- Days left

IRS Internet Scams: If the Tax Man Emails You Out of the Blue, It's Fraud. Always.

IRS Internet Email ScamsAs buddy-buddy as you might be with the IRS, don't expect to get an email from the government's tax agency any time soon. And if you do -- as our editor did recently -- you can rest assured that it's a scam.

Here's the note our editor got in her inbox:

From: IRS
Reply-To: "noreply@girs.com"
Subject: Tax Notification
Our Ref. S/11434/12
Your Ref. 18B/765/12

NOTICE OF TAX RETURN FOR YEAR 2011

Dear Taxpayer, I am sending this email to announce: After the last annual calculation of your fiscal activity we have determined that you are eligible to receive a tax return of: $253.04

To receive your return, you need to register for an e-Services account: Click here to register If you already have an e-Services account:

Click here to login For more info on government services go to www.irs.gov


It's tempting to take the bait. After all, who wouldn't want an extra $253.04?

But when DailyFinance followed up with the IRS, which is known for confusing documents, the agency made itself crystal clear: "The IRS does not initiate contacts with taxpayers through email," spokesman Anthony Burke said. "Our contacts go out to taxpayers through the U.S. mail. If we're sending you a notice of some sort, if there's a tax petition suit, you're going to get mail from us."

As with any email phishing scam, the danger is that if you follow the link, you could end up with a malware infection, such as a Trojan horse that logs your keystrokes and allows a hacker to gain access to your bank accounts.
Or, if you supply the website with personal information when it asks, you're laying yourself open to identity theft and larceny without the need for the hackers to go further.

In this case, the sending domain -- GIRS.com -- might at first glance be mistaken for an IRS site, but the URL actually sent recipients to a phishing page hosted in Saudi Arabia, according to Chester Wisniewski, a senior security adviser at digital security firm Sophos.

When we visited the now-disabled site, it did in fact look convincingly like an IRS website. The URL even contained the letters "IRS.gov" -- along with a long string of numbers that only a tech-savvy user might have recognized as problematic. (Astute readers of the email might also have picked up on the British spelling of the word "authorise" in the disclaimer, a tip-off that the author perhaps didn't learn English in the U.S.)

These days, Wisniewski noted, the majority of phishing and malware scams originate in the former Soviet Union, but in some ways, it's getting harder to tell. "They're hiring people to write professional English," he said. "The 419 guys are still writing broken African English. Small businesses in China trying to sell me large quantities of cheap goods and LED light bulbs -- there's lots of broken English. But the Russians behind banking fraud seem to be bringing more well-trained English [speakers]."

The result: What had been one of the biggest red flags of an Internet scam -- poor English -- is no longer one you can count on spotting.

The lesson is, if you're the least bit suspicious, don't take the bait. "I wouldn't give the IRS my email," Wisniewski said. "If your 'Spidey-sense' is tingling, just delete."

Jo-Stewart Rattray, the director of information systems security firm ISACA, advises going one step further.

"Pick up the phone and verify with the organization directly," she said. "Generally this is not the way that the IRS or banks choose to communicate with their taxpayers or customers ... The rule of thumb is, if it sounds too good to be true, it almost certainly is."

Increase your money and finance knowledge from home

Goal Setting

Want to succeed? Then you need goals!

View Course »

How to Avoid Financial Scams

Avoid getting duped by financial scams.

View Course »

TurboTax Articles

11 Fun Ways to Spend Your Tax Refund

There are plenty of practical ways to spend your tax refund ? such as saving for major expenses, banking it as the start of an emergency fund or paying down debt. But it?s hard to resist the allure of spending some or all of your refund on something a little more fun. If that?s the road you want to go down, here are some ways suggestions.

A Tax Filing Factsheet for eBay Sellers

You can find almost anything for sale on eBay, from a piece of fine art to clippings of Justin Bieber?s hair. So it's no surprise that the IRS doesn't view all sellers alike in the online marketplace. You may not have to pay tax at all if you are essentially hosting an online garage sale, but if you run your eBay account more like a business, you should be reporting your sales to the IRS.

Tax Tips for Handymen and Odd Jobs

If you work as a handyman or do odd jobs around town for money, you are operating a business in the eyes of the IRS. Since you own your own business, you're likely a self-employed sole proprietor. This means you'll have lots of potential tax deductions to investigate.

Identity Theft: 7 Steps to Reclaiming Your Identity and Keeping it Safe

As more personal information continues to be stored online, the risk of identity theft also increases. In 2014 alone, the Bureau of Justice reported that 17.6 million U.S. residents experienced identity theft. If someone uses your personal data pretending to be you, it's a serious crime. With quick, decisive action, you can help discover the fraud, stop further damage and reclaim your identity. Here are six steps to get you on your way.