IRS Tax Refund Phishing Scam
Since 11-30-05
From:
Waspscpo@aol.com [mailto:Waspscpo@aol.com]
Sent: Wednesday, November 30, 2005 12:39 PM
To: undisclosed-recipients:
Subject: IRS Tax Refund Phishing Scam
IRS Tax Refund Phishing Scam
http://antivirus.about.com/od/emailscams/a/irsphishing.htm?nl=1
November 30, 2005
A security flaw on a US government website has been exploited by a phishing scam
claiming to be an IRS refund notification. The phishing email claims the
recipient is eligible for a tax refund of $571.94. The email then tries to gain
credibility by instructing recipients to copy/paste the url rather than clicking
it.
That's because the link actually does point to a page on a legitimate government
website, http://www.govbenefits.gov .
The problem is, the page being targeted on that site allows the phishers to
'bounce' the user to another site altogether. The email used in the orginal IRS
tax refund phishing scam can be viewed in the
Phishing Scams Walkthrough. The subject line of the scam reads : [IRS] Tax
Refund.
The text of the email claims
"You are eligible to recieve a tax refund for $571.94" and instructs the recipient to access the link provided in the email.
The IRS tax refund phishing scam email also reads, "12 days left to apply for your refund. You may not receive your refund as quickly as you expected. A refund can be delayed for a variety of reasons. For example, a name and Social Security number listed on the tax return may not match the IRS records. You may have failed to electronically sign the return or applied after the deadline."
The email then claims,
"This email has been sent by the Internal Revenue Service, a bureau of the Department of the Treasury.
While at first glance the IRS tax refund phishing scam may seem clever, it shouldn't fool savvy users.
Both the targeted page and the redirected site have since been removed but the
security flaw itself reportedly still exists. This means that while the original
IRS tax refund phishing scam may no longer function, similar scams could soon
follow.
If you receive an email from any source that leads to a site requesting personal
or financial information, stop and think.
Contact the company in question (i.e. your bank, the IRS, eBay, or whomever the
pretend sender is) by conventional means (phone, letter, personal visit) and
verify that the information in the email is indeed valid. Chances are, it is
not.
---------------------------------------------------------------
Contributed,
YNCS Don Harribine, USN(ret)