Tax Refund Email from IRS at GovBenefits.gov is Fake! Don’t Get Caught by IRS Phishing Scam!   - 3,566 Views, 4 Comments

Summary: A fake email from the IRS telling you that you have a tax refund, and to go to the govbenefits.gov website isn't really from the IRS at all. It's a phish. Don't fall for it!

Previous Article « Yahoo Offers RSS by SMS
Read Next Article » The RIM Blackberry v. NTP Lawsuit Explained: You’re Not Likely to Lose Blackberry Service

  Follow Anne on Twitter     Friend Anne on Facebook

The IRS and Internet security experts are warning of a fake phishing email which appears to come from the IRS. The phishing scam takes the form of what claims to be an email from the IRS which advises you that you have a tax refund due.

What is particularly sneaky about this fake IRS email is that the link that it gives you, to govbenefits.gov, is genuine. It will take you to the real govbenefits.gov website, but then it invisibly redirects you to the phishers’ website. The reason that the phisher is able to do this is that the govbenefits.gov website has a security flaw which is known as an “open redirect”.

Explains Sophos security expert Graham Cluely, “This is more advanced than the typical phish, because the Web link really does - at first - take you to the real tax benefit web site. Unfortunately the way the government web site has been configured allows the phishers to bounce the unwary in their direction.”

Most of the fake IRS tax refund email has mentioned the precise “refund” amount of $571.94, but expect that to change as people catch on, and the phishers alter their tactics.

Tax Refund Email from IRS at GovBenefits.gov is Fake! Don’t Get Caught by IRS Phishing Scam!

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « Yahoo Offers RSS by SMS
Read Next Article » The RIM Blackberry v. NTP Lawsuit Explained: You’re Not Likely to Lose Blackberry Service

Read more:

»  Phishing at Blackpool: Man Arrested

»  Teach a Boy to Phish…

»  Yahoo Messenger Target of Effective Phishing Scam

»  Phishers Turn to SMS with Text Message Phishing

For additional similar stories check out our archives on Phishing

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

4 Comments »

  1. FAKE IRS TAX REFUND -

    We are pleased to inform you that upon review of your fiscal activity
    we have determined that you are eligible to receive a tax refund of
    $354.20 under section 501 (c) (3) of the Internal Revenue Code.

    Please submit the tax refund request and allow us 3-6 days in order
    to process it.

    A refund can be delayed for a variety of reasons. For example submitting
    invalid records or applying after the deadline.

    To access the online form for your tax refund, please use the link below:
    https://www.irs.gov/individuals/refund/0id=9659600.htm

    Note: For security reasons, we will record your ip-address, the date
    and time. Deliberate wrong inputs are criminally pursued and indicted.

    Because this letter could help resolve any questions regarding your exempt
    status, you should keep it in your permanent records.

    David Morgan
    Director, Tax Refunds Department

    This links to an offical IRS site, but when you submit it is to another site, which is transmitting your bank info, etc..
    Don’t fall for it.
    12/16/08

    Comment by Kaye — 12/16/2008 @ 9:43 am

  2. dont fall there is a new one out with another amount and it looks real however it does say almost the same thing about the fiscal year and all that dont fall for it

    Comment by kristina — 1/16/2009 @ 5:58 am

  3. the new emails are coming from organizations @internal.com
    After the last annual calculations of your fiscal activity we have
    determined that you are eligible to receive a tax refund of $182,50.
    Please submit the tax refund request and allow us 3-9 days in order to process it
    dont fall for this scam

    Comment by kristina — 1/16/2009 @ 6:02 am

  4. I dont know if this is the same one as the january postings describe, but this one includes a html attachemnt the the phisher wants you to ’submit’.

    anyone seen this one?

    Tax return 2008 - 2009
    2008 - 2009 Recalculation of you tax refund
    Local Office no. 182 28/July/2009
    TAX REFUND NUMBER: USA52/XXXXXXXXXIRS29/158

    ATTN: Dear Applicant

    After the last annual calculation of your fiscal activity we have determined that you are eligible to receive a tax refund of $314.79
    Your TRN (TAX REFUND NUMBER): USA52/2XXXXXXIRS29/158, complete the tax return form attached to this message.
    After completing the form, submit the form by clicking the SUBMIT button on form and allow us 5-9 business days in order to process it.

    Our head office address can be found on our web site at http://www.irs.gov/

    Note: For security reasons, we recommend that you close your browser after you have finished accessing your refund status.
    - For security reasons, we will record your ip-address and date.
    - Deliberate wrong inputs are criminally pursued and indicted.

    Sincerely,
    Jennifer Brough
    Tax Credit Officer
    Internal Revenue Service

    Comment by Nick — 7/28/2009 @ 7:50 am

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 12/2/2005
The Internet Patrol
Patrolling the Internet for You!