Follow Us:

Fake Income Tax, GST & Government Notice Scams on Email and WhatsApp: How to Identify and Stay Safe

Cybercriminals are increasingly exploiting taxpayers’ trust in government communications by sending fraudulent emails, WhatsApp messages, SMS alerts, and fake notices impersonating the Income Tax Department, GST authorities, Ministry of Finance, CBIC, MCA, and other government agencies. Their objective is to create panic and trick recipients into opening malicious attachments, clicking phishing links, downloading malware, disclosing sensitive information, or making fraudulent payments. These scams have become more sophisticated, with fraudsters using official logos, government terminology, fabricated reference numbers, and realistic-looking documents to make their communications appear genuine.

A recent example involves a phishing email carrying the subject “Tax Authority Checklist for July 2026 – COMM-2026-089 टैक्स ऑडिट के नतीजे No. TAX/PEN/2026-142″. The email claims to be issued by the Government of India and contains a brief message stating “No. TAX/PEN/2026-142, भारत सरकार, वित्त मंत्रालय (कृपया अटैचमेंट देखें),” urging recipients to open the attached PDF. At first glance, the communication appears official because it uses government references and tax-related terminology. However, a closer examination immediately reveals that it is fraudulent.

The most obvious warning sign is the sender’s email address. Although the sender’s name appears as “AMIT SHARMA”, the email actually originates from —-@yahoo.co.jp, which is a free Yahoo email account using a Japanese domain. The Income Tax Department or any other Government of India department does not issue statutory notices through free email services such as Yahoo, Gmail, Outlook, or Rediffmail. Genuine communications are generally sent through official government domains such as @incometax.gov.in, @gov.in, or @nic.in. The use of a free email service is by itself a strong indication that the communication is fraudulent.

Scam Alert - Fake Income Tax Email (1)

Another significant red flag is the subject line itself. Fraudsters intentionally use intimidating words such as “Tax Audit,” “Penalty,” “Final Notice,” “Verification,” “Compliance Failure,” or “Outstanding Demand” along with long reference numbers to create fear and compel recipients to act without verifying the authenticity of the communication. Genuine government notices generally contain proper document identification numbers, statutory references, assessment years, and taxpayer-specific details rather than vague and sensational subject lines designed to induce panic.

The email also lacks any personal identification details that would ordinarily be found in an authentic tax notice. A genuine Income Tax communication normally contains the taxpayer’s name, PAN, assessment year, document identification number (DIN), relevant statutory provisions, jurisdictional details, and a clear description of the proceedings. In contrast, the fraudulent email merely asks the recipient to “Please see attachment” without providing any meaningful information about the alleged tax issue.

The attached PDF is another cause for concern. Cybercriminals increasingly use PDF files because recipients generally perceive them as safe. However, such PDF files often contain embedded phishing links directing users to fake government websites, malicious QR codes, instructions to download Android APK files, or requests to verify PAN, Aadhaar, bank account details, or other confidential information. In many cases, merely opening the PDF may expose the user to phishing attempts, while clicking links within the document can lead to credential theft or malware installation.

This is not an isolated incident. Similar phishing campaigns have become increasingly common over the past several months. Fraudsters frequently send fake Income Tax refund emails claiming that a refund has been approved or is pending and asking taxpayers to update their bank account details through fraudulent websites. Others send fake tax demand notices threatening immediate recovery proceedings, penalties, interest, attachment of bank accounts, or prosecution unless payment is made immediately through suspicious payment links.

Businesses are also being targeted through fake GST communications. Many companies have reported receiving emails alleging cancellation or suspension of GST registration, GST audits, inspections, or discrepancies in returns. These messages typically instruct recipients to download attached notices or submit replies through fake portals designed to steal login credentials or distribute malware.

WhatsApp has emerged as another preferred medium for tax-related frauds. Users increasingly receive messages claiming that their PAN has been blocked, GST registration has been cancelled, Income Tax refunds are pending, TDS defaults have been detected, Annual Information Statement (AIS) mismatches have been identified, or GST inspections have been scheduled. Such messages often include shortened URLs or unknown websites that closely resemble official government portals. Clicking these links may result in phishing attacks or installation of malicious software.

Fraudsters have also expanded their activities beyond tax notices. Many individuals have reported receiving fake MCA compliance notices alleging director disqualification, company strike-off, ROC penalties, or DIN deactivation. Similarly, fake customs and courier messages falsely claim that imported parcels have been detained and require payment of customs duty or completion of KYC formalities. Another dangerous trend is the rise of so-called “digital arrest” scams, where fraudsters impersonate officials from the Income Tax Department, Enforcement Directorate, CBI, Customs, RBI, or local police, falsely accusing victims of money laundering, tax evasion, or other offences and coercing them into transferring money under the guise of an investigation.

One common feature across these scams is the use of fake websites. Fraudsters frequently register deceptive domain names using extensions such as .site, .top, .online, .store, or .vip, and design them to resemble official government portals. Some domains differ from genuine government websites by only a single letter, making them difficult to distinguish at first glance. These websites are often used to harvest login credentials, banking information, Aadhaar details, or one-time passwords.

The safest approach is to independently verify every tax-related communication before taking any action. Taxpayers should never rely solely on an email, WhatsApp message, or SMS. Any Income Tax notice should be verified by logging into the official Income Tax e-Filing portal using the taxpayer’s own account. GST-related communications should be checked directly on the GST portal, while company law matters should be verified through the MCA portal. If there is any uncertainty, taxpayers should consult their Chartered Accountant or tax advisor before responding.

Equally important is understanding what should never be done when receiving such communications. Recipients should avoid opening suspicious attachments, clicking unknown links, downloading APK files, sharing passwords or one-time passwords, entering PAN or Aadhaar details on unfamiliar websites, or making payments through links received via email or WhatsApp. Businesses should educate employees about phishing attacks, enable multi-factor authentication on email and tax portals, maintain updated antivirus software, and regularly back up important financial records.

If a suspicious email or WhatsApp message is received, the recipient should remain calm, avoid interacting with the sender, and delete the communication after verification. If any link has already been clicked or confidential information has been disclosed, passwords should be changed immediately, banks should be informed if financial information was shared, and the incident should be reported through the National Cyber Crime Reporting Portal or by calling the Cyber Crime Helpline (1930).

Cybercriminals continue to refine their techniques by exploiting taxpayers’ fear of audits, penalties, investigations, and regulatory action. Whether the communication claims to be an Income Tax audit notice, GST cancellation order, MCA compliance alert, refund intimation, customs notice, or penalty demand, the underlying objective remains the same—to steal information or money. Vigilance, verification through official government portals, and professional advice before acting on any unsolicited communication remain the most effective safeguards against these increasingly sophisticated scams.

Tags:

Join Taxguru’s Network for Latest updates on Income Tax, GST, Company Law, Corporate Laws and other related subjects.

Leave a Comment

Your email address will not be published. Required fields are marked *

Search Post by Date
July 2026
M T W T F S S
 12345
6789101112
13141516171819
20212223242526
2728293031