Risk:High — Fake government SMS messages steer recipients to imitation tax or benefits portals, exposing payments and submitted personal data to theft.
Install the app:Open the app and verify suspicious content in one scan.
Fake Government SMS: 5 Parts That Expose It
Fake government SMS campaigns impersonate tax authorities and social-benefits services, then direct recipients to fraudulent government portals. The same message structure also appears in phishing emails.
Five parts that expose the scam
- Sender: an official-looking identity
- Illustration: The sender presents the message as a tax authority or social-benefits service, even though that identity does not prove who sent it.
- Quick check: Ignore the displayed sender name and independently visit the agency’s published website.
- Claim: a tax or benefits issue
- Illustration: A reconstructed message may read: “Tax authority notice: your tax or social-benefit account requires action. Use this portal.”
- Quick check: Sign in through the official website you already know or type its address yourself; do not use the message link.
- Pressure: act before verifying
- Illustration: The SMS frames the supposed account issue as something requiring immediate attention, pushing you toward the link before you investigate.
- Quick check: Stop before transferring money or submitting information and contact the agency through its official channels.
- Link: a fake government portal
- Illustration: The destination imitates a taxation system or social-benefits platform but is hosted on a malicious domain.
- Quick check: Compare the full hostname with an independently obtained official address, such as `www.irs.gov`, `sede.agenciatributaria.gob.es`, or `www.ssa.gov`.
- Payoff: payment or sensitive information
- Illustration: The imitation portal leads you toward submitting account information, personal details, or a payment under the government agency’s identity.
- Quick check: Do not proceed; close the page and verify the underlying claim directly with the named authority.
Why this threat is serious
The 2026 GovTrap campaign reported by CTM360 involved more than 11,000 malicious domains linked to government impersonation, including taxation systems and social-benefits platforms. Its multi-region use of SMS smishing, email phishing, and fake portals means a polished page is not evidence of legitimacy. Treat every unexpected government link as untrusted until the agency confirms the claim through a separately verified channel.
Most common warning signals
- Unexpected tax or benefits notice
- Unverifiable government sender identity
- Pressure to act immediately
- Link to an unofficial domain
- Portal requests payment or personal data
What to do now
- Do not click, reply, submit data, or transfer money.
- Close any portal opened from the message.
- Visit the named agency by typing its official address.
- Change exposed passwords through the genuine service.
- Contact your bank immediately after any payment.
- Report the message through official fraud channels.
Sources
Further reading
- Account and Payment Recovery After Tax Refund Phishing
- Account and Payment Recovery Scam Defense Guide
- Prevent Account Takeover From Fake WhatsApp Alerts
FAQ
Is an unexpected IRS text with a portal link legitimate?
Do not use the link. Type `www.irs.gov` into your browser and verify the matter there; the IRS says it does not initiate contact by text to request personal or financial information.
How can I check whether a government portal is fake?
Do not rely on logos or page design. Check the complete hostname against the agency’s independently obtained official domain, such as `www.ssa.gov` or `sede.agenciatributaria.gob.es`.
What should I do after entering information?
Close the page, change any password you entered through the real service, replace reused passwords, and contact your bank or payment provider immediately if you submitted financial details or sent money.