Security Corner

Oct 18 2010   3:15PM GMT

Bogus EFTPS Failure Notices are Spear Phishing Attempt

Ken Harthun Ken Harthun Profile: Ken Harthun

Beware of this one, but it doesn’t take much to spot it’s a fake. Look at all the typos! There are so many of them, it’s almost funny. Can you believe that anyone would fall for something like this? Sad, but true, people are probably being duped by this right now.

I got 13 of these this morning, all with different headlines. They appear to be spear phishing attempts, as they reference “Cmopany Identifiaction Feild.” The links point to various TLDS in Romania, Hungary, Russia, Thailand, Estonia, Germany, even one in France.

If you click the link, you go to a page that appears to start Java (probably a keylogger app) and then you are redirected to the real EFTPS site.

EFTPS ONLINE
THE ESAIEST WAY TO PAY YOUR FEDREAL TAXES

Your Federal Tax Payment ID: 01037593731 has been not accepted.


Plaese, make sure that all informtaion you have sumbitted is corerct and refer to Code R21 to find out the informtaion about copmany payemnt. Plaese cnotact this page if you have any questions:
(Link Removed)

Rteurn Reason Code R21 – The identifiaction nmuber you enetred in the Cmopany Identifiaction Feild is not functional. Try sedning infromation to your acocuntant adivser using other optoins.

EFTPS: The Electronic Federal Tax Payment System

WARNING!
You are uisng an Official United States Government System, which may be used only for auhtorized purposes. Unauthorized modification of any information stored on this ssytem may result in criminal prosecution. The Govermnent may monitor and audit the usage of system, and all presons are hereby notified that the use of this system constittues cosnent to such monitoring and auditing. Unauthorized attempts to upload inofrmation and/or change information on this web site are stritcly prohibited and are subject to prsoecution under theCmoputer Farud and Abuse Act of 1986 and Title 18 U.S.C. Sec. 1001 and 1030.

 Comment on this Post

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: