Michael Cooney
Senior Editor

IRS issues e-mail scam alert

Opinion
Nov 2, 20073 mins

The IRS today warned the Internet community of a new scam e-mail that appears to be a solicitation from the IRS and the U.S. government for charitable contributions to victims of the recent Southern California wildfires has been making the rounds.

In some cases in an effort to appear legitimate, the bogus e-mails include text from an actual speech about the wildfires by a member of the California Assembly.

A link in the e-mail, when clicked, sends the e-mail recipient to a Web site that looks like the IRS Web site, but isn’t. They are then directed to click on a link that opens a donation form that asks for personal and financial information. The scammers can use that information to gain access to the e-mail recipient’s financial accounts.

The IRS does not send e-mails to taxpayers soliciting contributions to a charitable cause, the agency said on its Web site.

Recipients of the scam e-mail can help the IRS shut down the scheme by forwarding any e-mails to phishing@irs.gov.

The FBI, Better Business Bureau and California prosecutors last week issued warnings concerning potential disaster related fraud schemes in connection with the Southern California wildfires. Many of these schemes are Internet-based scams representing themselves to be disaster relief charities, the groups said.

It is a sad truth that following other tragic events like 9/11, Hurricanes Katrina and Rita, the Virginia Tech shootings, and the collapse of the Minneapolis bridge, dirtbags with criminal intent to solicit for contributions for a charitable organization and/or a good cause.

Given the recent wildfires in Southern California, consumers should be cautious before contributing to an unknown or unfamiliar charity, the FBI said.

In related news scammers are sending out virus-laden e-mails claiming to have information on complaints filed with the U.S. Federal Trade Commission, the FTC warned this week. The e-mail appears to come from frauddep@ftc.gov – a spoofed address – and it includes a malicious attachment that downloads keylogging software, which is used to steal sensitive information such as passwords and account numbers.

“While the e-mail includes the FTC seal, it has grammatical errors, misspellings, and incorrect syntax,” the FTC said in an alert, released Monday. “Recipients should forward the e-mail to spam@uce.gov and then delete it.” E-mail sent to this uce.gov address goes into the FTC’s spam database, which is used by investigators.

There was also bad news on the spam front this week. PDF spam, the summertime nuisance that flooded inboxes in early August and then quickly disappeared, is back and worse than ever. According to multiple threat researchers at security vendors, tens of thousands of spam messages were blasted out last week with attached PDF files, which infect the recipients’ PCs when viewed.

The subject lines of the new crop of PDF spam are finance-related, according to security vendors, using phrases designed to get the recipient’s attention such as “your credit report.” These e-mails contain no text, simply the attachment.