Fake IRS refund email uses Elon Musk to lure victims into giving up bank details


A new IRS tax scam promises a $5,000 refund courtesy of the world’s richest man – Elon Musk – tricking victims into handing over a slew of personal information, including driver’s licenses and bank account numbers.

Key takeaways:

According to new research by Cofense published Thursday, the IRS-spoofing emails use the tech mogul to lure victims into a full-fledged financial takeover – effectively giving hackers everything they need to drain bank accounts and carry out identity theft.

ADVERTISEMENT

It’s just one of dozens of Internal Revenue Service-themed phishing campaigns recently launched by cybercriminals attempting to take advantage of those in need during the busy US tax season, but this one capitalizing on Elon Musk was too good to pass up.

Musk IRS email page
IRS phishing scam used Elon Musk imagery and a fake $5,000 refund offer to lure victims. Image by Cofense

How the IRS refund scam works

The Musk name-dropping email looks pretty benign at first glance.

Addressed to “Dear Taxpayer,” and titled “Update Regarding Your Refund,” the email, dated only three days ago, includes an IRS-branded image header and a sender name set to “Internal Revenue Service (IRS).”

Musk IRS scam email
The phishing email used IRS branding and Elon Musk’s name to pitch a fake tax refund. Image by Cofense.

Cofense says the threat actor also adds a “legitimate IRS phone number” to a department called the IRS Practitioner Priority Service at the bottom of the message, making it that much more convincing to the recipient.

“You've received a tax refund from the IRS, courtesy of Elon Musk. To claim it, use the secure link below. Be sure to complete this soon,” it says, appearing to come from the IRS Support Team.

ADVERTISEMENT

If the reader clicks the "View Your Tax Refund” call-to-action button smack in the middle of the email, they are immediately redirected to the first of a seemingly endless stream of credential-harvesting sites, disguised as an application process to claim their refund.

jurgita justinasv Izabelė Pukėnaitė vilius Ernestas Naprys Gintaras Radauskas
Don't miss our latest stories on Google News. Add us as your Preferred Source on Google

Congratulations! You have been selected for $5,000 in funding from the IRS and Elon Musk

You've been selected to join the Elon Musk Dogecoin Initiative a unique opportunity to be part of something truly groundbreaking,” the page says, also notably missing a comma after Initiative.

Flanked on either side by images of Musk, the phishing site spouts off a variety of reasons why Musk is giving away the free refund, such as the war in the Middle East, gas prices, and cost-of-living increases. The site also continues to use IRS branding to make it appear legitimate, the research says.

Musk IRS scam DOGEcoin initiative
After clicking the email, victims were redirected to a fake IRS-Elon Musk “initiative” page designed to keep the scam moving. Image by Cofense

The ridiculously long missive from the alleged Musk then goes into intricate detail about the refund process and actions required for the user to set up their complimentary banking and cryptocurrency accounts to obtain the "free" funds.

Apparently, "compensation for the position is competitive and based on experience," while the victim must not only be prepared to take on certain “key responsibilities” such as maintaining accurate banking account records and communicating with the internal team, but also be “reliable, trustworthy, and able to maintain strict confidentiality.“

Victims are pushed to hand over IDs and bank details

After another poorly written, lengthy, and convoluted explanation about how the “refund scheme” works (guaranteed to make your head spin), the victim is then sent to yet another page where the real scamming begins.

ADVERTISEMENT

“Every $10,000 I provide… you purchase $9500 in bitcoin… take $500 for your commission…send back $9500 Bitcoin… weekly process… you get $500 back plus the $5000 benefit…” and so on.

Musk IRS scam data harvesting
The fake application page asked victims for personal details, including driver’s license and banking information. Image by Cofense

The user is presented with an application form in which they are expected to give away loads of personal information, from basic contact information such as name, address, and phone number to a driver’s license number, employer, and even their banking institution.

After entering their information, users are sent to yet another page this one a fake investment platform tied to the fictional “ElonMusk Dogecoin Initiative.”

At some point, victims are prompted to upload photo identification and provide bank routing and account numbers.

And if that’s not enough, the victim is eventually sent to a Bitcoin deposit page, complete with a QR code, that leads them directly to the scammer's BTC wallet address which is now linked directly to the victim’s bank account.

Musk IRS scam bitcoin wallet
The scam eventually pushed victims to a Bitcoin deposit page linked to the attacker’s wallet. Image by Cofense

Cofense says the threat actor funnels the stolen data via a bot on Telegram, pushing it directly into a threat-actor-controlled channel on the encrypted messaging platform.

Although Cofense has not observed any transactions in the attacker's crypto wallet as of Thursday, it says the threat actors would be capable of "much more sophisticated identity theft and social engineering attacks" beyond the initial data taken, with the added ability to "steal money directly from the victim’s bank account."

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
ADVERTISEMENT

The Musk phishing lure aligns with this year’s IRS’s Dirty Dozen tax scams list, which warns that impersonation schemes – including phishing, smishing, and AI-powered robocalls – remain one of the most persistent threats during the tax season.

The federal agency has repeatedly warned it does not contact taxpayers via email, text message, or social media to request personal or financial information.


Unlock more exclusive Cybernews content on YouTube.