Sunday, October 18, 2009

Five tips to spot scam emails from 'HMRC'

Many of us are used to receiving scam emails promising us something for nothing. Over the last couple of years fraudsters have been sending increasingly more sophisticated scam emails that purport to come from the taxman (HMRC). Even the Guardian, the Independent and the BBC are now reporting on this. Although they and other media tend to only be repeating the content of HMRC press notices and examples of recipients of scam emails.

Variations on such emails promise enticing opportunities such as tax refunds, the waiver of penalties, prize fund winnings, corrections to your NI record and updates to your HMRC security details. These emails are designed to fool the most suspicious of recipients and include links to what appear to be genuine pages of HMRC's website. In some cases, once you have been tricked into disclosing personal information you are then redirected to real HMRC web pages.

In theory we could all simply set our computer's spam filter to catch all emails that purport to come from HMRC. But the spammers know that many of us cannot do this. We may have registered to file our tax returns, our VAT and/or our Payroll returns over the web. We need to see the emails that confirm these have been received and processed. And although HMRC's press releases contain good advice they do not contain a simple summary.

So here are my five tips to help you identify scam emails that purport to come from 'HMRC':
  1. Email asks you to supply bank or credit card details or links you to an HMRC website that asks for this information;
  2. Email asks you to supply personal or password details or links you to an HMRC website that asks for this information;
  3. Email asks you to complete a form to receive a tax refund or rebate or links you to an HMRC website that asks you to do this;
  4. Email asks you to download an application or executable file (.exe) or links you to an HMRC website that asks you to do this;
  5. Email does not contain your name, was unexpected and does not relate directly and specifically to any details you have filed online with HMRC in the previous 48 hours.
HMRC would never send out genuine emails that do any of the above. Specifically they say:
  1. They never send notifications of a tax rebate over email;
  2. They never request that you update your security certification by email;
  3. HMRC's Online Services are only available to customers who register their details in advance;
  4. They never issue emails asking for personal details;
  5. If you receive an email requesting such information, please forward it to and then delete it;
  6. Never disclose personal information such as User IDs or Passwords in response to email requests;
  7. If you do follow a link to HMRC's website that requires you to enter sensitive personal information, only do so if there is a padlock in the bottom right hand corner of your Internet browser when you are on that page;
If you want to know more there is a dedicated and regularly updated page on the HMRC website that contains examples of the scams and frauds. The Tax Advice Network has reported on this in the past and offered practical tips and links in our weekly practical tax newsletter. HMRC also publish guidance on how you can make your online experience as secure as possible. This is aimed at the increasing number of taxpayers who have registered to communicate with HMRC online.

1 comment:

  1. This is very true, I have experienced it myself numerous times and I wonder why their doing that, I mean do they get something out of it,who could be generating all those spam/scam emails???

    even if you open filter for your mails you still get those...

    I think something must be wrong with the internet with ofcours millions of users worldwide...

    Its crazy because at times you believe something that is all fraud...