Warning: Serious Scam Involving IRS (W8 BEN)

By Angsuman Chakraborty, Gaea News Network
Wednesday, October 14, 2009

irs-w8ben-form-scamThere is a serious scam involving IRS (Internal Revenue Service, USA) which can fool even the most web-savvy people. Please read below for details on how you can protect yourself from this email which appears to genuinely come from IRS, inquiring about your tax exemption status.

I received an email today which states:

Our record indicates that you are a non-resident alien. As a result, you are exempted from United States of
America (USA) Tax reporting and withholdings on interest paid into your account and other financial
dealing. To protect your exemption from tax on your account and other financial benefit, you need to
recertify your exempt status. Therefore, you are to authenticate the following by completing form W-
8BEN, and return to us as soon as possible through the fax number: +1 -206-202-0110

If you are a USA Citizen and Resident Alien, this form W-8BEN is not meant for you, please indicate
“USA Citizen/Resident” on the form and return it to us. We shall then send you a form W9095.

When completing form W-8BEN, please follow the steps below.
We need you to provide your permanent address if different from the current mailing address on your

Form W-8BEN you must indicate if a non-USA resident, your country of origin to support your non-
resident status (if your bank account or other financial dealing has a USA address for mailing purpose).

If any joint account holder is now USA resident or Citizen, or in any way subject to USA tax reporting
laws, Please check the box in this section.

Please have all account holder(s) sign and date the form separately and fax it to the above-mentioned fax
number.

We wrote to you in April 2009 asking for this identification but have not received any reply. Please,
complete Form W-8BEN ‘attached” and return to us within 2 (two) weeks from the receipt of this letter
by faxing it, to enable us update your records immediately. If your account or any other financial benefits
are not rectified in a timely manner, it will be subjected to USA tax reporting and back up withholding (if
back up withholding applies, we are required by Law to withhold 30% of the interest paid to you).
We appreciate your cooperation in helping us protect your exempt status and also update our records.

The email looked genuine at first because:

  • It didn’t direct me to a website to fill-out a form or authenticate myself
  • The email address appeared to be from IRS at first glance (detailed investigation found it to be fraudulent)
  • The information was provided in pdf documents which is relatively immune to viruses

However on detailed investigation I found it to be yet another phishing scam, an innovative one I must admit. So what gave it away?

How to identify such phishing attempts?

scam-letter-irsInstead of talking about generic ways to protect yourself from phishing scams, I will detail how I found out that this was a phishing attempt.

Identify origin of email

The email originated from:
Received: from User ([174.141.9.35]) by backoffice.mcerrillos.cl with Microsoft SMTPSVC(6.0.3790.3959);

First of all IRS would never route their email through a Chilean site (mcerrillos.cl is owned by Municipalidad de Cerrillos). They aren’t that cheap. IRS surely owns their own email server when even small companies like us can own them. In fact IRS mail server is located at IRS.gov

Note: I got the information about the site from whois records.

The email was originally received from the following IP address: 174.141.9.35
This IP address can be faked, so having a valid IP address is no guarantee that the email originated from a proper location. However the email is definitely scam when this IP address doesn’t belong to the organization the email is claiming to come from.

In this case the IP address is owned by nuvox.com (used nslookup to find out), provider of web based business applications for communication which leverages Google applications like GMail etc. Again IRS will never send email from such setup. The address isn’t owned by IRS.

How to contact?

The most innovative aspect of this scam is that it doesn’t ask you to go to a fake website or send an email, both of which can easily be reported and taken down, but asks you to FAX the information instead.

The fax number is +1-206-202-0110

A reverse phone lookup at whitepages.com indicated that it is an unlisted Seattle address. Why would IRS unlist their FAX address?
Secondly I never worked in Seattle nor earned anything there. IRS does have an office in Seattle (Phone: 1-206-220-6015) but surely there is not reason why it would contact a person who never stayed there nor earned anything there and that too from an unlisted address.

In light of these evidences, I could conclusively determine that this was a fraud / scam. I hope the fax number is traced by government officials to shutdown this scam asap.

What is the standard operating procedure of the organization?

IRS is never known to communicate by email. It uses snail-mail.

What is phishing?

I have used the word phishing repeatedly without explaining it. In not so simple terms (will simplify later), phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords, bank account details, credit card details etc. by masquerading as a trustworthy entity in an electronic communication, mostly by email or instant message. Communications appearing to be from popular social web sites, government authorities like IRS  as was in this case, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public in handing out their sensitive information.

It often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. In this case however they have innovated and directing you to fax the information instead, making it look even more legitimate.

Discussion

FlaRiptide
May 11, 2010: 11:44 am

This is most likely NOT a scam. The IRS does NOT send out W-8BENs. They are sent by U.S. payors to foreign recipients of income. In other words, a non U.S. individual, corporation, partnership, etc. who receives income from a U.S. entity may be requested to complete a W-8BEN. Depending upon the foreign country in which they reside, they may be exempt from U.S. taxes. If the form is not completed and returned 30% tax may be withheld.


neil purrington
February 16, 2010: 2:20 pm

i recently had gs global[inshort]ring me up to say they wanted to buy my shares. everything was going through then the irs faxed me telling me i,d have to pay 10% before they would release the money.because i was not exempt from tax because of no w8ben form they sent w7 form instead.
is this right what the irs are doing?
ps i live in england

January 26, 2010: 10:48 pm

Great information, Thank you so much… keep up the great work.

October 30, 2009: 5:40 pm

Your analysis of this scam e-mail was excellent. You pegged this for what it is… a scam. One dead giveaway that what you have received through e-mail is a scam when it looks like it came from the Internal Revenue Service is to remember this simple fact: IRS does not initiate contact out of the blue with taxpayers using e-mail. In fact, we rarely have contact with taxpayers by e-mail. Generally we only contact someone using e-mail when they have initiated the contact with us and we are replying to their inquiry.

If you would like more information about phishing scams that are constantly popping up, check out the IRS web site. Go to IRS.gov and type in the search term “phishing.” Here is a direct link to the page: irs.gov/privacy/article/0,,id=179820,00.html

As you discovered, many of these scams are based in foreign countries and are difficult for the U.S. authorities to shut down. The W-8BEN scam is well known to us, and it is mentioned on a news release issued August 4, 2009. Use search term IR-2009-71 on the IRS.gov web site to read about this and other scams currently circulating on the internet and through e-mail. Here is a direct link to the news release: irs.gov/newsroom/article/0,,id=211669,00.html

Thanks for spreading the word on this type of scam. Unfortunately, we hear from people everyday who are caught up in these phishing schemes and surrender personal information to the identity thieves who are always looking for new ways to steal from victims.

Larry Wright
IRS Spokesman
Western United States


Rick
October 20, 2009: 7:52 am

The most obvious phishy thing about the w-8ben letter is that its English is riddled with mistakes!!!! It was not written by an educated English speaker. You don’t really need to explain more about why it is phishing.


Murali Ramachandran
October 17, 2009: 12:28 am

I received an email exactly similar to the one described above. It has exactly similar contents. Thanks for helping out. I couldn’t find out the origin of the email but I did check the W-8BEN form from the IRS and its totally different.

One other thing about the email id was that it ended with @irs.gov.org. The irs email ids end with @irs.gov.

Both these showed that the email was fake along with the comments given above. Thanks once again.

YOUR VIEW POINT
NAME : (REQUIRED)
MAIL : (REQUIRED)
will not be displayed
WEBSITE : (OPTIONAL)
YOUR
COMMENT :