Quarterly goods and services tax filings always bring a spike in SMS, WhatsApp and email lures promising fast refunds if taxpayers “confirm” bank details on look-alike websites. InfoHandle could not verify a Delhi Police cyber-cell press note dated September 2026 describing a specific cluster takedown; this article therefore documents the pattern Indian authorities have publicly warned about, and what Delhi businesses should do before clicking any link that mimics Central Board of Indirect Taxes and Customs or GST Network login pages.

What authorities have confirmed

The CBIC issued an alert on 21 July 2025 cautioning taxpayers about fake GST violation notices circulated on messaging apps, complete with forged Document Identification Numbers and CGST logos, according to CAclubindia’s summary of the board’s release. The Finance Ministry and Business Today have repeated that genuine summons must be checked through the “VERIFY CBIC-DIN” window at esanchar.cbic.gov.in before anyone pays a penalty or uploads credentials.

Separately, GSTN’s public guidance states refunds are processed only through www.gst.gov.in, not through parallel domains with similar blue-and-white interfaces. Fraudulent refund messages often route victims through a cloned login that harvests usernames, passwords and one-time passwords, then enables bogus return filings or bank account changes.

How the scam works

Attackers buy search advertisements or blast regional-language templates just before GSTR-1 and GSTR-3B deadlines. The user sees urgent language—“refund approved, verify within 24 hours”—and a URL that differs by one character from the official portal. Some campaigns host fake CBIC e-office login skins to capture credentials reused on the real GST site.

After credentials are stolen, mule operators file fictitious refund claims or divert input tax credit, patterns Delhi’s Department of Trade and Taxes and Economic Offences Wing have pursued in separate GST fraud cases reported by national media, distinct from the phishing-login vector but part of the same criminal economy.

Verification tools taxpayers should use

On 23 September 2025 the CBIC clarified that communications dispatched through its e-office public option carry a verifiable “Issue number” checked at verifydocument.cbic.gov.in, per CAclubindia’s note on Circular No. 252/09/2025-GST. Taxpayers should prefer typing gst.gov.in directly, enabling two-factor authentication, and refusing OTP entry on any third-party page.

If a notice arrives by email, match the sender domain to @gst.gov.in or official @gov.in handles; CBIC’s July 2025 alert stressed that violation notices do not arrive only via WhatsApp. Invalid DIN searches should be reported to the relevant CGST formation and through cybercrime.gov.in or the 1930 helpline.

Delhi-specific risk

Delhi’s dense MSME base and chartered accountant ecosystem make the capital a profitable target for refund lures during the monsoon quarter close. Cyber cells routinely publish festive-season advisories; even without a named September 2026 server seizure, helpdesks at Bhikaji Cama Place and Connaught Place tax districts field weekly calls from firms that clicked fake links. Aditya Banerjee’s security desk treats those anecdotal casework figures as directional, not statistical.

Practitioners should coach clients never to forward DSC or Aadhaar images in chat threads initiated by “GST help desks.” Legitimate consultants use formal engagement letters, not cold calls promising expedited refunds.

What businesses should do this week

Rotate GST portal passwords if any staff member admits to trying a refund link from SMS. Review authorised signatory lists and bank account validations inside the portal’s official workspace. Tell accounts receivable teams that customers will not receive genuine refund confirmations via random PDFs with payment QR codes.

For incident response, preserve URLs, UPI transaction IDs and WHOIS records before hosts go offline. Delhi Police cyber units accept complaints with those artefacts even when recovery is unlikely.

Why the headline matters

Scaffold titles sometimes imply a raid that press rooms have not corroborated. Until an official Delhi cyber-cell release names seized domains, the verified story is prevention: CBIC’s 2025 alerts, GSTN’s refund URL, the new verifydocument utility, and zero trust for CBIC login pages reached through advertisements. Filing season starts soon; the safest login is the one typed by hand.