Phishing: कर अनुपालन की कमी और दंड सूचना / Tax Compliance Deficiency and | Fake Income Tax Department Penalty Notice
The tax inspection of your company has revealed irregularities under Section 271(1)(c) of the Income Tax Act, 1961. The same forged Income Tax Department notice we dissected a month ago, rewritten to remove its worst mistakes and pointed at a convincing lookalike domain registered in Indonesia.
Complete Email
from: Raj Kumar Sharma fanniepwkm@outlook.com
reply-to: estefanyfortdelapue@vfemail.net
date: 09/07/2026 9:55 AM
subject: कर अनुपालन की कमी और दंड सूचना / Tax Compliance Deficiency and
Mailed by: outlook.com - Signed by: outlook.com
The subject line is truncated exactly as shown — it ends mid-phrase on the word "and". Its full form, कर अनुपालन की कमी और दंड सूचना / Tax Compliance Deficiency and Penalty Notice, appears as the Sub: line of the earlier version of this same notice, and that is where it came from.
Email Body
No. TAX/PEN/2025-142
भारत सरकार / Government of India
वित्त मंत्रालय / Ministry of Finance
आयकर विभाग / Income Tax Department
प्रवर्तन प्रभाग / Enforcement Division
Aayakar Bhawan,
New Delhi - 110001
आपकी कंपनी की कर निरीक्षण के दौरान आयकर अधिनियम, 1961 की धारा 271(1)(c) के तहत कर संबंधी अनियमितताएं पाई गई हैं। The tax inspection of your company has revealed irregularities under Section 271(1)(c) of the Income Tax Act, 1961.
आपकी कंपनी के लिए यह अनिवार्य है कि वह इस सूचना की प्राप्ति के 72 घंटे (3 दिन) के भीतर आयकर विभाग को निम्नलिखित विस्तृत दस्तावेज़ प्रस्तुत करे। It is mandatory for your company to submit the following detailed documents to the Income Tax Department within 72 hours (3 days) of receipt of this notice:https://www.incometax.my.id
कृपया इस दस्तावेज़ को सत्यापन के लिए अपनी कंपनी के वित्तीय प्रबंधक को अग्रेषित करें। Please forward this document to your company's Finance Manager for verification.
कृपया ध्यान दें कि निर्धारित नियमों का पालन न करने पर एकपक्षीय निर्णय लिया जा सकता है। Please note that failure to comply with the requirements may result in a unilateral decisiona.
Where the link actually goes:
The one hyperlink in the message, jammed directly onto the end of the word notice: with no space, points at:
https://www.incometax.my.id
![]()
Red Flags
This is government-impersonation phishing, and we have met it before. On 9 August 2026 we dissected an Income Tax Department "Audit Notification" that carried the same officer's name, the same allegation, the same penalty section, and the same 72-hour clock. This message, arriving four weeks later, is that notice again.
But it is not a copy. It has been edited, and the edits are the most interesting thing about it.
The August version was a sprawling office memorandum riddled with tells: emoji in a government letterhead, a date two months stale, a prosecution threat under the wrong section, a signature block with no jurisdiction, a public-circular ending pasted onto a private penalty notice, and a Hindi header missing the word भारत. Nearly all of that is gone. What remains is four short paragraphs, correct Hindi, no emoji, no self-contradicting boilerplate — and a link that no longer goes to a Chinese gaming domain but to something that reads, at a glance, like the Income Tax Department's own website.
Read the two side by side and you are watching an attacker iterate. The noise has been cut and the deception has been sharpened. That makes this version harder to dismiss and more worth understanding, because the things that still give it away are now the only things left.
There are eight of them, and every one survives the rewrite.
1. The Link Is the Upgrade — And It Leads to Indonesia
- Destination:
https://www.incometax.my.id
This is the single most important change from August, and it is the reason the campaign is more dangerous now.
The old link went to chuanqiweb.com — a Chinese gaming-adjacent domain with no path, so obviously unrelated to Indian taxation that noticing it required no expertise at all. The new one is a deliberate lookalike. It opens with the word incometax, carries a www., and ends in a two-letter country-style suffix after a short second level. Skimmed on a phone, it produces the shape of an official portal.
It is not one. Break the domain apart from the right, which is the only direction that matters:
.idis Indonesia's country-code top-level domain. Not India. India's ccTLD is.in.my.idis a second-level namespace within Indonesia's registry, opened for personal and individual use. It is among the cheapest domains available anywhere, registrable in minutes by anyone in the world with no verification of identity, organisation, or country.incometaxis therefore not a name that was assigned to anyone. It is a word that was still available for a few dollars, in a namespace where any word is.
Now compare that with what a genuine address looks like. Every Government of India web property lives under gov.in or nic.in, and the department's own properties are incometax.gov.in for the e-Filing portal and incometaxindia.gov.in for the department site. Registration in gov.in is restricted to verified government bodies and processed through the National Informatics Centre. That restriction is the entire security value of the suffix. No attacker can obtain a gov.in domain, which is precisely why they must build something that resembles one.
So the test is not "does the domain contain the words I expect?" — an attacker chooses those words. The test is what the address ends in, because that is the only part they cannot forge:
incometax.gov.in | The Government of India. Restricted registry, verified applicant. |
incometax.my.id | An individual, somewhere in the world, who paid for a personal Indonesian domain. |
The two strings differ by six characters and by everything else.
There is a second, quieter reason this change matters. A bare root URL on an unrelated Chinese host, as in August, is most naturally a malware drop. A lookalike domain carrying the impersonated brand in its own name is the classic infrastructure of a credential-harvesting portal — a counterfeit e-Filing sign-in page collecting PAN, password, and the OTP that follows. The domain will carry a valid TLS certificate and show a perfectly normal padlock, because certificates are free and attest to nothing but that the connection is encrypted. A padlock certifies the pipe, not the party at the other end of it.
2. Three Different People Sent This Email
- Display name: Raj Kumar Sharma
- From:
fanniepwkm@outlook.com - Reply-To:
estefanyfortdelapue@vfemail.net
A genuine message has one sender. This one presents three unconnected identities in a header two lines long.
The display name is free text. "Raj Kumar Sharma" is typed by the sender and verified by nobody. In the August notice this same name appeared at the bottom as the signing officer, "सहायक आयकर आयुक्त / Assistant Commissioner of Income Tax". Here the signature block has been deleted and the name promoted into the from: field — which is a meaningful move, because the display name is what most mail clients show and most phone clients show instead of the address.
The address is a free consumer mailbox. fanniepwkm@outlook.com is a disposable Outlook account, and the local part is a random string with no relationship to Raj Kumar Sharma, to any tax office, or to anything at all. The Government of India does not correspond from outlook.com. That single fact ends the enquiry before the letterhead is worth reading.
And the reply-to belongs to a third party entirely. estefanyfortdelapue@vfemail.net shares nothing with either of the other two — not the name, not the language, not the provider. vfemail.net is a free, privacy-oriented mail service of the kind chosen when the point is to not be identified.
That reply-to is worth pausing on, because it is new. In the August version the reply-to matched the from address exactly. Here they diverge, and the divergence is deliberate: the mailbox that sends is disposable, and the mailbox that receives is the one the attacker actually watches. Outlook accounts sending bulk mail get suspended quickly. Splitting the two means the campaign keeps running when the sending account dies, and any reply — including a suspicious recipient writing back to ask whether the notice is genuine — lands somewhere the attacker still controls.
Mailed by outlook.com, signed by outlook.com confirms only that Microsoft's servers really did send it. SPF and DKIM authenticate the transport, not the claim. The message is authentically from an Outlook account. It is not from the Income Tax Department, and no amount of passing authentication will ever make it so.
3. The Notice Asks You to Forward It to Your Finance Manager
- कृपया इस दस्तावेज़ को सत्यापन के लिए अपनी कंपनी के वित्तीय प्रबंधक को अग्रेषित करें। — Please forward this document to your company's Finance Manager for verification.
This sentence does not appear in the August version. It is the most sophisticated addition in the rewrite, and it is doing three jobs at once.
It launders the message through you. An email from fanniepwkm@outlook.com arrives at the finance team wearing every warning a mail gateway can attach: external sender, unknown domain, spam classification. The same email, forwarded by a colleague from an internal address, arrives with none of them. It is inside the perimeter, it comes from someone the recipient knows, and it carries an implicit endorsement — somebody looked at this and thought it needed acting on. The attacker is asking the target to carry the payload past their own organisation's defences, and the request sounds so much like ordinary office procedure that complying feels like diligence.
It routes the attack to the person who can act on it. Whoever opens info@ or a support mailbox cannot pay anything or file anything. The Finance Manager can. The instruction is a targeting correction applied by hand, after the fact, by an attacker who scraped a generic address and knows it is the wrong one.
And it borrows the word "verification" to prevent verification. Read it closely: you are told to send the notice to a colleague for verification. That sounds like a check. It is the opposite of one. Verification of a tax notice does not mean a second person reading the same email — it means logging in to incometax.gov.in and looking for it under e-Proceedings, which is a check the attacker cannot survive. The sentence substitutes an internal glance for an external test, and if two people inside the company both glance and both feel reassured that the other is handling it, the message has manufactured consensus out of nothing.
If you receive this, the forwarding instruction is a red flag, not an errand. A government department that wanted your Finance Manager to have a notice would send it to your Finance Manager. It knows who they are; the registered contact is in your e-Filing profile. It does not need you as a courier.
4. The Letterhead Fails Every Check That Can Be Made Against It
Four separate failures sit in the first six lines, and each is independently decisive.
There is no Document Identification Number. This is the single most powerful test available for any Indian tax communication, and it is worth knowing precisely. Since 1 October 2019, under CBDT Circular No. 19/2019, every notice, order, summons, letter, and correspondence issued by any income-tax authority must carry a computer-generated DIN. The circular states the consequence without qualification: a communication issued without a DIN is treated as invalid and deemed never to have been issued. This message carries none. It offers no reference that can be authenticated on the e-Filing portal — which is exactly the facility the DIN system was created to provide. A real notice invites verification because it survives verification.
The reference number it does carry is invented, and it is dated last year. No. TAX/PEN/2025-142 is new in this version — added, presumably, to fill the void where the DIN should be. But it is an English mnemonic, TAX for tax and PEN for penalty, of the kind a person makes up when they want a document to look filed. Real departmental references are machine-generated and follow the Income Tax Business Application format, something in the shape of ITBA/PNL/S/271/2026-27/ followed by a long numeric sequence. Note also the year: a 2025 reference on a notice sent in September 2026, describing an inspection in the present tense. The August version of this campaign was dated two months before it was sent. The same carelessness with dates has survived into the rewrite, merely relocated.
"Enforcement Division" does not exist. The letterhead reads प्रवर्तन प्रभाग / Enforcement Division. There is no such division of the Income Tax Department. The attacker has fused two entirely separate bodies: the Income Tax Department, under the Central Board of Direct Taxes, which administers direct taxation; and the Enforcement Directorate, a distinct agency under the Department of Revenue dealing with foreign-exchange and money-laundering matters. The hybrid sounds more menacing than either real body, which is why it was chosen. A genuine notice names a Ward or Circle — "Circle 4(1), Delhi" — because that is how jurisdiction over a taxpayer is actually assigned, and because you are entitled to know which officer holds your file.
And the address names no office. Aayakar Bhawan, New Delhi - 110001 is a real building name, used for income-tax offices in cities across India, quoted here with no floor, no room, no ward, no telephone number, and no officer. It is the address equivalent of writing "the office". Every element of this letterhead is a real-sounding word placed next to another real-sounding word, and not one of them narrows down to a place you could visit or a person you could call.
5. Section 271(1)(c) Has Not Applied to Any Assessment Since April 2017
- आयकर अधिनियम, 1961 की धारा 271(1)(c) के तहत — under Section 271(1)(c) of the Income Tax Act, 1961
The legal citation is the one thing the rewrite did not touch, and it remains wrong.
Section 271(1)(c) penalised concealment of income and the furnishing of inaccurate particulars. It carries an express proviso stating that the sub-section shall not apply to any assessment for the assessment year commencing on or after 1 April 2017. For every year since, the governing provision is Section 270A, which deals with under-reporting and misreporting of income on an entirely different basis and scale.
An officer of the Income Tax Department raising a fresh penalty proposal in September 2026 under 271(1)(c) would be invoking a provision that has been inapplicable for nine assessment years. It is not a technicality and it is not a matter of interpretation — the exclusion is written into the section itself.
The reason it is there is visible in its own popularity. Search for "income tax penalty section" and 271(1)(c) is what you find, because decades of case law, commentary, and appellate decisions reference it. The attacker picked the most-cited section, not the applicable one — which is the difference between quoting law and knowing it.
That the error survived a rewrite which fixed the Hindi, removed the emoji, deleted the wrong prosecution threat, and upgraded the domain is itself informative. The attacker corrected the things that looked wrong. They could not correct the things that were wrong, because that would have required understanding the law they are impersonating. Presentation improved; substance could not.
6. "The Following Detailed Documents" — And Then No Documents
- It is mandatory for your company to submit the following detailed documents to the Income Tax Department within 72 hours (3 days) of receipt of this notice: — followed by a URL, and nothing else.
Read the sentence to its end. It promises a list. The colon is there, the grammar is braced for an enumeration, and then the enumeration never comes. In its place sits a link.
This is the whole attack, in one broken sentence. The August version at least maintained the fiction: it announced a "📋 आवश्यक दस्तावेज़ सूची / Required Documents List" and offered a download button, so the click had a stated purpose. That scaffolding has been stripped out and nothing replaced it, leaving the pretext load-bearing but absent. The message demands documents from you and then hands you a website, and the two halves of that instruction have no logical connection whatsoever.
The inversion underneath is the same one that gave the August notice away. A department demanding records from you has no reason to send you anywhere. If the Income Tax Department wants your books, the submission happens where the proceeding already exists — inside your e-Filing account, under e-Proceedings, against a notice you can see, authenticate, and respond to. It does not happen at a domain you have never heard of, and it certainly does not begin with you visiting one.
Two smaller production faults sit in the same two sentences and point the same way. The URL is jammed directly onto the word notice: with no space, which is what happens when a link is pasted into a template by a script rather than typed by a person. And the closing sentence ends on "a unilateral decisiona" — a stray letter left on the last word of the message. The Hindi in this version is competent and the English is largely clean, which makes the leftover keystroke more revealing rather than less: nobody read this document through before sending it. A notice that could send your company into penalty proceedings was not proof-read once.
7. 72 Hours, and a Consequence That Does Not Exist
- इस सूचना की प्राप्ति के 72 घंटे (3 दिन) के भीतर — within 72 hours (3 days) of receipt of this notice
- एकपक्षीय निर्णय लिया जा सकता है — may result in a unilateral decision
The deadline is not a lawful one. Statutory notices under the Income Tax Act specify a compliance period measured in days or weeks — commonly 15 or 30 — and always state a calendar date, because a deadline that runs from "receipt" is unenforceable when the department cannot establish when receipt occurred. More fundamentally, Section 274 requires that no penalty be imposed without giving the assessee a reasonable opportunity of being heard. A three-day ultimatum, delivered by email, with no hearing date, no officer to appear before, and no case number to quote, is the precise opposite of that requirement.
The threatened consequence is emptier still. "Unilateral decision" is not a term in Indian tax law. No section provides for it, no notice threatens it, and no order is described as one. The nearest real concept is a best judgment assessment under Section 144, where an assessing officer determines liability on available material — and even that cannot be made without first issuing a show-cause notice giving the taxpayer an opportunity to explain.
Notice what has happened here between versions. The August notice threatened prosecution under Section 276C, which was the wrong section but at least a real one, and specific enough to check. This version has replaced it with a vague menace that names no provision at all. That is not a softening — it is a defensive edit. A specific false claim can be looked up and disproved; a vague one cannot. The threat has been made less checkable while remaining just as frightening, and that trade is the same instinct visible everywhere else in this rewrite.
The 72 hours exists for one purpose regardless of its legality: to close the gap between reading and clicking before anyone telephones their chartered accountant. Every fabricated deadline is a bet against a phone call.
8. Nothing in It Identifies You, and Nothing Identifies the Sender
Count what a genuine penalty notice must contain, and then count what is here.
About the recipient, the message contains: no company name, no PAN, no TAN, no assessment year, no date of the alleged inspection, no description of the irregularity, no amount, and no case number. It says "your company" four times and never once demonstrates knowledge of which company that is. There is no greeting and no addressee at all — the message opens directly on a reference number. Not one identifier appears that would let you look the matter up, because the attacker knows none of them. This went to a scraped address list, and the phrase "your company" is doing the work that a name would do in a real notice.
About the sender, after the signature block was deleted in this rewrite, there is now nothing whatsoever: no officer, no designation, no ward, no circle, no employee code, no telephone number, no departmental email. The August version at least signed itself. This one asserts the authority of the Government of India and then declines to say who is exercising it.
And there is a structural fact that settles all of this independently of anything above. A real notice is never only in your inbox. The Income Tax Department writes to the email registered against your PAN in the e-Filing profile, and every genuine notice appears simultaneously in the portal under e-Proceedings, where it can be read, authenticated by its DIN, and responded to. That portal copy is the whole point of the system: if a notice is real, it is on the portal. If it exists only in an email, it is not a notice — and checking takes under a minute, from a browser tab you open yourself.
Gmail, for its part, had already reached the same conclusion by a different route and filed the message in Spam before anyone read it.
How This Scam Works
The notice is not the attack. It is a short, official-looking justification for one click, and the four paragraphs exist only to make that click feel like compliance rather than risk. What makes this specimen worth studying is that it is the second draft of a campaign we have already seen, and every change between drafts tells you what the attacker learned.
- The List: Company addresses are harvested from websites,
WHOISrecords, and business directories. No PAN, no assessment year, and no company name are known — which is why none appear, and why the notice says "your company" instead of naming one. - The Authority: A Government of India letterhead with a ministry, a department, and a division. Indian businesses treat tax correspondence as non-negotiable, and that reflex fires long before anyone examines a sender address.
- The Accusation: "The tax inspection of your company has revealed irregularities." No inspection occurred, but the claim cannot be disproved from the reader's chair, and it produces exactly the flustered, faintly guilty state the attacker needs.
- The Clock: 72 hours, with no hearing, no officer to call, and no case number to quote. There is no path to compliance except the link — which is the entire function of the deadline.
- The Refinement: Between August and September, the obvious tells were sanded off. The emoji went, the stale date went, the wrong prosecution threat became a vague one, the Hindi was corrected, and the sprawling memorandum was cut to four paragraphs. Nothing was added to make the notice true; things were removed to make it harder to falsify.
- The Lookalike: The link is upgraded from an unrelated Chinese host to
incometax.my.id— a personal Indonesian domain wearing the department's name. It costs a few dollars, needs no verification, and will serve a padlock in the address bar. - The Referral: "Please forward this to your Finance Manager." The target is asked to carry the message past their own gateway and hand it, internally and implicitly endorsed, to the one person able to act on it.
- The Portal: The link resolves to a counterfeit e-Filing sign-in page. It asks for PAN and password, then for the OTP sent to the registered mobile — captured in real time and replayed into the genuine portal while the victim waits on a loading screen.
- The Harvest: An e-Filing login exposes returns, financial statements, bank account details, TDS records, and the full identity profile behind the PAN. On some infrastructure the same page also offers a "documents" archive, delivering an information stealer to anyone who prefers downloading to typing.
- The Use: Stolen credentials enable fraudulent refund claims and return amendments, but the more valuable product is the intelligence. Real financial data makes the next approach specific — and a second notice quoting your actual PAN, your real turnover, and a genuine assessment year is a far harder message to dismiss than this one.
- The Payment: In the variant that runs to completion, the fake portal or a follow-up call presents a penalty to be settled immediately to avoid the "unilateral decision", with account details supplied. Genuine tax payments are only ever made through the e-Filing portal's own payment gateway or authorised bank channels, never to an account quoted in an email.
Conclusion and Recommendations
There was no inspection, no irregularity, and no notice. There is a free Outlook mailbox, a reply address at an anonymous mail service, a letterhead assembled from real-sounding fragments that identify no office, a penalty section that stopped applying in 2017, and a personal domain in Indonesia dressed up as the Income Tax Department.
The instructive part is what changed since August. The attacker fixed the Hindi, deleted the emoji, removed the self-contradicting boilerplate, dropped the section they had cited incorrectly, and bought a domain that actually resembles the thing they are impersonating. Every one of those edits improved the disguise. Not one of them made the notice more true. Section 271(1)(c) is still inapplicable, there is still no Enforcement Division, there is still no DIN, and the notice still exists nowhere but in an inbox — because those are facts about Indian tax administration, and no amount of redrafting reaches them.
That is the durable lesson, and it is worth more than any list of tells. Cosmetic flaws get fixed between campaigns; structural ones cannot be. A defence built on spotting typos and clumsy translations expires the moment the attacker hires a better writer. A defence built on the notice is not on the portal, the domain does not end in gov.in, and there is no DIN survives every rewrite, because those checks test things the attacker has no power to change.
Immediate Actions:
- Do Not Click the Link:
incometax.my.idis not the Income Tax Department. Do not open it to "just have a look" — a lookalike login page can capture credentials from a single hurried autofill, and a valid TLS padlock will be sitting in the address bar the whole time. - Do Not Forward It: The message explicitly asks you to send it to your Finance Manager. Forwarding strips every external-sender warning and delivers the attack from a trusted internal address to the one person who can act on it. If you want finance to know, tell them about the phishing attempt — do not pass on the email as though it were a notice.
- Do Not Reply: The reply-to is a third, anonymous address at a free provider. Any response — including one asking whether the notice is genuine — confirms a live, human-attended mailbox and marks your address as worth pursuing.
- Check the Portal Instead, and Check It Yourself: Open a browser, type
incometax.gov.in, log in, and look under e-Proceedings. If a notice is real it is there, with a DIN you can authenticate. Ninety seconds, and it settles the question permanently. Never navigate from a link in the message. - Report and Delete: Use your mail client's phishing report rather than plain deletion, so the sender is scored and, on a corporate system, your security team sees the campaign. Government-impersonation phishing can also be reported to India's National Cyber Crime Reporting Portal at
cybercrime.gov.in, or the1930helpline. - If Anyone Has Already Entered Credentials: Change the e-Filing password immediately from a known-good device, check the portal's login history and any registered contact details for unauthorised changes, review recent returns and refund claims for amendments you did not make, and inform your chartered accountant. Speed matters most in the first hour, while a captured OTP is still the attacker's only foothold.
- Warn Whoever Else Received It: This is a bulk campaign — the same message is landing on other mailboxes in your organisation and in companies you work with. Thirty seconds of warning to a shared mailbox is worth more than a policy document.
Verification Steps:
- Read the Domain From the Right: The suffix is the only part an attacker cannot forge.
incometax.gov.inis the Government of India;incometax.my.idis a personal Indonesian domain that happens to begin with the same word. A brand name at the front of a URL is decoration. The registry at the end of it is the fact. - Demand the DIN: Any income-tax communication issued since 1 October 2019 without a computer-generated Document Identification Number is invalid and deemed never issued, by the department's own circular. No DIN, no notice — and a DIN can be authenticated on the e-Filing portal in seconds.
- Look for It on the Portal: Genuine notices appear under e-Proceedings, not merely in email. This is the strongest single test available, it requires no expertise, and it cannot be defeated by a better-written email.
- Read the Display Name Against the Address, Then Both Against the Reply-To: They should describe one sender. "Raj Kumar Sharma", an
outlook.comaccount, and avfemail.netreply address are three unrelated answers to "who sent this?" — all visible in the header before the message is opened. - Ask What the Sender Knows About You: A real notice names your company and quotes your PAN, the assessment year, and a case number, because those are how the proceeding exists in the department's own records. "Your company" repeated four times with no identifier anywhere proves the sender holds nothing but a scraped email address.
- Check the Section Against the Year: Cited provisions can be looked up in minutes, and fraudulent notices consistently reach for the most-quoted section rather than the applicable one. Section 271(1)(c) has not applied to any assessment year since 2017-18; Section 270A replaced it.
- Treat a Forwarding Instruction as a Warning: No government department asks you to relay its notices internally. It writes directly to the contact registered against your PAN. A message that wants to be passed along is a message that wants to shed the warnings attached to it.
- Verify Through a Route You Already Had: Your chartered accountant, your existing assessing officer, the portal you log into yourself. Never a link, address, or phone number supplied by the message being checked.
Additional Protection Tips
- Learn the Structural Checks, Not the Cosmetic Ones: This campaign fixed its Hindi, dropped its emoji, and bought a better domain in four weeks. Typos, awkward translations, and ugly formatting are the first things an attacker improves. Registry suffix, DIN, and portal presence are things they cannot improve, which is why those three are the whole defence and everything else is a bonus.
- Expect Second Drafts: A campaign that reaches inboxes will be run again, refined. If your organisation has seen a fraudulent notice once, the version that arrives next month will be cleaner, and the people who dismissed the first one on the strength of its clumsiness will have no reason to dismiss the second. Record what made it fake, not what made it look fake.
- Treat Tax, Legal, and Regulatory Threats as the Highest-Risk Category: Government impersonation works on Indian businesses because the cost of ignoring a genuine notice is severe and everybody knows it. That asymmetry is the leverage. The archive holds the Audit Notification and the fictitious "Renda Tax Department" working the identical instinct with different scenery.
- Never Let a Deadline Choose Your Response Time: 72 hours is not a legal period, it is a pressure device. Any message whose urgency exceeds the urgency of the underlying matter should slow you down rather than speed you up. A real deadline survives a phone call; a fabricated one is destroyed by it.
- Route All Tax Correspondence Through One Named Person: Notices arriving at
info@,support@, orsales@are, by definition, not from the department — it writes to your registered address. Establishing that every tax communication reaches finance through one channel means an approach on any other channel identifies itself as fake automatically. - Give Finance a Standing Rule About Forwarded Notices: An internally forwarded email carries no verification, however much it feels like it does. Any tax or payment notice must be confirmed on the portal by the person acting on it, regardless of which colleague passed it along — because "someone else looked at this first" is precisely the assumption this campaign is built to exploit.
- Enable Multi-Factor Authentication and Understand Its Limit: MFA on the e-Filing account and on every mailbox is essential, but a real-time phishing portal will ask for the OTP and replay it within seconds. MFA raises the cost of an attack; it does not remove the need to check where you are typing. Never enter a code on a page you reached by clicking.
- Adopt a Two-Person Rule for Money Leaving the Business: Any payment to a new beneficiary, any change of bank details, and any penalty or fee attached to an unexpected demand should require a second approval and a voice call to a number from your own records. These schemes depend on one person acting alone under time pressure.
- Make It Safe to Say "I Clicked It": The window to contain a stolen credential is measured in minutes, and shame is what closes it. A workplace where someone can report a mistake immediately, without consequence, recovers accounts that a workplace built on blame loses entirely.
Remember: A genuine tax notice can be found on the portal, authenticated by its DIN, and traced to a named officer with jurisdiction over your file; it does not arrive from a consumer mailbox, ask to be forwarded, or send you to a domain someone bought last week. When a message that claims government authority can only be verified by following its own link, the link is the message's real purpose — and the authority is the costume.
