A month ago, the New Zealand Department of Inland Revenue (IRD) issued a warning advising people not to respond to scam emails claiming to offer tax refunds. We have observed these types of scams before, but the individual campaigns come and go. Like any other phishing scam, this email campaign appears to look like a legitimate notification from Inland Revenue complete with the logo.
The link in the message body points to a phony web page that mimics the New Zealand IRD website. But the odd thing is the instruction in a red font stating “Please click on your following bank logo to continue the refund procedure”.



An analysis of the ACH spam campaign
Massive Rise in Malicious Spam
‘Just applied for my own @facebook.com email account’ Phish Spreading
Can’t Believe A Girl Did This Because of Justin Bieber? You Shouldn’t
RapidShare.com – The Phishing Begins