Postal Phishing Bypasses Email Defenses

The weak point is no longer the inbox. A paper IRS-style letter can make the fraud feel official, and the real theft happens later on the phone, where the victim is pushed to hand over a one-time code, password, or seed phrase themselves. Coinbase and DarkTower traced the scheme after a customer reported one of the letters. The mailing uses Treasury and IRS branding, a QR code, and a fake “Digital Asset Compliance Portal” that leads into a callback request; DarkTower also tied the domain to infrastructure registered days earlier and previously linked to phishing pages impersonating banks and delivery services. That means email filters and bad-link blocking miss the main control point. The same official-looking notice plus callback pattern can be reused against crypto accounts and other high-value targets that rely on phone-based verification.

Part of the PlainSec briefing for 2026-08-04

Every edition of this story: Postal Phishing Bypasses Email Defenses

Sources