
CyberWire Daily Signals, scams, and a Salesforce snatch.
Mar 10, 2026
Brian Baskin, Threat Researcher at Sublime Security, explains tax-season employee impersonation scams in a concise, practical chat. He walks through why tax time is a prime target. He outlines common phishing tricks, targets in HR and finance, and modern defensive checks to watch for. Short, alerting, and focused on the scamming methods you should recognize.
AI Snips
Chapters
Transcript
Episode notes
Tax Season Supplies Ready-Made Urgency For Attackers
- Tax season naturally creates urgency attackers exploit to bypass skepticism.
- Brian Baskin explains IRS deadlines and fear give adversaries a ready-made reason to pressure victims into swift action.
Always Verify Tax Email Destinations Before Acting
- Verify the destination before acting on tax-related emails by checking phone numbers, domains, and searching the organization independently.
- Brian Baskin recommends confirming any unusual form requests, QR codes, or caller numbers against official IRS or employer resources.
Treat Unexpected W-2 Or IRS Attachment Requests As Suspicious
- Beware attachments and links asking for tax forms, W-2s, or login credentials; treat unexpected requests as suspicious.
- Brian Baskin highlights malicious PDFs and fake sites used to harvest credentials or deliver payloads.

