{"success":true,"data":{"id":"irs-tax-refund-cross-domain","label":"Fake IRS \"tax refund pending — verify identity / bank account to claim\" notice sent from a non-IRS domain — by-definition impersonation phish: the IRS does not initiate contact via email. Credential-harvest, SSN-harvest, and bank-account-takeover cross-domain phish. Real IRS mail originates from irs.gov only.","description":"Fake IRS (Internal Revenue Service) \"tax refund pending — verify your identity, SSN, or bank account to claim refund or stimulus payment\" notification sent from a non-IRS sending domain (From / Reply-To / link domains do not align with irs.gov / treasury.gov) demanding the recipient click an off-domain link to release a pending tax refund — by-definition impersonation phish: the IRS publicly states it does NOT initiate contact with taxpayers by email, text message, or social media (irs.gov/newsroom/tax-scams-consumer-alerts). Any cold inbound email referencing IRS + tax refund + verify identity + click link is therefore credential-harvest, SSN-harvest, and bank-account-takeover. IRS impersonation is the #1 government-impersonation phishing lure tracked by FTC, FBI IC3, CISA, and TIGTA across 2020–2025. Distinct from fake-irs-tax-debt-collection-scam (debt-collection pretext) and fake-irs-tax-refund-deposit-phish (deposit pretext catalogue entry) — this is the engine signal targeting IRS + refund-pending / claim-stimulus / verify-identity-to-receive vocabulary with cross-domain From-link mismatch. Detection: IRS brand vocabulary + tax-refund / claim-stimulus / verify-bank urgency + sender or link domain ≠ irs.gov / treasury.gov + no DMARC alignment. Trash score: +5. Source: GC1-R32; IRS Tax Scams Consumer Alerts (irs.gov/newsroom/tax-scams-consumer-alerts); TIGTA IRS impersonation report 2024; FTC IRS impostor advisory 2024–2025; FBI IC3 2024 government-impersonation tracker; CISA government-impersonation phishing alert.","tier":"warning","category":"other","isThin":false}}