is that a scam?
← Back to all scams
HIGH tax Share

Hacker changes your Income Tax e-filing account details and claims a fake refund in your name

Cybercriminals hack NRI and resident IT e-filing accounts, change the registered email, mobile, and bank account, then file a forged revised return to divert a large fraudulent refund to a mule account. Victims only discover it when they receive an IT notice.

Also known as: income tax e-filing account hack, NRI tax refund fraud, ITR account takeover, fake revised IT return fraud

What to do right now

  1. 1 Log in to incometax.gov.in immediately and check your registered email, mobile number, and bank account — change any that you did not set
  2. 2 Check your filed returns: any 'revised return' you did not submit is a red flag — contact your CA or the IT Department helpline at 1800-103-0025
  3. 3 If a fraudulent refund has been credited, report to your Assessing Officer immediately and file a complaint at https://cybercrime.gov.in or call 1930
  4. 4 Enable two-factor authentication on your income tax portal login if available
  5. 5 Check your linked Aadhaar and PAN details for unauthorised changes on https://www.incometax.gov.in/iec/foportal/help/all-topics/verify-your-identity
  6. 6 Report at https://cybercrime.gov.in or call 1930 (national cyber helpline).

Red flags

  • You receive an IT notice for a 'revised return' you never filed — this is the primary warning sign
  • Your registered email or mobile on the income tax portal suddenly changes without your knowledge
  • Refund status shows 'credited' to an account number you do not recognise
  • You are an NRI who has not checked your income tax login for several months — this gap is specifically exploited
  • You receive a phishing email or SMS claiming to be from the IT Department asking you to 'update bank details' for refund — this is the typical initial access step

Known variants

  • July deadline phishing surge (2026): fake ITR incomplete and refund pending SMS/email campaigns spike in July. Lookalike domains (incometax-refund.in, itr-filing-portal.net) harvest portal credentials before the July 31 deadline. Attackers then change registered email, mobile, and bank details and file a fraudulent revised return.

    Last seen: 7/30/2026

Sources

Share this with someone who might need it