The Internal Revenue Service issued a statement warning about a fake email and urged taxpayers to delete it. Experts claim that there may have been access to taxpayers’ database.
Read the article in La Tercera-Pulso.
On Monday afternoon, information began circulating among tax experts about a possible hack of the Internal Revenue Service (SII) platform. In response, the agency led by Javier Etcheberry published a statement on its website warning about the situation, which was later shared with the press.
“In light of the circulation of a fake email attempting to impersonate institutional messaging, the Internal Revenue Service (SII) calls on all taxpayers to exercise maximum caution regarding this type of communication,” the statement began.
It detailed that “the email currently circulating refers to a supposed ‘Business Closure Order’ procedure and includes a link to access more information.” Therefore, it requested “that individuals who have received an email similar to the one shown proceed to delete it.”
In its message, the agency emphasized that “as part of its institutional policy, the SII will never send messages containing download links or redirecting to external websites, nor will it request personal information or taxpayers’ passwords.”
It also reiterated that “if you receive emails with these characteristics, including links and access prompts, we recommend not clicking on them, as they are intended to obtain personal data or damage your devices—both of which constitute criminal offenses.”
Criticism from tax experts
Following this situation, experts quickly raised concerns. One of them was Juan Alberto Pizarro, president of the Tax Commission of the Association of Accountants, who urged the SII to make greater investments in its web platform technology.
“Clearly, beyond maintenance and patching of the platform, what is needed is a strong investment in new systems that ensure continuity, stability, and security of the SII platform, aligned with the highest international standards. We have observed weaknesses not only during critical periods such as the tax filing season, but also in monthly processes like VAT filings, where deadlines have even had to be extended,” Pizarro stated.
Christian Delcorto, Partner of Tax Consulting and Compliance at CCL Auditores Consultores, provided further insights: “Unlike previous cases, we understand that there was access to the database of contact details used for notifications registered on the SII platform. As a result, these emails are reaching those individuals directly, containing malware intended to take control of devices or steal sensitive data. Therefore, we recommend deleting the email from inboxes.”
According to Delcorto, “the key difference between this communication and previous phishing emails is that, in this case, the email addresses and contacts appear to have been sourced from the contact database within the SII. Consequently, many taxpayers—through their legal representatives—received the message simultaneously, suggesting that this is not merely an email impersonating an SII account.”