top of page
Search

Fake Tax Emails That Demand Action Within 72 Hours? Stop and Verify First.

  • Dr Kevin Ho
  • Jun 15
  • 3 min read
Scammers utilizing shady methods to steal your company's data for crime
Scammers utilizing shady methods to steal your company's data for crime

Scammers are becoming increasingly sophisticated in their attempts to impersonate government agencies, and the latest wave of tax-related scams demonstrates just how convincing these schemes can be.


Recently, fraudulent emails claiming to be from the Inland Revenue Board of Malaysia (LHDN) have been circulating among businesses and taxpayers. These emails allege serious tax offences such as under-declaration of income, submission of inaccurate information, or even tax evasion. Recipients are then given an alarming ultimatum: submit documents within 72 hours or face severe penalties.


The emails appear professional. They cite legal provisions, reference tax laws, provide names of purported officers, and even include contact details and links to download supposedly required forms.


At first glance, many recipients may understandably assume the emails are genuine.

That is exactly what the scammers are counting on.



The Psychology Behind the Scam

The scam is not merely a technical attack. It is a psychological one.

The emails are carefully designed to trigger fear and urgency. By threatening penalties of up to 300% of unpaid taxes, imprisonment, and the freezing of tax credits, scammers attempt to create panic.


When people panic, they stop thinking critically.

Instead of independently verifying the notice, some recipients may click links, download files, disclose sensitive information, or contact the scammers directly.

This tactic is not unique to tax scams. It is commonly used in phishing attacks worldwide. The objective is to pressure victims into acting before they have time to verify the legitimacy of the communication.


The Red Flags

One of the most obvious warning signs is the sender's email address.

While the fraudulent emails may contain the words "LHDN" or "hasil.gov.my" within the display name, the actual email addresses originate from unrelated domains.


LHDN has repeatedly reminded the public that official emails are only sent from addresses ending with:

Any email claiming to represent LHDN but originating from another domain should be treated with extreme caution.


Another red flag is the demand for immediate action within a very short timeframe. Scammers often use deadlines such as 24, 48, or 72 hours to create a false sense of urgency.


The Governance and Risk Management Lesson

From a governance perspective, this incident highlights an important principle that applies not only to cybersecurity but to business decision-making in general:

Never make important decisions under pressure without verification.

Whether it involves a suspicious tax notice, an unexpected payment request from a supplier, or an urgent instruction supposedly coming from senior management, verification should always be part of the process.


Good governance requires controls.

A simple verification step can prevent significant financial losses, data breaches, and reputational damage.

For businesses, this means implementing clear procedures for handling communications that involve:

  • Regulatory enforcement actions

  • Requests for confidential information

  • Financial transactions

  • Changes to banking details

  • Urgent compliance demands

Employees should be trained to verify first and act second.


What Should You Do If You Receive Such an Email?

If you receive an email claiming to be from LHDN and demanding action within 72 hours:

  • Do not click on any links.

  • Do not download attachments.

  • Do not reply to the email.

  • Do not contact the phone number listed in the email.

  • Do not provide financial or company documents.

Instead, verify the matter independently through LHDN's official website or official contact channels.

If there is a genuine issue with your tax affairs, it will be far safer to confirm it directly with the

relevant authority than through contact details provided in a suspicious email.


Final Thoughts

Cybersecurity is often viewed as a technology issue, but in reality, many successful attacks exploit human behaviour rather than technical weaknesses.


The most effective defence is not necessarily better software. It is better judgement.

Whenever an email attempts to frighten you into immediate action, pause and verify.

Scammers thrive on urgency.


Good governance begins with due diligence.


 
 
 

Comments


bottom of page