Did you receive a stressful message from the Tax Authority? A phishing attack is trying to trap Israelis

Shtetl
August 6, 2026   
Illustration
Photo: 
Nati Shohat, Flash90

In recent days, a new and sophisticated phishing campaign has been spreading that impersonates the Tax Authority, with the aim of getting citizens to download a malicious file or provide personal information.

The message, sent by e-mail, is worded as an apparent official notice of the opening of an investigation into suspected tax offenses, and exerts pressure on the recipient by threatening criminal proceedings if he does not act within 72 hours.

The email states that an investigation has been opened against the recipient for evading income and performing artificial actions to obtain a tax advantage, while demanding that they 'download the investigation report' via a link attached to the email, stating that the download is only suitable for Windows computers. According to security experts, this is one of the main signs of an attempt to insert a malicious file into the victim's computer.

The notice is even supposedly signed by the 'Director of Enforcement and Investigations at the Tax Authority'.

However, an investigation conducted by the Israeli cyber company BrandShield shows that this is a phishing attempt that includes a long list of clear warning signs.

Among other things, the message is not sent from government servers at all, but from a foreign email address, while the address displayed in the body of the message includes a spoof domain that does not belong to the State of Israel.

In addition, the dates are written in a format that is not accepted in Israel, the fax number that appears is incorrect, the wording includes errors and unusual style, and the requirement to download a file within a time limit - and especially the emphasis that this can only be done from a Windows computer - is a familiar characteristic of phishing attacks that aim to inject malware into the victim's computer.

The method of contacting is also unusual: the Tax Authority does not announce the opening of an investigation via this type of email, and they certainly do not require the citizen to download files via a link sent in the email.

In official cases, a notification is usually sent that a document is waiting in the personal area of ​​the government website, and entry is made exclusively through the government website or using government identification.

Yoav Keren, CEO of the cyber company Brandshield, says that this is a classic example of the change that phishing attacks have undergone in recent years.

""Attackers are no longer satisfied with messages riddled with easily identifiable errors. Today, they construct credible scenarios, use formal language, case numbers, dates, and legal threats to pressure people into action. The goal is to override the victim's judgment through a sense of urgency.".

He said, "Almost every successful phishing attempt relies on three components: authority, intimidation, and urgency. When a threat of investigation, a demand to perform an action within a short time, and a link to download a file appear together - you should stop immediately and not click.".

Keren adds that in recent years there has been a significant increase in the volume of predictions for government bodies and well-known brands, with artificial intelligence tools allowing criminals to produce more convincing messages, quickly and at low cost.

According to him, "Artificial intelligence did not invent phishing, but it made it cheaper, faster, and more convincing. Today, any attacker can produce messages that look completely professional within minutes, so users must stop relying solely on the quality of the wording.".

According to cyber experts, there are several signs that should raise a red flag in any message of this type:

  • The sender's address does not end with the government's official domain (gov.il).
  • Pressure is exerted to act quickly through the threat of fines or criminal proceedings.
  • The message requires downloading a file or opening a link.
  • There are inconsistent details such as a date in an unusual format, incorrect phone or fax numbers, or wording that is not typical for a government entity.
  • An unusual prompt such as Windows only appears, sometimes indicating an attempt to distribute a malicious file.

Keren: "If you receive a message that appears to be from a government authority, never click on the link in the message. Open your browser yourself, type in the official website address, and log in to your personal area. The rule of thumb is simple: if the message tries to pressure you to act immediately, there is a high chance that someone is trying to scam you.".