Tax season in New Zealand runs from April through July, and every year the pattern repeats: CERT NZ receives a spike in reports of fake IRD text messages as soon as the filing window opens. The 2025 season was no exception — IRD-themed smishing campaigns were among the top five reported scam types in Q2.
Smishing (SMS phishing) is effective precisely because people treat text messages differently to emails. Most of us have been trained to be suspicious of unexpected emails. Texts feel more personal, more urgent, and less obviously suspect. Scammers know this.
What IRD smishing looks like in practice
The standard IRD smishing message follows one of two templates:
The refund lure:
> "Inland Revenue: Your tax refund of $NNN.NN is ready. Verify your details to receive payment: [link]"
The debt threat:
> "IRD NOTICE: Unpaid tax debt of $NNN.NN. Failure to act may result in legal proceedings. Click here to resolve: [link]"
Both create urgency. Both include a link. The link leads to a convincing fake myIR login page designed to harvest your IRD number, date of birth, and bank account details in a single session.
The messages are sent at scale — thousands of New Zealand mobile numbers at a time, scraped from data breaches, social media, and purchased lists. The scammer doesn't know if you have a refund or a debt. They're betting that enough recipients do, and that the urgency will override scepticism.
What the real IRD will and won't do by text
IRD does use text messages for some communications — primarily two-factor authentication codes when you log in to myIR. That's it.
IRD will never text you to:
- Inform you of a refund amount
- Warn you of outstanding debt
- Ask you to click a link to verify your details
- Request payment via a link
- Ask for your IRD number, bank details, or password
If a text claims to be from IRD and asks you to click a link or provide information, it is a scam. No exceptions.
Why these scams work on employees
For businesses, the risk isn't just personal — it's organisational. Employees who receive an IRD smishing message during work hours may:
- Click the link on a work device, potentially exposing the device to malware
- Enter credentials that are shared with work systems (password reuse)
- Provide IRD numbers that are used in company tax filings
- Forward the message to colleagues ("has anyone else got this?")
A single click doesn't always end at a credential harvest page. Some smishing links install mobile malware that harvests all stored passwords, contacts, and banking apps from the device.
The tell-tale signs of a fake IRD text
The sender number looks odd — Real IRD messages for 2FA come from a short code or registered sender ID. A 10-digit mobile number claiming to be IRD is an immediate red flag.
The link doesn't go to ird.govt.nz — Real IRD links point to 'ird.govt.nz' or 'myir.ird.govt.nz'. Scam links use lookalike domains: 'ird-refunds.nz', 'nzird.co.nz', 'inland-revenue.net'. Check the domain before you click anything.
The amount is specific but generic — Scammers use amounts like $312.47 or $876.00 because they look real. Real IRD refund notifications come through myIR, not text.
It asks for action outside myIR — Any legitimate IRD communication directing you to take action will point you to myIR directly via your browser, not through a text link.
What to do if you or a staff member receives one
- Don't click the link — Even loading the page can trigger tracking scripts
- Delete the message — Don't forward it to others
- Report it to CERT NZ — Use the report form at cert.govt.nz
- Check myIR directly — If you're genuinely worried about your tax position, go to 'myir.ird.govt.nz' by typing it directly into your browser
- If you clicked — Change your myIR password immediately, contact your bank if you entered financial details, and notify your IT team if it was on a work device
Making this a training moment
Tax season smishing is one of the most effective real-world examples to use in security awareness training. It's locally relevant, happens on a predictable schedule, and targets something every employee deals with personally.
A short training reminder sent to staff in April — before the smishing campaigns peak — significantly reduces click rates. The timing matters: training delivered the week before a known threat is far more effective than training delivered after an incident.
For more on how to build awareness around NZ-specific phishing threats, see our post on the phishing gap in NZ employee training.
SecureAZ includes NZ-localised phishing simulation templates — including IRD refund smishing — so your team encounters a safe version of the real thing before the real one arrives. Start a free trial and have your first simulation running before tax season peaks.