iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Cybercriminals widen net as assessees rush to meet I-T return filing deadline

Cybercriminals widen net as assessees rush to meet I-T return filing deadline

Cybercriminals are exploiting India's income-tax return filing season by sending forged department notices over WhatsApp and setting up phishing sites that clone the official e-filing portal, according to Bengaluru-based security firm CloudSek. The attacks use malware-laden ZIP attachments and fake login pages to steal banking credentials, OTPs and Aadhaar/PAN data.

iG
iGEN Editorial
August 1, 2026
Cybercriminals widen net as assessees rush to meet I-T return filing deadline

Cybercriminals are exploiting the income-tax return (ITR) filing season in India by sending forged tax department notices over WhatsApp and other messaging platforms, according to a report by Bengaluru-based cybersecurity firm CloudSek. TNN reported that the campaign comes at a time when millions of taxpayers are expecting messages related to refunds, notices and compliance deadlines, making them more likely to trust official-looking communications.

Forged notices and malware ZIPs target Android users

In the WhatsApp campaign documented by CloudSek, victims receive an “office memorandum” from an unknown or compromised account masquerading as the income tax department. The forged document features the government of India emblem, bilingual English and Hindi text, fabricated reference numbers and the name of a fake tax official to appear authentic, CloudSek reported. The notice falsely claims that discrepancies have been detected under Sec 271(1)(c) of the Income Tax Act and warns of prosecution under Sec 276C, giving recipients just 72 hours to respond.

Instead of including a web link, the message carries a ZIP attachment named “ITD.zip”, presented as tax documents. On Android devices, opening the file installs malware capable of accessing SMS messages, including banking one-time passwords (OTPs), contacts and keystrokes. The malware can also overlay fake login screens on banking and payment applications to capture usernames, passwords, and other sensitive information, CloudSek detailed.

Phishing sites clone the official e-filing portal

In a parallel campaign, fraudsters direct users to websites designed to closely resemble the official income-tax e-filing portal, according to CloudSek. These fake sites prompt users to enter PAN number, Aadhaar, passwords, OTPs, and bank account details, the firm reported. The report said attackers are using two primary methods: malware-laden WhatsApp attachments and phishing websites that closely mimic the official income-tax e-filing portal.

Two attack vectors compared

CloudSek’s report describes the two primary attack channels and the data each targets:

Feature WhatsApp malware campaign Phishing portal campaign
Delivery channel WhatsApp and other messaging platforms Websites resembling the official e-filing portal
Lure Forged “office memorandum” from the income tax department Clone of the official income-tax e-filing portal
Document features Govt of India emblem, bilingual text, fabricated reference numbers, fake official, Sec 271(1)(c), Sec 276C, 72-hour deadline N/A
Payload ZIP attachment “ITD.zip” installing Android malware Fake login pages
Data targeted SMS, banking OTPs, contacts, keystrokes, bank/payment app credentials PAN number, Aadhaar, passwords, OTPs, bank account details

The forged notice’s 72-hour response window and the threat of prosecution under Sec 276C are designed to pressure recipients into opening the ZIP attachment without verifying the source, according to the CloudSek report. The campaign’s use of a ZIP file rather than a web link demonstrates how attackers are adapting delivery mechanisms, the report indicated.

CloudSek’s findings were reported by TNN as assessees rushed to meet the I-T return filing deadline. The firm said the campaign relies on official-looking branding — government emblems, legal references and department names — to convince taxpayers that the messages are genuine.


Sources: Business-Today

Keep Reading

Recommended Stories

World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains Technology

World Cup Scams Are Getting Harder to Spot as AI Fuels Surge in Fraudulent Domains

The 2026 FIFA World Cup has triggered an unprecedented wave of sophisticated scams, with AI-generated websites and phishing campaigns making fraud harder to spot. More than 13,000 FIFA-themed domains were registered in early 2026, with roughly one in 41 identified as malicious. Cybersecurity firms warn that AI is both enabling attackers and powering defenses, but collaboration and human vigilance remain critical.

June 22, 2026
North Korean Phishing Scheme Targets Developers for Crypto Theft Technology

North Korean Phishing Scheme Targets Developers for Crypto Theft

A North Korean phishing campaign, led by the group UNK_DeadDrop, targets developers with fake job offers to steal cryptocurrency. This operation mirrors tactics used by Lazarus but employs email-based lures and new payloads.

June 9, 2026
5.9 crore income tax returns filed by July 31 deadline, says I-T department Business

5.9 crore income tax returns filed by July 31 deadline, says I-T department

The Income-tax Department reported 5.9 crore returns filed by July 31, the annual deadline for most individuals. The tally is lower than the over 7.3 crore filings recorded by last year's extended deadline on September 16, 2025. Returns are still accepted until December, with penalties, and business-income filers face later deadlines.

August 1, 2026
India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky Technology

India Records Highest Mobile Threat Detections Among 8 Asia-Pacific Markets in Q1 2026: Kaspersky

India logged the most mobile threat detections among eight Asia-Pacific markets in Q1 2026, with 18,187 cases, ahead of Indonesia's 15,163. Kaspersky also reported a 49% year-on-year rise in average detections per affected user, alongside a resurgence of the Rewardsteal and Thamera trojans.

August 27, 2026