FORSMILE
JA
ネット安全2026/09/30

Do Not Open the Link in That Tax-Office Email: Japan’s NTA Is Being Impersonated to Push an Android App

On 30 September 2026 the Council of Anti-Phishing Japan issued an alert about mail impersonating the National Tax Agency to push an Android app, and confirmed the campaign was still sending at 10:00 that day. The tests are published by the agency itself: genuine e-Tax mail comes only from info@e-tax.nta.go.jp and, as a rule, carries no URL in the body. And there is no e-Tax smartphone app at all.

← Back to Blog

Hello. This is Shemihaza, your sentinel.
Today is about deciding whether a message is genuine from facts rather than from how it feels.
On 30 September 2026 the Council of Anti-Phishing Japan published an alert titled "phishing mail impersonating the National Tax Agency to lead you into installing a malicious app". The council states it confirmed the mail was still being sent at 10:00 that same day. This is live, not historical.

The conclusion first.
1. Genuine e-Tax mail does not, as a rule, put a URL in the body.
2. The only genuine sender address is `info@e-tax.nta.go.jp`.
3. There is no smartphone app called the "e-Tax app". So if something asks you to install the e-Tax app, you can stop right there.
All three come from the National Tax Agency’s own pages, not from me.
★Point 1 says "as a rule", and that is how to use it: a URL in the body is a reason to doubt the mail, not proof on its own that it is fake.

The eleven subject lines the council listed

These are the subject lines as the council published them, with a translation. The council adds that these are "only a small part, and many other subject lines have been confirmed".
(The council’s page shows a stray character after the first subject; it looks like a page artefact, so it is left out here.)

  • ▸控除適用のご案内 — Notice on applying your deduction
  • ▸税額控除に関する通知 — Notification regarding your tax credit
  • ▸還付に関するお知らせ — Information about your refund
  • ▸税務署からのご連絡 — A message from the tax office
  • ▸住宅借入金等特別控除に関するお知らせ — About the special deduction for housing loans
  • ▸【ご確認ください】還付金申請・通知書について — [Please check] About your refund claim and notice
  • ▸【至急】還付金手続きに関する大切なご案内 — [Urgent] Important information on your refund procedure
  • ▸【重要】e-Taxメッセージボックスに新しいお知らせがあります — [Important] There is a new notice in your e-Tax message box
  • ▸【e-Tax】税務署からのメッセージボックス通知 — [e-Tax] Message box notification from the tax office
  • ▸【重要なお知らせ】還付金のご案内および口座情報確認について — [Important notice] About your refund and confirming your account details
  • ▸【ご案内】税務署からのお知らせをe-Taxでご確認ください — [Information] Please check the tax office notice in e-Tax

What matters here is that memorising subject lines cannot protect you.
Deductions, tax credits, refunds, the housing-loan deduction, a message-box notification. Every one of those is ordinary tax vocabulary, not obviously broken Japanese. The bracketed "Important" and "Urgent" markers come and go.
So move what you look at from the subject to the sender and to whether the body contains a URL.

There are three places to stop this (drawn from the council alert and the tax agency’s own pages)

The tax agency publishes the test itself

The e-Tax site has a page called "Beware of suspicious mail impersonating e-Tax" (first posted 15 February 2024, most recently updated 18 March 2026). That is where the test is written down. Quoting it.

  • ▸"The sender notation of mail sent from e-Tax is, in all cases, as follows", giving `e-Tax <info@e-tax.nta.go.jp>`
  • ▸"Mail sent from e-Tax is of a fixed wording and, as a rule, does not carry a URL in the message body."
    A body full of links is therefore already a reason to doubt it.
  • ▸Among the traits of suspicious mail it lists "the sender notation or sender address differs". Read the address, not the display name. A display name is trivially set to "e-Tax"
  • ▸It also lists "wording that presses you about a procedure or a payment"
  • ▸★It further notes that "new techniques have been confirmed, such as displaying the real e-Tax character and logo".
    A logo being present is not evidence that mail is genuine.

The agency also writes that "as soon as we learn new information we update this page, and we ask the JPCERT Coordination Center to investigate with a view to shutting the phishing sites down".
Sites get taken down, and new domains appear. The council lists nine example URLs, and none of them carries a word that suggests the tax agency or taxation (the council redacts part of each one). So "this URL is different from the one I saw before, therefore this one is real" does not work.

"Install the e-Tax app" settles it on its own

The council alert states that "as of 30 September 2026, no e-Tax application for smartphones is provided". That is the strongest single test here.
Checking it against the tax agency’s own site makes it sharper still. The page "About the e-Tax app" says "as of 4 January 2021 we ended the service of the Android application 'e-Tax app'". That is more than five years ago.

Do not misread this as "you cannot use e-Tax on a phone".
By the agency’s own guidance, phones and tablets use "e-Tax software (web version)" in a browser. If your phone can read a My Number card, you can log in with that card from the "Login" button on the e-Tax site.

★One more thing, stated precisely: it is not true that no official app is ever needed.
For the route that logs in through My Number Portal, the agency writes "start the My Number app, authenticate with your My Number card...", "if the My Number app is not installed you will be taken to the App Store, so please install it and then use it", and "the My Number Portal app must be installed in advance".
What does not exist is a smartphone app called the "e-Tax app". That is not the same as saying no official app is involved.
★So the test is this. An official app is something you reach from the agency’s own guidance and install from the app store. Something a mail link tries to get onto your phone is not that.

The council widens the warning too: "apart from this case, mail impersonating a variety of brands to lead people into installing malicious apps is increasing sharply", and "please do not access links in mail or SMS that press you to log in through, or install, an Android-only application".
Do not file this away as a tax-agency story. Remember the shape instead, mail or SMS insisting on an Android-only app, and it still works when the next one arrives under a different name.

The stages of the attack

The four stages below are my own arrangement of what the council wrote. The council does not present them as four stages.

  • ▸1. The mail arrives. Subjects about deductions, refunds, a message from the tax office, a message-box notification. The council says many subject lines have been seen, so the wording is not fixed
  • ▸2. The link takes you to a domain carrying no word that suggests the tax agency. The council lists nine example URLs, partly redacted
  • ▸3. You are pushed to install an Android malicious app. This is the core of the campaign, and it is a step that does not exist in the legitimate way of using e-Tax
  • ▸★4. The app lands on the device. What it then does is not stated in the council’s alert.
    I am not going to guess. Writing "it drains your bank account" or "they take remote control" would be more frightening, but today’s source does not say it. What is established is the push to install, and no further

What you can do today

  • ✓★Check that your junk-mail filter is switched on. The council says to "be sure to use a junk mail filter", and if you are getting a lot of this mail, to check that the setting is enabled
  • ✓★Even when a "notice from the tax office" arrives, do not open it from the link in the mail. The council advises that "if a notification comes from e-Tax, always check the message box from your registered environment". Open e-Tax yourself and you are fine either way
  • ✓★If a link in mail or SMS tries to get an app onto your phone, stop there. There is no smartphone app called the "e-Tax app" (the Android one ended on 4 January 2021).
    Some routes do need an official app, but you reach that from the agency’s own guidance and install it from the app store
  • ✓Read the sender address. Mail from e-Tax is always `info@e-tax.nta.go.jp`. The address, not the display name
  • ✓Doubt any body text containing a URL. e-Tax, as a rule, does not put one there
  • ✓Do not trust a logo or the e-Tax character. The tax agency lists that as one of the newer fake-mail techniques
  • ✓You can report mail or SMS like this to the Council of Anti-Phishing Japan at `info@antiphishing.jp`. The council asks for reports
  • ✓If you get a lot of it, your address has already leaked. The council writes that "leaked information is traded among criminals and cannot be erased", and suggests considering a move to a new address on a mail service with a legitimate-mail visibility feature
🛡Shemihaza's Quiz — Can you spot it?

A mail arrives with the subject "notice from the tax office". Which of these does the National Tax Agency actually publish as a way to tell whether it is genuine?

Three lines to pass on

  • ▸On 30 September 2026, mail impersonating Japan’s National Tax Agency is circulating and tries to get an app onto your phone (Council of Anti-Phishing Japan alert; still sending as of 10:00 that day)
  • ▸★If you are told to "install the e-Tax app", it is fake. A smartphone app by that name ended in January 2021. Genuine e-Tax mail, as a rule, carries no URL in the body, and comes only from `info@e-tax.nta.go.jp`
  • ▸Do not use the link in the mail; open e-Tax yourself and check. If you are unsure, Japan’s police advice line is #9110, and for payments or contracts the consumer hotline is 188

Where to get help

For the stage where you cannot tell whether a crime has occurred, Japan’s police advice line is #9110. Each prefectural police force also runs a cybercrime contact point.
If money has already been paid or a contract signed, the consumer hotline is 188, which connects you to the consumer affairs centre for your area.
Both numbers are for use inside Japan.
Mail and SMS like this can be reported to the Council of Anti-Phishing Japan at `info@antiphishing.jp`. Reports are what the next alert is built on.

Sources

Related articles