Parcel Plus tax clients had refunds redirected after spear phishing attack
- Organization
- Parcel Plus
- Exploit
- Phishing
- Industry
- Professional Services
Parcel Plus, a family-run shipping, printing, notary and tax preparation business in Hanover, Pennsylvania, told customers in late March 2025 that it had been targeted in a spear phishing attack the company said was linked to foreign actors.
The attackers altered the direct deposit details on filed federal tax returns so that refunds would be routed to accounts they controlled. Of roughly 5,000 federal returns the business had prepared that season, it had identified 21 clients whose banking details were changed, and it said it expected the count to rise. Redirecting refunds appeared to be the object of the attack.
Parcel Plus announced the incident in a Facebook post on the evening of 27 March 2025 rather than through a formal breach notification, and the Hanover Evening Sun reported it the next day. The company said it was working with the IRS and with its tax software provider and believed it had fixed the underlying problem. The FBI opened a case file on the matter.
According to the business, the IRS assured it that affected clients would still receive their refunds, but the compromised returns would have to be refiled on paper, which would require additional documentation and delay payment. Parcel Plus, which had served the Hanover area for 39 years, asked customers with questions to contact it directly.