E-mail Scam Soliciting Donations To California Wildfire Victims
E-mail Scam Soliciting Donations To California Wildfire Victims
WASHINGTON, D.C. â The Internal Revenue Service is warning taxpayers to be on the lookout for a new e-mail scam that appears to be a solicitation from the IRS and the US government for charitable contributions to victims of the recent Southern California wildfires.
In an effort to appear legitimate, the bogus e-mails include text from an actual speech about the wildfires by a member of the California Assembly.
The scam e-mail urges recipients to click on a link, which then opens what appears to be the IRS website but which is, in fact, a fake. An item on the phony website urges donations and includes a link that opens a donation form that requests the recipientâs personal and financial information.
âPeople should exercise caution when they receive unsolicited e-mail or e-mail from senders they donât know,â said Richard Spires, IRS Deputy Commissioner for Operations Support. âThey should avoid opening any attachments or clicking on any links until they can verify the e-mailâs legitimacy.â
The bogus e-mails appear to be a âphishingâ scheme, in which recipients are tricked into providing personal and financial information that can be used to gain access to and steal the e-mail recipientâs assets.
The IRS also believes that clicking on the link downloads malware, or malicious software, onto the recipientâs computer. The malware will steal passwords and other account information it finds on the victimâs computer system and send them to the scamster.
Generally, scamsters use the data they fraudulently obtain to empty the recipientâs bank accounts, run up charges on the victimâs existing credit cards, apply for new loans, credit cards, services, or benefits in the victimâs name or even file fraudulent tax returns to obtain refunds rightfully belonging to the victim.
The IRS does not send e-mails soliciting charitable donations. As a rule, the IRS does not send unsolicited e-mails or ask for personal and financial information via e-mail. The IRS never asks people for the PINs, passwords, or similar secret access information for their credit card, bank, or other financial accounts.
Recipients of the scam e-mail who clicked on any of the links should have their computers checked for malicious software and should monitor their financial accounts for suspicious activity, taking measures to prevent unauthorized access as necessary. Any unauthorized activity should be reported to law enforcement authorities and to the three major credit companies.
More information on how to handle actual or potential identity theft may be found in IRS Publication 4535, Identity Theft Protection and Victim Assistance, available on the IRS website. Information is also available on the Federal Trade Commissionâs identity theft website.
Recipients of the scam e-mail can help the IRS shut down this scheme by forwarding the e-mail to an electronic mail box, phishing@irs.gov, using instructions found in âHow to Protect Yourself from Suspicious E-Mails or Phishing Schemesâ on the genuine IRS website, IRS.gov.
This mail box was established to receive copies of possibly fraudulent e-mails involving misuse of the IRS name, logo or website for investigation.
The IRS and the Treasury Inspector General for Tax Administration (TIGTA) work with the US Computer Emergency Readiness Team (US-CERT) and various Internet service providers and international CERT teams to have the phishing sites taken offline as soon as they are reported.
Since the establishment of the mail box last year, the IRS has received more than 30,000 e-mails from taxpayers reporting almost 600 separate phishing incidents. To date, investigations by TIGTA have identified almost 900 host sites in at least 55 different countries, as well as in the United States.
Recipients of questionable e-mails claiming to come from the IRS may also call TIGTAâs toll-free hotline at 800-366-4484.
The IRS has come across numerous schemes in which e-mails claim to come from the IRS. More information on these schemes may be found on the genuine IRS website, IRS.gov, by entering the term âphishingâ in the search box.