Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

AI forged tax official website invoice verification pages used to defraud corporate finance account passwords

The primary targeted groups are SME finance personnel, bookkeeping accountants, cashiers, and individual business operators. Typically aged between 25 and 45, they work at a fast pace, handle large volumes of invoices, have some familiarity with tax system operations, but lack deep cybersecurity awareness. Regarding psychological vulnerabilities, these groups tend to feel a sense of urgency near the end of the month or filing deadlines. Upon receiving emails or text messages containing tax authority names, driven by the fear of penalties for delayed filing, they often click links without verification. Furthermore, some finance personnel lack awareness of the realism of AI-generated web pages, assuming counterfeit websites must look crude, which lowers their guard.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionChina(全国)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary targeted groups are SME finance personnel, bookkeeping accountants, cashiers, and individual business operators. Typically aged between 25 and 45, they work at a fast pace, handle large volumes of invoices, have some familiarity with tax system operations, but lack deep cybersecurity awareness. Regarding psychological vulnerabilities, these groups tend to feel a sense of urgency near the end of the month or filing deadlines. Upon receiving emails or text messages containing tax authority names, driven by the fear of penalties for delayed filing, they often click links without verification. Furthermore, some finance personnel lack awareness of the realism of AI-generated web pages, assuming counterfeit websites must look crude, which lowers their guard.

骗局怎么运作

  • Step 1: Scammers use AI tools to batch-collect invoice verification page styles from the official websites of provincial and municipal tax bureaus, including page layouts, logos, fonts, button colors, and prompt messages, generating pixel-level counterfeit pages. These pages automatically adapt to various screen sizes and browsers via AI, making it difficult for ordinary finance personnel to distinguish true from false with the naked eye.
  • Step 2: By mass-sending text messages or emails disguised as the State Taxation Administration or local tax bureaus, scammers use pretexts such as 'invoice verification notice', 'tax system upgrade, please re-verify', or 'abnormal invoices pending processing for your company' to lure finance personnel into clicking links. Sender addresses in the emails are spoofed to look like official domains while actually being phishing domains.
  • Step 3: After clicking the link, finance personnel enter the forged invoice verification page, which requests information such as the corporate unified social credit code, electronic tax bureau login account, password, and the handler's mobile number. Some pages also pop up 'For security verification, please enter the received SMS verification code' to bypass two-factor authentication.
  • Step 4: The scammers' backend receives the entered accounts and passwords in real-time and immediately attempts to log into the genuine electronic tax bureau system to query corporate input invoice information, download billing data, or directly modify the company's bound mobile number and bank account information. Some rings complete multiple operations in a short time, making it difficult for victims to notice.
  • Step 5: After acquiring tax system access permissions, scammers can further execute downstream crimes such as issuing fraudulent invoices, defrauding tax retention refunds, transferring corporate funds, or selling corporate billing qualifications. If the victim discovers the anomaly and reports it later, the scammers have already hidden their identities via multi-layer proxies, making investigation extremely difficult.

红旗信号(看到这些快跑)

  • 🚩 The invoice verification links provided in text messages or emails do not start with chinatax.gov.cn or provincial tax bureau official domain prefixes, but instead contain randomized letters, hyphens, or non-.gov.cn suffixes.
  • 🚩 The counterfeit page requests the electronic tax bureau login password or SMS verification code, whereas legitimate invoice verification platforms typically only require the invoice code, number, issuing date, and check code, and never ask for account passwords.
  • 🚩 The page displays urgency-inducing phrases such as 'System is upgrading, please re-verify your identity' or 'Your account has security risks, please log in immediately to process.'
  • 🚩 The address bar lacks a security lock indicator, or the certificate is issued to an entity unrelated to tax authorities, and the bottom of the page lacks a genuine record number and public security authority filing link.
  • 🚩 Clicking 'Contact Us' or 'Help Center' links on the page redirects to blank pages, third-party chat tools, or inaccessible addresses, inconsistent with the official site structure.

真实案例

  • In March 2026, Finance Person A at a trading company in a certain region received a text message during end-of-month reconciliation stating that 3 of the company's invoices failed verification and required immediate login and processing. Person A clicked the SMS link to enter the counterfeit page, entered the electronic tax bureau account password and verification code. Subsequently, the account was logged into from another location, and corporate input invoice data was exported. According to tax authority bulletins, the ring used the acquired invoice information to downstream issue fraudulent value-added tax special invoices, involving a tax amount of approximately 1.2 million RMB. (Source: [https://www.ctfiot.com/305972.html](https://www.ctfiot.com/305972.html))
  • In January 2026, multiple bookkeeping agencies in various regions reported that the tax accounts of multiple micro-enterprises they managed were logged into in batches during the same time period, and some corporate invoice collection permissions were modified. Security companies traced the attack and found that attackers collected login credentials of at least 47 enterprises through AI-generated forged invoice verification pages, with page templates highly resembling a provincial tax bureau's official website.
  • In November 2025, Person B, engaged in bookkeeping, saw a link titled 'Internal Training on Tax System Operations' in their moments feed. Upon clicking, they were guided to a counterfeit invoice verification platform, where they filled in the tax account information of 12 enterprises under their management. Subsequently, these enterprises successively received tax anomaly alerts, and investigations revealed that someone had impersonated the companies to apply for invoice quota increments. (Source: [https://www.zikeys.com/shop/article!content.action?id=2c916302993bef2901997093ec210701](https://www.zikeys.com/shop/article!content.action?id=2c916302993bef2901997093ec210701))

Official Stance

  • In April 2026, the State Taxation Administration released the 'Notice on Being Vigilant Against Counterfeit Tax Websites and Phishing Information' on its official website and official WeChat account, explicitly stating that tax authorities will not request enterprises to input login passwords and verification codes via text message or email links.
  • In February 2026, tax departments in multiple regions posted anti-fraud tips in tax service halls, reminding taxpayers to look for official platforms for invoice verification and never input electronic tax bureau account information on third-party pages.
  • In December 2025, the National Anti-Fraud Center published anti-fraud classroom content on Sina Weibo, listing 'forged tax official website phishing' as one of the key scam types targeting SME finance.

How to Protect Yourself

  • ✅ For invoice verification, directly visit the National Value-Added Tax Invoice Verification Platform of the State Taxation Administration or official entry points published by provincial tax bureaus; do not access any verification systems via links in text messages or emails.
  • ✅ Set a high-complexity password exclusively for the electronic tax bureau account, and enable secondary verification such as SMS or app face scanning to prevent direct login after password theft.
  • ✅ Finance personnel should regularly participate in cybersecurity training to understand the characteristics of AI-generated phishing pages, and immediately exit and verify with supervising tax authorities upon encountering verification pages requesting verification codes or passwords.
  • ✅ Enterprises can deploy DNS security filtering and email security gateways to intercept forged tax domains and phishing emails, while installing anti-phishing extensions in browsers.
  • ✅ Once account anomalies or password entry on suspicious pages is discovered, immediately log into the official platform to modify the password, unbind the replaced bound mobile number, and report to local public security and tax authorities.