ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Scammers steal £47 million from HMRC in sophisticated phishing attack

The British tax authority said scammers posed as genuine tax payers to steal £47 million in the name of tax rebates, but authorities prevented a further £1.9 billion in losses.

 

In a Treasury Select Committee meeting, Angela MacDonald, Deputy Chief Executive of His Majesty’s Revenue and Customs (HMRC), said that scammers had tried to access identity information, “masquerade” as taxpayers, and extracted £47 million at HMRC’s expense. The organisation was, however, able to safeguard £1.9 billion that multiple scammers had attempted to steal.

 

She stressed that this was not a cyber breach of HMRC, but rather organised crime through phishing activity. She also noted that many customers had never set up an online account and were unaware of the fraud until they were contacted. 

 

MacDonald added that the HMRC is working closely with the Information Commissioner and investing in systems to stay ahead of digital threats.

 

“Every single organisation [is] facing some kind of cyber threat… it is a continuing piece of work for us to invest in our systems... to try to outpace the criminals,” she added.

 

Echoing MacDonald’s statement, HMRC’s Chief Executive, John-Paul Marks, informed the committee that the compromised accounts had been secured, and taxpayers who are being contacted will experience “no financial loss.”

 

“It’s about 0.2 per cent of the PAYE population, around 100,000 people, who we have written to, are writing to, to notify them that we detected activity on their PAYE account,” he said.

 

Marks added that a criminal investigation was launched last year, leading to several arrests, and that HMRC had taken steps to delete compromised accounts in order to protect customers.

 

Committee chair, Dame Meg Hillier, expressed her disappointment upon learning about the scam when it was reported in the news.

 

“A word to the wise... let me use my position as chair just to remind you, gently – well perhaps not so gently – that it would be normal to advise parliament of things if you’re appearing in front of a committee. Not to have it announced during the committee hearing,” she said.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543