IRAS Tax Refund Scam: The Fake Payout Email That Wants Your Card Details

An email says IRAS has found an overcharge and your refund is ready. A reference number and a portal link make it look like routine tax correspondence.

If an IRAS tax refund scam has reached your inbox, there’s a safer way to check the promised payout before following its instructions.

Illustrative tax refund email promising S$650 through a fictional claim link

Overview

A refund promise that borrows IRAS’s identity

These messages impersonate Singapore’s Inland Revenue Authority. IRAS is the real tax agency; the fraudulent refund emails are not an offer from that agency.

The hook is an apparent windfall from a previous overcharge. Instead of demanding an alarming tax payment, the sender gives you a reason to expect money.

IRAS’s official refund and payout scam advisory confirms this impersonation. Its examples include a message promising S$650 and other amounts that change between variants.

A precise amount can make the email feel personal. It still doesn’t establish that the sender accessed your tax account or that the refund exists.

The illustration above recreates the general refund lure with fictional contact details. It isn’t a genuine IRAS notice or evidence of your entitlement.

The card payout request exposes the deception

The fraudulent link leads to a copied tax website. There, the recipient is asked to choose a debit or credit card as the refund method.

IRAS doesn’t pay tax refunds to cards. A form asking for that payout method is taking you outside the agency’s genuine process.

Genuine refunds are automatically credited through registered bank or PayNow accounts. You can review your own refund position through myTax Portal.

This isn’t just an inconvenient billing policy or a slow refund. It is a confirmed attempt to collect information by pretending to be the tax authority.

The signs that matter more than the email’s appearance

  • The message announces a refund amount and tells you to claim it through an unsolicited link.
  • The destination asks for a card as the way to receive your tax payout.
  • Official-looking link text doesn’t match where the link actually leads.
  • The form asks for banking secrets or verification codes to complete the supposed refund.
  • The promised credit can’t be confirmed independently inside your real tax account.

Don’t try to settle the question by comparing logos. Go to the agency’s genuine website yourself and check the account information you can actually verify.

A real refund and a fraudulent email can coexist. Having money owed to you doesn’t make a particular claim link trustworthy.

How a Genuine IRAS Refund Differs

The strongest check is the refund process, not a tiny spelling mistake. A page can have polished English and still ask for the wrong kind of information.

IRAS directs taxpayers to their secure portal for confidential tax information. The agency says it doesn’t send emails announcing your tax refund amount.

Navigate independently to myTax Portal. Don’t use a portal address copied from the suspicious email as your starting point.

If your genuine account shows a refund, follow the instructions within that verified service. An unrelated card form isn’t required just because the email says otherwise.

You might legitimately need to maintain account details for payments. Make those changes through the authenticated agency process, not through a surprise message.

Also distinguish receiving money from authorizing money to leave. A bank notification describing a purchase, transfer, or new device isn’t merely confirming a tax credit.

Read what an approval actually says before acting. The amount printed on the refund page isn’t a reliable description of the operation your bank is approving.

If the portal and the message disagree, ask IRAS through contact details reached from its official website. Don’t ask the sender to validate its own claim.

How the IRAS Tax Refund Scam Works

Step 1: The email creates a believable reason to claim money

The message says a review found an overcharge, a refund has been approved, or a payout needs confirmation. Its tone resembles ordinary administrative correspondence.

A tax reference gives the reader something concrete to focus on. The invitation to review details seems less risky than an obvious request to send money.

You may think you are correcting a record rather than making a purchase. That expectation makes a linked form feel like part of the refund process.

The scam doesn’t need an authentic tax calculation. It needs the recipient to accept the story long enough to move from the inbox to its page.

Step 2: A convincing link moves you away from the genuine portal

The visible link may contain an official-looking tax address. The underlying destination can be something entirely different, including an intermediary that redirects again.

In the agency’s S$650 example, the displayed portal-style text conceals a different destination. The appearance of the text isn’t proof of who controls the page.

On a computer, inspecting a link without clicking can help reveal a mismatch. On a phone, preview behavior varies, so independent navigation is usually simpler.

Don’t open the link merely to inspect it more closely. You already have a safer route to check the claim through the real agency.

Step 3: The copied page asks how you want the refund paid

The page presents debit or credit card choices as a convenience. This is the point where a reassuring refund story becomes a request for valuable financial data.

A card number, expiration date, and security code aren’t harmless administrative details. Entering them into an impostor’s form exposes a payment instrument.

A copied heading or tax logo doesn’t change that. The fake page is asking you to use a payout method that IRAS specifically rules out.

Leave the form without completing it. If you already typed information, don’t assume it remained private because you stopped before the last screen.

Step 4: Further verification can increase the exposure

Some versions request banking information or codes. What matters is the operation behind the request, not the label “verification” placed beside it.

Never send a banking code to an email contact or enter it into an unverified tax form. Contact your bank if you’ve already done that.

A follow-up request to correct an error can be another attempt to keep you engaged. Don’t provide a second card to make the promised credit appear.

IRAS also warns that some links can deliver malicious software. That possibility calls for checking downloads and installations, not assuming every clicked email infected the device.

Step 5: The victim waits for a credit while the account needs attention

The refund promise can keep someone waiting after submitting details. They may check for the incoming amount while overlooking small or unfamiliar outgoing transactions.

If card or banking information was shared, review both pending and posted activity. Tell the bank about the phishing exposure even if no charge appears yet.

Don’t rely on the fake page’s confirmation screen. A successful-looking submission can be displayed without any connection to IRAS or an actual refund.

The useful next step is containment, not chasing the promised money. Save the evidence, secure the affected accounts, and verify any real tax credit separately.

Sender Names, Domains, and Reference Numbers

A sender display name is just the name your email app shows. Seeing IRAS there doesn’t establish that the agency sent the message.

The actual address may reveal an unrelated domain. Even a plausible address should be considered alongside the requested action and the independent portal check.

IRAS says legitimate email addresses use its iras.gov.sg domain. Don’t treat a copied visible sender string as the only authentication test.

Official words can appear anywhere in a deceptive web address. The presence of “tax” or “IRAS” doesn’t make a separate domain part of the agency.

HTTPS protects a connection to the site you opened. It doesn’t prove that the operator is the tax authority or that a refund form is legitimate.

A reference number can be invented just as easily as a heading. Compare it with information obtained through the genuine service, not another page linked in the email.

Keep screenshots of these details if you report the attempt. Don’t post your genuine tax identifier, financial records, or security codes in a public warning.

When discussing the scam with family, focus on the card-payout mismatch. It’s a more useful test than asking them to memorize every possible fake domain.

What to Do if You Have Fallen Victim to This Scam

  1. Leave the refund conversation. Stop filling out the page and don’t answer follow-up requests. Use the genuine IRAS portal to check whether any refund is due.

    If you only read the email, preserve enough information to report it and then remove it. Reading a refund promise doesn’t mean your card was exposed.

  2. Tell the card issuer exactly what you entered. Use the bank’s official app or the contact printed on your card, not a number supplied by the email.

    Explain whether you gave the full card details, banking credentials, a code, or an approval. Ask which protections, card replacement, or transaction checks are needed.

  3. Review activity without waiting for the refund. Check pending charges, transfers, and unfamiliar account changes. Record amounts and times rather than relying only on merchant names.

    Ask your bank how to dispute unauthorized activity and whether anything can still be stopped. A refund decision depends on the circumstances, so don’t assume reimbursement.

  4. Secure any exposed login. Change a shared password through the real service on a trusted device. If you reused it elsewhere, protect those accounts too.

    Review available session and security settings. If Singpass information or approvals were involved, contact Singpass through its genuine service and inspect suspicious login alerts.

  5. Check what the link left behind. Look for unexpected downloads, installed applications, browser extensions, or notification permissions. Don’t open a downloaded file to determine whether it’s suspicious.

    If you installed or ran something, use a safe device for banking while the affected one is assessed. A qualified technician can help contain a suspected compromise.

    Malwarebytes is a useful option for checking a device after risky software exposure. It can’t withdraw information from a phishing form or undo a bank approval.

  6. Keep a concise record and report. Save the email, destination, screenshots, and bank reference numbers. Report the impersonation through IRAS’s official contacts and your email provider.

    In Singapore, the ScamShield helpline is 1799. If money was taken, make a police report and provide the bank with the corresponding reference.

  7. Expect another attempt to recover your trust. A caller may repeat the refund amount or your personal details. Knowing them doesn’t authenticate the caller.

    Don’t pay an agent to unlock the refund or recover stolen money. Keep discussions with the actual agency and bank on independently verified channels.

    AdGuard can supplement browser filtering against some malicious destinations. It doesn’t decide your tax entitlement or authenticate every email that claims a payout.

Protecting Future Tax Correspondence Without Ignoring Real Notices

You don’t need to stop using online tax services. The goal is to avoid letting an unsolicited message choose where you log in or provide financial information.

Keep a bookmark for the genuine tax portal after verifying it independently. Use it when an email claims that your account needs attention.

Maintain your contact details within the real services you use. Security alerts can help you spot access that you didn’t initiate.

For households, agree that refund emails won’t be completed while multitasking. Taking a minute to open the genuine portal is easier than repairing several compromised accounts.

A family member helping with taxes should receive relevant documents through an agreed channel. Forwarding a claim link without context can make it appear preapproved.

Email spam and phishing filters add another barrier. Keep them enabled, but don’t assume a message is safe simply because it reached your inbox.

When a real notice needs attention, act through the real agency. Rejecting the fake card form doesn’t mean ignoring an actual tax obligation or missing legitimate support.

The same distinction helps when someone insists the link is necessary. Ask for information you can verify inside your account rather than agreeing to another untrusted form.

If you manage company tax correspondence, tell colleagues about the refund route. A convincing administrative email should not bypass your existing financial-information controls.

Record who is allowed to update payout details and how changes are confirmed. That keeps a believable email from becoming an unofficial way to alter financial instructions.

After a reported incident, review the process without blaming the recipient. A clear response route makes the next employee more likely to ask for help promptly.

Frequently Asked Questions

Is an email promising an IRAS card refund genuine?

No. IRAS explicitly says it doesn’t process tax refunds to debit or credit cards. Check the refund through your actual tax account instead.

What if I’m genuinely expecting a tax refund?

You can still receive a scam email. Confirm the amount and status within myTax Portal; don’t let your expectation authenticate a separate claim link.

Does the S$650 amount identify every version?

No. It’s one published example. Amounts, references, subjects, and destinations can change while the false payout and information request remain the same.

Is a portal-looking link enough to trust the email?

No. Visible link text can conceal another destination. Open the genuine agency website independently rather than using an unsolicited refund button.

Should I cancel my card after merely reading the message?

Reading alone doesn’t expose card details. If you entered financial data or authorized anything, contact the issuer and let it assess the needed protections.

What if the page says my refund is being processed?

That confirmation doesn’t establish a real payout. Stop interacting, check the genuine portal, and protect any card or account information already supplied.

The Bottom Line

Don’t enter card details to claim an IRAS refund from an unsolicited email. The request contradicts the agency’s genuine payout process.

Check myTax Portal through an independently opened address. If you’ve already shared information or approved an operation, contact your bank immediately and secure the affected accounts.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Fake PAAC Staff Scam: WhatsApp Groups Push Apps That Target Your Banking

Next

Ninja Van Redelivery Scam: A Tiny Parcel Fee Can Put Your Card in a Wallet