CyberWire Daily

Signals, scams, and a Salesforce snatch.

Mar 10, 2026
Brian Baskin, Threat Researcher at Sublime Security, explains tax-season employee impersonation scams in a concise, practical chat. He walks through why tax time is a prime target. He outlines common phishing tricks, targets in HR and finance, and modern defensive checks to watch for. Short, alerting, and focused on the scamming methods you should recognize.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Tax Season Supplies Ready-Made Urgency For Attackers

  • Tax season naturally creates urgency attackers exploit to bypass skepticism.
  • Brian Baskin explains IRS deadlines and fear give adversaries a ready-made reason to pressure victims into swift action.
ADVICE

Always Verify Tax Email Destinations Before Acting

  • Verify the destination before acting on tax-related emails by checking phone numbers, domains, and searching the organization independently.
  • Brian Baskin recommends confirming any unusual form requests, QR codes, or caller numbers against official IRS or employer resources.
ADVICE

Treat Unexpected W-2 Or IRS Attachment Requests As Suspicious

  • Beware attachments and links asking for tax forms, W-2s, or login credentials; treat unexpected requests as suspicious.
  • Brian Baskin highlights malicious PDFs and fake sites used to harvest credentials or deliver payloads.
Get the Snipd Podcast app to discover more snips from this episode
Get the app