Tax refund phishing spikes around July payments — how to spot and block scams

As the French income-tax refund calendar approaches key payment dates (notably 24 and 31 July 2026), cybercriminals are intensifying phishing and smishing campaigns that impersonate the tax administration. These scams — delivered by email, SMS or phone — typically claim a refund or “trop-perçu” and push victims to click a link, enter credentials or disclose banking details. Below is a practical guide to the tactics being used, observable indicators of compromise (IoCs) and concrete defensive steps for both organisations and individual users.

How the scams operate

Attackers exploit the predictable timing and emotional trigger of a tax refund: the promise of money creates urgency and lowers skepticism. Common elements of recent campaigns include:

  • Messages with a precise monetary amount to appear legitimate.
  • Use of official logos, visual styles and formal tone to mimic the tax authority.
  • Urgency or a deadline that pressures recipients to act quickly.
  • Links to fake websites that request personal details, tax identifiers or bank data.
  • Variants delivered via SMS (smishing) and phone calls (vishing), often using caller-ID spoofing.

Practical indicators of compromise (IoCs)

You can’t always rely on the visible address alone. Look for patterns and technical signs:

  • Sender address mismatches: the “From” display name shows the tax service while the underlying email domain is unrelated, misspelled or uses additional words.
  • Reply‑to or Return‑Path headers that differ from the displayed sender.
  • Links that point to non-official domains, IP addresses, or URL shorteners; hovering reveals a different target than the visible text.
  • DMARC/SPF/DKIM failures in email authentication (mail that fails these checks is higher risk).
  • Attachments in unexpected formats (HTML, ZIP, or executable content) or pages that immediately ask for credentials or card details.
  • SMS from unfamiliar shortcodes or international numbers that include links; voice messages requesting card validation are red flags.
  • Web certificates that don’t match the impots.gouv.fr domain or show as self-signed.

Recommended steps for individual users

Simple habits cut risk dramatically:

  • Do not click links in unsolicited emails or SMS about refunds. Instead, open your browser and navigate to the tax site by typing the official address or using a saved bookmark.
  • Remember that legitimate tax refunds are paid automatically to the bank account on file; you will not be asked to pay fees or to validate by card to receive a refund.
  • Check sender details and hover over links to inspect the real URL. Look for small domain typos or unusual top-level domains.
  • Enable multi-factor authentication (MFA) on your tax and email accounts and use a password manager to avoid credential reuse.
  • Report suspicious messages to local authorities and to national cybersecurity assistance platforms (for example, the government’s cyber assistance service referenced by French authorities).
  • Keep devices and browsers updated and use reputable endpoint protection and web-filtering tools on mobile devices.

Defensive measures for organisations

Companies and public-sector bodies can limit exposure and protect users and employees:

  • Enforce email authentication: publish and enforce SPF, DKIM and DMARC records with a policy of quarantine or reject to reduce spoofed mail.
  • Deploy MTA-STS and DANE where possible to harden mail transport security, and monitor authentication reports for anomalous senders.
  • Use secure web gateways and URL-rewriting/scanning to block known phishing sites, and enable sandboxing for attachments.
  • Integrate threat-intel feeds that include phishing domains and hashes; automate blocking in firewalls and proxy devices.
  • Run frequent, realistic phishing simulations combined with mandatory awareness training and clear reporting channels.
  • Harden customer support and payment flows: never ask users for full payment card numbers by email or SMS and log requests for verification attempts.
  • Maintain an incident response playbook and a process to quickly take down phishing pages by liaising with registrars, hosts and national CSIRT teams.

Why timing matters and what to watch for now

Seasonal events such as scheduled tax refunds provide predictable windows for attackers to amplify success rates. The July payment dates referenced in recent warnings create a narrow opportunity where recipients expect communications about money — attackers exploit that expectation. Expect a rise in multi-channel campaigns (email + SMS + voice), more convincing visual spoofing, and rapid domain churn where fraudsters register new domains for short-lived landing pages.

Remain cautious around any unsolicited message that requests personal or banking information, and follow official channels to verify refund status. If you suspect you’ve interacted with a phishing site, change affected passwords, enable MFA, contact your bank if you disclosed financial details, and report the incident to national cyber assistance services.

Source: French national cyber assistance service advisory published 15 July 2026; its guidance underlines that refunds are credited automatically to the bank account registered with the administration and that no payment or card validation will be requested to obtain a lawful refund.

Source: Cybermalveillance.gouv.fr