{"id":3840,"date":"2011-01-28T07:01:11","date_gmt":"2011-01-28T14:01:11","guid":{"rendered":"http:\/\/blog.webroot.com\/?p=3840"},"modified":"2018-01-30T13:17:03","modified_gmt":"2018-01-30T20:17:03","slug":"tips-to-avoid-tax-season-scams","status":"publish","type":"post","link":"https://www.webroot.com/blog/2011\/01\/28\/tips-to-avoid-tax-season-scams\/","title":{"rendered":"Tips to Avoid Tax Season Scams"},"content":{"rendered":"<p><strong>By Jeff Horne<\/strong>, <em>Director, Threat Research<\/em><\/p>\n<p class=\"getsocial\" style=\"text-align:left;\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2005.png\" alt=\"\" \/><a title=\"Add to Facebook\" rel=\"nofollow\" href=\"http:\/\/www.facebook.com\/sharer.php?u=http:\/\/blog.webroot.com\/2011\/01\/28\/tips-to-avoid-tax-season-scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2015.png\" alt=\"Add to Facebook\" \/><\/a><a title=\"Add to Digg\" rel=\"nofollow\" href=\"http:\/\/digg.com\/submit?phase=2&amp;url=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;title=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2025.png\" alt=\"Add to Digg\" \/><\/a><a title=\"Add to Del.icio.us\" rel=\"nofollow\" href=\"http:\/\/del.icio.us\/post?url=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;title=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2035.png\" alt=\"Add to Del.icio.us\" \/><\/a><a title=\"Add to Stumbleupon\" rel=\"nofollow\" href=\"http:\/\/www.stumbleupon.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;title=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2045.png\" alt=\"Add to Stumbleupon\" \/><\/a><a title=\"Add to Reddit\" rel=\"nofollow\" href=\"http:\/\/reddit.com\/submit?url=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;title=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2055.png\" alt=\"Add to Reddit\" \/><\/a><a title=\"Add to Blinklist\" rel=\"nofollow\" href=\"http:\/\/www.blinklist.com\/index.php?Action=Blink\/addblink.php&amp;Description=&amp;Url=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;Title=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2065.png\" alt=\"Add to Blinklist\" \/><\/a><a title=\"Add to Twitter\" rel=\"nofollow\" href=\"http:\/\/twitter.com\/home\/?status=Tips%20to%20Avoid%20Tax%20Season%20Scams+%40+http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2075.png\" alt=\"Add to Twitter\" \/><\/a><a title=\"Add to Technorati\" rel=\"nofollow\" href=\"http:\/\/www.technorati.com\/faves?add=http:\/\/blog.webroot.com\/2011\/01\/28\/tips-to-avoid-tax-season-scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2085.png\" alt=\"Add to Technorati\" \/><\/a><a title=\"Add to Yahoo Buzz\" rel=\"nofollow\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;headline=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2095.png\" alt=\"Add to Yahoo Buzz\" \/><\/a><a title=\"Add to Newsvine\" rel=\"nofollow\" href=\"http:\/\/www.newsvine.com\/_wine\/save?u=http%3A%2F%2Fblog.webroot.com%2F2011%2F01%2F28%2Ftips-to-avoid-tax-season-scams&amp;h=Tips%20to%20Avoid%20Tax%20Season%20Scams\" target=\"_blank\"><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2105.png\" alt=\"Add to Newsvine\" \/><\/a><img decoding=\"async\" style=\"border:0;margin:0;padding:0;\" src=\"http:\/\/getsocialserver.files.wordpress.com\/2009\/08\/gs2115.png\" alt=\"\" \/><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irspage2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignleft size-full wp-image-3842\" title=\"20110126_taxtips_IRSpage2_crop\" src=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irspage2_crop.png\" alt=\"\" width=\"282\" height=\"212\" \/><\/a>As tax season rolls around again in the US and UK, it seems like a good time to <a href=\"http:\/\/blog.webroot.com\/2010\/04\/06\/8-tips-for-filing-taxes-online-safely\/\" target=\"_blank\">revisit the perils<\/a> taxpayers face seemingly every year at around this time.<\/p>\n<p>Phishing attacks against taxpayers are already in full swing &#8212; not that they haven&#8217;t been going continuously since last year. But this is high season for scams involving Web pages that look like the IRS or HMRC&#8217;s own Web site.<\/p>\n<p>Scam messages typically contain dire warnings or outrageously large promises for a refund. The messages often are presented as if they originate from a tax authority, but contain links leading to phishing Web pages, or malicious attached files.<\/p>\n<p>These scam pages typically appear to look exactly like a page on the real IRS or HMRC Web site. If you receive such a message, don&#8217;t reply to the sender, don&#8217;t email any sensitive information, and don&#8217;t follow any link in the message.<\/p>\n<p>The pages <em>promise <\/em>to automatically transfer a tax refund to the recipient&#8217;s bank account, if you only would provide the scam artist with your complete banking, credit card, and personal details.<\/p>\n<p><!--more--><\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_wrongurl.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3844\" title=\"20110126_taxtips_wrongurl\" src=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_wrongurl.png\" alt=\"\" width=\"493\" height=\"108\" \/><\/a><\/p>\n<p>Most of these fake Web pages <em>don&#8217;t <\/em>have <strong><a href=\"http:\/\/www.hmrc.gov.uk\" target=\"_blank\">www.hmrc.gov.uk<\/a><\/strong> or <strong><a href=\"http:\/\/www.irs.gov\" target=\"_blank\">www.irs.gov<\/a> immediately after the http:\/\/<\/strong> in the URL&#8212;though many may include (in the American example) <em>www.irs.gov<\/em> somewhere else in the URL, as shown above. Not sure if the site you&#8217;re looking at is real? Try typing the URL into the Address Bar yourself.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irsurl-good_text.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3845\" title=\"20110126_taxtips_IRSURL-good_text\" src=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irsurl-good_text.png\" alt=\"\" width=\"247\" height=\"112\" \/><\/a><\/p>\n<p>Government tax collection agencies don\u2019t contact taxpayers by email to let them know they&#8217;ve received a refund, and they already know where to send the money if you&#8217;ve chosen to e-file and asked them to electronically deposit your refund. They certainly don&#8217;t need to know your debit card&#8217;s PIN code, just to pick one dangerous piece of information typically requested in a bogus &#8220;refund form.&#8221;<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irspage2-2.png\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3848\" title=\"20110126_taxtips_IRSpage2.2_crop\" src=\"http:\/\/webrootblog.files.wordpress.com\/2011\/01\/20110126_taxtips_irspage2-2_crop.png\" alt=\"\" width=\"360\" height=\"244\" \/><\/a><\/p>\n<p>And if you haven&#8217;t yet filed your taxes, but receive a &#8220;refund notification&#8221; email from the IRS (if you\u2019re in the States), or the HMRC (if you\u2019re in the UK), <a href=\"http:\/\/blog.webroot.com\/2009\/10\/14\/irs-tax-warning-fraud-crosses-the-pond\/\">it is most likely a scam<\/a>.<\/p>\n<p>We&#8217;ve also seen numerous spam emails over the past year that claim to originate with various tax authorities which contain dangerous file attachments. If you receive a message, purportedly from the IRS (<a href=\"http:\/\/blog.webroot.com\/2009\/11\/12\/phishing-scheme-targets-e-payment-processor-nacha\/\" target=\"_blank\">or some other government agency<\/a>), which has a file attached, don&#8217;t open the attachment. Over the past year, we&#8217;ve also seen numerous spam emails that <a href=\"http:\/\/blog.webroot.com\/2010\/02\/10\/tax-themed-phishing-scams-cross-more-national-borders\/\" target=\"_blank\">claim to originate with various tax authorities<\/a> which contain dangerous file attachments. If you receive a message, purportedly from the IRS (or any other government agency), which has a file attached, don&#8217;t open the attachment.<\/p>\n<p><a href=\"http:\/\/webrootblog.files.wordpress.com\/2010\/04\/20091026_fdic_spam.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-2513\" title=\"20091026_fdic_spam_crop\" src=\"http:\/\/webrootblog.files.wordpress.com\/2010\/04\/20091026_fdic_spam_crop.jpg\" alt=\"\" width=\"332\" height=\"83\" \/><\/a><\/p>\n<p>Always download the latest updates to Windows, as well as any non-Microsoft applications (such as <a href=\"http:\/\/get.adobe.com\/reader\/\" target=\"_blank\">Adobe Reader<\/a>, <a href=\"http:\/\/www.foxitsoftware.com\/pdf\/reader\/reader4.php\" target=\"_blank\">Foxit Reader<\/a>, or whatever application you use to read .PDF documents). These updates can help prevent infections that take advantage of security vulnerabilities in those products.<\/p>\n<p>When it comes to preparing and collecting the information you need to file your taxes, you should always start the same way: Perform a full scan of the computer with an up-to-date antivirus program. Do this <strong>before <\/strong>you log into your bank account or any other Web site that may hold your private financial data, including your online tax filing service, if you use one.<\/p>\n<p>Remember that Web browsers <em>sometimes <\/em>transmit information insecurely, and that a nefarious user can sniff that information if you use an open, unencrypted wireless Internet connection, whether you happen to be in public (such as in a coffee house), or in your living room. If you plan to file your taxes online, or work with any Web site that holds your sensitive financial information, don&#8217;t use an open wireless connection to do it.<\/p>\n<p>Surfing the Web to find tax information is also risky, especially if you use search engines. Poisoned search results may inadvertently lead you to dangerous sites. Instead, go directly to <strong>www.irs.gov<\/strong> or <strong>www.hmrc.gov.uk<\/strong> to download your tax forms or retrieve information. For state taxes, go directly to your state&#8217;s Web site and search there. (<a href=\"http:\/\/us.gov\/Agencies\/State_and_Territories.shtml\" target=\"_blank\">Click here<\/a> for a list of all US state Web sites).<\/p>\n<p>I&#8217;d also recommend that you use a browser other than Internet Explorer to file taxes. If you use Firefox, consider installing the <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/noscript\/\" target=\"_blank\">NoScript<\/a>, <a href=\"https:\/\/addons.mozilla.org\/en-US\/firefox\/addon\/adblock-plus\/\" target=\"_blank\">AdBlock Plus<\/a>, and the <a href=\"https:\/\/www.eff.org\/https-everywhere\" target=\"_blank\">HTTPS Anywhere<\/a> add-ons, which, in combination, capably prevent most Web-borne threats from causing infections, and protect your logins from sniffing.<\/p>\n<p>Finally, when you&#8217;ve finished filing your taxes, collect your forms and tax return documents and burn them to a CD or DVD, which you file in a folder somewhere. Delete the tax record documents and returns from your computer&#8217;s hard drive (preferably using a utility that can perform a secure wipe of the data), and clear the browser&#8217;s cache using the browser&#8217;s own privacy settings. <a title=\"wordpress blog stats\" href=\"http:\/\/www.statcounter.com\/wordpress.com\/\" target=\"_blank\"><img decoding=\"async\" src=\"http:\/\/c.statcounter.com\/4868061\/0\/92d716bc\/1\/\" alt=\"wordpress blog stats\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>By Jeff Horne, Director, Threat Research As tax season rolls around again in the US and UK, it seems like a good time to revisit the perils taxpayers face seemingly every year at around this time. Phishing attacks against taxpayers are already in full swing &#8212; not that they haven&#8217;t been going continuously since last [&hellip;]<\/p>\n","protected":false},"author":65,"featured_media":17052,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3005],"tags":[],"yst_prominent_words":[8367,8345,8361,8363,8347,8357,8373,8369,8349,8341,8365,8371,8351,8355,8343,8353,6531,8359,6965,4621],"acf":[],"_links":{"self":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3840"}],"collection":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/users\/65"}],"replies":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/comments?post=3840"}],"version-history":[{"count":1,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3840\/revisions"}],"predecessor-version":[{"id":23911,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/posts\/3840\/revisions\/23911"}],"wp:featuredmedia":[{"embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media\/17052"}],"wp:attachment":[{"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/media?parent=3840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/categories?post=3840"},{"taxonomy":"post_tag","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/tags?post=3840"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https://www.webroot.com/blog/wp-json\/wp\/v2\/yst_prominent_words?post=3840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}