en

India’s ITR Season Creates a New Cyber Risk as Crypto Profits Meet Refund Scams

image
rubric logo Security

India’s tax-filing rush is colliding with its expanding cryptocurrency market, creating a timely opening for phishing gangs. As taxpayers reconcile exchange records, wallet transfers, and deductions, fraudulent messages can appear unusually relevant.

CoinDCX co-founder Sumit Gupta warned that genuine refunds rarely arrive immediately after filing. He said messages claiming “refund approved” while demanding urgent updates should be treated as warning signs. Gupta, therefore, advised taxpayers to avoid embedded links and verify every claim through the official income-tax portal.

Crypto Adoption Reshapes India’s Tax-Filing Burden

India ranked first in Chainalysis’ 2025 Global Crypto Adoption Index, covering centralized platforms, retail activity, decentralized finance, and institutional transfers. That scale has moved digital assets deeper into tax compliance, where users must document activity across several financial systems.

The India ITR process now includes exchange statements, wallet histories, token disposals, and tax deduction records. As a result, cryptocurrency is no longer an isolated category for many filers. Instead, it has become another reporting area requiring detailed reconciliation and consistent documentation.

Accordingly, India’s crypto tax framework requires virtual digital asset income to be reported separately. Such income is taxed at 30%, with applicable surcharges and cess added. However, taxpayers may generally deduct only the acquisition cost.

Other expenses usually cannot be deducted, while losses cannot be set off against virtual digital asset income. In addition, a 1% tax deduction applies to qualifying transfer payments. Users filing ITR-2 or ITR-3 must disclose transactions through Schedule VDA.

Meanwhile, transfers between personal wallets can resemble disposals when records lack clear labels. The process becomes harder for users active across several exchanges or wallets. Staking, airdrops, and business payments may further introduce different dates, records, and acquisition values.

Complex Filing Records Give Phishing Scams More Credibility

The reporting burden does not make taxpayers careless. However, it gives fraudulent messages a believable context during filing. For instance, someone expecting a refund may accept a request to correct bank details.

Another filer may react quickly to a claimed mismatch involving TDS or Schedule VDA. Criminals need only a plausible prompt when millions check tax messages and refund updates.

That pressure is especially strong during the India ITR deadline period, when taxpayers are gathering documents, correcting errors, and monitoring reminders. As a result, a message mentioning a crypto transaction can therefore appear specific.

Official communication can also be copied as the department sends filing and verification reminders. Its July campaign directed taxpayers toward the e-filing portal and cited the July 31 deadline for many individuals.

Criminals can copy that timing, language, and visual style. However, the crucial difference is where taxpayers respond. Genuine notices can be verified by manually opening the official portal and reviewing the authenticated account.

This distinction matters for crypto users, who often move between exchanges, wallets, tax software, banks, and government services. Consequently, every additional platform gives criminals another setting to imitate.

How Fake Refund Alerts Steal Taxpayer Credentials

Building on that complexity, tax refund scams begin with an SMS, email, or WhatsApp message impersonating a government department, bank, preparer, or financial platform. The message may claim that a refund was approved, delayed, or rejected.

The recipient is then directed to a cloned portal, shortened link, fake support number, or malicious application. Each route pulls the taxpayer away from the official system and into an environment controlled by criminals.

Once there, a counterfeit page may request a PAN, Aadhaar number, e-filing password, card details, bank credentials, or one-time password. Similarly, some schemes instruct users to install Android packages disguised as tax applications.

CERT-In, for instance, documented the Drinik banking trojan in 2021, which used an Income Tax Department lookalike website and malicious application. The software collected personal information while seeking access to messages, calls, and contacts.

Together, these methods combine authority, reward, and urgency. The sender imitates a government institution, promises funds, and pressures the recipient to act before verifying the claim independently.

Notably, tax refund scams succeed because they appear to resolve an immediate problem. A delayed payment, failed bank validation, or alleged filing error can create anxiety. That urgency leaves taxpayers less time to verify the message.

Cybercrime Losses Reveal the Scale of India’s Fraud Risk

The scale of cybercrime shows why tax-themed phishing deserves attention. Complaints on the National Cyber Crime Reporting Portal rose from 1.03 million in 2022 to 2.27 million in 2024.

Besides, reported cyber-fraud losses climbed from ₹2,290 crore to ₹22,846 crore during the period. By December 2025, the government said its response system had prevented ₹7,130 crore from being siphoned.

That intervention covered more than 2.3 million complaints, showing the reach of digital fraud and the importance of rapid reporting. Quick action matters once stolen funds begin moving.

Crypto tax records can add another layer of sensitivity as they may reveal exchange accounts, transaction histories, and wallet information. Such details can help criminals tailor follow-up messages or target financial services.

However, no legitimate tax process requires a wallet seed phrase or private key. Those credentials provide direct control over digital assets and should never appear in any tax form, refund page, or support chat.

Therefore, the strongest defense is to separate notification from action. A taxpayer may read an alert but should open the Income Tax Department portal manually or through a bookmark.

Independent Verification Is the Strongest Defense

Inside the account, users can review refund status, pending actions, notices, and filed returns. The department says it never requests PINs, passwords, or banking access details through email.

Taxpayers should also complete e-verification through approved methods and confirm that the account is pre-validated. Filing remains incomplete without verification, while refunds may fail when validation is missing.

Therefore, any corrections should occur only inside the official portal. They should never be made through message links, remote-access applications, or caller-guided screen-sharing sessions, even when the displayed details appear accurate.

Crypto users require additional record discipline. They should preserve exchange statements, transaction hashes, wallet addresses, acquisition costs, and TDS certificates. These records should be reconciled before responding to any alleged mismatch.

Meanwhile, strong passwords, app-based multi-factor authentication, and withdrawal allowlists can reduce potential damage. Seed phrases and private keys should never be entered into a tax form, refund page, or support chat.

Anyone who clicks a suspicious link should immediately change affected passwords, contact the relevant bank or exchange, and review recent account sessions. Financial fraud should also be reported through helpline 1930 or the National Cyber Crime Reporting Portal.

CoinDCX’s “Satark Rahe” campaign with Cyber Dost and I4C reinforces a simple sequence: pause, verify, and act only after confirming the source. That habit remains essential throughout the filing process.

Related: IRS Alerts Crypto Investors to Fake Tax Letters Targeting Digital Assets