Full Report
In this testimonial, learn firsthand from one of our Security Awareness Consultants at Curricula about how a fake IRS phishing scam worked on one student.
Analysis Summary
# Incident Report: The "IRS" Phishing & Vishing Gift Card Scam
## Executive Summary
A college student was targeted by a sophisticated multi-stage social engineering attack involving phishing, vishing, and physical movement. The attacker, impersonating an IRS agent, coerced the victim into purchasing $10,000 in Apple gift cards to settle a fabricated tax debt. Despite intervention by a bystander, the funds were liquidated before recovery actions could be completed.
## Incident Details
- **Discovery Date:** June 3, 2021 (Date of public disclosure/report)
- **Incident Date:** Undisclosed (Prior to publication)
- **Affected Organization:** Private University (Student Affairs/Police Department)
- **Sector:** Higher Education
- **Geography:** United States
## Timeline of Events
### Initial Access
- **Date/Time:** Undisclosed
- **Vector:** Phishing Email
- **Details:** The student ("Jamie") received an email with the subject line “IRS URGENT: IMMEDIATE ACTION REQUIRED,” alleging legal action and arrest for tax discrepancies.
### Lateral Movement
- **Not Applicable:** This was a social engineering attack against an individual rather than a technical network intrusion. The "movement" was physical, as the attacker directed the victim to move from campus to retail locations and the statehouse via Uber.
### Data Exfiltration/Impact
- **Data Impact:** The victim submitted personal information via a malicious webform and disclosed their real-time location and address via phone.
- **Financial Impact:** $10,000 was stolen via five $2,000 Apple gift cards. The PINs were read to the attacker over the phone.
### Detection & Response
- **Detection:** An Uber driver overheard the victim reciting gift card numbers on speakerphone and alerted the victim that they were being scammed.
- **Response Actions:** The driver returned the student to campus; the student filed a report with the University Police Department. The responding officer contacted Apple Corporate to freeze the cards.
## Attack Methodology
- **Initial Access:** Phishing (Email-based lure).
- **Persistence:** Vishing (Voice Phishing); the attacker insisted the victim stay on the phone throughout the entire physical ordeal to maintain psychological control.
- **Privilege Escalation:** N/A.
- **Defense Evasion:** Use of untraceable gift cards as a payment method; spoofing/impersonating a government authority (IRS).
- **Credential Access:** N/A (Personal Identity Information gathered via webform).
- **Discovery:** Attacker used a webform to gather victim's address and location.
- **Lateral Movement:** Physical coercion/direction of the victim.
- **Collection:** Recitation of gift card PINs over a voice call.
- **Exfiltration:** Digital redemption of gift card balances.
- **Impact:** Financial loss and psychological distress.
## Impact Assessment
- **Financial:** $10,000 USD (Direct loss).
- **Data Breach:** Exposure of victim’s PII (Name, Address, Location).
- **Operational:** Disruption to the student’s education and university security resources.
- **Reputational:** N/A (Student anonymity maintained).
## Indicators of Compromise
- **Network indicators:** Phishing link (URL not provided in text, but described as a "webform").
- **Behavioral indicators:** High-urgency communication, threats of arrest, demand for payment via non-standard methods (gift cards), insistence on staying on a live call during transit.
## Response Actions
- **Containment measures:** The Uber driver intervened to stop the transmission of remaining card details.
- **Eradication steps:** The victim contacted University Police to document the crime.
- **Recovery actions:** Attempted contact with Apple to freeze funds; however, recovery was unsuccessful as the funds had already been spent.
## Lessons Learned
- **Psychological Vulnerability:** Scammers leverage "low floor" engagement (an easy first click) to build commitment before escalating to high-value demands.
- **Institutional Gaps:** Students (particularly first-years) may lack financial literacy regarding how government agencies communicate, making them prime targets for authority-based scams.
- **Community Vigilance:** The intervention of the Uber driver highlights the importance of public awareness and bystander intervention in stopping active scams.
## Recommendations
- **Education:** Implement Security Awareness Training (SAT) specifically tailored to students, focusing on the fact that the IRS never initiates contact via email or phone to demand immediate payment via gift cards.
- **Verification:** Always verify "urgent" claims by hanging up and calling the official, publicly listed number of the organization in question.
- **Retail Cooperation:** Training for retail employees at Apple stores and similar outlets to identify and question large-volume gift card purchases, especially by young adults or the elderly.