British tax payers struck by phishing scam

Filed Under: Spam

Metro newspaper

British newspapers are warning their readers of a phishing scam that has been spread via spam email, telling recipients that they have been awarded a tax refund from the HMRC (Her Majesty's Revenue and Customs).

The phishing attacks have been seen arriving from faked addresses such as refundtax@hmrc.gov.co.uk or taxrefund@hmrc.gov.uk, and the fact that it is being seen so much now is no surprise. January 31st is the deadline for self-assessment forms to be filed with the HMRC, and some taxpayers will be hoping for a rebate.

Of course, for many people it's a dream come to true to think that they might actually be getting some money back from the tax man rather than having to give money to the Inland Revenue, so it's not surprising if people might eagerly click on the link without thinking of the possible consequences.

The HMRC has warned the British public of the threat, and posted information on its website. They emphasise that while they might send tax payers emails from time to time, they would never do so requesting login, bank or credit cards details.

Furthermore, the HMRC says it would always inform tax payers of rebates via post - and not by email.

HMRC phishing email

What's that old saying? In this world nothing can be said to be certain, except death and taxes? Maybe they should add a third certainty: phishing.

, ,

About the author

Graham Cluley is senior technology consultant at Sophos. The readers of Computer Weekly voted him security blogger of the year in 2009 and 2010, and he pipped Stephen Fry to the title of "Twitter user of the year" too. Which was nice. He was also named "Best Security Blogger" by the readers of SC Magazine in 2011. You can subscribe to Graham's updates on Facebook, follow him on Twitter and circle him on Google Plus for regular updates.