Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

100,000 HMRC Accounts Targeted in a £48.8m Scam Campaign: Why HMRC Says It Wasn’t Hacked

HMRC says criminals used externally obtained personal information to target about 100,000 online tax accounts and pursue fraudulent PAYE repayments. Here’s what the figures mean and what to do if you suspect your account was affected.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

HMRC says criminals used personal information obtained outside the tax authority to make unauthorised attempts to access about 100,000 customer online tax accounts. The aim was to claim fraudulent PAYE repayments from public funds—not to empty those taxpayers’ bank accounts. HMRC’s 2024–25 annual report estimates the resulting revenue loss at £48.8 million and says affected customers will not suffer a personal tax loss.

That distinction matters: HMRC says its systems were not breached in the sense of criminals breaking into a central database and extracting it. The incident was still a large-scale cyber-enabled fraud involving taxpayer identities and HMRC services.

What happened in the HMRC scam campaign?

HMRC’s annual report says organised criminal groups used personal information from external sources, including phishing and other cyber-enabled crime, to attempt unauthorised access to approximately 100,000 customer online tax accounts. The figure is about 0.22% of HMRC’s customer base, according to the report. HMRC’s formal wording is “unauthorised attempts to access”; it does not establish that every account was successfully taken over.

Contemporary reporting described criminals creating PAYE accounts in the names of people who had not previously set up an HMRC digital account, as well as trying to access existing accounts. The reported purpose was to generate repayment claims through PAYE. HMRC’s published account confirms the external data and access attempts, but does not describe every lure, credential source or technical step. HMRC’s annual report: accountability; ITPro’s account of the campaign.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Criminals obtained personal information outside HMRC, including through phishing and other cyber-enabled crime.
  2. They used that information to impersonate taxpayers and, according to contemporary reporting, create PAYE records or accounts and/or access existing accounts.
  3. They pursued fraudulent tax repayment claims.
  4. HMRC’s controls identified suspicious activity; affected accounts were locked down or otherwise remediated.

It is not established how many of the approximately 100,000 attempts led to successful access, fraudulent account creation or completed claims.

Why does HMRC say it wasn’t hacked?

“Hack” is often used broadly to mean any cyberattack. HMRC’s distinction is narrower: it says criminals did not penetrate its central infrastructure and extract a database. Instead, the campaign used externally obtained personal data to act through taxpayer accounts and HMRC’s online services.

Term What it means here
Infrastructure breach Attackers penetrate HMRC’s own network or application infrastructure and directly extract or alter data. HMRC says this was not what happened.
Account takeover Someone uses credentials or identity information to act through a customer’s legitimate account.
Fraudulent account creation Someone creates an account or PAYE record using another person’s identity.
Phishing A criminal tricks someone into sharing credentials or personal information, commonly using a fake message or website.
Cyber-enabled fraud Fraud carried out using online systems, stolen information and digital impersonation. The HMRC campaign fits this broader description.

HMRC officials rejected the conventional “HMRC was hacked” description, while the chair of the Treasury Select Committee challenged the distinction. Both points can be understood together: the available account does not describe a central HMRC database breach, but criminals did use stolen data and HMRC’s digital services in a substantial cyber-enabled fraud. ITPro’s reporting on HMRC’s position and the parliamentary response.

Were taxpayers’ bank accounts emptied?

HMRC says the criminals sought fraudulent repayments from the Exchequer, rather than direct withdrawals from the affected taxpayers’ personal bank accounts. It also says affected customers will not bear a personal tax loss as a result of the incident. That does not mean there was no risk to personal information or no disruption: unauthorised account activity can require account recovery and correction of tax records.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

HMRC confirms that externally obtained personal information was used. Separately, ACCA reported after discussions with HMRC that personal and bank information had been obtained in the attacks. Do not assume that a particular person’s bank details were exposed without confirmation about that individual. HMRC’s chief executive performance report; ACCA’s account of its discussions with HMRC.

Why did the reported loss change from £47m to £48.8m?

News coverage in June 2025 reported an estimated loss of approximately £47 million. HMRC’s 2024–25 annual report later put the estimated revenue loss from the incident at £48.8 million “to date.” These are dated estimates of the same campaign, not evidence by themselves of a separate £1.8 million incident. The available figures do not explain the change in detail. Neither amount represents money taken directly from 100,000 taxpayers’ bank accounts. June 2025 reporting; HMRC 2024–25 annual report PDF.

When did it happen, and who was affected?

Reporting in June 2025 said the activity began in 2024; the public disclosure followed officials’ discussions with Parliament’s Treasury Select Committee in early June 2025. The reason for the timing of disclosure has not been established in the cited public accounts.

ACCA reported that the affected accounts were personal accounts, not company or agent accounts, and that most affected taxpayers were unrepresented, although some had agents. It also reported that agents were not automatically notified when a client was affected during the initial response. These details come from ACCA’s account of its discussions with HMRC, rather than the headline wording in HMRC’s annual report.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What did HMRC do in response?

HMRC says it remediated affected accounts, wrote to affected customers and continued to strengthen fraud controls. Contemporary reporting described account lockdowns, resetting or deleting compromised login credentials, correcting inaccurate tax-record information and checking for other changes. HMRC’s 2024–25 chief executive performance report also describes work on a Fraud Prevention Centre focused on identity-related security issues. HMRC’s chief executive performance report; ITPro’s reporting on the response.

What to do if you suspect someone accessed your HMRC account

Use GOV.UK directly rather than following a link in a message. HMRC’s guidance lists unexpected access codes, being unable to log in because your password has changed, changes to tax records, and unexpected HMRC letters or payments as possible signs of suspicious activity.

  1. Go to your account directly. Type GOV.UK into your browser or use a saved official bookmark. Do not use a link or phone number from a suspicious message.
  2. Check your account and tax records. Look for unfamiliar changes, repayment claims, letters or payments. Do not assume an unexpected payment is a legitimate refund; leave it untouched while you check with HMRC.
  3. Report suspected access to HMRC. Use the security console or online reporting form in HMRC’s suspicious-account guidance. HMRC says it aims to make initial contact within 10 working days after a report. That is a target for initial contact, not a guarantee that the issue will be resolved by then.
  4. Secure your login if you can still access it. Change the HMRC password, and change it anywhere else you reused it. HMRC advises using a unique password and multi-factor authentication where available. See HMRC’s guidance on keeping login details safe.
  5. Tell HMRC if you disclosed information. If you gave personal or payment details to a suspicious sender, contact HMRC through verified GOV.UK contact details. Contact your bank immediately if money was transferred or a bank account may be involved.
  6. Report any wider online fraud or financial loss. Use Report Fraud in England and Wales, or Police Scotland in Scotland. These routes are separate from reporting suspicious activity in your HMRC account.

If HMRC has locked your account, that may be a protective measure; it does not prove you caused the problem. Avoid repeated login attempts or messages offering to unlock it. Use HMRC’s official recovery and reporting routes. If an agent manages your tax affairs, the agent should use HMRC’s current agent reporting process; HMRC says agents can report suspicious activity through the security console when multi-factor authentication is activated. Agents should not use a client’s personal HMRC sign-in credentials.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to report a suspicious HMRC message

Use the reporting route that matches the message. HMRC’s current guidance says it will not send a text, email or phone call asking for personal or payment information or notifying someone of a tax rebate. That warning does not mean HMRC never communicates digitally; it concerns requests and rebate notifications of the kind described in its scam guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Suspicious HMRC email: forward it to [email protected].
  • Suspicious HMRC text: forward it to 60599; your network may charge for the message.
  • Suspicious HMRC social-media account: email [email protected].
  • Other suspicious text messages: forward them to 7726, the free spam-reporting service. For a text specifically impersonating HMRC, use HMRC’s 60599 route.

For current contact details and further reporting routes, see HMRC’s guide to reporting suspicious messages, calls and social accounts and GOV.UK’s general phishing-reporting guidance.

What remains unclear

HMRC’s published figures do not give a definitive count of successful account takeovers, fraudulent account creations or completed repayment claims among the approximately 100,000 access attempts. They also do not identify the precise source of each person’s information or explain in detail how the £47 million estimate reported in June 2025 became the £48.8 million estimate in the annual report. The cited material does not establish whether all losses had been recovered.

Later reporting described arrests connected with the campaign, including arrests by Romanian police and an earlier arrest in Preston. An arrest is not a conviction, and the reports do not establish that the entire network was dismantled. ITPro’s report on arrests connected with the campaign.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.