By:
CA Anil K. Jain
Chartered Accountant | Economist | Policy Researcher | Author
President – Ahimsa Foundation India
Email: CAINDIA@HOTMAIL.COM
Chapter Synopsis
This chapter examines cyber frauds targeting India's
digital tax ecosystem, where the digitisation of income tax processes has
created new vulnerabilities for criminals. The Permanent Account Number (PAN)
and Aadhaar now serve as universal keys to tax infrastructure, making them
prime targets for identity theft and financial fraud.
The chapter identifies six major fraud patterns. Phishing
emails and SMS promise tax refunds, directing victims to fake portals that
harvest PAN, bank details, and card information. Fake ITR filing websites mimic
the official e-filing portal, collecting sensitive data while charging
fraudulent filing fees. Malicious mobile apps, exemplified by the Drinik
trojan, request excessive permissions to capture credentials, OTPs, and
personal data from over 100,000 devices. Fake income tax notices exploit
taxpayer fear, demanding immediate payment of non-existent penalties or
directing victims to malware-laden links. PAN card related frauds involve
identity theft for fraudulent refund claims or loan applications. Tech
support scams impersonate tax officials, using remote access apps to drain
bank accounts.
The legal framework combines the Information
Technology Act (Sections 66C, 66D, 66, 43), the Bharatiya Nyaya Sanhita
(sections on cheating, forgery, and theft), and the Income Tax Act (Section
277A). Reporting requires immediate action through 1930, cybercrime.gov.in, bank notification,
and CERT-In reporting.
Prevention centers on
taxpayer awareness: the Income Tax Department never requests passwords, OTPs,
or CVV; verify all communications through the official portal (incometax.gov.in); bookmark the genuine website; and avoid downloading apps from
unsolicited links. The chapter concludes that while legal remedies exist,
digital literacy is the ultimate defense against fraudsters who weaponise
taxpayer trust and fear of state authority.
1.
Introduction
The
Income Tax Department of India has undergone a quiet digital revolution. The
days of standing in serpentine queues to file paper returns, of manually
depositing challans in designated banks, and of waiting months for a refund
cheque to arrive by post are fading into memory. Today, a taxpayer can file
returns, claim refunds, respond to notices, and even appeal assessments
entirely online through the official e-filing portal (incometax.gov.in). The
Permanent Account Number (PAN) and Aadhaar have become the universal keys to
this digital tax infrastructure, linking every financial transaction—salary,
investment, property purchase, foreign remittance—to a single verifiable
identity.
This
digital transformation, while enormously convenient, has opened a new front for
cyber criminals. The tax system touches every earning citizen, making it a
universal target. The promise of a tax refund is a powerful lure, and the fear
of an income tax notice is a potent weapon of intimidation. Fraudsters exploit
both. They send phishing emails announcing bogus refunds, create fake filing
portals that harvest sensitive personal and financial data, distribute
malware-laced mobile apps disguised as official tax tools, and issue
counterfeit tax demands that terrify victims into paying non-existent
penalties. The sums involved are substantial; the information harvested—PAN,
Aadhaar, bank account details, income history—is a goldmine for identity theft
and downstream financial fraud.
This
chapter explains the most common forms of income tax related cyber frauds in
India, illustrated with real-world cases. It outlines the legal framework that
criminalises these acts and provides practical guidance on recognising,
reporting, and preventing such frauds.
Quotation:
“The Income Tax Department will never ask for your PIN, password, or OTP. If an
email or SMS asks for these, it is a fraud. The taxpayer’s first defence is
this simple rule.” — Central Board of Direct Taxes, Public Advisory, 2023.
2.
Common Types of Income Tax Cyber Frauds
Income
tax cyber frauds fall into distinct patterns, each exploiting a specific aspect
of the tax system. Understanding these patterns is the key to avoiding them.
A. Phishing Emails and SMS Claiming Tax Refunds: This is by far the most prevalent income tax fraud. The fraudster sends an email or SMS that appears to come from the Income Tax Department, informing the recipient that he or she is eligible for a substantial tax refund. The message looks official: it bears the logo of the Income Tax Department, the national emblem, and sometimes even a forged signature of a tax official. The message contains a link to claim the refund.
i.
Modus Operandi:
a) The
link directs the victim to a fake website that mimics the official e-filing
portal. The domain name may be something like “incometaxrefund.in” or
“itaxindia.gov.in”—close enough
to the genuine “incometax.gov.in” to
deceive a casual observer.
b) The
fake website asks the victim to enter PAN, Aadhaar number, bank account
details, and credit or debit card information, ostensibly to “verify” the
refund credit.
c) Once
the details are submitted, the fraudster uses them to access the victim’s
actual bank account through net banking or to make fraudulent transactions.
·
Example: In 2023, a pan-India
phishing campaign sent SMS messages reading: “Dear taxpayer, your income tax
refund of Rs. 15,490 has been approved. Click here to credit to your bank
account: [link].” The link led to a fake portal that harvested PAN and bank
details. Thousands of taxpayers in Maharashtra, Gujarat, and Rajasthan fell
victim. The Indian Cyber Crime Coordination Centre (I4C) traced the domain to a
server in Russia and coordinated a takedown with CERT-In.
B.
Fake Income Tax Return (ITR) Filing Websites: During
the tax filing season (typically July to December), fraudsters set up websites
that look exactly like the official e-filing portal. They often use search
engine optimisation (SEO) techniques to ensure that their fake portal appears
prominently in search results when a taxpayer types “file ITR online.”
i.
Modus Operandi:
a) The
taxpayer lands on the fake portal and begins the filing process, entering PAN,
Aadhaar, income details, and bank account information.
b) The
portal may even generate a fake acknowledgment (ITR-V), giving the taxpayer a
false sense of completion.
c) The
data entered is sold on the dark web or used for identity theft and financial
fraud. In some cases, the fraudster also charges a “filing fee” that is
pocketed.
·
Example: In 2022, the Delhi Police
Cyber Cell busted a racket that operated over 15 fake ITR filing websites. The
portals, with names like “easyincometaxfiling.com” and
“quickitr.in,” had
processed over 50,000 fake filings during the tax season, collecting PAN and
bank details that were later used for loan frauds. The gang had earned over
₹1.2 crore in fraudulent filing fees.
C.
Malicious Mobile Apps (The Drinik Trojan): One of the most
dangerous income tax fraud campaigns in India involved a banking trojan
named Drinik, which evolved from a simple SMS phishing tool into a
full-fledged malware targeting Indian taxpayers.
i.
Modus Operandi:
a) The
victim receives an SMS or WhatsApp message, purportedly from the Income Tax
Department, stating that a refund has been calculated and that the taxpayer
must download a specific app to receive it.
b) The
app, named something like “Income Tax Refund” or “ITR Refund App,” is hosted on
a third-party website, not the official app store.
c) Once
installed, the app requests permissions—accessibility services, SMS access—that
appear necessary for the refund process.
d) In
reality, the malware reads every on-screen text (capturing passwords and PINs),
intercepts all SMS messages (capturing OTPs), and exfiltrates the victim’s
contact list, PAN, Aadhaar, and bank details to a remote server controlled by
the fraudsters.
e) The
fraudsters then use the harvested data to log into the victim’s net banking,
drain the account, or sell the identity data on the dark web.
·
Example: The Drinik campaign, first
detected in 2021 and peaking in 2022, infected over 100,000 Android devices
across India. The I4C estimated cumulative losses exceeding ₹25 crore. The
malware was regularly updated to evade detection, and the command-and-control
servers were located in Eastern Europe. CERT-In issued multiple advisories, and
Google Play Protect was updated to block the malware.
D.
Fake Income Tax Notices (Intimidation Fraud): Fraudsters
exploit the fear that the words “Income Tax Department” can evoke. They send
fake tax notices via email or SMS, alleging discrepancies in the taxpayer’s
return, demanding immediate payment of a penalty, or threatening prosecution,
arrest, and attachment of property.
i.
Modus Operandi:
a) The
fake notice is often designed to mimic the format of genuine departmental
communications—Section 143(1) intimation, Section 148 reassessment notice, or a
demand under Section 156.
b) The
notice may contain a forged document number, the name of a real tax officer,
and a demand for payment into a specified bank account. The fraudster uses the
fear of legal consequences to override the victim’s critical thinking.
c) The
communication may demand payment of a “penalty” via UPI or bank transfer.
Alternatively, it may ask the victim to click a link to “view the notice,”
which then installs malware.
·
Example: In 2021, a senior citizen in
Chennai received an email with the subject line “Notice under Section 148 –
Reopening of Assessment.” The email, bearing the Income Tax Department logo,
accused him of under-reporting capital gains and demanded a penalty of ₹2.5
lakh to be paid within 24 hours to avoid prosecution. The man, terrified,
transferred the money. When he later consulted a chartered accountant, he
discovered the notice was fake. The cyber cell traced the bank account to a
mule account in Jharkhand.
E.
PAN Card Related Frauds: The PAN card is the most widely used
identity document in India’s financial system. A fraudster who obtains a
victim’s PAN can open bank accounts, apply for credit cards, secure loans, and
file fraudulent tax returns in the victim’s name.
i.
PAN Misuse for Fake ITR
Filing: Fraudsters use stolen PAN and Aadhaar details to file fake income
tax returns, claiming fraudulent refunds. The genuine taxpayer discovers the
fraud only when his or her own return is rejected for “duplicate filing,” or
when a tax demand arrives for income he or she never earned.
ii.
Phishing for PAN Details: Fake
websites and apps offering “instant PAN card generation” or “PAN correction
services” harvest the applicant’s identity documents and biometric data.
iii.
Mutable Case Example: In 2023, a
Bengaluru-based IT professional discovered that a tax return had been filed in
his name by an unknown person, claiming a refund of ₹34,000. The refund had
already been credited to a bank account opened with his PAN and a forged
address proof. The bank account was traced to a mule network in Rajasthan. The
case is under investigation by the Income Tax Department and the local cyber
cell.
F.
Tech Support Scams Impersonating the Income Tax Department: A
variation of the tech support scam involves fraudsters calling taxpayers,
posing as IT department officials, and offering “help” with e-filing, refunds,
or resolving a notice. The caller instructs the victim to download a remote
access application such as AnyDesk or TeamViewer, ostensibly for technical
support. Once the application is installed and the access code is shared, the
fraudster takes control of the victim’s computer or phone, accesses internet
banking, and transfers funds.
Quotation:
“The Income Tax Department communicates primarily through the e-filing portal
and registered email. Any unsolicited phone call, SMS with a link, or demand
for immediate payment is almost certainly a fraud. The taxpayer must learn to
trust the official channel and verify before acting.” — Dr. Sanjay Bahl,
Director General, CERT-In, in a 2023 public awareness video.
3.
Legal Framework
Income
tax cyber frauds attract prosecution under a combination of the Information
Technology Act, 2000, the Indian Penal Code / Bharatiya Nyaya Sanhita, 2023,
and the Income Tax Act, 1961.
A. Information
Technology Act, 2000:
i.
Section 66C (Identity
Theft): Fraudulent use of another person’s PAN, Aadhaar, digital
signature, or password. Punishment: imprisonment up to three years and fine up
to ₹1 lakh.
ii.
Section 66D (Cheating by
Personation): Impersonating the Income Tax Department, a tax official, or
any other person through a computer or communication device. Punishment:
imprisonment up to three years and fine up to ₹1 lakh.
iii.
Section 66 (Hacking): Unauthorised
access to a computer system with dishonest or fraudulent intent, applicable to
malware like Drinik that captures credentials. Punishment: imprisonment up to
three years and fine up to ₹5 lakh.
iv.
Section 43 (Civil Liability): The
affected person can claim damages for unauthorised access, data theft, or
introduction of malware.
B. Bharatiya
Nyaya Sanhita, 2023 / Indian Penal Code:
i.
Section 318 BNS (Section 420
IPC): Cheating and dishonestly inducing the delivery of property. The
fraudster induces the victim to pay a fake penalty or to part with money on the
pretext of a refund.
ii.
Section 319 BNS (Section 419
IPC): Cheating by personation.
iii.
Sections 336–340 BNS (Forgery, old
Sections 463–471 IPC): Making or using forged electronic documents, such
as fake tax notices bearing forged signatures of tax officials.
iv.
Section 303 BNS (Theft, old Section 379
IPC): Where data is “property” and is stolen—for example, the harvesting
of a PAN database by a fake ITR portal.
C. Income
Tax Act, 1961:
i.
Section 277A: Punishes the
falsification of books of account or documents, which could extend to
fabricated digital ITR filings and fake refund claims.
ii.
The Act does not specifically address
phishing against taxpayers, but the fraudulent claiming of refunds using stolen
identities can be prosecuted under the general anti-evasion and fraud
provisions.
D. Regulatory
and Institutional Mechanisms:
i.
The Central Board of Direct Taxes
(CBDT) regularly issues advisories warning taxpayers against phishing
emails and fake websites.
ii.
The Indian Cyber Crime Coordination
Centre (I4C) and the National Cyber Crime Reporting Portal (cybercrime.gov.in) are
the primary platforms for reporting.
iii.
The CERT-In Directions, 2022, mandate
that all cyber incidents, including phishing campaigns targeting taxpayers, be
reported within six hours.
Quotation:
“The legal tools exist to punish income tax cyber frauds. The challenge is the
speed and volume of these crimes. For every fake portal taken down, two more
appear. The long-term solution is not just prosecution, but a digitally
literate taxpayer base that does not fall for the bait.” — Dr. Karnika Seth,
Cyber Law Expert, in a 2023 commentary.
4.
Reporting and Redressal: A taxpayer who has fallen victim to
an income tax cyber fraud must act quickly to minimise damage and enable law
enforcement to freeze the fraudster’s accounts.
A. Step
1: Report to the Income Tax Department.
i.
Send an email to the Income Tax Department
at webmanager@incometax.gov.in with full details of the fraudulent
communication, including screenshots, headers, and the sender’s email ID or
phone number.
ii.
File a complaint on the e-filing portal (incometax.gov.in) under
the “Grievance” section.
iii.
If your PAN has been misused, apply for a
rectification and flag the fraudulent return or account.
B. Step
2: Report to Cyber Crime Authorities.
i.
Call the national cyber crime
helpline 1930 immediately if a financial loss has occurred. The
operator will attempt to freeze the beneficiary account.
ii.
File a formal complaint on cybercrime.gov.in.
Upload screenshots of the fraudulent message, the transaction receipt, and any
communication with the fraudster.
iii.
Register an FIR at the local police
station, citing the relevant sections of the IT Act and BNS/IPC.
C. Step
3: Inform Your Bank.
i.
If you have shared bank details or if an
unauthorised transaction has occurred, call your bank’s fraud helpline, block
the account, and request a chargeback where applicable.
D. Step
4: Report to CERT-In.
i.
CERT-In accepts reports of phishing
websites and malicious apps at incident@cert-in.org.in. Reporting helps in
the early takedown of fraudulent infrastructure.
5.
Prevention: A Taxpayer’s Guide
The
best defence against income tax cyber frauds is a healthy scepticism and a few
simple habits:
·
Bookmark the official portal. The
genuine Income Tax e-filing website is https://www.incometax.gov.in.
Always type the URL directly or use a bookmarked link. Never navigate to the
portal through an email link, an SMS link, or a search engine advertisement.
·
Remember: The IT Department never asks for
sensitive details. No genuine communication from the Income Tax Department
will ask for your net banking password, UPI PIN, credit card CVV, or OTP. Any
such request is a fraud.
·
Verify notices through the portal. If
you receive an email or SMS about a tax demand, a refund, or a notice, log into
the official e-filing portal independently to verify. All genuine
communications are reflected in the “Worklist” or “My Account” section.
·
Do not download apps from links in
messages. Install official tax-related apps only from the Google Play
Store or Apple App Store, and only those published by the Income Tax Department
or authorised agencies.
·
Check the sender’s email
address. Genuine emails from the Income Tax Department come from addresses
ending in @incometax.gov.in.
Fraudulent emails often use addresses
like incometax@gmail.com, itax.refund@yahoo.com, or similar. Be
particularly suspicious of generic email domains.
·
Do not panic. Fake notices rely on
fear and urgency. Take a moment to breathe, consult a tax professional or the
department’s helpline, and verify before taking any action.
·
Protect your PAN. Do not share your
PAN casually. Be cautious when providing it to employers, financial
institutions, or online platforms, and ensure they have a legitimate need for
it.
Conclusion
Income
tax cyber frauds are crimes of deception that weaponise the taxpayer’s trust in
the state and his or her fear of its coercive power. They range from the crude
SMS promising an improbable refund to the sophisticated malware campaign that
silently harvests every keystroke. The common element is the impersonation of
the tax authority—an institution whose communications carry weight and urgency.
The legal framework provides for prosecution and, in some cases, restitution,
but prevention is overwhelmingly more effective than cure.
The
digitisation of the tax system is an irreversible and welcome transformation.
It has increased transparency, reduced corruption, and made compliance easier
for millions. But it also demands a digitally literate citizenry. A taxpayer
who knows the official portal, who reads emails with a sceptical eye, who
pauses before clicking a link, and who verifies every demand through official
channels is a hard target. Building that digital literacy, across every income
bracket and every age group, is the long-term project that will ultimately
secure India’s tax ecosystem against the predators of the digital age.
Quotation: “The Income Tax Department serves the nation by collecting revenue for development. Taxpayers serve the nation by paying their dues honestly. Cyber fraudsters who exploit this sacred relationship are committing not just a crime against an individual, but a crime against the state itself.” — N.S. Nappinai, Advocate, Supreme Court, in a 2024 article on tax frauds.
Chapter References
1.
Information Technology Act, 2000, Sections
43, 66, 66C, 66D.
2.
Bharatiya Nyaya Sanhita, 2023, Sections
303, 318, 319, 336–340.
3.
Income Tax Act, 1961, Section 277A.
4.
Central Board of Direct Taxes, Public
Advisory on Phishing Emails and Fake Websites, 2023.
5.
CERT-In, Advisory on Drinik
Banking Trojan Targeting Taxpayers, 2022.
6.
I4C, Report on Income Tax Related
Cyber Frauds, 2023.
7.
Delhi Police Cyber Cell, Investigation
Report on Fake ITR Filing Websites, 2022.
8.
National Cyber Crime Reporting
Portal, Guidelines for Victims of Tax Fraud, 2023.
9.
Income Tax Department, E-Filing
Portal Security Guidelines, 2023.
No comments:
Post a Comment