OCS banner and logo
Keeping clients' computers safe and profitable for over 30 years



Home Forms About Current Newsletter subscribe 
Search All Articles

Browse by Category


powered by pmc2m

 

Tax Season, Tax Scammers

Preview:Evil computer scammer

Tax season, Tax scammers. Be very careful during tax season because miscreants are out to fleece you. They can come up on the top of search results and appear legitimate. Here is an explanation and two good mitigation strategies.

It is tax season, and tax help and accounting software assistance scammers proliferate. Be very careful if you do a search to get help with your accounting or taxes. It is common for scammers to pretend to be the "Official Site", though they have nothing to do with the company. In 2022 Google says it removed 5.2 billion ads and suspended over 6.7 million advertiser accounts. However, billions of scam ads slip by them. The scammers are clever. They often buy a slot above the results that will appear for the company you are trying to contact.

Two Types of Search Results

Searches have two types of results: organic and paid. Organic are the results that earned their way by being useful to people. Paid is just that: an advertisement. The problem is that scammers can pay and get results above legitimate companies. However, legitimate companies also pay. Scammers claim to be the "Official Site" or otherwise appear to be the real company. Google and Bing put paid ads at the top, but also intersperse them throughout the organic results. Users often go to these scam sites believing they are official site. You.com and DuckDuckGo limit their paid ads to the top of the results. They also have many fewer ads.

What the Crooks Do

They have lots of ways to get your money. They may sell you phony support policies, or demand you pay for a software upgrade. They may require you to let them connect to your computer so they can help you, then plant malware on your computer and steal credit card or banking information. The point is, if you are calling or chatting back and forth with a professional con man, then you can slip up. The goal is not to connect with them at all.

The One Single Best Defense

Ublock Origin is probably the most helpful single defense. It blocks many ads and thus, reduces your chances of being scammed by fake ads. But only use one ad-blocker. If you are using another one, uninstall it before adding this one.

Use Islegitsite.com

If you have to find results online rather than from your CPA or friends, check the site out with Islegitsite.com. This is a great site to learn more about specific websites.

You can enter the name of a site into Islegitsite.com and they'll give you a report on it. Their reports are jock full of lots of great information. Here are some of the most important factors to consider.
  • Is it obviously malicious?
  • Does it have a WOT rating? WOT stands for "Web of Trust". Most smaller sites do not have enough people rating them to have a WOT rating, but if they do have one, good or bad, that is important information.
  • They check with 9 sites that keep a blocklist of malicious sites and display those results.
  • When was the site created? A site created in the last few months is more likely to be a scam than one that is 20 years old.
  • Does it use an HTTPS connection? Often scam sites just post something and do not care. I wouldn't trust any site that didn't use HTTPS.
  • How popular is the website? I ignore this because they compare each site to big sites like Google and Amazon. Local companies or specialized companies are always low traffic on that scale.
  • Did it pass APIVoid security check? APIVoid lists web shops that are fake.
  • Is it in a risky country?
  • Do they accept email at their website? If a company claims to be an official site or a reputable training or support company, they should accept email. Not accepting email to their site is a red flag.
  • A set of links to other websites that might have information about larger companies. Those particularly useful are
    • TrustPilot
    • McAfee Secure certified
    • Reddit discussions

Further Reading

  • MalwareBytes did a good article
  • As always, Brian Krebs has an excellent article




Date: March 2024


Creative Commons License
This article is licensed under a Creative Commons Attribution-NoDerivs 3.0 Unported License.

 
 
  Please direct questions/suggestions about website to the webmaster