Debunking email hoaxes and exposing Internet scams since 2003!


Hoax-Slayer Logo Hoax-Slayer Logo

DividerDivider
Home    About    New Articles    RSS Feed    Subscriptions    Contact
DividerDivider
Bookmark and Share









Issue 101 - April 2010 - Page 12

Pages in this month's issue:
  1. The WHY Yacht - Luxurious 58x38 Yacht from Wally Hermès
  2. IRS Tax Refund Phishing Scam
  3. Beware of Dubious Facebook "Free Offer" Groups
  4. Google "Received Your Resume" Malware Email
  5. Sandeep Money For Forwarding Charity Hoax
  6. F1 Key Virus Warning
  7. Muslim Protest Photographs - Pictures From London
  8. Apartment Cleaner Overpayment Scam
  9. Sundarbans Ghost Chain Letter
  10. Western Union Unauthorized Transaction Phishing Scam
  11. Haiti Earthquake Money Laundering Scam
  12. South African Revenue Service Tax Refund Phishing Scam

Issue 101 Start Menu

Previous Article

South African Revenue Service Tax Refund Phishing Scam

Outline
Email, purporting to be from the South African Revenue Service (SARS) claims that the recipient can claim a tax refund by clicking a link and submitting an online tax refund request form.



Brief Analysis
The email is not from SARS and the promised refund does not exist. The message is a phishing scam designed to trick recipients into handing over their personal and financial information to Internet based criminals. Those who follow the link in the message will be taken to a bogus web page designed to resemble the genuine SARS website. The bogus page will contain a form that asks the visitor to submit personal and financial information. All information submitted on the form will be sent directly to scammers.

Detailed analysis and references below example.
Example:
From: refunds@sars.gov.za
Subject: SARS Tax Return Payment

Tax Refund Notification


After the last annual calculations of your fiscal activity, we have determined that you are eligible to receive a tax refund of 8,582.50 ZAR. Please submit the tax refund request and allow 2-3 days in order to process it.

Click Here to submit you tax refund request

Note : A refund can be delayed a variety of reasons, for example submitting invalid records or applying after deadline.

Yours Sincerely
South African Revenue Service.

Screenshot:

SARS Tax Refuns Phishing Scam




Detailed Analysis
This email, which claims to be from the South African Revenue Service (SARS), informs the recipient that he or she is eligible for a tax refund of 8,582.50 ZAR. To claim the refund, the recipient is instructed to follow a link in the message and fill out an online "tax refund request" form.

However, the email is not from SARS and the claim that the recipient is eligible for a refund is untrue. In fact, the promised refund is just the bait used to entice recipients into visiting a bogus website and disclosing private personal and financial information. Those who click the link in such messages will be taken to a fake website that is constructed to closely resemble the genuine SARS website. The fake website will contain a form which is very similar to genuine eFiling forms published on the legitimate SARS website. The fake form requests bank and credit card details, including the card's PIN, along with other personal information. All information on this form can then be collected by the criminals running the scam and used for bank and credit card fraud.

In order to make the scammers' claims seem more genuine, the fraudulent email uses genuine SARS logos stolen from the SARS website and includes secondary links that point to the genuine SARS site. To drive the illusion even further, the scammers also use "spoofing", a technique in which an email's header is forged in such a way that a message appears to have been sent by a person or entity other than the actual sender. Thus, even though the email address shown in the "From" field of the email may appear as a genuine SARS address ( refunds@sars.gov.za), it actually originated from a different sender that has no connection to SARS whatsoever.

SARS has published information on its website warning South African taxpayers about such phishing scams. SARS will never send unsolicited emails that ask taxpayers to provide login credentials, bank and credit card details, PINS or other sensitive personal information.

Internet users should be very cautious of any emails that claim to be from their country's tax department and request that they provide personal or financial information either via links in the message or attached files. South Africans are not the only taxpayers who are regularly targeted by phishing scammers. Very similar scams have recently targeted people living in the United Kingdom, the United States, Canada, Australia and India.

Bookmark and Share



References:
SARS Emails Scams & Phishing Attacks
HM Revenue & Customs Tax Refund Phishing Scam
IRS Tax Refund Phishing Scam
Department of Finance Phishing Scam
Australian Tax Refund Scam Email
Indian Department of Revenue Tax Refund Scam

Previous Article

Issue 101 Start Menu

Pages in this month's issue:
  1. The WHY Yacht - Luxurious 58x38 Yacht from Wally Hermès
  2. IRS Tax Refund Phishing Scam
  3. Beware of Dubious Facebook "Free Offer" Groups
  4. Google "Received Your Resume" Malware Email
  5. Sandeep Money For Forwarding Charity Hoax
  6. F1 Key Virus Warning
  7. Muslim Protest Photographs - Pictures From London
  8. Apartment Cleaner Overpayment Scam
  9. Sundarbans Ghost Chain Letter
  10. Western Union Unauthorized Transaction Phishing Scam
  11. Haiti Earthquake Money Laundering Scam
  12. South African Revenue Service Tax Refund Phishing Scam