“Your refund of $1,284 is ready—confirm direct deposit.” That subject line is a classic tax refund phishing hook. Scammers clone IRS, state department-of-revenue, TurboTax, H&R Block, and Credit Karma Tax branding, then steal logins, Social Security numbers, or one-time codes.
Broader IRS and benefits scripts: Fake IRS and benefit scams. Login-theft patterns: Phishing and account takeover. Real filing basics: Filing taxes for beginners.
Hard rules about real IRS contact
| Claim in the email/text | Reality |
|---|---|
| “Click to release your refund” | IRS does not email or text unsolicited refund-release links |
| “Pay a small fee / gift cards / crypto to process” | IRS does not demand gift cards, crypto, or wire for a refund |
| “We need your SSN and bank login to deposit” | Real refunds use the bank info you put on the return |
| Threat of arrest in 24 hours if you do not click | Impersonation scare tactic; see also phone variants in the IRS scams guide |
The IRS initiates most refund communication through your tax return transcript, IRS Online Account, or postal mail—not a random Gmail blast. State agencies vary slightly; still type the official URL yourself.
Tells on fake refund messages
- Display name “IRS.gov” with a reply address like
refund-secure@irs-deposit.com - Urgency tied to “today only” deposit windows
- Attachments named
W2_Refund.exeorDeposit_Form.HTML - Links to lookalike domains (
irѕ.govwith a homoglyph,irs-refund.us,turbotax-security.com) - Requests for remote-access software “so an agent can finish your e-file”
- Upsells that funnel into refund anticipation loans you did not request
Landscape of related fraud: Credit and debt scams. SSN exposure follow-up: Protect your SSN.
Worked example
Chris gets an email: “IRS — Refund Adjustment Notice. Direct deposit failed. Update account in 12 hours.” The button goes to a page that looks like an IRS login and asks for SSN, prior-year AGI, and bank routing numbers.
Chris does not click. Chris opens a new browser tab, types irs.gov, signs into the real IRS Online Account, and sees no such notice. Chris deletes the email and reports it to phishing@irs.gov / ReportFraud.ftc.gov. No bank data shared; no second loss.
If you already clicked or typed data
- Change passwords on email, tax software, and bank—from a different device if possible.
- Turn on MFA everywhere those credentials overlapped.
- Call your bank’s fraud line (number on the card or statement) if you entered routing/account numbers.
- Place a fraud alert or freeze if you shared SSN; watch for new credit.
- Consider an IRS IP PIN if tax identity theft is plausible.
- Do not pay a “recovery specialist” who cold-contacts you next.
Parallel “account locked—call security” bank texts: Fake bank security alerts.
Related hook when scammers demand AGI or SSN to “release” a wage transcript: Fake IRS transcript phishing.
Checklist
- Never use links inside unsolicited refund emails or texts.
- Type irs.gov or your state DOR URL yourself.
- Remember: IRS will not demand gift cards, crypto, or secrecy.
- Verify refund status only inside official accounts or the Where’s My Refund tool you navigate to manually.
- Treat tax-software password resets with the same care as bank resets.
- Report phishing and document what you shared, if anything.
Educational only. Not legal or tax advice. Scam tactics and IRS procedures change; rely on official IRS and state agency channels.