Scammers are sending text messages that look like IRS refund notifications, complete with QR codes that redirect recipients to fake government websites designed to harvest bank login credentials. The IRS flagged this tactic on its 2026 Dirty Dozen tax scams list, warning that fraudulent texts, emails, and direct messages now routinely impersonate the agency and use QR codes to lure taxpayers into entering personal and financial information. The Federal Trade Commission issued a separate alert about texts and emails claiming a tax refund has been “processed” or “approved,” confirming that this scheme is active across multiple federal enforcement radars.
Why QR-code refund texts are surging during filing season
The timing is not accidental. Tax season creates a window when millions of Americans are already expecting refund updates, making a text about a pending deposit far more believable than it would be in October. The IRS has made clear that it uses text messages on an opt-in basis only, limited to appointment reminders and certain account updates sent from the official short code 91040. The agency does not text taxpayers to request bank details, Social Security numbers, or login credentials. Any message that does is fraudulent by definition.
What makes the current wave harder to spot is the QR code itself. The Taxpayer Advocate Service, an independent organization within the IRS, has acknowledged that legitimate IRS notices sometimes contain QR codes linking to pages on IRS.gov. Scammers exploit that overlap by embedding codes that route to malicious lookalike sites instead. The visual similarity between a real QR code on an official notice and a fake one in a text message gives recipients little reason to hesitate before scanning.
The FBI has separately warned that unsolicited QR codes, including those arriving in packages, are being used to prompt victims to hand over personal and financial data or to download malware that steals it silently. That alert is not specific to tax scams, but it confirms the same credential-theft mechanism at work: scan a code, land on a page that mimics a trusted institution, and enter information that goes straight to criminals.
How three federal agencies traced the same scam pattern
The IRS, FTC, and FBI have each documented different angles of the same fraud chain. On its annual Dirty Dozen list, the IRS describes scammers sending emails, direct messages, or texts that appear to come from the agency and direct recipients to fake websites to “verify” accounts or claim refunds. The IRS defines this category of attack as “smishing,” the use of fraudulent text messages to extract sensitive data.
The FTC’s consumer alert zeroes in on the bait itself: messages telling recipients that a tax refund has been processed or approved. The goal, according to the FTC, is to collect Social Security numbers and bank account details so criminals can steal refunds or commit identity theft. The Treasury Inspector General for Tax Administration has also flagged correspondence that pressures recipients to act immediately or face penalties, a hallmark of many IRS-themed scams. Taken together, the three agencies describe a consistent pattern: a fake IRS communication, a QR code or link leading to a convincing copy of an IRS page, and a form that captures personal and financial data under the guise of confirming a refund.
In some cases, victims report that the fraudulent sites even display partial personal information that appears accurate, such as a name or city, to build trust before asking for full bank login credentials. That data can be enough for criminals to initiate unauthorized transfers, open new accounts, or file additional fraudulent tax returns in future years. Because the fraud often begins with a taxpayer voluntarily typing information into a spoofed site, victims may not realize they have been compromised until money disappears or the IRS later flags conflicting returns.
How to verify real IRS contact and avoid QR-code traps
Officials stress that the safest response to any unexpected tax-related text is to assume it is a scam. The IRS outlines how it normally contacts taxpayers, emphasizing that it initiates most communication through regular mail and that legitimate electronic outreach follows predictable patterns. Taxpayers can review these contact methods on the agency’s guide to recognizing genuine IRS communication before responding to any message that claims to be from the government.
Security experts recommend several practical steps. First, do not scan QR codes or click links in unsolicited messages about refunds, account holds, or audits, even if they display an IRS logo or reference a plausible dollar amount. Instead, navigate directly to IRS.gov by typing the address into a browser or using a trusted bookmark, then sign in through the official account portal to check refund status or notices. If a message claims to reference a specific notice number, compare it to any physical letters you have received and look up that notice on IRS.gov independently.
Second, treat any request for full bank login credentials as an immediate red flag. The IRS does not need your online banking password to issue a refund or verify your identity. Legitimate tax administration relies on routing and account numbers provided on a return, not on direct access to your bank account. Similarly, be wary of forms that ask for a combination of data points-full Social Security number, date of birth, and driver’s license number-that could enable broad identity theft if stolen.
Finally, report suspicious messages rather than simply deleting them. The IRS encourages taxpayers to forward phishing texts and emails that appear to come from the agency to its designated reporting address, and the FTC accepts reports through its fraud complaint portal. Sharing examples helps investigators track new variants, including evolving QR-code tactics, and can lead to faster takedowns of spoofed sites before more taxpayers are drawn in by promises of easy refunds.



