Outline
Email purporting to be from phone service provider Vodafone claims that recipients are eligible to receive a tax refund and should click a link to access an online refund form.
Brief Analysis
The email is not from Vodafone and – hardly surprisingly – promises of a tax refund are false. The email is a phishing scam designed to trick users into divulging personal and financial information. As scams go, this attempt is rather bizarre. It is unclear why scammers would choose to use a phone service provider as the supposed sender of a tax refund notification. But, in any case, users should not click on any links or open any attachments in these emails.
Example
Subject: Vodafone Tax Refund!
After the last bill payment calculations of your Vodafone activity our Customer Care Service
have determined that you are eligible to receive a tax refund of 18.60 AUD.
Please submit the tax refund request and allow us 1-3 days in order to process it.
In order for us to return the excess payment, we need to confirm a few extra details
after which the funds will be credited to your specified bank account.
To access the form for your tax refund, click on the link below.
[Link Removed]
Note: A refund can be delayed a variety of reasons, for example submitting invalid records
or applying after deadline.
Vodafone Hutchison Australia Pty Ltd
2012 Vodafone Hutchison Australia Pty Limited. ABN 76 096 304 620
Registered in England No 1833679.
Detailed Analysis
Since April 2013, users have reported receiving emails purporting to be from Vodafone Australia that claim recipients are eligible for an unexpected tax refund. The messages claim that users can receive a tax refund of $18.60 by clicking a link and filling in an online form.
Surprise, surprise, the email is not from Vodafone and users certainly are not going to receive a tax refund by following the link. The email is a phishing attempt designed to fool users into submitting their personal and financial information to cybercriminals. Those who fall for the ruse and click the link will be taken to a bogus web page that hosts a form like the one shown in the following screenshot:
Alas, all of the sensitive information input on the bogus form can be collected by criminals and used to commit credit card fraud and identity theft.
To enhance your privacy and security and offer you a better user experience, Hoax-Slayer is now ad-free! Can you help us stay online?
After the last annual calculations of your fiscal activity we have discovered that you are eligible to receive a tax refund of $302.19 AUD. Kindly complete the tax refund request and allow 6-9 working days to process it.
A refund can be delayed for a variety of reasons. For example submitting invalid records or applying after the deadline.
To access the form for your tax refund, please visit:
[link removed]
Vodafone Australia warned customers about this scam attempt back in April 2013 noting that it “does not send emails asking for confidential information such as credit card details or account passwords”. However, recent submissions indicate that the scam emails are still being distributed. If you receive one of these emails, do not click on any links or open any attachments that it contains. Note also that Vodafone customers are currently being targeted in other phishing campaigns, including one that claims that they must verify account details due to a system upgrade.
Since you’ve read this far…
…can I ask you for a big favour?To enhance your privacy and security and offer you a better user experience, Hoax-Slayer is now ad-free. To keep the site online, I now rely on voluntary contributions from site visitors along with commissions from a few trusted products and services that I promote via reviews on the site.
If you found the above report useful, please consider supporting Hoax-Slayer by making a donation. Any amount you can give will be greatly appreciated.
You can donate using your credit card via the form below. Donations are collected securely via the online payment service Stripe. Stripe uses state of the art security to keep your data safe.
Thank-you.
Brett Christensen