HMRC Phishing Scam: £47m Stolen
- The United Kingdom's tax authority, HMRC, revealed that scammers pilfered £47 million from the online accounts of approximately 100,000 individuals by impersonating taxpayers.
- HMRC clarified that the incident involved attempts to fraudulently claim money from the tax authority, not directly from its customers.
- The scammers employed phishing tactics to obtain customer details and later attempted to claim rebates.
Scammers have stolen a staggering £47 million from approximately 100,000 online accounts by impersonating taxpayers, according to a recent HMRC report. Authorities are now contacting affected individuals to reassure them that their accounts are secure following this major phishing attack.A criminal investigation has been underway, leading to arrests in teh past year. The fraudsters used sophisticated phishing tactics to gain access to customer data, attempting to claim rebates fraudulently. HMRC confirms this was not a cyberattack but a targeted scam exploiting personal data. The agency is also reinforcing its security measures to shut down compromised accounts and prevent further damage, as revealed in a treasury Select Committee meeting.News Directory 3 will continue to provide updates as the agency further investigates and increases IT systems. Discover what’s next as the government plans further investments in HMRC’s IT systems to defend against future online fraud.
HMRC Taxpayer Scam: £47 Million Stolen in Phishing Attack
Updated June 4, 2025
The United Kingdom’s tax authority, HMRC, revealed that scammers pilfered £47 million from the online accounts of approximately 100,000 individuals by impersonating taxpayers. The agency is now contacting those affected to assure them that their accounts are secure, no funds were lost, and no action is required on their part.
HMRC clarified that the incident involved attempts to fraudulently claim money from the tax authority, not directly from its customers. The agency also confirmed that a criminal investigation took place last year, resulting in arrests.
The scammers employed phishing tactics to obtain customer details and later attempted to claim rebates. Phishing involves using externally gathered personal information to impersonate individuals and gain access to services. HMRC emphasized that this was not a cyberattack or hacking incident of the kind that has recently impacted major retailers.
Angela MacDonald, HMRC’s deputy chief executive, informed members of Parliament at a Treasury Select Committee meeting Wednesday that a “lot of money” was taken, deeming it “very unacceptable.” John-Paul Marks, HMRC’s permanent secretary and chief executive, told the committee that “a lot of work [was] then done to intercept this incident” and that they “identified and locked down the compromised accounts.”
MPs rebuked HMRC representatives for failing to promptly notify the committee about the fraud. MacDonald explained that the scam largely involved criminals creating new accounts using phished information.Many of the individuals whose information was used did not have or need online tax accounts, meaning they were unaware of their involvement in the scheme.
MacDonald noted that ”the nature of the attack altered thru the year, as we were closing it down, and closing accounts down.” She added, “They were moving their MO [method] over… We took a lot of action to actually tackle the perpetrators.”
According to MacDonald,a significant challenge was ensuring they were communicating with the legitimate customer and not the criminal controlling the account. She stated that she maintained communication with the information commissioner and followed their advice on managing the incident.
MacDonald stated, “We are living in an environment where every single association was facing some kind of cyber threat,” adding that continuous investment in systems is necessary “to try to outpace the criminals.”
What’s next
The government is expected to announce further investments in HMRC’s IT systems during next week’s spending review, aiming to bolster defenses against future online fraud and taxpayer scams.
