Debunking email hoaxes and exposing Internet scams since 2003!


Hoax-Slayer Logo Hoax-Slayer Logo

DividerDivider
Home    About    New Articles    RSS Feed    Subscriptions    Contact
DividerDivider
Bookmark and Share







Issue 101 - April 2010 - Page 2

Pages in this month's issue:
  1. The WHY Yacht - Luxurious 58x38 Yacht from Wally Hermès
  2. IRS Tax Refund Phishing Scam
  3. Beware of Dubious Facebook "Free Offer" Groups
  4. Google "Received Your Resume" Malware Email
  5. Sandeep Money For Forwarding Charity Hoax
  6. F1 Key Virus Warning
  7. Muslim Protest Photographs - Pictures From London
  8. Apartment Cleaner Overpayment Scam
  9. Sundarbans Ghost Chain Letter
  10. Western Union Unauthorized Transaction Phishing Scam
  11. Haiti Earthquake Money Laundering Scam
  12. South African Revenue Service Tax Refund Phishing Scam

Issue 101 Start Menu

Previous Article            Next Article

IRS Tax Refund Phishing Scam

Outline
Email, purporting to be from the IRS, claims that the recipient is eligible for a tax refund and should click on an included link to access the refund.



Brief Analysis
The message is not from the IRS and the promised refund is just the bait used by Internet criminals to trick recipients into disclosing their personal and financial information. Those who follow the link in the email will be taken to a bogus website designed to resemble the genuine IRS website. Once on the bogus website, they will be asked to provide credit card details and other personal information. All information provided can be collected and used by Internet scammers for fraud and identity theft.

Example
From: 13674805@irs.gov
Subject: Internal Revenue Service: Please submit the tax refund


After the last annual calculations of your fiscal activity we have determined that you are eligible to receive a tax refund of $548.50. Please submit the tax refund request and allow us 3-6 days in order to process it.

A refund can be delayed for a variety of reasons.
For example submitting invalid records or applying after the deadline.

In order to complete your tax refund please click the link:
[Link Removed]

Note: For security reasons, we will record your ip-address, the date and time. Deliberate wrong inputs are criminally pursued and indicated.

Regards,
Internal Revenue Service

Copyright 2009, Internal Revenue Service U.S.A. All rights reserved.



Detailed Analysis
Phishing scammers use a variety of tactics designed to trick victims into divulging their personal information. One such tactic is to send out bogus emails that claim that the recipient is eligible for a tax refund from the Internal Revenue Service (IRS). The message instructs recipients to click on a link to apply for their refund.

However, the email is not from the IRS, and clicking the link opens a bogus website designed to steal personal information such as credit card details and social security numbers. The scammers can retain the private information submitted on this fake website and use it to commit credit card fraud or identity theft. In order to further the illusion of legitimacy, the fake website closely resembles pages on the genuine IRS website. The scam email itself also uses seemingly official graphics and formatting to fool potential victims into believing its claims.

The IRS has published information warning US taxpayers about IRS related phishing scams. The warning notes:
The IRS does not initiate taxpayer communications through e-mail.
  • The IRS does not request detailed personal information through e-mail.
  • The IRS does not send e-mail requesting your PIN numbers, passwords or similar access information for credit cards, banks or other financial accounts.
Some versions of these scam emails attempt to trick recipients into opening an attachment rather than following a link. These attachments open a web-based form that again asks for personal and financial information that can be collected by Internet criminals.

In fact, criminals have used variants of this IRS tax-refund ruse to target US based victims for a number of years. Moreover, scammers also use very similar tactics to target taxpayers living in the United Kingdom, Canada, Australia, India and South Africa. You should treat any unsolicited email that claims that you are eligible for a tax refund with the utmost suspicion. Government tax entities such as the IRS do not send refund notifications via unsolicited email. If you receive such an email, do not follow any links in the message or open any attachments that it may contain.

Bookmark and Share

comments powered by Disqus

References
How to Report and Identify Phishing, E-mail Scams and Bogus IRS Web Sites
HM Revenue & Customs Tax Refund Phishing Scam
Department of Finance Phishing Scam
Australian Tax Refund Scam Email
Indian Department of Revenue Tax Refund Scam
South African Revenue Service Tax Refund Phishing Scam

Previous Article            Next Article

Issue 101 Start Menu

Pages in this month's issue:
  1. The WHY Yacht - Luxurious 58x38 Yacht from Wally Hermès
  2. IRS Tax Refund Phishing Scam
  3. Beware of Dubious Facebook "Free Offer" Groups
  4. Google "Received Your Resume" Malware Email
  5. Sandeep Money For Forwarding Charity Hoax
  6. F1 Key Virus Warning
  7. Muslim Protest Photographs - Pictures From London
  8. Apartment Cleaner Overpayment Scam
  9. Sundarbans Ghost Chain Letter
  10. Western Union Unauthorized Transaction Phishing Scam
  11. Haiti Earthquake Money Laundering Scam
  12. South African Revenue Service Tax Refund Phishing Scam