Scammers are sending counterfeit IRS letters through the mail that closely mimic a real tax notice received by roughly one percent of taxpayers during the 2026 filing season. The fake letters include QR codes that, instead of directing recipients to IRS.gov, route them to copycat websites designed to harvest bank account details and personal information. The scheme exploits a narrow window created by the IRS’s own mass mailing of Notice CP53E, a legitimate form sent when the agency lacks valid direct-deposit information for a refund, giving fraudsters a built-in pool of anxious recipients primed to act quickly.
How CP53E timing gives scammers a built-in advantage
Notice CP53E is triggered when the IRS cannot process a taxpayer’s refund because of missing or invalid direct-deposit information. The notice gives recipients a 30-day window to respond with corrected banking details, creating urgency that scammers can weaponize. A taxpayer who has already filed a return and expects a refund is far more likely to scan a QR code and enter sensitive data under time pressure than someone receiving an unsolicited letter out of the blue.
The IRS reported that about one percent of taxpayers received a CP53E notice due to missing or invalid banking information during the current filing season. That figure, while small as a percentage, translates into a sizable population of people who may have already been told by the IRS to expect exactly this kind of letter. Fraudsters who match the timing, envelope style, and formatting of the genuine notice can blend their fakes into a wave of authentic correspondence, raising the odds that a recipient will comply without verifying the source.
Because the authentic CP53E letters are sent only to people with refund delays, many recipients are already frustrated or worried when the envelope arrives. That emotional context makes them more susceptible to any message that appears to offer a quick fix. Scammers exploit this by mirroring the language of the real notice, emphasizing deadlines and the risk of losing a refund if the recipient does not act quickly. The more closely the counterfeit tracks the genuine layout and tone, the less likely a hurried taxpayer is to question whether the QR code is safe.
How the QR codes drain bank accounts
Legitimate CP53E notices may contain a QR code that directs recipients to IRS.gov, where they can update their banking information through the agency’s secure portal. Fraudulent versions of the letter swap that code for one pointing to a lookalike domain built to capture account numbers, routing numbers, and Social Security numbers. The Taxpayer Advocate Service has warned that fake notices may route to malicious lookalike sites designed to steal personal and banking information, while genuine codes point only to IRS.gov.
The technique is not limited to tax fraud. The FBI’s Internet Crime Complaint Center has documented how criminals tamper with QR codes across a range of settings, from parking meters to mailed correspondence, to redirect victims to fraudulent domains that lead to stolen funds. The practice, sometimes called “quishing,” relies on the fact that most people cannot distinguish a legitimate QR code from a malicious one by sight. Once a victim lands on a typosquatted site and enters banking credentials, the stolen data can be used to initiate unauthorized transfers before the person realizes anything is wrong.
In the CP53E copycat scheme, the fraudulent site typically imitates the IRS color scheme and logo, and may request more information than the real portal would ask for at once. Instead of routing users through the IRS’s existing account-creation and identity-verification tools, the fake forms can present a single page requesting full bank details, date of birth, and Social Security number. The absence of multi-step security checks-such as one-time codes or prior account login-can be a subtle warning sign that the page is not part of the legitimate IRS infrastructure.
Physical mail adds a layer of perceived legitimacy that email phishing often lacks. A printed letter bearing IRS branding, a notice number, and a QR code carries more weight for many recipients than an email that might be flagged by a spam filter. The U.S. Postal Inspection Service has separately described how QR codes embedded in physical communications can be weaponized to route victims to phishing sites, reinforcing that the threat extends well beyond digital channels. When the envelope and letter appear official, people are more inclined to trust the embedded technology without taking the extra step of navigating to IRS.gov on their own.
What taxpayers still cannot verify on their own
No federal agency has published data on how many fake CP53E letters carrying malicious QR codes have actually been mailed, how many people entered banking information on the fraudulent sites, or which specific domains were used. The Taxpayer Advocate Service and the IRS have issued warnings and verification guidance, but neither has released case counts or geographic breakdowns of confirmed incidents. The FBI’s IC3 advisory on QR-code tampering addresses the general mechanism without tying it to specific tax-related mailings or dollar losses.
That gap matters because taxpayers who receive a CP53E-style letter have no reliable way to determine from the letter alone whether the QR code is safe. The IRS advises recipients to avoid scanning any QR code in a suspicious notice and instead type IRS.gov directly into a browser to check their refund status or update banking details through their online account. Suspected fakes can be forwarded to official IRS phishing contacts or reported to the Treasury Inspector General for Tax Administration.
Without public statistics on how often the counterfeit notices are appearing, taxpayers must rely on process, not probability. That means assuming any unexpected QR code is unsafe until proven otherwise, even if the surrounding letter looks authentic. It also means recognizing that a real CP53E notice will never require you to provide full banking credentials or other highly sensitive data through a single QR-linked form. The safest approach is to treat the paper notice as an alert and then complete all actions through channels you initiate yourself.
How to safely respond to a CP53E-style letter
The first practical step for anyone holding a letter that looks like a CP53E notice is to set the letter aside and log in to an IRS online account at IRS.gov directly, not through any link or code on the paper. If the account shows a pending refund issue or a CP53E notice on file, you can follow the instructions there or call the IRS using the phone number listed on the official site. If your account shows no such notice, that is a strong indication that the mailed letter may be fraudulent.
Taxpayers who are unable to access an online account should use phone numbers obtained from IRS.gov, not from the letter, to confirm whether the notice is genuine. When calling, have your Social Security number and filing status ready, but do not read bank account information from the letter aloud unless an IRS representative has first verified that a legitimate CP53E notice was issued to you. If the representative cannot find a corresponding notice in the system, you should assume the mailed document is a scam and follow the reporting instructions provided by the agency.
Consumers can further protect themselves by adopting a few general rules for QR codes in financial contexts: never scan a code on a document that also provides a web address you can type manually; avoid entering full banking credentials on any page reached solely via QR; and verify the domain name in the browser’s address bar before submitting personal information. These habits reduce the risk not only from CP53E copycats but from the broader wave of QR-based scams described by federal law enforcement.
Until agencies release more precise data on the scope of the counterfeit CP53E problem, taxpayers should assume that timing and appearance alone are not enough to validate a notice. The safest course is to ignore the QR code entirely, confirm any refund issue through an IRS account or trusted phone number, and report suspicious letters so investigators can track emerging patterns. By shifting from reactive scanning to deliberate verification, recipients can blunt the advantage scammers gain from piggybacking on legitimate IRS mailings.
More from Morning Overview
*This article was researched with the help of AI, with human editors creating the final content.