Scams

Government & Business-Filing Impersonation Scams

By Nick · Updated
government filing scambusiness compliance scamtrademark scamUSPTO scam

Definition

A government-filing impersonation scam is a fraud that uses a business's own public filing records — an LLC registration number, a trademark serial number, an annual-report due date — to construct a fake compliance notice that looks more credible than a generic phishing email, because it cites details only a filer would expect an agency to know.

How It Compares

What the real agency does What the scam does
Fee Washington's actual annual report fee is roughly $60. Real USPTO trademark fees are paid through official USPTO.gov filing systems, not read out over a phone call. Charges $200+ for an "annual compliance filing," or a one-time $575 "declaration fee" collected mid-call by card.
Contact channel Files, notices, and correspondence go through USPTO.gov or the Secretary of State's official portal — email only ever comes from an @uspto.gov address with nothing appended after it. Emails from a lookalike domain (e.g. teas@uspto.gov.lawoffice128.us — "uspto.gov" is embedded in a domain that isn't uspto.gov at all), then follows up with a live phone call running a script.
What they ask for Never asks you to read your own trademark or company name aloud "for the recording," never demands payment by phone, never collects officer/director home addresses through a self-serve web form. Reads a disclaimer quoting the Constitution and a law section that doesn't exist, asks the target to say their trademark name aloud "for the recording" before charging the card — or, in the LLC-compliance variant, walks the target through a full web form collecting officers' and directors' names and home addresses before the checkout page.

The Evidence

The Washington LLC compliance case: a text message carried a real LLC's actual state filing number and claimed the business was out of compliance, needing to "file the Washington annual report right now." This wasn't a simple link-and-collect page — it was a full web application, hosted on real infrastructure, that walked the target through entering officers' and directors' names and home addresses before handing them to a checkout page charging $200+ for a filing that costs $60 through the actual Secretary of State. The same code and flow was found running under fake portals in at least three other states. The tell, every time: none of it happens on a .gov domain.

The USPTO trademark case: a fake USPTO email cited a real trademark serial number and arrived from teas@uspto.gov.lawoffice128.us — a domain built specifically to make "uspto.gov" appear inside it. Investigating the domain turned up:

  • Registration timing: lawoffice128.us was registered three months before the email was sent.
  • WHOIS: the registrant was listed at the TCL Chinese Theatre in Hollywood — a fabricated address reused as filler.
  • Infrastructure cluster: three other domains (lawoffice116, lawoffice122, lawoffice133) shared identical nameservers, mail servers, cloud host, and registrar with the original — the same operator running multiple identities off one infrastructure stack. Widening the search past that identical-infrastructure cluster of four surfaced 11 active domains total following the same lawoffice###.us naming pattern, though seven of those sit on different, unrelated hosting.
  • SPF configured correctly — well enough to pass through spam filters that catch less careful phishing operations.
  • Multi-channel escalation: the email was followed by a live phone call reading a script, asking for a card number to cover a "$575 declaration fee," promising immediate use of the ™ symbol and the ® symbol "in a few months."

Both cases follow the same underlying playbook: take a real, public filing detail, wrap it in a slightly-wrong domain, and charge several times the real agency's actual fee.

What To Do About It

  1. Don't reply to the email or text, and don't call back a number it provides. Navigate directly to the agency's official site (uspto.gov, or your state's Secretary of State site) and check your filing status there.
  2. Check the domain character by character. A domain containing "uspto.gov," your state agency's name, or ".gov"-adjacent text is not the same as being sent from that agency — look for what comes after the agency name in the domain, and remember real state filings never happen off a .gov domain.
  3. Never read sensitive information aloud "for the recording" on an inbound or unexpected call, and never authorize a card charge mid-call for a filing fee.
  4. Don't fill out a multi-step web form collecting officer/director names and home addresses in response to an unsolicited compliance text — a real annual-report filing happens on your state's own portal, which you navigate to yourself.
  5. Call the agency's published number yourself if you're unsure whether a notice is real, using a number you looked up independently — not one in the notice.
  6. Use a registered agent or privacy service where your filing type allows it. Trademark and LLC filings are public record, which is exactly how scammers get enough real detail to sound credible.

Caveats & Edge Cases

Not every compliance-reminder email or third-party filing-service offer is a scam — legitimate registered-agent and compliance-monitoring services exist and do charge fees for convenience. The distinguishing signals are the lookalike domain, the phone-based pressure to pay immediately, and requests for information (like saying a trademark name aloud) that no real agency needs. Using a registered agent reduces public exposure of your filing details but does not eliminate it entirely, since some information remains part of the public record regardless.

Think you've spotted a scam?

Send it to us and we'll investigate it for free — the findings help build pages like this one.

← Back to Security Research