enough credibility from a familiar institution and a believable business moment to feel safe for long enough to trigger a click.
What makes the impersonation convincing enough to work
Successful lures usually combine a few pressure points rather than depending on one trick. They borrow the tone of a government notice, mimic sender names and layout, and use wording that sounds procedural instead of emotional. When the message also references deadlines, penalties, or overdue action, it creates a narrow “act now” channel that discourages the recipient from pausing to inspect details.
Brand impersonation matters because employees often judge trust before they verify destination. If the email looks like a normal administrative notice, the recipient may focus on the request itself instead of the surrounding signals, such as link destination, reply address, or whether the payment route is legitimate. That is especially effective when the target is busy, multitasking, or expecting tax-related correspondence.
The same pattern explains why awareness training alone has limited effect. People can recognise phishing in the abstract and still respond to a message that matches their current context. The practical defence is to make verification the default behaviour for any message that asks for credentials, demands immediate action, or redirects payment into a channel outside the normal workflow.
For teams that want examples of how social engineering can turn a believable support interaction into broad access, the MGM Resorts Breach 2023, Scattered Spider case is a useful reminder that routine-looking requests can be the entry point to much larger compromise.
How organisations should think about the control problem
The control problem is not simply “detect more phishing”, it is “make a single deceptive email insufficient to cause loss”. That means verification paths for payment changes, out-of-band confirmation for sensitive requests, and technical controls that reduce the value of any one clicked message. If a false tax notice can trigger neither credential reuse nor an immediate money transfer, the campaign loses much of its power.
Employees also need clear rules for when a message must be treated as suspicious. If it contains urgent tax language, a payment request, or a link to a login page, the default action should be to verify through a known channel rather than interact with the message directly. The organisation should make that safe, fast alternative obvious, because ambiguity is where these lures succeed.
On the technical side, mail filtering, link isolation, browser protections, and strong authentication all reduce the blast radius, but none of them replace user verification for payment-related prompts. The most resilient posture combines user behaviour, workflow controls, and phishing-resistant authentication so that a convincing email does not automatically translate into access or loss.
Risk and Threat Considerations
These emails are risky because they exploit a high-trust, high-tempo business process. The threat is not just credential theft, it is also fraudulent payment diversion, account takeover, and follow-on access when the victim reuses credentials or hands over verification codes.
Failure mechanism: The attacker mirrors a legitimate tax notice closely enough to trigger routine compliance behaviour, then uses urgency and authority to compress judgment before the recipient verifies the source or destination.
Impact: A single successful lure can lead to credential compromise, financial loss, inbox compromise, or a broader internal foothold if the employee account is used for lateral phishing or business process abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AT — Awareness and Training | Employee phishing resilience depends on recognition and verification behavior. |
| PR.AC — Access Control Management | Phishing becomes harmful when stolen credentials or prompts are accepted as access. | |
| Recommendation — Train staff to verify urgent tax or payment emails through an independent channel. Enforce access controls that limit damage from compromised employee credentials. | ||
| CIS Controls v8 | 14 — Security Awareness and Skills Training | These campaigns exploit routine human decision-making that training must address. |
| 6 — Access Control Management | Payment diversion and account misuse are reduced when access paths are tightly controlled. | |
| Recommendation — Run role-based phishing training focused on tax and payment impersonation. Require independent verification for sensitive financial or account-change requests. | ||
Practitioner Guidance
What to prioritise: Put payment-change verification and tax-related exception handling ahead of generic “spot the phishing email” messaging. If a lure can produce an irreversible transfer, the process needs a stronger control than user suspicion alone.
What to verify: Confirm that employees know the approved channel for tax, payroll, and finance queries, and that any request to pay, update bank details, or reauthenticate is verified outside the email thread. Test whether the alternate channel is actually usable under time pressure.
Common mistake: Treating these messages as a seasonal awareness issue instead of a repeatable business-process abuse pattern. Attackers succeed when the organisation assumes the problem is only email content, rather than the decision path the email is trying to shortcut.
Practitioner takeaway: The most effective defence is to make legitimacy prove itself through process, not appearance, because these emails work when employees are asked to trust the look and urgency of the message instead of an independent confirmation path.
Related resources from NHI Mgmt Group
- Why do domain name scams still work against well-run businesses?
- Why do vishing attacks still work against trained employees?
- Why do package impersonation and dependency confusion still work against mature teams?
- Why do social engineering attacks work so well against employees in high-pressure situations?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org