- news
- TAX
IRS warns crypto holders about fake compliance portal scam
Related
Refund generated by IRS computer error is rebate refund
Taxpayer’s Social Security benefits are taxable despite his subsequently repaying them
NIL organization denied tax-exempt status
TOPICS
Fraudsters are mailing letters that direct cryptocurrency holders to a bogus “Digital Asset Compliance Portal” that mimics IRS.gov to collect personal information and digital asset credentials, the IRS said in a news release.
The letters claim that recipients must enroll in the portal, and the letters include a QR code that directs recipients to a fraudulent website, the IRS said. The site may seek personal information, cryptocurrency wallet information, exchange account credentials, or other sensitive data.
“The IRS does not operate a Digital Asset Compliance Portal,” the release said. “This is a scam.”
IRS Criminal Investigation (IRS-CI) Chief Jarod Koopman urged taxpayers to verify the source of unexpected requests for personal information before responding and to report potential fraud to law enforcement.
Fraud details
Victims receive what appears to be an official IRS letter claiming they must enroll in a “Digital Asset Compliance Portal” before a deadline. The letter instructs them to scan a QR code, which directs them to a fraudulent website designed to look like IRS.gov.
How to respond
Taxpayers affected by a fraud scheme should take several steps, the IRS said:
- Stop communicating with the fraudster;
- Change passwords for affected financial accounts;
- Contact their financial institution or cryptocurrency exchange immediately if you shared credentials;
- Preserve screenshots, emails, and letters; and
- Report information to IRS-CI at www.IRS.gov/SubmitATip.
IRS-CI advised taxpayers not to scan QR codes from unsolicited letters, emails, or text messages, especially those claiming to be from a government agency.
However, the IRS uses QR codes on some legitimate correspondence, including recent CP53E notices.
In response to questions from the JofA, an IRS-CI representative said taxpayers should not scan QR codes included in letters from the IRS. Instead, they should go to IRS.gov or contact the agency using contact information on that site.
The news release does not identify how fraudsters obtained the names and addresses of cryptocurrency holders, and an IRS-CI representative declined to answer questions about the scope of the scam.
Coinbase and cybersecurity firm DarkTower traced the campaign to a domain registered through a Hong Kong registrar and hosted in Romania, the IRS said.
— To comment on this article or to suggest an idea for another article, contact Martha Waggoner at Martha.Waggoner@aicpa-cima.com.
