Phishing: Audit Notification | Fake Income Tax Department Penalty Notice
The tax inspection of your company has revealed irregularities under Section 271(1)(c) of the Income Tax Act, 1961. A forged Government of India memorandum sent from a free Outlook mailbox, demanding documents within 72 hours via a Chinese gaming domain.
Complete Email
from: Internal Audit Team juanatanyadrpz@outlook.com
to: info@dewiride.com
reply-to: juanatanyadrpz@outlook.com
date: 08/09/2026 2:28 PM
subject: Audit Notification
Email Body
सरकार / Government of India
वित्त मंत्रालय / Ministry of Finance
आयकर विभाग / Income Tax Department
प्रवर्तन प्रभाग / Enforcement Division
Aayakar Bhawan,
New Delhi - 110001
Dated: June 09, 2026
OFFICE MEMORANDUM
Sub: कर अनुपालन की कमी और दंड सूचना / Tax Compliance Deficiency and Penalty Notice
1.आपकी कंपनी की कर निरीक्षण के दौरान आयकर अधिनियम, 1961 की धारा 271(1)(c) के तहत कर संबंधी अनियमितताएं पाई गई हैं। The tax inspection of your company has revealed irregularities under Section 271(1)(c) of the Income Tax Act, 1961.
2.इस सूचना की प्राप्ति के 72 घंटे (3 दिन) के भीतर निम्नलिखित दस्तावेज़ आयकर विभाग को प्रस्तुत करना अनिवार्य है। It is mandatory to submit the following documents to the Income Tax Department within 72 hours (3 days) of receipt of this notice.
📋 आवश्यक दस्तावेज़ सूची / Required Documents List
नीचे दिए गए लिंक से दस्तावेज़ डाउनलोड करें / Download documents from the link below
📄 दस्तावेज़ डाउनलोड करें / Download Documents
3.निर्धारित समयावधि में दस्तावेज़ प्रस्तुत न करने पर आयकर अधिनियम की धारा 276C के तहत कानूनी कार्रवाई की जाएगी। Legal action will be taken under Section 276C of the Income Tax Act if documents are not submitted within the stipulated time.
(राज कुमार शर्मा)
Raj Kumar Sharma
सहायक आयकर आयुक्त
Assistant Commissioner of Income Tax
To: All concerned taxpayers
Copy to: Director (Systems), CBDT, for uploading on Income Tax Department Website External Email
Where the link actually goes:
The "दस्तावेज़ डाउनलोड करें / Download Documents" text carries a single hyperlink:
https://chuanqiweb.com/
![]()
Red Flags
This is government-impersonation phishing with a malware-delivery payload. It borrows the most intimidating authority available to an Indian business — the Income Tax Department, an alleged inspection, a named penalty section, and a criminal-prosecution threat — and attaches a 72-hour clock to a single download link. The document layout is convincing at a glance because government memoranda are visually dull by nature, and dullness is easy to counterfeit. Every substantive detail, however, is wrong.
1. The Government of India Does Not Send Mail From Outlook.com
- Sender:
juanatanyadrpz@outlook.com
This settles the matter before a single line of the memorandum is worth reading. Genuine Income Tax Department communication originates from the incometax.gov.in domain — typically donotreply@incometax.gov.in or an officer's @incometax.gov.in address. It never arrives from a free consumer mailbox.
The local part is also nonsense: juanatanyadrpz is a random string with no relationship to "Raj Kumar Sharma," to any Indian tax office, or to the words "Internal Audit Team" shown as the display name. It is a disposable account created in seconds, and the display name is free text typed by the attacker.
2. There Is No Document Identification Number
This is the single most decisive test for any Indian tax communication, and this email fails it outright.
- Since 1 October 2019, under CBDT Circular No. 19/2019, every notice, order, letter, and correspondence issued by any Income Tax authority must carry a computer-generated Document Identification Number (DIN).
- The circular is unambiguous about the consequence: a communication issued without a DIN is treated as invalid and deemed never to have been issued.
- This memorandum carries no DIN, and provides no way to authenticate it on the e-Filing portal — which is precisely the facility the DIN system exists to provide.
A real notice invites verification because it can survive verification. This one offers no reference of any kind.
3. "Enforcement Division" Is Not Part of the Income Tax Department
The letterhead reads प्रवर्तन प्रभाग / Enforcement Division. No such division exists within the Income Tax Department. The attacker has conflated two entirely separate bodies:
- The Income Tax Department, under the Central Board of Direct Taxes (CBDT), administers direct taxation.
- The Enforcement Directorate (ED) is a distinct agency under the Department of Revenue, handling FEMA and money-laundering matters.
Fusing the two produces a fictional office that sounds more frightening than either. Real tax correspondence identifies a specific Ward or Circle — for example, "Circle 4(1), Delhi" — because that is how jurisdiction over a taxpayer is actually assigned.
4. The Memorandum Is Dated Two Months Before It Was Sent
- Dated: June 09, 2026
- Received: Sunday, 9 August 2026, at 14:28
The same day and month, two months apart — the classic signature of a template reused with a stale date left behind, or a hastily edited month field. There is no scenario in which a government notice imposing a 72-hour deadline is delivered two months after the date it bears. Compounding this, it arrived at 2:28 PM on a Sunday. Statutory notices are issued during working hours on working days.
5. The Cited Penalty Section Was Retired Nearly a Decade Ago
- Section 271(1)(c) penalised concealment of income and furnishing inaccurate particulars. It was superseded by Section 270A for Assessment Year 2017-18 onwards.
An Assistant Commissioner of Income Tax raising a fresh penalty proposal in 2026 under 271(1)(c) would be citing a provision that no longer applies to current assessment years. The attacker searched for "income tax penalty section," found the most frequently quoted one, and pasted it in — without knowing it had been replaced.
6. The Threatened Section Does Not Cover the Alleged Failure
- Section 276C prosecutes a wilful attempt to evade tax — a criminal provision requiring proof of deliberate evasion, prosecuted in court after sanction from a senior authority.
- Failing to produce documents in response to a notice is dealt with under an entirely different route: Section 272A(1) or 271(1)(b), which impose monetary penalties.
The attacker reached for the scariest-sounding section — the one carrying imprisonment — regardless of whether it fits the alleged conduct. Real notices match the provision to the default, because they have to survive appeal.
7. 72 Hours Is Not a Lawful Deadline
- Statutory notices under the Income Tax Act specify a compliance period measured in days or weeks, commonly 15 or 30 days, and always state a calendar date.
- Section 274 requires that no penalty be imposed without giving the assessee a reasonable opportunity of being heard. A three-day ultimatum delivered by email, with no hearing date and no assessing officer to respond to, is the opposite of that.
The 72-hour window exists for one reason: to move the reader from reading to clicking before anyone has time to telephone their chartered accountant.
8. The Instruction Is Backwards — And That Is the Whole Attack
Read points 2 and 3 together and the logic collapses:
- The notice says you must submit documents to the Income Tax Department.
- It then tells you to download documents from a link.
A department demanding records from you has no reason to send you a download. This inversion is not sloppiness — it is the payload. The entire memorandum exists to justify the one action the attacker actually wants, and "here is the list of what to submit" is the pretext that makes downloading an unknown file from a stranger feel like compliance.
There is also no attachment on this message. A genuine "Required Documents List" would be a PDF on the notice itself, or an item in your e-Proceedings tab — not a link to a website.
9. The Link Is a Chinese Domain With No Path
- Destination:
https://chuanqiweb.com/
Two things are wrong here, and either alone is fatal:
- The domain is not Indian and not governmental. Every Government of India web property lives under
gov.inornic.in— the Income Tax Department's own portal isincometax.gov.in..gov.inregistration is restricted to verified government bodies, which is exactly why it cannot be counterfeited. A commercial.comdomain is not, and cannot be, a government host. chuanqi(传奇) is Chinese for "legend" — a name overwhelmingly associated with Chinese online-game portals and download sites. Appendingwebproduces a generic Chinese hosting name with no conceivable connection to Indian taxation.
Note also that the link points at the bare root of the domain — no directory, no file name, nothing identifying a document. A real download link ends in a file. A root URL is a landing page: it can serve a fake login form to one visitor, a malicious archive to the next, and a harmless holding page to a security scanner, all decided at request time.
10. Addressed to Nobody, About a Specific Company
The memorandum contradicts itself on who it is for:
- "To: All concerned taxpayers" — a broadcast circular addressed to the general public.
- "The tax inspection of your company has revealed irregularities" — a specific finding against one specific company.
These cannot both be true. A penalty proposal arising from an inspection names the assessee. Beyond that, the notice contains no PAN, no TAN, no assessment year, no notice or case number, no penalty amount, no company name, and no inspection date. Not one identifier that would let you look the matter up — because the attacker knows none of them. This went to a scraped list.
11. Sent to a Public Inbox Instead of the Registered Email
The recipient is info@ — a general enquiries address published on a website. The Income Tax Department does not use scraped addresses. It writes to the email registered against the PAN in the e-Filing profile, and every genuine notice appears simultaneously in the portal under e-Proceedings, where it can be read, authenticated by DIN, and responded to.
That portal copy is the point: if a notice is real, it is on the portal. If it exists only in your inbox, it is not a notice.
12. The Bilingual Formatting Betrays Machine Translation
Genuine bilingual government documents present Hindi and English as separate blocks, columns, or pages, produced by the department's own translation cell. This memorandum splices them into single run-on lines — a Hindi sentence immediately followed by its English rendering, inside the same numbered point.
Other tells in the same vein:
- The header reads simply
सरकार / Government of India. The correct Hindi is भारत सरकार ("Bharat Sarkar"). Dropping "भारत" is what a translation engine does when fed the bare word "Government." - Numbered points run into their text with no space —
1.आपकी,2.इस,3.निर्धारित. - 📋 and 📄 emoji appear in a Government of India office memorandum. They are there to draw the eye toward the download line. No official communication uses them.
13. "Office Memorandum" Is the Wrong Instrument
An Office Memorandum (OM) is an internal government instrument — used between offices and departments to convey decisions or policy. It is not, and never has been, the means of serving a penalty proceeding on a taxpayer. That is done by a Notice issued under the relevant section, such as Section 274 read with 271.
The closing line — "Copy to: Director (Systems), CBDT, for uploading on Income Tax Department Website" — is genuine CBDT circular boilerplate, lifted verbatim from public policy documents. It is also self-defeating: a confidential penalty notice against one company is never uploaded to a public website. The attacker copied the ending of a real circular without understanding what it means.
14. The Signature Has No Office Behind It
- "Raj Kumar Sharma, सहायक आयकर आयुक्त / Assistant Commissioner of Income Tax." No Ward or Circle, no designation code, no office address beyond a generic building name, no telephone number, no employee identifier.
- "Aayakar Bhawan, New Delhi - 110001" is a real building name used for tax offices across India, quoted here without a room, floor, or jurisdiction — the address equivalent of "the office."
A real signature block tells you exactly which officer holds jurisdiction over your file, because you are entitled to appear before them.
15. The Gateway's Own Warning Is Sitting in the Text
The last line ends: "...for uploading on Income Tax Department Website External Email."
"External Email" is not part of the memorandum. It is the security banner injected by the recipient's own mail gateway, flagging that the message originated outside the organisation — and it has bled into the body text. The infrastructure had already labelled this email as external before anyone read a word of it.
How This Scam Works
The memorandum is not the attack. It is a three-page justification for one click, and every section of it — the letterhead, the sections of the Act, the officer's name — exists to make that click feel like obedience rather than risk.
- The Authority: A Government of India letterhead with a ministry, a department, and a division. Indian businesses are conditioned to treat tax correspondence as non-negotiable, and that reflex fires before the sender address is ever examined.
- The Accusation: "The tax inspection of your company has revealed irregularities." No inspection occurred, but the claim is unfalsifiable from the reader's chair — and it produces exactly the flustered, guilty response the attacker needs.
- The Criminal Threat: Section 276C carries prosecution. Naming a section with imprisonment attached converts anxiety into panic, and panic is what shortens the gap between reading and clicking.
- The Clock: 72 hours, with no hearing, no officer to call, and no case number to quote. There is no path to compliance except the link, which is the point of the deadline.
- The Click: The target opens
chuanqiweb.com— a domain unconnected to Indian government infrastructure, likely a compromised or purpose-built host, with a valid TLS certificate that renders a perfectly normal padlock in the address bar. - The Payload: A bare root URL can serve anything, and campaigns of this shape resolve to one of two outcomes. Malware delivery is the more common: an archive named after the promised documents, containing a
.lnk,.js,.hta, or macro-enabled file that installs an information stealer or a remote access trojan. The alternative is credential harvesting — a counterfeitincometax.gov.insign-in page demanding e-Filing credentials, PAN, and the OTP that follows. - The Escalation: Either outcome hands over the finance function. A stealer takes browser-stored passwords, banking sessions, and accounting files. Stolen e-Filing access exposes complete financial history, PAN and TAN details, and bank particulars — enough to file fraudulent returns, redirect refunds, and build a far more credible spear-phishing attack against the same company, its accountant, and its customers.
Conclusion and Recommendations
No inspection took place and no notice was issued. This is a forged office memorandum sent from a free Outlook mailbox, dated two months before it arrived, citing a superseded penalty section and a criminal provision that does not apply, carrying no Document Identification Number, and pointing at a Chinese commercial domain with nothing but a root URL behind the word "Download."
Immediate Actions:
- Do Not Click the Link:
chuanqiweb.comis not a Government of India host and cannot become one. There is nothing to download and nothing to verify by visiting. - Do Not Reply: The reply-to is the attacker's own Outlook mailbox. A reply — even a denial or a demand for the case number — confirms a live, human-attended inbox at a real company and invites a targeted follow-up.
- Do Not Send Any Documents: Financial statements, GST returns, bank statements, and PAN or TAN details supplied "in compliance" go straight to a criminal, and are precisely the material needed for identity fraud and a convincing second approach.
- Report It as Phishing: Use the report button in your mail client, and forward it to
webmanager@incometax.gov.in— the Income Tax Department's published address for reporting phishing that impersonates it. Report to CERT-In atincident@cert-in.org.inand on the National Cyber Crime Reporting Portal,cybercrime.gov.in. - If Someone Already Clicked or Downloaded Anything: Disconnect that machine from the network and treat it as compromised. Run a full endpoint scan, change every password from a different device — starting with the e-Filing portal, email, and banking — and check the e-Filing profile for altered contact details or bank accounts.
Verification Steps:
- Log In to the Portal, Never the Email: Type
incometax.gov.inyourself and check e-Proceedings. Every genuine notice appears there. If it is not on the portal, it was not issued. - Authenticate the DIN: The portal's "Authenticate Notice/Order Issued by ITD" service confirms whether a document is real. No DIN on the notice means there is nothing to authenticate, and that alone is conclusive.
- Read the Domain Right to Left: The owner of
chuanqiweb.comischuanqiweb.com— a commercial.com. Indian government sites end ingov.inornic.in, and that suffix cannot be bought. - Check the From Address, Not the Display Name: "Internal Audit Team" is free text anyone can type.
juanatanyadrpz@outlook.comis the only part with evidentiary value. - Call Your Chartered Accountant Before You Do Anything Else: Any competent CA identifies this in seconds. That call is faster than the 72-hour deadline the email invented to prevent it.
Additional Protection Tips
- Learn the DIN Rule and Apply It Every Time: No DIN, no notice. It is a single, binary check that defeats the entire category of fake Indian tax correspondence, and it requires no security expertise.
- Treat Government Impersonation as the Highest-Pressure Lure There Is: Fake notices from the Income Tax Department, GST authorities, the ED, and the police convert well precisely because the perceived cost of ignoring them feels enormous. The pressure itself is the tell.
- Deploy Phishing-Resistant MFA: SMS and app-based OTPs can be relayed in real time by modern phishing kits. FIDO2 security keys and passkeys cannot — they are cryptographically bound to the genuine domain and will not authenticate against a lookalike.
- Block Executable and Script Content at the Gateway and the Endpoint: Archives containing
.lnk,.js,.hta,.vbs, and macro-enabled Office files are the standard delivery vehicles behind a "download your documents" link. Filter them in transit, and disable macros from the internet by policy. - Restrict Who Watches the Shared Inbox — and Train Them: Generic
info@andaccounts@mailboxes take the first hit, and a legal threat landing in front of an untrained reader is exactly the outcome the attacker is buying. - Establish a Single Route for Tax Correspondence: Decide in advance that all tax matters are handled through the e-Filing portal and your CA, and that no action is ever taken on the strength of an email. A standing rule removes the individual judgement call that urgency is designed to distort.
- Enforce SPF, DKIM, and DMARC on Your Own Domain: It will not stop mail from
outlook.com, but it does stop the next attacker forging your company's own address to send a notice like this to your staff, vendors, and customers.
Remember: Real authority never needs a countdown. A government department that genuinely holds a case against you can name the section, quote your PAN, cite the assessment year, and show you the notice on its own portal — and it gives you weeks, in writing, to reply. Urgency without identifiers is not enforcement; it is a sales technique for a click.
