Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Criminals reportedly took over around 100,000 taxpayers’ HMRC online accounts and obtained approximately £47 million in tax rebates. HMRC said its core systems were not directly compromised: the incident involved attackers impersonating taxpayers through legitimate accounts. That distinction matters, but it does not remove the need for stronger checks on logins, account changes and payments.
What happened in the HMRC phishing incident?
In a report published on June 5, 2025, Computer Weekly said HMRC disclosed to the Treasury Select Committee that criminals had accessed around 100,000 taxpayer accounts and fraudulently obtained approximately £47 million in tax rebates. The figures are reported estimates; the coverage does not establish whether £47 million was the amount claimed, paid, or ultimately unrecovered. Computer Weekly’s account of the incident also reported that affected taxpayers were contacted, did not personally lose money and were not treated as suspects. Arrests had been made, but the report did not provide details of charges or court outcomes.
The reported sequence is phishing, account access, impersonation and fraudulent rebate claims. The precise messages used, authentication methods involved, campaign duration, detection trigger and amount recovered have not been established in the available coverage.
Recommended Free Tools
Was HMRC itself hacked?
HMRC’s reported explanation was that attackers had not directly compromised its core systems. The incident is more accurately described as account takeover and identity fraud: criminals gained access to legitimate taxpayer accounts and acted as if they were the account holders.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Phishing is deception intended to make someone disclose credentials, approve access or take another unsafe action.
- Account takeover means an attacker gains control of a genuine user account.
- Identity fraud means an attacker impersonates another person, often using stolen credentials or personal information.
- A system breach generally means unauthorised access to an organisation’s infrastructure, applications or databases.
These terms describe different stages and do not settle responsibility. Even if a service’s infrastructure remains intact, its operator is responsible for detecting suspicious account behaviour and protecting payments made through the service.
How can phishing turn into a rebate fraud?
- Deception: a taxpayer is persuaded to reveal credentials, approve an authentication request or otherwise expose access.
- Account access: the criminal enters a legitimate HMRC account, potentially using credentials, a stolen session or a recovery route.
- Impersonation: activity appears to come from the taxpayer because it is performed through that account.
- Claim and payment: a fraudulent rebate claim is submitted and, if checks do not stop it, money may be paid.
- Detection and response: the service identifies the activity, blocks further claims or payments, investigates related accounts and contacts affected users.
The broad chain is consistent with the reported account-takeover explanation, but the exact technique at each stage is not public in the cited coverage. It does not establish whether credentials came from reused passwords, whether multi-factor authentication (MFA) was available or bypassed, or whether HMRC’s online service had a software vulnerability.
Why call it avoidable if phishing is hard to eliminate?
“Avoidable” is most defensible as a claim about limiting the scale and financial impact, not guaranteeing that nobody will ever be deceived. A criminal can begin with a single victim’s mistake; a large public loss depends on whether stolen access can be used repeatedly without timely detection, additional checks or payment controls.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #2
- FIDO2 + FIDO U2F certified and supported USB security key
- Secured by NXP semiconductors
- Works in every browser and application without installing any drivers
- Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
Security experts quoted in the Computer Weekly report argued for stronger authentication, better visibility across account activity and faster remediation. Those controls can raise the cost of an attack or stop claims after an account is taken over, even when they cannot prevent every phishing message reaching a taxpayer.
Why was it still hard to stop?
A stolen login can look like a legitimate login. The user is real, the HMRC service is genuine, and the claim may follow a normal-looking workflow. A perimeter defence may see no intrusion into HMRC infrastructure at all. The warning signs can appear only when activity is considered across accounts and over time.
Different parts of the chain need different safeguards:
Rank #3
- FIDO2 + FIDO U2F certified and supported USB security key
- Supports Computers, Laptops, Tablets, and Mobile Devices with a USB-C port and/or NFC
- Works without downloading any drivers. Supported OS: Android, Chrome OS, Windows, MacOS, Linux
- Durable design made to last for a long time with everyday use. Water-resistant (IP67)
- Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.
- Block phishing delivery: protect email and messaging channels and make official communications harder to impersonate.
- Reduce credential theft: use phishing-resistant sign-in options and secure recovery paths.
- Spot account takeover: identify unusual devices, locations, session behaviour or changes to account details.
- Detect fraudulent claims: compare claims and account activity across the service rather than treating every valid login as equally trustworthy.
- Stop or recover payments: apply extra checks to risky transactions and provide a rapid route to hold or recall suspicious payments.
Monitoring has trade-offs. A genuine taxpayer may travel, use a VPN, change devices or submit several claims for legitimate reasons. Blocking on a single signal can cause false alarms; combining signals and using risk-based review can reduce that risk, though it requires careful privacy, retention and access controls.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWould MFA have prevented the fraud?
MFA adds a verification step beyond a password, but it is not a complete answer. SMS codes and app codes may be relayed through deceptive login pages; push prompts can be approved under pressure or fatigue; attackers may steal an active session rather than a password. Account recovery can also become a weaker way around sign-in controls.
Passkeys and FIDO2 security keys are designed to resist credential phishing more strongly than passwords and one-time codes. They still require workable enrolment, accessible alternatives and secure recovery for people who lose or change devices. The report does not establish whether HMRC offered, required or had MFA bypassed in this incident, so it would be wrong to claim that MFA was absent—or that any single MFA method would have stopped the fraud.
Rank #4
- FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
- PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
- BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
- ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
- THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
What controls matter after a user signs in?
Authentication answers whether a sign-in passed a check; it does not prove that the person is acting legitimately or that a particular payment should be made. For a public service handling claims and refunds, post-login and transaction controls are central.
- Step up verification for sensitive actions: ask for stronger confirmation when a user changes bank or contact details or submits an unusual claim.
- Analyse patterns across accounts: flag clusters sharing devices, network addresses, payment destinations or other behavioural signals, rather than judging every account in isolation.
- Use risk-based payment review: hold or manually check unusually rapid, high-risk or atypical claims, while avoiding blanket delays for ordinary refunds.
- Contain quickly: let authorised responders freeze accounts, revoke active sessions and tokens, investigate linked activity and preserve relevant login and claim records.
- Secure recovery and delegated access: apply robust checks to password resets, support requests, email changes and access used by agents, rather than making these routes easier to exploit than normal login.
More verification can delay legitimate refunds; broad monitoring can create privacy concerns and false positives. A proportionate system weighs multiple signals and applies extra friction where the combined risk is high.
Did earlier data breaches help the attackers?
A legal expert quoted in the report said earlier data breaches and cyberattacks had put personal information in criminals’ hands, helping them impersonate taxpayers or make claims more credible. That is an attributed explanation, not a published forensic account of what this campaign used.
Best Value
- SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
- PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
- COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
- DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
- USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.
The available coverage does not identify what information attackers possessed, where it came from, or whether it was used to pass identity checks rather than simply make phishing more convincing. Nor does it establish whether compromised email accounts or other services played a role. Those distinctions matter: data exposed elsewhere can make a social-engineering attempt more persuasive without proving that HMRC’s own records were the source.
What does the disclosure criticism mean?
Computer Weekly reported that the Treasury Select Committee chair learned of the incident through earlier media coverage and criticised HMRC over the time taken to disclose it. Delayed notification is more than a political communications problem: it can limit victims’ chance to secure accounts, hinder containment across related accounts and weaken public confidence.
A useful public account should state what is confirmed and what remains unknown, explain which people may be affected, give clear protective steps and describe how claims and payments were contained. The cited report does not supply a detailed public account of the exact remediation advice given to taxpayers.
What taxpayers can do
- Do not follow an unexpected message link to claim a refund. Open HMRC through a route you already know and sign in there.
- Use a unique password for your HMRC account and secure the email account used for recovery with strong authentication.
- Do not share passwords or one-time authentication codes in response to a call, text or email.
- Check account activity and payment details; contact HMRC promptly through an official route if something looks unfamiliar.
- Report suspected phishing using the UK National Cyber Security Centre’s guidance and reporting service. Computer Weekly reported that the service had received more than 41 million scam reports by April 2025; that is a time-specific figure, not a measure of this incident. The report also points readers to the NCSC service.
HMRC impersonation is not the same as an attacker controlling a taxpayer’s account. Email authentication standards such as DMARC, DKIM and SPF can help an organisation protect its own sending domain, but they do not stop criminals using lookalike domains, compromised taxpayer email, text messages, phone calls or stolen web sessions.
What should public digital services take from the incident?
The lesson is not that every phishing attempt can be stopped. Government services serve millions of people whose email and devices the service does not control; some will be deceived. The service can still limit what a stolen session can do through phishing-resistant identity options, careful recovery checks, monitoring after login, transaction verification, rapid containment and prompt, candid notification.
HMRC’s reported explanation points to account takeover rather than a confirmed intrusion into its core systems. That distinction narrows what is known about the incident, but it does not make the reported fraud a problem only for individual taxpayers: the resilience of the claims and payment process is also a public-sector responsibility.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

