Skip to main content

Phishing: Judicial Notice | Renda Tax Department, Government of India - A Brazilian Template With India Pasted In

Β· 21 min read
Jagdish Kumawat
Jagdish Kumawat
Founder @ Dewiride

Judicial Notice. Case Matter: Tax Dispute / Financeira. Investigating Authority: Renda Tax Department, Government of India. A summons from a tax authority that does not exist, sent from a free Outlook mailbox, still carrying the Portuguese words of the template it was copied from.

Complete Email​

from: Renda Tax Department damonapah@outlook.com
date: 08/10/2026 9:20 AM
subject: (no subject)

Mailed by: outlook.com - Signed by: outlook.com

Email Body​

════════════════════════════════════
Judicial Notice
════════════════════════════════════
Process Number: 52291157
Case Matter: Tax Dispute / Financeira
Investigating Authority: Renda Tax Department, Government of India
Hearing date: August 25, 2026
Time: 10:30 AM
Location: Nova DΓ©lhi Judicial Complex, India
Related Document: https://taxation01jf.com/download/tax-documents1
Please share this information internally with the finance department for reference purposes.

Attacking email screenshot


Red Flags​

This is a government impersonation phish, and its opening move is to make you feel legally cornered before you have finished reading. A process number, a hearing date, a time, a venue, an investigating authority: nine lines of procedural furniture arranged to produce one reflex, which is to open the "Related Document" and find out what you have been accused of. There is no accusation. There is no case. The furniture exists to carry the link.

What makes this particular message worth taking apart is that it was translated badly. The forger did not write a fake Indian tax notice. He took a fake Brazilian one and ran it through a find-and-replace, and three words survived the process that should not have.

1. "Renda" and "Financeira" Are Portuguese Words Left in an English Notice​

  • Investigating Authority: Renda Tax Department
  • Case Matter: Tax Dispute / Financeira

Renda is Portuguese for income or revenue. Brazil's income tax is Imposto de Renda, collected by the Receita Federal. Financeira is Portuguese for financial. Neither word is English, neither is Hindi, and neither appears in any Indian statute, department name, or court listing.

Read "Renda Tax Department" back through that lens and the origin of the phrase is obvious: it is Income Tax Department with the middle word left untranslated. The template was written for a Portuguese-speaking audience, the country name was swapped to India, the language was swapped to English, and the swap was done by hand against a word list rather than by anyone who reads either language. Two words at the heart of the claim never got converted.

This is not a small slip. The name of the authority issuing the notice is half in a foreign language, and it is the single most checkable fact in the message.

2. There Is No "Renda Tax Department" in the Government of India​

India has one direct-tax authority and it is called the Income Tax Department, administered by the Central Board of Direct Taxes (CBDT) under the Department of Revenue, Ministry of Finance. Indirect tax sits with the Central Board of Indirect Taxes and Customs (CBIC). There is no third body, no "Renda" division, and no department of that name at any level of central or state government.

The name is doing the work here. An organisation with tax-sounding words in it, attributed to the Government of India, is enough for most readers to stop verifying. But a government body is a matter of public record: it has a website on a restricted domain, a published address, a citizen charter, and an officer you can name. Nothing in this notice can be looked up, because the issuer does not exist.

There is a second, harder rule this message fails. Since 1 October 2019, every communication issued by any income-tax authority in India must carry a computer-generated Document Identification Number (DIN), and the CBDT's own circular states that a communication issued without one is invalid and deemed never to have been issued. This message has no DIN. Under the department's own rules, even if the body were real, the notice would be void on its face.

3. A Government of India Summons Sent From a Free Outlook Mailbox​

  • Address: damonapah@outlook.com
  • Display name: Renda Tax Department

outlook.com is Microsoft's free consumer mail service. Anyone can open an account on it in two minutes, type any words they like into the display name field, and send. The display name is not a credential; it is a text box.

Genuine correspondence from the Income Tax Department arrives from the department's own restricted domains - incometax.gov.in, and the wider gov.in and nic.in space. Those registries are closed: .gov.in is administered by the National Informatics Centre and is available only to Indian government entities. That closure is the entire security value of the domain. A tax authority that cannot send mail from its own domain is not a tax authority.

The local part gives the same answer. damonapah is not a department, not a division, not a designation, and not a name that appears anywhere in the notice. It is the string that happened to be free.

Now note the two headers that look reassuring and are not:

  • mailed-by: outlook.com
  • signed-by: outlook.com

Those lines mean the message genuinely originated from Microsoft's consumer infrastructure and was cryptographically signed by it. The authentication passed - and it certified the sending service, not the sender's claim. SPF and DKIM answer "did this mail really come from the domain it says it did?" They never answer "is this person who they say they are." The mail is authentically from outlook.com. It is authentically not from the Government of India, and no header check will ever tell you otherwise. This is the most widely misread signal in email security.

4. The Notice Names No One, Including the Party It Is Against​

Count what a real judicial notice contains and this one does not:

  • No recipient - no name, no company, no address, no salutation of any kind
  • No PAN, TAN, GSTIN, or assessment year - the identifiers every Indian tax proceeding is indexed by
  • No section of the Income Tax Act under which anything is alleged
  • No amount in dispute
  • No assessing officer, ward, circle, or bench
  • No signature, designation, seal, or letterhead
  • No contact channel - no phone number, no office, no reply instruction

A notice that does not name the person it is issued against is not a notice of anything. It cannot be, because the legal effect of service depends on identifying the party served.

Then there is the reference itself: Process Number: 52291157. Eight bare digits, no prefix, no year, no bench code, no check digit. Indian tax and court references are structured and self-describing - an appeal before the Income Tax Appellate Tribunal reads like ITA No. 1234/Del/2025, and a notice issued through the department's ITBA system carries a long DIN encoding the section, the assessment year, and the issuing unit. A round eight-digit integer belongs to no Indian system. It was chosen to look like a reference to someone who has never read one.

5. "Nova DΓ©lhi Judicial Complex" Is Not a Place​

Two separate problems sit in that one line.

The spelling. Nova DΓ©lhi is the Portuguese rendering of New Delhi, accent and all. English writes New Delhi with no accent; Hindi transliteration produces no acute accent either; Spanish would give Nueva Delhi. That Γ© is the third Portuguese fingerprint on the message, and it survives in the venue line precisely because a find-and-replace targeting the words "Brazil" and "BrasΓ­lia" would sail straight past it.

The venue. Courts in Delhi have names, and every one of them is publicly listed. The Delhi High Court sits at Sher Shah Road. District courts sit at Tis Hazari, Patiala House, Karkardooma, Rohini, Saket, and Dwarka. Tax appeals go to the Commissioner (Appeals), then the ITAT, then the High Court. There is no "Nova DΓ©lhi Judicial Complex" - the phrase is a generic placeholder of the sort that appears in a template where the real venue is meant to be filled in later, and never was.

  • Related Document: https://taxation01jf.com/download/tax-documents1

Strip the nine lines of procedural set dressing and this URL is what remains. It is the only action available and the only reason the email was sent.

The domain is not a government domain. taxation01jf.com is an ordinary .com that anyone can register for a few hundred rupees with no verification of who they are. Indian government documents live on gov.in and nic.in, and income-tax notices specifically live inside your authenticated account on incometax.gov.in - not on an open web path that anyone with the URL can fetch.

The name is engineered for a glance, not a read. It opens with taxation, which is the word your eye is looking for, and the reader is expected to stop there. What follows is 01jf - a two-digit number and two random letters, the padding that gets appended when a plain word is already taken and a fresh, unblocked domain is needed for this wave of the campaign. The path tells the same story: /download/tax-documents1, numbered, because there is a tax-documents2 behind the next one.

Google has already seen where it goes. The red banner above the message is not a heuristic guess about tone or formatting. It reads: "It contains a suspicious link that was used to steal people's personal information." That is a statement about observed behaviour on a known-bad URL - the link has a history, and the history is credential and identity theft. When a mail provider moves from "this looks like spam" to "this link was used to steal", the question of what the page does has already been answered.

7. A Hearing You Are Never Actually Asked to Attend​

Look at what the notice does with its own hearing.

It gives a date, 25 August 2026, a time, 10:30 AM, and a venue. Then it stops. It does not instruct you to appear. It does not state what happens if you do not. It does not tell you how to seek an adjournment, file a reply, or appoint counsel. It does not attach the order, the summons, or a single page of case papers.

A summons exists for exactly one purpose: to compel attendance and to warn you of the consequence of absence. This one compels nothing. The hearing is not the point of the email; it is the pressure that carries the link.

The date is chosen with the same care. Fifteen days out is long enough to read as a genuine listing - real proceedings are scheduled weeks ahead, and a demand for action in the next hour would read as a scam to anyone. It is also short enough to make "I will look into this properly next week" feel unwise. Slow-burn urgency of this kind survives scrutiny far better than a 24-hour deadline, and it produces the same click.

8. "Please Share This Internally With the Finance Department"​

This is the most carefully written sentence in the message, and it is doing four jobs at once.

It recruits you as the delivery mechanism. The attacker has reached one mailbox and does not know whose. Rather than guess, he asks the person who received it to hand-carry the phish to the right target. A message forwarded internally by a colleague arrives without the external-sender banner, without the spam classification, and with an implicit endorsement it never earned. Your forward launders it.

It selects the highest-value recipients in the building. Finance is where payment authority, banking credentials, tax portal logins, PAN and GSTIN records, and vendor master data all sit. It is precisely the department a tax-themed lure is written for.

It lowers the temperature on purpose. "For reference purposes" asks nobody to do anything, and a request that demands no action attracts no scrutiny. The reader forwards it as housekeeping rather than escalating it as a threat, and somewhere down that chain a finance user opens the document because it arrived internally and looked routine.

It quietly covers a gap in the attacker's knowledge. He does not know the recipient's role, the company's name, or who handles its tax affairs. This one sentence outsources all three questions to the victim.

9. No Subject Line at All, and Gmail Had Already Ruled Twice​

The subject field is empty. A judicial notice announcing a hearing arrived with nothing in the line that a court reference, a case number, or the words "Judicial Notice" would occupy.

That is a deliberate choice, not an oversight. Subject lines are heavily weighted by spam classifiers, and phrases like "URGENT TAX NOTICE" score against the sender immediately. An empty subject scores nothing because there is nothing to score. The cost is that the message looks odd in the inbox list - and the calculation is that a reader who opens it anyway will be held by the body.

It did not work. Two verdicts sat above the text before a word of it was read:

  • Spam - the message was classified and filed on arrival, so it is visible at all only because someone went looking in the spam folder.
  • "This message might be dangerous. It contains a suspicious link that was used to steal people's personal information. Avoid clicking links or replying with personal information." - a red, full-width warning naming the specific mechanism.

Both fired automatically, correctly, and unaided. The only remaining path from this email to actual harm runs through a human being deciding to overrule them.


How This Scam Works​

The first email is a lure, not an attack. Nothing has been stolen when it lands in your inbox, and nothing will be until someone opens the link - which is why every stage below is built to move you from reading to clicking as quickly as possible.

  1. Take a Template That Already Works: Fake judicial and tax notices are a mature, high-yield genre in Brazil, where Receita Federal and court-summons lures circulate constantly. The template arrives with its structure proven: the box rules, the process number, the hearing block, the document link. Reusing it costs nothing and skips the hardest part of the job.
  2. Localise It Badly: Country, city, and department names are swapped by hand. Brasil becomes India, the currency and statute references are dropped rather than replaced, and the language is switched to English. Renda, Financeira, and the accent in DΓ©lhi survive, because a find-and-replace only changes what it was told to look for.
  3. Register a Disposable Domain: A plausible word plus random padding - taxation01jf.com - bought anonymously and used for one wave. It will be reported and blocklisted within days, which is expected and priced in.
  4. Open a Free Consumer Mailbox: An outlook.com or gmail.com account, with the authority's name typed into the display-name field. It passes SPF and DKIM for the free provider, which is exactly the point: the mail is technically well-formed and authentically sent, and only the identity claim is false.
  5. Blast It at Scraped Business Addresses: No subject line, no attachment, plain text only, sent to info@, accounts@, and contact@ addresses harvested from websites, WHOIS records, and directories. The message is not personalised because it does not need to be - a tax notice is frightening to everyone, and the operator is playing volume.
  6. Convert the Reader Into a Courier: The closing line asks the recipient to forward the mail to finance. This is the step that gets the phish through the perimeter, because the internal forward strips the warnings and adds a colleague's implicit trust.
  7. Land Them on the Page: The link leads to whichever of the two payloads the operator has configured. Either a credential harvester - a copy of the income tax e-filing login, a Microsoft 365 sign-in, or a "verify your identity to download the case file" form asking for PAN, Aadhaar, date of birth, and bank details - or a file download, where "tax-documents" arrives as a document that runs a macro or an installer. The URL path, /download/, points at the second, and Google's warning confirms the first has been observed. Many campaigns serve both, depending on the visitor.
  8. Use What Was Taken: Identity data supports fake refund claims, loan and credit applications, and the far more convincing follow-up call from "the department" quoting details only the department should know. Credentials support mailbox access, which supports invoice fraud - the attacker reads real supplier threads and inserts an altered bank account into one. Payloads support ransomware.
  9. Burn It and Rebuild: The domain is blocklisted, the mailbox is closed, and both are replaced within days. The template is permanent. Only the disposable parts are disposed of, and the next wave goes out as tax-documents2.

Conclusion and Recommendations​

There is no case, no hearing, no complex in Nova DΓ©lhi, and no Renda Tax Department. There is a Brazilian phishing template with India typed over the top of it, sent from a free Outlook mailbox to a scraped business address, wrapped around a link that Google has already watched steal people's personal information. Every procedural detail in the message - the process number, the date, the time, the venue - exists to make the link feel like something you are obliged to open.

It arrived less than a day after a forged Income Tax Department penalty notice reached the same organisation, also from a throwaway outlook.com mailbox, also pointing at a document download on an unrelated .com. Two different templates, the same week, the same playbook. Indian businesses are being worked systematically with tax-authority lures, and the volume is the strategy.

Immediate Actions:​

  • Do Not Open the Link: taxation01jf.com is the whole attack. Google has classified it as a URL used for stealing personal information, and there is no version of "just looking" that is free - a visit alone can fingerprint your browser, and the page is designed to make the next step feel natural.
  • Do Not Forward It, Least of All to Finance: The email asks you to do this by name. Forwarding it internally is the single action that removes every protection the mail system applied. If colleagues need to be warned, send them a screenshot in a separate message with the link removed, or raise it through IT.
  • Do Not Reply: There is no reply-to and no signature, but a reply to the sending address still confirms a live, attended, human-read mailbox at a real company - and that promotes you from a scraped string to a qualified target for hand-written attacks.
  • Leave It in Spam and Delete It: The filter was right. Marking it "not spam" to read it properly, or whitelisting the sender, trains the system against you.
  • Check Whether Anyone Already Clicked: This matters more than the email itself. Ask directly, without blame, because people conceal clicks out of embarrassment and the delay is what causes the damage. If someone did enter credentials, reset that password immediately, revoke active sessions, enable or re-verify MFA, and check mailbox rules for newly created forwarding or auto-delete rules - that is the first thing an attacker sets up after taking an account.
  • Report It: Forward phishing that impersonates the tax authority to webmanager@incometax.gov.in, copying CERT-In at incident@cert-in.org.in. For any incident involving loss or attempted fraud, use the National Cyber Crime Reporting Portal at cybercrime.gov.in or the helpline 1930. If money has moved, report within the first few hours - that window is when a transfer can sometimes still be frozen.

Verification Steps:​

  • Authenticate the Notice Where the Department Says To: The Income Tax e-Filing portal at incometax.gov.in has an "Authenticate Notice/Order Issued by ITD" service that validates a notice against its DIN. A genuine notice also appears inside your own account under e-Proceedings. If it is not in your account and it has no DIN, it is not from the department - and this one has neither.
  • Check the Domain After the @, Not the Name Before It: Renda Tax Department is typed text. damonapah@outlook.com is the sender. Make reading the address, not the display name, the reflex - it resolves the majority of impersonation attempts in one second.
  • Confirm the Authority Exists Before Engaging With Its Demands: Search the exact name of the issuing body. "Renda Tax Department" returns no Indian government entity, because there is none. This step takes less time than reading the notice did, and it ends the matter.
  • Read the Full URL, Slowly, Left to Right: The domain is everything before the first single slash - here, taxation01jf.com. The reassuring words after it are chosen by the attacker and mean nothing. Government documents come from gov.in or nic.in; a .com claiming to host a government file is disqualifying on its own.
  • Contact the Department Through a Number You Found Yourself: If a notice worries you, call the Income Tax helpline listed on the official portal, or your chartered accountant. Never use a phone number, email address, or link supplied inside the message you are trying to verify.
  • Search a Distinctive Phrase: Paste an exact line - "Investigating Authority: Renda Tax Department" - into a search engine. Templated campaigns appear verbatim on scam-reporting forums, and a phrase that returns nothing at all is equally informative.

Additional Protection Tips​

  • Teach the Team That "Signed By" Is Not "Verified As": Passing SPF, DKIM, and DMARC proves a message really came from the domain it claims. It proves nothing about the words in the display name. This email is a perfect specimen: fully authenticated, entirely fraudulent. Staff who believe a green authentication signal means a trusted sender are the ones this technique is built for.
  • Make "Forward It On" a Reportable Event: Attacks that ask to be circulated internally defeat perimeter controls by using your staff as the transport. Establish that suspicious mail goes to IT or security, never sideways to another department, no matter how reasonable the request in the message sounds.
  • Give People a Reporting Button and Never Punish Its Use: A one-click "Report Phishing" button in the mail client, plus a standing promise that reporting a click is met with help rather than blame, is worth more than any awareness poster. Attacks succeed in the hours between the click and the disclosure.
  • Expect Authority-Themed Lures to Peak Around Tax Deadlines: Filing seasons, GST return dates, and audit periods are when a tax notice is most plausible and least likely to be questioned. Brief finance teams in advance of those dates, not after an incident.
  • Enforce MFA on Every Mailbox and Portal Login: Phishing that harvests a password is neutralised if the password alone is not enough. Prefer app-based or hardware authenticators over SMS, and make MFA mandatory rather than optional for finance and administrative accounts.
  • Route All Government Correspondence Through One Named Owner: Decide in advance who verifies notices from tax, GST, labour, and regulatory bodies, and require that anything arriving in a shared mailbox reaches them unopened and unforwarded. This removes the well-meant individual click that starts the sequence.
  • Verify Bank Detail Changes Out of Band, Always: The most profitable outcome of a mailbox compromise is a redirected supplier payment. A callback to a number already on file, made to a person you know, before any account change is actioned, defeats it - and it costs two minutes.
  • Reduce What Can Be Scraped: Published info@ and accounts@ addresses end up on lists like this one permanently. Contact forms, role-based aliases, and WHOIS privacy limit the exposure, and accepting that a public address will receive this traffic is part of planning for it.

Remember: No government in the world serves a legal notice by unsigned email from a free consumer mailbox, and no tax authority asks you to fetch your own case file from a .com domain. Real notices name you, cite the law, carry a reference you can authenticate on an official portal, and tell you what happens if you ignore them. When a notice names everything except the person it is against, the notice is not about you at all - it is about the link.


Share this post