Income Tax Related Cyber Frauds

By: CA  Anil K. Jain 
Chartered Accountant | Economist | Policy Researcher | Author
President – Ahimsa Foundation India
Email:
CAINDIA@HOTMAIL.COM

Chapter Synopsis

This chapter examines cyber frauds targeting India's digital tax ecosystem, where the digitisation of income tax processes has created new vulnerabilities for criminals. The Permanent Account Number (PAN) and Aadhaar now serve as universal keys to tax infrastructure, making them prime targets for identity theft and financial fraud.

The chapter identifies six major fraud patterns. Phishing emails and SMS promise tax refunds, directing victims to fake portals that harvest PAN, bank details, and card information. Fake ITR filing websites mimic the official e-filing portal, collecting sensitive data while charging fraudulent filing fees. Malicious mobile apps, exemplified by the Drinik trojan, request excessive permissions to capture credentials, OTPs, and personal data from over 100,000 devices. Fake income tax notices exploit taxpayer fear, demanding immediate payment of non-existent penalties or directing victims to malware-laden links. PAN card related frauds involve identity theft for fraudulent refund claims or loan applications. Tech support scams impersonate tax officials, using remote access apps to drain bank accounts.

The legal framework combines the Information Technology Act (Sections 66C, 66D, 66, 43), the Bharatiya Nyaya Sanhita (sections on cheating, forgery, and theft), and the Income Tax Act (Section 277A). Reporting requires immediate action through 1930, cybercrime.gov.in, bank notification, and CERT-In reporting.

Prevention centers on taxpayer awareness: the Income Tax Department never requests passwords, OTPs, or CVV; verify all communications through the official portal (incometax.gov.in); bookmark the genuine website; and avoid downloading apps from unsolicited links. The chapter concludes that while legal remedies exist, digital literacy is the ultimate defense against fraudsters who weaponise taxpayer trust and fear of state authority.

1. Introduction

The Income Tax Department of India has undergone a quiet digital revolution. The days of standing in serpentine queues to file paper returns, of manually depositing challans in designated banks, and of waiting months for a refund cheque to arrive by post are fading into memory. Today, a taxpayer can file returns, claim refunds, respond to notices, and even appeal assessments entirely online through the official e-filing portal (incometax.gov.in). The Permanent Account Number (PAN) and Aadhaar have become the universal keys to this digital tax infrastructure, linking every financial transaction—salary, investment, property purchase, foreign remittance—to a single verifiable identity.

This digital transformation, while enormously convenient, has opened a new front for cyber criminals. The tax system touches every earning citizen, making it a universal target. The promise of a tax refund is a powerful lure, and the fear of an income tax notice is a potent weapon of intimidation. Fraudsters exploit both. They send phishing emails announcing bogus refunds, create fake filing portals that harvest sensitive personal and financial data, distribute malware-laced mobile apps disguised as official tax tools, and issue counterfeit tax demands that terrify victims into paying non-existent penalties. The sums involved are substantial; the information harvested—PAN, Aadhaar, bank account details, income history—is a goldmine for identity theft and downstream financial fraud.

This chapter explains the most common forms of income tax related cyber frauds in India, illustrated with real-world cases. It outlines the legal framework that criminalises these acts and provides practical guidance on recognising, reporting, and preventing such frauds.

Quotation: “The Income Tax Department will never ask for your PIN, password, or OTP. If an email or SMS asks for these, it is a fraud. The taxpayer’s first defence is this simple rule.” — Central Board of Direct Taxes, Public Advisory, 2023.

2. Common Types of Income Tax Cyber Frauds

Income tax cyber frauds fall into distinct patterns, each exploiting a specific aspect of the tax system. Understanding these patterns is the key to avoiding them.

A. Phishing Emails and SMS Claiming Tax Refunds: This is by far the most prevalent income tax fraud. The fraudster sends an email or SMS that appears to come from the Income Tax Department, informing the recipient that he or she is eligible for a substantial tax refund. The message looks official: it bears the logo of the Income Tax Department, the national emblem, and sometimes even a forged signature of a tax official. The message contains a link to claim the refund.

                     i.            Modus Operandi:

a)      The link directs the victim to a fake website that mimics the official e-filing portal. The domain name may be something like “incometaxrefund.in” or “itaxindia.gov.in”—close enough to the genuine “incometax.gov.in” to deceive a casual observer.

b)      The fake website asks the victim to enter PAN, Aadhaar number, bank account details, and credit or debit card information, ostensibly to “verify” the refund credit.

c)      Once the details are submitted, the fraudster uses them to access the victim’s actual bank account through net banking or to make fraudulent transactions.

·         Example: In 2023, a pan-India phishing campaign sent SMS messages reading: “Dear taxpayer, your income tax refund of Rs. 15,490 has been approved. Click here to credit to your bank account: [link].” The link led to a fake portal that harvested PAN and bank details. Thousands of taxpayers in Maharashtra, Gujarat, and Rajasthan fell victim. The Indian Cyber Crime Coordination Centre (I4C) traced the domain to a server in Russia and coordinated a takedown with CERT-In.

B. Fake Income Tax Return (ITR) Filing Websites: During the tax filing season (typically July to December), fraudsters set up websites that look exactly like the official e-filing portal. They often use search engine optimisation (SEO) techniques to ensure that their fake portal appears prominently in search results when a taxpayer types “file ITR online.”

i.            Modus Operandi:

a)      The taxpayer lands on the fake portal and begins the filing process, entering PAN, Aadhaar, income details, and bank account information.

b)      The portal may even generate a fake acknowledgment (ITR-V), giving the taxpayer a false sense of completion.

c)      The data entered is sold on the dark web or used for identity theft and financial fraud. In some cases, the fraudster also charges a “filing fee” that is pocketed.

·         Example: In 2022, the Delhi Police Cyber Cell busted a racket that operated over 15 fake ITR filing websites. The portals, with names like “easyincometaxfiling.com” and “quickitr.in,” had processed over 50,000 fake filings during the tax season, collecting PAN and bank details that were later used for loan frauds. The gang had earned over ₹1.2 crore in fraudulent filing fees.

C. Malicious Mobile Apps (The Drinik Trojan): One of the most dangerous income tax fraud campaigns in India involved a banking trojan named Drinik, which evolved from a simple SMS phishing tool into a full-fledged malware targeting Indian taxpayers.

i.            Modus Operandi:

a)      The victim receives an SMS or WhatsApp message, purportedly from the Income Tax Department, stating that a refund has been calculated and that the taxpayer must download a specific app to receive it.

b)      The app, named something like “Income Tax Refund” or “ITR Refund App,” is hosted on a third-party website, not the official app store.

c)      Once installed, the app requests permissions—accessibility services, SMS access—that appear necessary for the refund process.

d)      In reality, the malware reads every on-screen text (capturing passwords and PINs), intercepts all SMS messages (capturing OTPs), and exfiltrates the victim’s contact list, PAN, Aadhaar, and bank details to a remote server controlled by the fraudsters.

e)      The fraudsters then use the harvested data to log into the victim’s net banking, drain the account, or sell the identity data on the dark web.

·         Example: The Drinik campaign, first detected in 2021 and peaking in 2022, infected over 100,000 Android devices across India. The I4C estimated cumulative losses exceeding ₹25 crore. The malware was regularly updated to evade detection, and the command-and-control servers were located in Eastern Europe. CERT-In issued multiple advisories, and Google Play Protect was updated to block the malware.

D. Fake Income Tax Notices (Intimidation Fraud): Fraudsters exploit the fear that the words “Income Tax Department” can evoke. They send fake tax notices via email or SMS, alleging discrepancies in the taxpayer’s return, demanding immediate payment of a penalty, or threatening prosecution, arrest, and attachment of property.

i.            Modus Operandi:

a)      The fake notice is often designed to mimic the format of genuine departmental communications—Section 143(1) intimation, Section 148 reassessment notice, or a demand under Section 156.

b)      The notice may contain a forged document number, the name of a real tax officer, and a demand for payment into a specified bank account. The fraudster uses the fear of legal consequences to override the victim’s critical thinking.

c)      The communication may demand payment of a “penalty” via UPI or bank transfer. Alternatively, it may ask the victim to click a link to “view the notice,” which then installs malware.

·         Example: In 2021, a senior citizen in Chennai received an email with the subject line “Notice under Section 148 – Reopening of Assessment.” The email, bearing the Income Tax Department logo, accused him of under-reporting capital gains and demanded a penalty of ₹2.5 lakh to be paid within 24 hours to avoid prosecution. The man, terrified, transferred the money. When he later consulted a chartered accountant, he discovered the notice was fake. The cyber cell traced the bank account to a mule account in Jharkhand.

E. PAN Card Related Frauds: The PAN card is the most widely used identity document in India’s financial system. A fraudster who obtains a victim’s PAN can open bank accounts, apply for credit cards, secure loans, and file fraudulent tax returns in the victim’s name.

         i.            PAN Misuse for Fake ITR Filing: Fraudsters use stolen PAN and Aadhaar details to file fake income tax returns, claiming fraudulent refunds. The genuine taxpayer discovers the fraud only when his or her own return is rejected for “duplicate filing,” or when a tax demand arrives for income he or she never earned.

       ii.            Phishing for PAN Details: Fake websites and apps offering “instant PAN card generation” or “PAN correction services” harvest the applicant’s identity documents and biometric data.

     iii.            Mutable Case Example: In 2023, a Bengaluru-based IT professional discovered that a tax return had been filed in his name by an unknown person, claiming a refund of ₹34,000. The refund had already been credited to a bank account opened with his PAN and a forged address proof. The bank account was traced to a mule network in Rajasthan. The case is under investigation by the Income Tax Department and the local cyber cell.

F. Tech Support Scams Impersonating the Income Tax Department: A variation of the tech support scam involves fraudsters calling taxpayers, posing as IT department officials, and offering “help” with e-filing, refunds, or resolving a notice. The caller instructs the victim to download a remote access application such as AnyDesk or TeamViewer, ostensibly for technical support. Once the application is installed and the access code is shared, the fraudster takes control of the victim’s computer or phone, accesses internet banking, and transfers funds.

Quotation: “The Income Tax Department communicates primarily through the e-filing portal and registered email. Any unsolicited phone call, SMS with a link, or demand for immediate payment is almost certainly a fraud. The taxpayer must learn to trust the official channel and verify before acting.” — Dr. Sanjay Bahl, Director General, CERT-In, in a 2023 public awareness video.

3. Legal Framework

Income tax cyber frauds attract prosecution under a combination of the Information Technology Act, 2000, the Indian Penal Code / Bharatiya Nyaya Sanhita, 2023, and the Income Tax Act, 1961.

A.    Information Technology Act, 2000:

                    i.            Section 66C (Identity Theft): Fraudulent use of another person’s PAN, Aadhaar, digital signature, or password. Punishment: imprisonment up to three years and fine up to ₹1 lakh.

                  ii.            Section 66D (Cheating by Personation): Impersonating the Income Tax Department, a tax official, or any other person through a computer or communication device. Punishment: imprisonment up to three years and fine up to ₹1 lakh.

                iii.            Section 66 (Hacking): Unauthorised access to a computer system with dishonest or fraudulent intent, applicable to malware like Drinik that captures credentials. Punishment: imprisonment up to three years and fine up to ₹5 lakh.

                iv.            Section 43 (Civil Liability): The affected person can claim damages for unauthorised access, data theft, or introduction of malware.

 

B.     Bharatiya Nyaya Sanhita, 2023 / Indian Penal Code:

                    i.            Section 318 BNS (Section 420 IPC): Cheating and dishonestly inducing the delivery of property. The fraudster induces the victim to pay a fake penalty or to part with money on the pretext of a refund.

                  ii.            Section 319 BNS (Section 419 IPC): Cheating by personation.

                iii.            Sections 336–340 BNS (Forgery, old Sections 463–471 IPC): Making or using forged electronic documents, such as fake tax notices bearing forged signatures of tax officials.

                iv.            Section 303 BNS (Theft, old Section 379 IPC): Where data is “property” and is stolen—for example, the harvesting of a PAN database by a fake ITR portal.

C.    Income Tax Act, 1961:

                    i.            Section 277A: Punishes the falsification of books of account or documents, which could extend to fabricated digital ITR filings and fake refund claims.

                  ii.            The Act does not specifically address phishing against taxpayers, but the fraudulent claiming of refunds using stolen identities can be prosecuted under the general anti-evasion and fraud provisions.

D.    Regulatory and Institutional Mechanisms:

                    i.            The Central Board of Direct Taxes (CBDT) regularly issues advisories warning taxpayers against phishing emails and fake websites.

                  ii.            The Indian Cyber Crime Coordination Centre (I4C) and the National Cyber Crime Reporting Portal (cybercrime.gov.in) are the primary platforms for reporting.

                iii.            The CERT-In Directions, 2022, mandate that all cyber incidents, including phishing campaigns targeting taxpayers, be reported within six hours.

Quotation: “The legal tools exist to punish income tax cyber frauds. The challenge is the speed and volume of these crimes. For every fake portal taken down, two more appear. The long-term solution is not just prosecution, but a digitally literate taxpayer base that does not fall for the bait.” — Dr. Karnika Seth, Cyber Law Expert, in a 2023 commentary.

4. Reporting and Redressal: A taxpayer who has fallen victim to an income tax cyber fraud must act quickly to minimise damage and enable law enforcement to freeze the fraudster’s accounts.

A.    Step 1: Report to the Income Tax Department.

                    i.            Send an email to the Income Tax Department at webmanager@incometax.gov.in with full details of the fraudulent communication, including screenshots, headers, and the sender’s email ID or phone number.

                  ii.            File a complaint on the e-filing portal (incometax.gov.in) under the “Grievance” section.

                iii.            If your PAN has been misused, apply for a rectification and flag the fraudulent return or account.

B.     Step 2: Report to Cyber Crime Authorities.

                    i.            Call the national cyber crime helpline 1930 immediately if a financial loss has occurred. The operator will attempt to freeze the beneficiary account.

                  ii.            File a formal complaint on cybercrime.gov.in. Upload screenshots of the fraudulent message, the transaction receipt, and any communication with the fraudster.

                iii.            Register an FIR at the local police station, citing the relevant sections of the IT Act and BNS/IPC.

C.    Step 3: Inform Your Bank.

                    i.            If you have shared bank details or if an unauthorised transaction has occurred, call your bank’s fraud helpline, block the account, and request a chargeback where applicable.

D.    Step 4: Report to CERT-In.

                    i.            CERT-In accepts reports of phishing websites and malicious apps at incident@cert-in.org.in. Reporting helps in the early takedown of fraudulent infrastructure.

5. Prevention: A Taxpayer’s Guide

The best defence against income tax cyber frauds is a healthy scepticism and a few simple habits:

·         Bookmark the official portal. The genuine Income Tax e-filing website is https://www.incometax.gov.in. Always type the URL directly or use a bookmarked link. Never navigate to the portal through an email link, an SMS link, or a search engine advertisement.

·         Remember: The IT Department never asks for sensitive details. No genuine communication from the Income Tax Department will ask for your net banking password, UPI PIN, credit card CVV, or OTP. Any such request is a fraud.

·         Verify notices through the portal. If you receive an email or SMS about a tax demand, a refund, or a notice, log into the official e-filing portal independently to verify. All genuine communications are reflected in the “Worklist” or “My Account” section.

·         Do not download apps from links in messages. Install official tax-related apps only from the Google Play Store or Apple App Store, and only those published by the Income Tax Department or authorised agencies.

·         Check the sender’s email address. Genuine emails from the Income Tax Department come from addresses ending in @incometax.gov.in. Fraudulent emails often use addresses like incometax@gmail.com, itax.refund@yahoo.com, or similar. Be particularly suspicious of generic email domains.

·         Do not panic. Fake notices rely on fear and urgency. Take a moment to breathe, consult a tax professional or the department’s helpline, and verify before taking any action.

·         Protect your PAN. Do not share your PAN casually. Be cautious when providing it to employers, financial institutions, or online platforms, and ensure they have a legitimate need for it.

 

Conclusion

Income tax cyber frauds are crimes of deception that weaponise the taxpayer’s trust in the state and his or her fear of its coercive power. They range from the crude SMS promising an improbable refund to the sophisticated malware campaign that silently harvests every keystroke. The common element is the impersonation of the tax authority—an institution whose communications carry weight and urgency. The legal framework provides for prosecution and, in some cases, restitution, but prevention is overwhelmingly more effective than cure.

The digitisation of the tax system is an irreversible and welcome transformation. It has increased transparency, reduced corruption, and made compliance easier for millions. But it also demands a digitally literate citizenry. A taxpayer who knows the official portal, who reads emails with a sceptical eye, who pauses before clicking a link, and who verifies every demand through official channels is a hard target. Building that digital literacy, across every income bracket and every age group, is the long-term project that will ultimately secure India’s tax ecosystem against the predators of the digital age.

Quotation: “The Income Tax Department serves the nation by collecting revenue for development. Taxpayers serve the nation by paying their dues honestly. Cyber fraudsters who exploit this sacred relationship are committing not just a crime against an individual, but a crime against the state itself.” — N.S. Nappinai, Advocate, Supreme Court, in a 2024 article on tax frauds.

 

Chapter References

1.        Information Technology Act, 2000, Sections 43, 66, 66C, 66D.

2.        Bharatiya Nyaya Sanhita, 2023, Sections 303, 318, 319, 336–340.

3.        Income Tax Act, 1961, Section 277A.

4.        Central Board of Direct Taxes, Public Advisory on Phishing Emails and Fake Websites, 2023.

5.        CERT-In, Advisory on Drinik Banking Trojan Targeting Taxpayers, 2022.

6.        I4C, Report on Income Tax Related Cyber Frauds, 2023.

7.        Delhi Police Cyber Cell, Investigation Report on Fake ITR Filing Websites, 2022.

8.        National Cyber Crime Reporting Portal, Guidelines for Victims of Tax Fraud, 2023.

9.        Income Tax Department, E-Filing Portal Security Guidelines, 2023.

 

No comments:

Post a Comment