{"id":21350,"date":"2025-10-13T19:43:17","date_gmt":"2025-10-13T19:43:17","guid":{"rendered":"http:\/\/localhost\/?p=21350"},"modified":"2025-10-13T19:43:17","modified_gmt":"2025-10-13T19:43:17","slug":"phishing-scams-exploit-new-yorks-inflation-refund-program","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=21350","title":{"rendered":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-14T00:05:13&#8243;,&#8221;description&#8221;:&#8221;A warning from the New York State on their website informs visitors that:\\n\\n\\u003e \u201cScammers are calling, mailing, and texting taxpayers about income tax refunds, including the inflation refund check.\u201d \\n\\nHere&#8217;s the warning on the website:\\n\\n![New York State Department of Taxation and Finance warning](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/10\/warningNYS.png)\\n\\nWe can confirm that several phishing campaigns are exploiting a legitimate initiative from New York State, which automatically sends refund checks to eligible residents to help offset the effects of inflation.\\n\\nAlthough eligible residents do not need to apply, sign up or provide personal information, the scammers are asking targets to provide payment information to receive their refund.\\n\\nBleepingComputer reported an example of a SMS-based phishing (smishing) campaign with that objective.\\n\\n![text message example](https:\/\/www.malwarebytes.com\/wp-content\/uploads\/sites\/2\/2025\/10\/text_screenshot.png)\\n\\n\\u003e \u201cNew York Department of Revenue  \\n\\u003e   \\n\\u003e Your refund request has been processed and approved. Please provide accurate payment information by September 29, 2025. Funds will be deposited into your bank account or mailed to you via paper check within 1-2 business days.\\n\\u003e \\n\\u003e URL (now offline)\\n\\u003e \\n\\u003e   * Failure to submit the required payment information by September 29, 2025, will result in permanent forfeiture of this refund\u2026.\u201d\\n\\u003e \\n\\n\\nAs you can see, it uses all the classic phishing techniques: you need to act fast, or the consequences will be severe. The sending number is from outside the US (Philippines) and the URL they want you to follow is **not** an official one (Official New York State Tax Department website and online services are under `tax.ny.gov`).\\n\\nIf recipients click the link, they are directed to a fake site impersonating the tax department, which asks for personal data such as name, address, email, phone, and Social Security Number\u2014enough information for identity theft.\\n\\nScammers typically jump at opportunities like these\u2014situations where people expect to receive some kind of payment, but are uncertain about the process. By telling victims they need to act fast or they will miss out, they hope to catch targets off guard and act on impulse.\\n\\n## How to stay safe\\n\\n  * **Never reply to or click links** in unsolicited tax refund texts, calls, or emails.\\n  * **Do not provide** your Social Security number or banking details to anyone claiming to process your tax refund.\\n  * **Legitimate inflation refunds** are sent automatically if you\u2019re eligible, there are no actions required.\\n  * **If in doubt** , contact the alleged source through known legitimate lines of communication to ask for confirmation.\\n  * **Report** scam messages and suspicious contacts to the NYS Tax Department or IRS immediately.\\n  * **Use an up-to-date real-timeanti-malware solution**, preferably with a web protection component.\\n\\n\\n\\n**Pro tip:** Did you know that you can submit scams like these to Malwarebytes Scam Guard? It immediately identified the text shown above as a scam.\\n\\n* * *\\n\\n**We don &#8216;t just report on threats &#8211; we help safeguard your entire digital identity**\\n\\nCybersecurity risks should never spread beyond a headline. Protect your\u2014and your family&#8217;s\u2014personal information by using identity protection.&#8221;,&#8221;published&#8221;:&#8221;2025-10-13T22:39:35&#8243;,&#8221;modified&#8221;:&#8221;2025-10-13T22:39:35&#8243;,&#8221;type&#8221;:&#8221;malwarebytes&#8221;,&#8221;title&#8221;:&#8221;Phishing scams exploit New York\u2019s inflation refund program&#8221;,&#8221;source&#8221;:&#8221;&#8221;,&#8221;references&#8221;:&#8221;&#8221;,&#8221;id&#8221;:&#8221;MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994&#8243;,&#8221;bulletinFamily&#8221;:&#8221;blog&#8221;,&#8221;cwe&#8221;:null,&#8221;cvelist&#8221;:[],&#8221;sourceData&#8221;:&#8221;&#8221;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:0,&#8221;severity&#8221;:&#8221;NONE&#8221;,&#8221;vector&#8221;:&#8221;NONE&#8221;,&#8221;version&#8221;:&#8221;NONE&#8221;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;https:\/\/www.malwarebytes.com\/blog\/news\/2025\/10\/phishing-scams-exploit-new-yorks-inflation-refund-program&#8221;,&#8221;category_name&#8221;:&#8221;News&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;&#8221;,&#8221;version&#8221;:&#8221;&#8221;,&#8221;vendor&#8221;:&#8221;&#8221;,&#8221;ai_description&#8221;:&#8221;AI processing failed &#8211; returned non-JSON response&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;2025-10-14T00:05:13&#8243;,&#8221;description&#8221;:&#8221;A warning from the New York State on their website informs visitors that:\\n\\n\\u003e \u201cScammers are calling, mailing, and texting taxpayers about income tax refunds, including&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[6,8,12,115,13,33,7,11,5],"class_list":["post-21350","post","type-post","status-publish","format-standard","hentry","category-category_news","tag-cve","tag-cvss","tag-exploit","tag-malwarebytes","tag-news","tag-none","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=21350\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;2025-10-14T00:05:13&#8243;,&#8221;description&#8221;:&#8221;A warning from the New York State on their website informs visitors that:nnu003e \u201cScammers are calling, mailing, and texting taxpayers about income tax refunds, including...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=21350\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-13T19:43:17+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994\",\"datePublished\":\"2025-10-13T19:43:17+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350\"},\"wordCount\":682,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"exploit\",\"malwarebytes\",\"news\",\"NONE\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_news\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=21350#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350\",\"name\":\"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2025-10-13T19:43:17+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=21350\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=21350#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=21350","og_locale":"en_US","og_type":"article","og_title":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;2025-10-14T00:05:13&#8243;,&#8221;description&#8221;:&#8221;A warning from the New York State on their website informs visitors that:nnu003e \u201cScammers are calling, mailing, and texting taxpayers about income tax refunds, including...","og_url":"https:\/\/zero.redgem.net\/?p=21350","og_site_name":"zero redgem","article_published_time":"2025-10-13T19:43:17+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=21350#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=21350"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994","datePublished":"2025-10-13T19:43:17+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=21350"},"wordCount":682,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","exploit","malwarebytes","news","NONE","Security","tapic","Vulnerability"],"articleSection":["category_news"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=21350#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=21350","url":"https:\/\/zero.redgem.net\/?p=21350","name":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2025-10-13T19:43:17+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=21350#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=21350"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=21350#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"Phishing scams exploit New York\u2019s inflation refund program_MALWAREBYTES:4385805C4D27360D191B2E4CA33DD994"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/21350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=21350"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/21350\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=21350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=21350"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=21350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}