Tax Compliance Scams Foreign Investors Should Avoid
A convincing tax message is not a tax obligation until the company verifies the sender, taxpayer record, period, document, payment route, authority, and evidence independently.
Foreign investors should treat urgent requests to update Coretax data, download an application, share a one-time code, disclose credentials, pay a personal or unfamiliar bank account, settle an unverified tax bill, appoint a surprise agent, or keep the matter secret as potential fraud indicators. Stop the action, preserve the original message, reach DGT or the known adviser through independently sourced official channels, compare the claim with the company's tax account and records, and require a controlled approval before any data, document, credential, filing, or payment is released.
Separate tax-channel verification from general provider due diligence. For every suspicious tax request, verify the sender, official account or notice, taxpayer record, payment destination, requested authority, credential need, and response deadline through independently sourced channels. Use the Indonesian document verification checks for cross-registry evidence, and require a controlled incident record before releasing data, credentials, documents, filings, or money. DGT's 2026 warnings reinforce the need for independent verification.
Key takeaways
- Verify the sender and requested action through an independently reached official DGT channel before clicking, replying, calling, or paying.
- Keep Coretax credentials, recovery, authorization codes, certificates, devices and taxpayer documents under company control.
- Match every notice or bill to taxpayer identity, tax type, period, legal basis, official account, return, ledger and approval.
- If fraud is suspected, preserve evidence, contain access, contact financial institutions promptly, verify tax status and obtain local advice.
In this article
Verify a tax request
Check the official domain, sender, taxpayer, period, notice, account, requested action, and payment route independently.
Verify the DJP sender, domain, and requested action
Do not use the phone number, link, QR code, attachment, application, bank account, or support contact contained in a suspicious message to verify that same message. Record the displayed sender, full email headers where available, telephone or messaging account, exact domain, URL, attachment name and hash where safely handled, claimed office and officer, taxpayer identity, tax period, amount, deadline and requested action. Then navigate independently to pajak.go.id or a previously verified DGT channel and confirm the claim.
DGT warned in January 2026 that criminals imitate Coretax-related technical addresses and that official DGT domains end in pajak.go.id. The official DGT digital tax scam warning contrasts the official Coretax domain with deceptive lookalikes. A valid-looking logo, copied employee name, taxpayer data, HTTPS lock, sponsored result, or familiar chat profile does not override the domain and independent verification test.
Create an approved contact register from DGT's official website, known tax-office correspondence, the company's validated adviser engagement, and independently verified bank and legal contacts. Train staff to forward suspicious messages to a security owner without interacting with links or files. Use a callback script that asks for the official document identifier, tax type, period, taxpayer account location, legal response route and verification method without disclosing new sensitive data to the caller.
| Red flag | Independent test | Safe action |
|---|---|---|
| Urgent Coretax update link | Type the official domain independently and check the live account | Do not click, install or enter credentials |
| Officer requests payment | Verify notice and payment route with DGT through known channels | Hold payment and preserve the request |
| New tax agent contacts staff | Confirm legal entity, engagement and authority with management | Share no files, codes or taxpayer data |
| Attachment claims to be a bill | Verify document identifier and taxpayer account before opening | Quarantine and escalate through security controls |
Protect Coretax identity, credentials, and authority
Inventory every person and provider with access to taxpayer accounts, registered email and telephone, recovery, authorization code or electronic certificate, delegated role, device, password manager, file share, tax document archive, bank payment authority and sensitive identity material. Distinguish director or legal representative, preparer, reviewer, submitter, payment maker, approver, adviser and system administrator. Remove departed or unnecessary users through the proper process and verify that recovery does not point to a former employee or agent.
DGT's official Coretax manual library provides the current operating materials for registration, taxpayer data, authorization, returns and payments. Use the current official route rather than accepting a remote-access utility or unofficial mobile application from a caller. DGT's scam warnings specifically identify phishing and malicious application downloads as methods used to obtain personal or taxpayer data.
Adopt a no-credential-by-chat rule. One-time codes, passwords, recovery links, authorization material and certificates should not be sent casually to an agent, colleague or purported officer. Where a provider is legitimately engaged, use documented limited authority, controlled company contact data, approved devices or access route, maker-checker review, activity logs, file versioning and prompt revocation. Keep the company able to retrieve its full filing and payment history without asking the provider for permission.
Identity
Legal representative, taxpayer details, registered contacts and supporting documents remain current and controlled.
Access
Named users, least privilege, approved device, recovery, logs, backup and departure revocation are reconciled.
Delegation
Written scope, duration, permitted acts, review, evidence delivery, confidentiality, termination and revocation are explicit.
Secure Coretax access
Reconcile users, roles, recovery, certificates, devices, advisers, payment authority, logs, and revocation.
Validate tax notices, bills, agents, and payments
Before responding or paying, match the claim to the exact taxpayer, NPWP or identifier, tax type, period, return, transaction, legal basis, official notice number, issue date, service channel, response deadline, billing or payment code, amount, bank route, ledger balance, prior payment and correspondence. Require a reviewer independent of the requester. For a surprise assessment, audit, collection or penalty claim, obtain the full official instrument and qualified Indonesian advice before admitting liability or transferring money.
DGT issued a June 2026 warning about fraudulent tax-bill emails and has repeatedly explained that phishing can request data updates or malicious downloads. Review the official DGT fake tax-bill email warning and the official phishing announcement . These warnings support verification, not an assumption that every unexpected notice is fake.
Validate a tax adviser or payment intermediary separately. Confirm legal entity, professional identity where relevant, office, responsible person, service contract, scope, authority, invoice, company bank account, data security, subcontractors, complaint route, and deliverables. The provider should supply calculations, source schedules, draft and final returns, official receipts, billing records, payment evidence and reconciliation. Never pay tax to an individual's account because a provider labels it a government shortcut.
Notice test
Official source, number, taxpayer, period, issue and receipt dates, deadline, legal route and live account match.
Payment test
Approved obligation, official billing data, legal payee, bank route, amount, period, receipt and ledger posting match.
Agent test
Verified entity, people, scope, authority, invoice, bank, security, workpapers, receipts, access and termination match.
Contain and document a suspected tax scam incident
If someone clicked, installed software, shared data or credentials, approved a login, changed recovery, filed a return, or made a payment, activate the incident plan. Record who did what, device and account, time, data exposed, files opened, credentials used, tax actions, payment details, communications and current access. Preserve original messages, headers, domains, numbers, attachments and bank records without forwarding malware broadly or altering the evidence. Isolate affected devices through qualified security support.
DGT stated in January 2026 that fraud impersonating DGT is criminal conduct and that it coordinates with competent institutions. See the official DGT public warning . Use verified authority channels and Indonesian legal advice to determine reporting. Contact the bank or payment provider promptly about available protective measures; recovery is not guaranteed, and staff should not confront a suspected perpetrator in a way that creates safety or evidence risk.
Reset and recover accounts through independently verified official routes, review registered contacts and delegated roles, revoke compromised access, check filings, payments, notices and taxpayer data for unauthorized changes, and notify insurers, auditors, directors, data-protection or other stakeholders where law and advice require. Maintain an action log and obtain written closure evidence where available. Then remediate the cause: training, payment approval, domain filtering, device security, provider oversight, access review and response drills.
Containment
Stop interaction, isolate affected devices, protect accounts, hold payments and preserve original evidence.
Verification
Confirm taxpayer, filing, payment, notice, registered contacts and access state through official and known channels.
Recovery
Bank and authority contact, legal and security advice, access reset, data review, stakeholder duties and control remediation.
Official references and review basis
The following primary sources were checked on August 1, 2026. They establish the regulatory or service boundary used in this article; bank, tax office, OSS, AHU, and immigration decisions can still depend on the current record and the facts of a particular application.
- DGT — Five digital tax scam methods — January 2026 official warning on lookalike Coretax domains and digital fraud methods.
- DGT — Fake tax-bill email warning — June 2026 official warning about fraudulent tax billing emails.
- DGT — Phishing announcement — Official explanation of phishing messages and malicious downloads impersonating DGT.
- DGT — Public fraud warning — January 2026 official statement on tax-authority impersonation fraud.
- DGT — Coretax manual library — Official current operating materials for taxpayer data, authority, returns and payments.
The verification gate before acting on a tax request
Act only after an independently reached official channel confirms the sender, taxpayer, document, tax type, period, legal route, deadline, account status, billing data and payment destination. Keep Coretax identity and authority under company control, require dual review for data and money, and retain the source evidence, approval and official receipt for every legitimate action.
If fraud is suspected, stop, preserve, contain and verify before communicating or paying further. Escalate compromised credentials, unauthorized filings, data disclosure, diverted funds or threats to qualified Indonesian legal, tax, banking and security professionals. Use the Indonesia company registration framework to rebuild tax controls inside the entity's wider governance.
Prepare a tax fraud response
Preserve evidence, contain access, verify filings and payments, contact institutions, and remediate controls.
Frequently asked questions