ELSTER Tax Phishing Wave Hits Germany in Summer 2026

Every summer, millions of German employees file their tax returns and then wait, hopefully, for a refund. Attackers know this calendar as well as any Steuerberater, and in 2026 they are exploiting it at unprecedented scale. Fake 'Steuerbescheid' and 'Steuererstattung' emails impersonating ELSTER and the Finanzamt are now among the most effective real-world lures hitting German inboxes, and the timing is no accident.
A 400 Percent Surge in US Tax-Authority Impersonation
In spring 2026, security firm Hoxhunt detected the largest tax-related phishing campaign ever recorded in its global threat data, with US tax-authority impersonation up more than 400 percent against the prior two-year baseline, according to the company's 2026 research announcement. Notably, these were not crude mass blasts: the research describes personalized lures blended into corporate workflows, tax-themed messages engineered to look like the routine administrative traffic employees process at work every day.
The same release points to a broader escalation. Malicious phishing emails reported by users in the United States rose 147.3 percent in spring 2026, and 11 percent of AI-generated phishing emails carried malicious attachments. Tax season is simply where this larger wave concentrates, because a deadline plus the prospect of money creates the perfect emotional conditions for a click.
The Fake ELSTER Refund Mail, Dissected
In late June 2026, German consumer-protection organizations warned about fake ELSTER mails promising a 'Steuererstattung' circulating in the wild, a pattern also covered by German outlet inFranken.de. The mechanics are consistent: the mail claims a refund has been calculated and is waiting, then directs the victim to a form that harvests login credentials and personal data, exactly the information needed for payment fraud and identity theft.
The lure works because it inverts the usual phishing psychology. Most phishing threatens something bad: a locked account, a missed delivery, a policy violation. The refund mail promises something good, and greed plus anticipation lowers defenses at least as effectively as fear. An employee who filed their 2025 return three weeks ago is not surprised to hear from the tax office; they are expecting it. The attacker's message slots neatly into an existing expectation, which is what makes seasonal phishing so much more effective than random-topic spam.
The One Rule: The Finanzamt Never Emails Your Refund
The defensive lesson here is unusually clean, and that makes it teachable. The official ELSTER security page states plainly that the tax administration never sends tax data or invoices as email attachments. Genuine communication about your Steuerbescheid happens inside the ELSTER portal itself, which you reach by typing the address yourself or using the official app, never through a link or attachment in an email.
That gives every employee a rule simple enough to survive a stressful Monday morning:
- An email announcing a tax refund, with a link or attachment to claim it, is fraudulent. Full stop.
- Never enter your IBAN, identification number, or personal data on a page reached from a tax-themed email.
- To check for real correspondence, open elster.de directly in your browser and log in there.
- Received one at work? Report it to IT like any other phishing mail, because colleagues almost certainly got it too.
If the refund is real, it is waiting in your ELSTER account and in your bank account. No genuine Erstattung has ever been lost by refusing to click an email link.
Why Seasonal Lures Belong in the Corporate Threat Model
Security teams sometimes dismiss tax phishing as a private-life problem, since the Finanzamt deals with individuals. That is a mistake for three reasons. First, these mails arrive in corporate inboxes, and Hoxhunt's data shows attackers deliberately blending them into workplace traffic. Second, an employee who enters credentials or personal data on a phishing page often reuses passwords across private and corporate accounts, converting a private mistake into an enterprise incident. Third, attachment-based variants can carry malware straight onto the corporate endpoint the mail was opened on.
Seasonality also gives defenders a rare gift: predictability. You know German employees file 2025 returns over the summer and that Bescheide and refunds follow in the weeks after. That is precisely when tax-themed awareness content and phishing simulations have maximum relevance. A simulated refund lure sent during filing season, followed by instant coaching for anyone who clicks, teaches more in thirty seconds than a generic annual training module. Platforms like empowsec make this practical, letting you schedule seasonal simulation scenarios and track through risk scoring whether the 'Finanzamt never emails refunds' rule has actually stuck across departments.
Tax season is only the sharpest example of a broader pattern worth teaching. Attackers ride whatever the calendar makes plausible: year-end bonus letters, insurance adjustments, holiday delivery notices, enrollment windows. The technique is identical each time - meet an expectation the victim already holds, and borrow an authority they cannot easily verify. Employees who learn to recognize that seasonal-expectation pattern through the ELSTER example carry the same skepticism into every other season. For German subsidiaries of international companies, the lesson counts twice, since staff face both local ELSTER lures and the global wave of tax-authority impersonation reflected in the Hoxhunt data.
Key Takeaways
- Tax phishing is surging. Hoxhunt recorded its largest tax-related phishing campaign ever, with US tax-authority impersonation up over 400 percent versus the prior two-year baseline.
- The ELSTER refund mail is the flagship lure. Fake Steuererstattung messages harvest login credentials and personal data from employees expecting real tax correspondence.
- Teach one memorable rule: the tax administration never sends tax data or invoices as email attachments; real Bescheide live in the ELSTER portal.
- Treat it as a corporate risk. These mails hit work inboxes, and password reuse and malicious attachments turn private lapses into company incidents.
- Use the calendar. Schedule tax-themed security awareness training and simulations for filing season, when the lesson is most vivid.
Attackers plan their campaigns around your employees' calendars. The defense is to plan your training around the same dates, and to make sure that when the fake refund arrives, it lands on someone who already knows the Finanzamt never emails money.


