Phishers jump on HMRC tax blooper
By Tom Brewster,
Fraudsters have leapt on the chance to initiate a phishing scam based around the tax error debacle.
Millions are thought to have paid the wrong tax and HM Revenue and Customs (HMRC) will be contacting the affected people this month, but only via post.
Phishers, as is often the case, have made the most of a big news story and sent out messages pretending to be from the HMRC.
“Tax refund scam mails have been popular for a long time, but in the current climate of ‘our tax office has screwed up in spectacular fashion’ it seems phishers will be giving it some serious attention,” said Christopher Boyd, Sunbelt Software’s senior threat researcher, in a blog post.
One email intercepted by Sunbelt took the target to a fake HMRC website, asking for personal data, including a full name, address, phone number and mother’s maiden name.
The page also auto-filled a tax file number box in its bid to convince users of the site’s supposed legitimacy.
Boyd said people can expect a “deluge of spam mail with infectious attachments,” noting the UK tax office does not send “random emails asking for personal information.”
A fraudulent file
Sophos has also spotted similar emails, many containing the subject line “You Have An HMRC Refund” and an attached form that asks for data such as credit card details.
“If you do make the mistake of filling in the form, your confidential data is uploaded to a Chinese server,” said Graham Cluley, senior technology consultant at Sophos.
“You're not going to receive a windfall because of this form - you've just been phished.”
HMRC told IT PRO affected people will not be contacted by email or phone, and will not be asked to send personal information to anyone.
Last month, HMRC reported a spike in tax scam phishing emails being reported to the Government body.
It had shut down over 180 websites sending out fake tax rebate messages over a three-month period.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Yahoo CEO resigns after CV debacle
- Apple iPad 3 vs iPad 2 head-to-head review
- Macs under attack?
- HP to bring indestructible plastic displays and Memristor storage to market
- Fusion-IO share price soars on back of Dell merger rumours
- Android users warned of fake app store malware risk
- Dell PowerEdge R820 review
- Is BT the key to broadband Britain?
- What is your password worth?
- Police quiz UK teen over TeamPoison attacks
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





You can't report
You can't report these phishers if you use hotmail, they have killed the view source option to view headers required for reporting, all you get now is a load of random numbers, letters and symbols known as wingding fonts. You can't contact them to report the problem as all you get is a link to their forums which they don't even monitor, dare I say it typical Micro$oft.
By dfruk on Friday Sep 10