“Is this spam?”
The message looked surprisingly legitimate.
Japan’s National Tax Agency. e-Tax. “Important.” A tax refund. A deadline. Security notes. A privacy policy. An official-looking postal address. A government corporate number. A copyright footer.
Scroll to the bottom and it still looks respectable.
Almost too respectable.
Then it gives a specific planned refund amount in the ¥80,000 range, and for half a second the brain says:
“Wait, really?”
But the link tells a different story.
The email is wearing a National Tax Agency suit.
Its name tag says:
shoofimafi[.]com
Government suit.
Mystery .com name tag.
Case closed.
The uncomfortable part is that modern phishing no longer has to look like a badly translated ransom note. Japan’s National Tax Agency explicitly warned in an update dated March 18, 2026 that attackers are using real-looking e-Tax logos and characters in increasingly polished phishing campaigns [1].
The game has changed.
Do not ask:
“Does it look suspicious?”
Ask:
“Is its structure authentic?”
1. Looking professional is part of the attack
The fake email stacks credibility cues:
- National Tax Agency and e-Tax branding
- a specific refund amount
- a processing deadline
- references to My Number card authentication
- notes about service hours
- privacy-policy language
- government-looking address and registration information
- polished HTML buttons
Every piece looks plausible in isolation.
And none of it is hard to copy.
The National Tax Agency says phishing emails may spoof the visible sender name or address and may even use genuine-looking e-Tax logos [1]. Japan’s Council of Anti-Phishing also notes that phishing websites are often copied from real sites and can be extremely difficult to distinguish visually [2].
So these are weak signals:
“the Japanese sounds natural” “the logo is correct” “the footer has an address” “the page has a privacy policy”
Attackers can copy all of that.
A meticulous footer does not make a criminal legitimate.
2. Dissect the URL and the costume falls off
The suspicious link, defanged for safety, looked like this:
hxxps://shoofimafi[.]com/HNG2lycwWJ.chiba-city[.]jp
At a glance, the ending contains “chiba-city.jp.”
That sounds governmental.
But URLs are not read by vibes.
The 2026 consumer guideline from the Council of Anti-Phishing explains that, in an ordinary URL, the domain sits between “https://” and the first following “/” [2].
So this link breaks down as:
- scheme: hxxps
- actual host: shoofimafi[.]com
- path: /HNG2lycwWJ.chiba-city[.]jp
“chiba-city.jp” is not the destination.
It is text inside the path.
Think of it this way:
the building is not the tax office.
It is a random building with “tax-office-looking words” painted in the hallway.
Official e-Tax services use the e-tax.nta.go.jp family.
This link does not.
That alone is enough to stop.
3. The Android app instruction is a giant historical error
The email instructed Android users to download an “e-Tax app.”
But the National Tax Agency’s own website says the Android “e-Tax app” service ended on January 4, 2021 [3].
A 2026 email telling you:
“Don’t have the Android e-Tax app? Download it here”
has accidentally invented time travel.
You expected a tax refund.
Instead, a discontinued 2021 app came back from the dead.
This is a useful lesson: phishing kits often reuse old genuine text. If you know the current state of the service, old-but-real fragments become a red flag.
4. The timeline also collapses
The message claimed, in substance, that the refund had been finalized based on the full 2026 income-tax year, defined as January 1 through December 31, even though the message was dated in September 2026.
Japan’s National Tax Agency explains that income tax is calculated for the full calendar year from January 1 to December 31, with the normal filing process occurring afterward [4].
In September, December 31 has not happened yet.
The email has already processed the next 3 months of future income.
That is not tax administration.
That is prophecy.
There are legitimate refunds and tax procedures that can happen during a year or relate to earlier years. The key is narrower:
Does the period claimed by the message match the date on which it says the result is final?
Attackers can copy design perfectly and still fail at institutional chronology.
5. What genuine e-Tax email behavior looks like
According to e-Tax, official notification emails use a fixed format and are shown as coming from:
e-Tax (National Tax Electronic Filing and Payment System) info@e-tax.nta.go.jp [5]
But do not turn that into a new shortcut.
A correct-looking sender is not proof.
The National Tax Agency explicitly warns that visible sender names and addresses can be spoofed [1].
The stronger signal is behavioral:
official e-Tax notification emails generally do not include URLs in the body [1][5].
For refund processing, the official instructions say to open the e-Tax website independently, log in to the web version, then go to My Page → Refund/Tax-related items → Refund processing status [6].
That separation is powerful.
Do not let the email choose your destination.
Choose the official destination yourself.
6. HTTPS, padlocks and official-looking footers are not identity cards
An old rule of thumb said:
“Look for HTTPS and a padlock.”
That is no longer enough.
The Council of Anti-Phishing explains that phishing sites can also use encrypted connections and valid certificates; a padlock alone does not establish that the site belongs to the organization you intended to visit [2].
HTTPS mainly tells you:
“the connection to this server is encrypted.”
It does not tell you:
“this server belongs to Japan’s National Tax Agency.”
You can have a beautifully encrypted conversation with a scammer.
It is still a scam.
The same is true for:
- logos
- addresses
- registration numbers
- privacy-policy text
- copyright notices
These are public information.
Public information can be copied.
7. A 30-second verification routine
Once you stop judging by visual polish, the process becomes shorter.
1) Do not use the link in the message
Refunds, overdue bills, identity verification, account suspension, deadlines and prizes are designed to trigger action.
Separate the emotion from the click.
2) For money, taxes or accounts, open the official service independently
Use a bookmark, a known official app, or manually enter the official site.
The Council of Anti-Phishing recommends accessing services through known correct URLs or official applications rather than relying on links inside unverified messages [2].
3) If you inspect a URL, inspect the host
Look between “https://” and the first “/.”
Brand-looking words inside the path do not change where the browser connects. Even 100 official-looking words in the path do not change the actual host.
4) Check institutional time
Is the tax year even finished? Is the advertised app still supported? Does the procedure actually exist?
5) Ignore the fear of “missing out if it is real”
If a legitimate refund exists, you should still be able to see it by opening the official service yourself.
If a real tax problem exists, you should still be able to verify it through official channels.
A legitimate government process should not depend on your trusting one surprise email button.
8. Why this matters now: scale plus polish
According to the Council of Anti-Phishing, 82,338 phishing reports were submitted in Japan in August 2026, about 24.5% more than the previous month [7].
Government-themed phishing also increased that month.
The same report notes polished HTML messages, abuse of legitimate online services, and other techniques that make simple visual judgment less reliable [7].
So the old stereotype is dangerous:
“Bad grammar means phishing.” “Ugly design means phishing.” “Scams look obviously fake.”
Modern attacks increasingly assume the opposite.
Expect the appearance to pass.
Then verify the structure.
9. What to do if you clicked
You only opened the page
Close it and do not submit anything.
Then independently open the official service and check the real status.
You entered credentials
Go to the official service through a trusted route and change the relevant credentials.
If you reused the same password elsewhere, change those copies too.
You entered card details
Contact the card issuer through its official channel immediately and follow its instructions for blocking or replacing the card.
You installed an unknown Android application
Treat this as higher risk than merely opening a webpage.
Stop unnecessary network use, protect important accounts from a separate trusted device, and use official security tools or professional support to inspect the device.
Do not assume that deleting the app automatically ends the problem.
Conclusion: inspect the structure, not the costume
The email looked strong.
National Tax Agency. e-Tax. Refund. Deadline. Privacy policy. Government address. Registration number.
All present.
But structurally it collapsed:
- the destination was not a National Tax Agency domain
- it promoted an Android e-Tax app discontinued in 2021
- its tax-year timeline did not make sense
- its navigation pattern did not match official e-Tax guidance
That leads to the useful rule:
“It looks legitimate, which is exactly why appearance is not the test.”
Government suit.
Mystery .com name tag.
Read the name tag.
Sources
- e-Tax, “Beware of suspicious emails impersonating e-Tax,” updated 2026-03-18 e-tax.nta.go.jp
- Council of Anti-Phishing Japan, Consumer Anti-Phishing Guideline 2026 antiphishing.jp
- e-Tax, Android “e-Tax app” service ended 2021-01-04 e-tax.nta.go.jp
- National Tax Agency, overview of Japan’s income tax system nta.go.jp
- e-Tax, guidance on official “Notice from the Tax Office” emails e-tax.nta.go.jp
- e-Tax, refund processing status confirmation e-tax.nta.go.jp
- Council of Anti-Phishing Japan, August 2026 phishing report, 2026-09-18 antiphishing.jp
