{"id":18856,"date":"2022-04-25T13:10:11","date_gmt":"2022-04-25T21:10:11","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/25\/news-12589\/"},"modified":"2022-04-25T13:10:11","modified_gmt":"2022-04-25T21:10:11","slug":"news-12589","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/25\/news-12589\/","title":{"rendered":"Watch out for this SMS phish promising a tax refund"},"content":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 25 Apr 2022 20:52:38 +0000<\/strong><\/p>\n<p>Imagine logging into your bank\u2019s website after responding to a text message claiming you\u2019re due a refund, only to see a warning to watch out for bogus texts:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"55886\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/attachment\/created-with-gimp-14\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7.jpg\" data-orig-size=\"644,392\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7-300x183.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7-600x365.jpg\" width=\"600\" height=\"365\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7-600x365.jpg\" alt=\"\" class=\"wp-image-55886\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7-600x365.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7-300x183.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish7.jpg 644w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>Beware of SMS phishing!<\/figcaption><\/figure>\n<\/div>\n<p>For those who don&#8217;t read Dutch, the warning reads:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>Never respond to unusual emails or texts!<\/p>\n<p>Fraudsters often send e-mails under the guise of renewing your debit card or digipas. Never go into that. They refer to websites that are not owned by Argenta. Argenta will also never ask you to provide your card number by telephone because you will allegedly receive a new debit card or digipas.<\/p>\n<p>Do you still receive suspicious messages?<\/p>\n<p>Have you already passed on codes over the phone? Or has money already been withdrawn from your account? Please contact us immediately on (available 24\/7 for victims of phishing).<\/p>\n<\/blockquote>\n<p>The warning above is genuine, on a real bank&#8217;s website. But the warning, in this case, comes too late because this is the last and only legitimate stop in a victim&#8217;s passage through a phishing scam.<\/p>\n<h2>The bogus SMS trail begins<\/h2>\n<p>Here\u2019s one of the <a href=\"https:\/\/twitter.com\/AnnDeCraemer\/status\/1517951227522338816\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">suspect SMS messages<\/a>, as tweeted by Twitter user @ypselon:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>it has been decided that you will receive a refund. to receive this amount you can visit our website [url removed]<\/p>\n<\/blockquote>\n<p>The text claims to be from \u201cFOD\u201d. This is the <a href=\"https:\/\/financien.belgium.be\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Federale Overheidsdienst Financien<\/a> in Belgium. The suspect URL includes a domain registered just this month (often a red flag), in India, rather than Belgium.<\/p>\n<p>Visiting the site presents you with a message that says:<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"55887\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/attachment\/created-with-gimp-15\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1.jpg\" data-orig-size=\"996,914\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1-300x275.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1-600x551.jpg\" loading=\"lazy\" width=\"600\" height=\"551\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1-600x551.jpg\" alt=\"\" class=\"wp-image-55887\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1-600x551.jpg 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1-300x275.jpg 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish1.jpg 996w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><figcaption>A fake FOD website offering fake refunds<\/figcaption><\/figure>\n<\/div>\n<blockquote class=\"wp-block-quote\">\n<p>Refund:<\/p>\n<p>In order to receive a refund of your personal income tax, you must verify your account so that we can transfer the full amount of \u20ac278.35 to the correct account.<\/p>\n<p>It is important to carry out a one-time verification as a check. Afterwards you will receive the amount on your account within a few working days.<\/p>\n<\/blockquote>\n<p>For &#8220;one-time verification&#8221; read &#8220;send us money&#8221;.<\/p>\n<p>We all love a tax refund so it\u2019s an effective hook to lure in potential victims. Continuing reveals a large assortment of banks commonly used in Belgium.<\/p>\n<h2>A slippery phish<\/h2>\n<p>The scam site includes customised pages for each popular bank. Some ask for card details, others for account numbers. All are fake, all are trying to hoover up information that can be used to steal your money.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img decoding=\"async\" data-attachment-id=\"55888\" data-permalink=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/attachment\/created-with-gimp-16\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5.jpg\" data-orig-size=\"461,482\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;Created with GIMP&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;Created with GIMP&quot;,&quot;orientation&quot;:&quot;1&quot;}\" data-image-title=\"Created with GIMP\" data-image-description=\"\" data-image-caption=\"&lt;p&gt;Created with GIMP&lt;\/p&gt; \" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5-287x300.jpg\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5.jpg\" loading=\"lazy\" width=\"461\" height=\"482\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5.jpg\" alt=\"\" class=\"wp-image-55888\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5.jpg 461w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/04\/dbphish5-287x300.jpg 287w\" sizes=\"auto, (max-width: 461px) 100vw, 461px\" \/><figcaption>A phishing site asks for credit card details for a &#8220;one-time verification&#8221;<\/figcaption><\/figure>\n<\/div>\n<p>No matter which route you go down, entering your details will neither verify your identity nor secure you a tax refund. But all will leave you poorer and eventually redirect you to your bank\u2019s real website (where you might encounter a warning about falling for scams like the one you&#8217;ve just fallen for).<\/p>\n<p>At this point, your only option is to contact the bank for real, and tell them what\u2019s happened. If you&#8217;re lucky, you may be able to have them shut things down. If not, days or weeks of hassle might lie in wait. <\/p>\n<h2>Faking it to make it<\/h2>\n<p>Fake tax refunds are hugely popular. They\u2019re especially rampant during (or immediately following) any tax season. The Federale Overheidsdienst Financien has <a href=\"https:\/\/financien.belgium.be\/nl\/phishing\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">some advice<\/a> for avoiding scams like this..<\/p>\n<ul>\n<li><strong>If the FOD helped you with a tax return the previous year<\/strong>, it may contact you by phone. The organisation warns that if the caller doesn\u2019t know your name; asks for payment for assistance; asks to come to your home; or requests passwords, PINs, email, or address, then you should hang up.<\/li>\n<li><strong>Report any request to provide confidential data<\/strong> related to banking you receive by email, text, or WhatsApp.<\/li>\n<li><strong>If you\u2019re asked to make a payment to the FOD directly<\/strong>, check their site because there\u2019s only a limited number of ways to make a payment to an official account.<\/li>\n<\/ul>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/\">Watch out for this SMS phish promising a tax refund<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Christopher Boyd| Date: Mon, 25 Apr 2022 20:52:38 +0000<\/strong><\/p>\n<p>We take a look at a round of phishing mails being sent to people in Belgium, promising tax-related refunds.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/scams\/2022\/04\/steer-clear-of-this-sms-tax-refund-phish\/\">Watch out for this SMS phish promising a tax refund<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[16278,4645,11539,18313,16802,10511,3924,25815,10574,11706,25816,15669],"class_list":["post-18856","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-banks","tag-belgium","tag-fake","tag-login","tag-mail","tag-phish","tag-phishing","tag-refund","tag-scams","tag-sms","tag-tax-refund","tag-text"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18856"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18856\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18856"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}