By Sunil Garodia
First publised on 2026-08-01 13:26:56
Every institution that inspires fear inspires imitation, and the Income Tax Department, an institution that has spent decades cultivating the former, has now acquired an unwanted double. As the ITR filing deadline approached this year, CloudSek's threat intelligence team documented a coordinated campaign in which cybercriminals impersonated the department itself, sending forged notices over WhatsApp and other messaging platforms, some laced with malware, others linking to phishing portals built to mirror the government's e-filing website down to its Hindi typography. The researcher Shobhit Mishra put the underlying logic plainly: filing season hands attackers a ready-made script, because it is the one time of year when a message about tax discrepancies, refunds or compliance deadlines does not appear suspicious. It appears expected.
What makes this campaign worth dwelling on is not its sophistication but its calibration. The forged notices are bilingual, carrying English and Hindi text with fabricated reference numbers and an invented tax official's name, an unnecessary flourish except that this kind of verisimilitude is precisely what defeats casual scrutiny. They cite Section 271(1)(c) of the Income Tax Act, threaten prosecution, and impose a seventy-two hour response window, a deadline chosen not because it corresponds to any real procedural timeline but because seventy-two hours is long enough to feel official and short enough to foreclose the instinct to verify. The file itself, distributed as an archive under names like "ITD.zip", installs malware on Android devices capable of reading SMS messages, which is to say capable of intercepting the one-time passwords that stand between a compromised phone and an emptied bank account. This is not incidental design. It is the entire point of the exercise, and it is why I have argued in my own work on cyber scams that OTP interception, not password theft, has become the critical vulnerability in India's digital banking ecosystem.
The arrival of generative artificial intelligence has only sharpened this threat. Fraudsters no longer need poor grammar or amateur layouts to persuade victims. AI tools now allow them to produce convincing bilingual notices, polished emails, realistic voice messages and increasingly persuasive chat interactions that closely resemble official communications. The challenge for citizens is no longer identifying obvious mistakes; it is recognising sophisticated deception that appears professionally produced.
The second vector, phishing websites replicating the official e-filing portal, deserves equal attention because it exploits a different failure mode. The malware route depends on a victim installing something. The website route depends only on a victim typing something into a form that looks correct, which is a lower bar and therefore a wider net. PAN, Aadhaar, banking credentials and OTPs entered into such a site require no technical compromise of the victim's device at all, only a moment's inattention to a URL bar. Any exhaustive account of the current threat landscape has to treat this as the more dangerous of the two, precisely because it asks less of the attacker and forgives more of the victim's ordinary carelessness.
There is a structural point buried in Mishra's observation that is worth stating without embellishment. Fraud of this kind does not succeed by inventing new psychological weaknesses. It succeeds by attaching itself to institutional rhythms that already carry legitimate urgency, filing deadlines, refund cycles, compliance notices, so that the fraud inherits the credibility of the calendar. This is precisely the mechanism I have documented in the context of banking fraud and the loan-app ecosystem, where scammers borrow legitimacy from RBI circulars and festival-season loan demand rather than manufacturing it from nothing. The Income Tax Department's own communication style, formal, threat-adjacent, procedurally opaque to most taxpayers, is not a design flaw exactly, but it is a vulnerability the department shares with every state institution that expects citizens to fear its correspondence more than they question it.
Seen this way, the ITR phishing campaign is merely the latest expression of a much larger phenomenon. It is not really a story about tax filing at all. It is the current instalment of a pattern that recurs against every fixed point on India's administrative and social calendar. Examination season produces forged admit cards and impersonated recruitment boards. Election season produces coordinated misinformation built primarily to influence rather than directly defraud, but built on the same exploitation of an audience primed to act on unverified information. Festival season produces fraudulent shopping portals and fake courier notifications timed to the surge in genuine online orders. Tax season produces the Income Tax Department's doppelganger. The technical vector changes each time, malware here, a spoofed portal there, but the underlying calculation is constant: identify the moment when a national institution or event has already trained citizens to expect an urgent, unfamiliar message, then supply that message. This is what makes cybercrime awareness a poor candidate for a once-a-year campaign timed to filing season and forgotten by August. The vulnerability being exploited is not tax-specific, and treating it as though it were ensures that the same population will be freshly unprepared for whichever calendar event comes next.
India has strengthened its response through the National Cyber Crime Reporting Portal, the 1930 cyber fraud helpline and improved coordination between banks and law-enforcement agencies. These measures have undoubtedly reduced losses in many cases. Yet enforcement remains inherently reactive. Fake domains can be registered in minutes, phishing infrastructure is easily replaced, and malware campaigns can shift across jurisdictions faster than investigators can dismantle them. Prevention therefore remains both cheaper and more scalable than post-fraud recovery.
None of this argues for taxpayer fatalism. This is the same principle that runs through my cybercrime awareness workshops and books: verify the institution before responding to the message, because the message itself can no longer be trusted. In practice that means never acting on a notice, of any kind, received outside an institution's official portal or registered channel, never opening an unsolicited archive file regardless of its apparent sender, and treating any communication invoking a compliance deadline of less than a week as evidence against itself rather than evidence of urgency. The department could also do more, a verified sender protocol for WhatsApp communications and clearer public guidance on what an authentic notice looks like would cost little and close much of this gap. Institutional reform moves more slowly than the calendar repeats itself. Until that changes, the most effective cybersecurity tool available to any taxpayer will not be antivirus software or stronger passwords. It will be the habit of verifying before obeying.
The lead image is AI-generated









