Cybercriminals are capitalizing on a legitimate government program in New York State to conduct phishing and smishing (SMS phishing) campaigns. The New York State Department of Taxation and Finance has issued a public warning about fraudulent messages being sent to taxpayers regarding the state's inflation relief refund. These scams falsely claim that residents need to click a link and provide personal and financial information to receive their payment. The official program, however, is automatic and requires no action from taxpayers. This campaign is a classic example of social engineering, preying on public interest in a real-world event to steal sensitive information.
The scam leverages a legitimate government initiative to gain credibility and trick potential victims.
Spearphishing Link (T1566.002) via SMS) and email phishing.Victims who fall for this scam face a high risk of identity theft and financial fraud.
Public education is the primary defense against this type of broad-based phishing campaign.
.gov).User Training (M1017).Public awareness campaigns and user education are the most effective defenses against widespread social engineering scams.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats