Tax Refund Email from IRS at GovBenefits.gov is Fake! Don’t Get Caught by IRS Phishing Scam!   12/2/2005 - 1,290 views,

Summary: A fake email from the IRS telling you that you have a tax refund, and to go to the govbenefits.gov website isn't really from the IRS at all. It's a phish. Don't fall for it!

Previous Article « Yahoo Offers RSS by SMS
Read Next Article » The RIM Blackberry v. NTP Lawsuit Explained: You’re Not Likely to Lose Blackberry Service

The IRS and Internet security experts are warning of a fake phishing email which appears to come from the IRS. The phishing scam takes the form of what claims to be an email from the IRS which advises you that you have a tax refund due.

What is particularly sneaky about this fake IRS email is that the link that it gives you, to govbenefits.gov, is genuine. It will take you to the real govbenefits.gov website, but then it invisibly redirects you to the phishers’ website. The reason that the phisher is able to do this is that the govbenefits.gov website has a security flaw which is known as an “open redirect”.

Explains Sophos security expert Graham Cluely, “This is more advanced than the typical phish, because the Web link really does - at first - take you to the real tax benefit web site. Unfortunately the way the government web site has been configured allows the phishers to bounce the unwary in their direction.”

Most of the fake IRS tax refund email has mentioned the precise “refund” amount of $571.94, but expect that to change as people catch on, and the phishers alter their tactics.

Get FREE email alerts of new Internet Patrol stories!
    *We never share your email address with anyone

Email Address:
Date of first visit:
How you found us:

Subscribe
to The Internet Patrol on your cell phone    Email the link for this page to a friend!

Read more:

»  Teach a Boy to Phish…

»  Phishing at Blackpool: Man Arrested

»  Yahoo Messenger Target of Effective Phishing Scam

»  Don’t Say That Aunty Didn’t Warn You - This Month’s Fake Microsoft Security Update MS05-039

For additional similar stories check out our archives on Phishing

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


We apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day!

 
The Internet Patrol
Patrolling the Internet for You!