SecurCheckCyber Center
Need help
Back to analysis tools
All cyber threats
Human manipulation

Fake French tax-office crypto letter

Fake digital-asset portal, tax phishing, quishing

A fake paper letter impersonates the French tax authority and demands an urgent cryptocurrency declaration through a QR code leading to a fraudulent site.

Fiche de sensibilisationPrête à diffuser à vos équipes ou clients

MIGHT YOU BE AFFECTED?

Turn knowledge into action.

How does this work?

The letter mimics an official document, cites regulations and threatens a fine to create a sense of obligation. The QR code conceals the real address: instead of impots.gouv.fr, it leads to a fake portal collecting personal, banking or cryptoasset information. A logo, case reference or legal wording does not authenticate a letter.

REAL-WORLD EXAMPLE

« You receive a letter requiring you to register on a supposed digital-asset portal before 5 September 2026. It threatens a fine and offers only a QR code for the process. »

Typical sequence

  1. 1A letter impersonates the French tax authority and targets cryptoasset holders
  2. 2A short deadline, legal references and a threatened fine create urgency
  3. 3The QR code leads to a domain unrelated to impots.gouv.fr
  4. 4The site collects identity, banking, login or cryptoasset access information

Warning signs

  • A supposedly official digital-asset portal requires registration
  • An unusually short deadline and a financial threat discourage verification
  • The only route is a QR code, with no official address in plain text
  • The final address differs from impots.gouv.fr or another genuine government domain
  • Requests for credentials, bank details, wallet information, a private key or a seed phrase

How to protect yourself

  • Do not scan the QR code or enter information on the proposed site
  • Open impots.gouv.fr yourself using a bookmark or by typing the address
  • Verify the letter with your local tax office using contact details from its official site
  • Upload a photo or PDF to SecurCheck Universal Analysis to check the document, text and QR code separately
  • Never share a private key, seed phrase, one-time code or bank details because of an unexpected letter
  • Keep the letter, envelope and fake address as evidence for reporting

If you think you are affected

If you only opened the site, close it without downloading anything. If you entered a password, change it from the official service and enable strong authentication. If you shared banking information, contact your bank immediately. Treat a disclosed seed phrase or private key as a compromised wallet and move remaining assets to a new wallet created on a trusted device. Preserve evidence and report the fraudulent site.

Get help

Last updated: 6 September 2026