The department is particularly worried after taxpayers recently brought to its notice certain emails which have very cleverly "spoofed the department's identity" by using almost resembling addresses to cheat gullible taxpayers over the Internet.
One such example is hackers using the email domain-- "mailto:noreply@incometaxindia.Gov.In", noreply@incometaxindia.Gov.In" to send such phishing emails.
Also Read
"The CERT-In has been informed that these emails are a serious concern for the taxpayers and the Income Tax department as this malicious assault over the Internet directly dents the taxman's efforts to effectively engage with the tax paying public in a paperless and non-adversarial manner and dissuades an individual from conducting safe e-transactions," a senior official supervising the counter operations in this domain said.
The CERT-In is the nodal agency to combat hacking, phishing and to fortify security-related defences of Indian Internet domain.
The department, the official said, has asked the cyber security sleuths to specifically go behind the fraud and malicious email domains and URLs and ensure that such e-links are not able to send emails to the bonafide address of the taxpayer.
"These over 100 instances have multiple strains of fraud communications identified in them. The department is implementing all best practises to further bolster its e-services vis-a-vis dealing with taxpayers," the official said.
The phishing emails issue has become such a menace that
the Central Board of Direct Taxes (CBDT) early this month issued a statement and public advisory assuring taxpayers that it never asks them about their vital personal financial data like PIN numbers, passwords or details of credit or debit cards.
Such an advisory is also prominently posted by it on the official website of the department--http://www.Incometaxindia. gov.In, incometaxindia.Gov.In.
In cyber crime paralance, phishing denotes a cheating attempt to trick someone into clicking a malicious link in a seemingly legitimate email and subsequently trying to break through a computer's defence and fraudulently skimming away money from e-accounts.
The IT department has also adopted some globally followed best practises in its systems units which helps in automatic differentiation between a fake and an original email.
The taxman has also suggested some counter-measures for the taxpayers to check against a phishing email, which tend to seek vital details of a person and then cleverly cleans up their funds from either the bank account or debit/credit card.
It has been adviced by the department that domain names should be checked for incorrect or mis-spelt sounding variants of original IT department links, not opening any attachment, not to click on links provided in such an e-communication and usage of good anti-virus and firewall on the operating system.
Taxpayers have also been suggested to just forwardsuch emails to CERT-In on their officialmailto: id--incident@cert-in.Org.In and "id--incident@cert-in.Org. in, for proper action.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)