HMRC Tax Season Phishing Wave — What UK Taxpayers Need to Know Right Now

Every year, without fail, as HMRC deadlines approach, a wave of phishing attacks impersonating His Majesty’s Revenue and Customs floods UK inboxes and mobile phones. 2026 is no exception and this year’s campaigns are more sophisticated, more targeted, and more convincing than ever before.
PhishScout has identified and analysed multiple active phishing campaigns currently impersonating HMRC, with lures ranging from tax refund notifications and self-assessment overdue warnings to PAYE discrepancy notices and NI number verification requests. This advisory covers what the attacks look like in detail, how to identify them, what HMRC will actually never do, and critically what to do if you or someone you know has already fallen victim.
Why HMRC Impersonation Attacks Work
Before examining specific campaigns, it’s worth understanding why HMRC is such an effective impersonation target for phishers.
Universal recognition. Every adult in the UK has a relationship with HMRC. Unlike a bank impersonation attack (which only works if you use that bank), HMRC is relevant to essentially the entire adult population. The attacker’s audience is the entire country.
Emotional levers. HMRC communications typically trigger one of two powerful emotional responses: the promise of money (a tax refund) or the fear of punishment (overdue tax, penalties, legal action). Both emotions impair rational judgement and accelerate impulsive action.
Complexity creates uncertainty. The UK tax system is genuinely complex. Many people are uncertain about exactly what they owe, whether they’re owed a refund, and whether they’re fully compliant. Attackers exploit that uncertainty with messages like “Your tax affairs require review” — vague enough that almost anyone might think it could apply to them.
Seasonal legitimacy. HMRC communications are expected at certain times of year — around the January self-assessment deadline, the April year-end, and the July payment deadline. A phishing email arriving during these windows has a natural cover story.
Active Campaigns — Detailed Analysis
Campaign 1: Tax Refund Notification
Current status: Active. High volume. Targeting general UK population.
Email subject lines observed:
“You have a tax refund of £349.20 — claim by 14 September 2026”
“HMRC: Your tax refund is ready to be processed”
“Unclaimed tax refund — action required within 7 days”
“Your PAYE tax overpayment: £782.50 awaiting claim”
The email design closely mirrors genuine HMRC communications — the HMRC crown logo, the correct GOV.UK colour scheme (dark green and white), and footer text including standard HMRC disclaimers. The quality of the impersonation has improved significantly in 2025-2026, likely reflecting the use of AI tools to improve design and copy quality.
The email body states that the recipient is owed a specific tax refund amount (personalised amounts in the £200-£900 range are most common — large enough to be interesting, small enough not to trigger scepticism). A green button labelled “Claim your refund” or “Start your claim” is provided.
Once clicked, the link leads to a convincingly designed fake Government Gateway login page. Some campaigns use subdomain-based spoofing (e.g. login.gov-uk-hmrc-refund.com) that looks plausible at first glance. Once credentials are entered, the victim is typically redirected to the genuine gov.uk website — creating the impression that the login succeeded, while the attacker now has their Government Gateway credentials.
More sophisticated variants then immediately request payment card details under the pretense of processing the refund, harvesting both Government Gateway credentials and payment card information in a single interaction.
Real-world damage: HMRC credential theft enables attackers to change the victim’s bank account details for repayments (redirecting genuine future refunds to attacker-controlled accounts), access personal tax information, file fraudulent tax returns, and in some cases access information useful for wider identity fraud.
Campaign 2: Self-Assessment Overdue Notice
Current status: Active. Higher sophistication. Targeting self-employed individuals and landlords.
Email subject lines observed:
“Final notice: Self-Assessment return overdue — penalty imminent”
“Urgent: Outstanding Self-Assessment balance — legal proceedings may follow”
“HMRC: Failure to file Self-Assessment by [date] will result in £1,600 penalty”
These emails carry a tone of urgency and mild threat. They claim the victim has an overdue Self-Assessment return or unpaid tax liability and that failure to act immediately will result in significant financial penalties or legal proceedings.
The language deliberately creates panic. Phrases like “legal proceedings,” “debt collection agency,” and “bailiff referral” appear in more aggressive variants. The 2026 campaigns have adopted increasingly specific language — naming correct penalty amounts (the genuine £100 late filing penalty, the daily penalties of £10 per day after three months) to appear more credible.
These campaigns specifically target individuals known to be self-employed or landlords, identified from leaked datasets or purchased data. Some variants include the victim’s full name and National Insurance number (sourced from previous data breaches) to add a veneer of legitimacy.
Campaign 3: PAYE Tax Code Change Notification
Current status: Active. Targeting employed individuals. Lower sophistication but high volume.
Email subject lines observed:
“Your PAYE tax code has been updated — action required”
“Important: Your tax code is changing from 6 April 2026”
“HMRC: Please review your updated tax code”
These emails target employed individuals with the straightforward claim that their PAYE tax code has been changed and they need to log in to review it. The lure exploits genuine PAYE complexity — many employees don’t fully understand their tax code and are uncertain whether a change is expected.
The fake Government Gateway login page harvests credentials. Some variants follow up the credential harvest with a phone call (vishing) from an attacker posing as an HMRC adviser to extract additional personal information.
Campaign 4: National Insurance Number Verification
Current status: Active. New variant. Targeting all UK adults.
Email and SMS subject lines observed:
“Your National Insurance number requires verification”
“Action required: Confirm your NI number to avoid suspension”
“HMRC: NI number discrepancy identified — verify immediately”
This variant, observed with increasing frequency in mid-2026, exploits the universal coverage of National Insurance numbers. The email claims that HMRC has identified a “discrepancy” or “irregularity” with the victim’s NI number and that it requires immediate verification to prevent suspension. The verification page requests the victim’s full NI number, date of birth, and address — information used for identity fraud, fraudulent benefit claims, and tax return fraud.
Campaign 5: HMRC SMS Smishing
Current status: Active. Very high volume. Targeting all UK mobile users.
Text messages observed:
“HMRC: A tax refund of £312 is owed to you. Verify your details at: [shortened URL]”
“HMRC reminder: Your Self-Assessment is overdue. Avoid a £100 fine: [link]”
“HMRC: We have tried to contact you. Call 03xxxxxxxx or visit [link] to avoid a warrant”
The SMS variant uses URL shorteners (bit.ly, tinyurl.com) and newly registered domains designed to look governmental. HMRC genuine texts never use shortened URLs.
How to Identify a Fake HMRC Communication
What HMRC Will NEVER Do
HMRC will never:
Send you a text message or email with a link to claim a tax refund
Ask for your bank account details, credit or debit card number, or PIN via email, text, or phone
Request payment via bank transfer to a non-HMRC account
Accept payment via iTunes gift cards, Google Play vouchers, cryptocurrency, or PayPal
Threaten immediate arrest, bailiff action, or police intervention via email or text
Offer to send a courier to your home with a tax refund
Ask you to verify your National Insurance number by clicking a link
Use an email address ending in anything other than @hmrc.gov.uk
Send texts from premium rate numbers or unusual number formats
Checking the Sender
Genuine HMRC emails always come from addresses ending in @hmrc.gov.uk. Every other domain is an impersonation.
Domains currently impersonating HMRC in active campaigns:
hmrc-notifications.com
hmrc-refund-portal.co.uk
gov-hmrc.co.uk
hmrc.services-gov.uk
hmrc-secure-portal.net
gov-uk-hmrc.com
taxrefund-hmrc.co.uk
hmrc-gov-uk.net
hmrc-verify.uk
Checking Links Before Clicking
Hover over any link in an email claiming to be from HMRC. The URL should begin with https://www.gov.uk or https://www.tax.service.gov.uk. Any other domain is not HMRC.
Verifying Directly
If you receive any communication about your tax affairs and are uncertain whether it is genuine, do not click any links. Open a new browser tab, type gov.uk manually into the address bar, and log into your Government Gateway account directly. If there’s nothing in your account corresponding to the email, it’s a phishing attempt.
What to Do If You’ve Been Targeted
If you received the email but didn’t click anything:
Forward to phishing@hmrc.gov.uk and delete it.
If you clicked the link but didn’t enter any information:
Run an anti-malware scan. Change passwords for any accounts accessed from that device as a precaution. Report the URL to PhishScout.
If you entered your Government Gateway username and password:
Act immediately:
- Go to https://www.gov.uk/government-gateway and log in now
- Change your password to something unique and strong
- Enable two-step verification if not already active
- Check your HMRC account for unauthorised changes — particularly bank account details for repayments, new tax returns filed in your name, or changes to contact information
- Check your email account and change that password too
If you entered payment card details:
- Call your bank or card provider immediately — 24/7 fraud lines are on the back of your card
- Request cancellation of the card and ask about reversing transactions
- Ask specifically about chargeback for any unauthorised payments
If you transferred money to an attacker:
- Call your bank immediately and request a transfer recall
- Report to Action Fraud: actionfraud.police.uk or 0300 123 2040
- Report to your local police if you’ve suffered significant financial loss — obtain a crime reference number
Reporting channels:
Phishing email → phishing@hmrc.gov.uk
Phishing text → Forward to 60599 (free, all UK networks)
Online fraud → gov.uk/report-suspicious-emails-websites-phishing
Financial fraud → Action Fraud: 0300 123 2040
PhishScout community → phishscout.net
Protecting Others
Many victims of HMRC phishing are older relatives or individuals under financial stress who are particularly susceptible to the fear of tax debt or the promise of an unexpected refund. Share these key rules with anyone who might be vulnerable:
HMRC will never text or email a link to claim a refund. If anyone contacts you about unpaid tax, hang up and call HMRC directly on 0300 200 3300. Never pay anything to anyone who contacts you out of the blue about tax. If you’re not sure, ask someone you trust before doing anything.
The most effective protection against HMRC phishing is not technical — it’s social. A quick conversation with a family member about these scams is worth more than any spam filter.
Active IOCs — Current Campaign Infrastructure
The following domains have been identified as part of active HMRC phishing campaigns as of September 2026. Do not visit any of these URLs:
hmrc-refund-portal.co.uk
gov-hmrc-claim.com
hmrc-notifications.com
taxrefund-hmrc.co.uk
hmrc.services-gov.uk
hmrc-secure-portal.net
gov-uk-hmrc.com
hmrc-verify.uk
hmrc-tax-refund.co.uk
hmrc-gov-refund.com
Submit any additional HMRC phishing URLs you encounter to PhishScout for analysis and inclusion in our threat feed.
Conclusion
HMRC phishing campaigns are a persistent, year-round threat that intensifies around key UK tax dates. The campaigns are professionally designed, emotionally sophisticated, and increasingly difficult to identify on appearance alone. The most reliable defence is understanding the simple rule: HMRC will never send you a link via email or text to claim a refund or resolve a tax issue. They will always ask you to log into your account at gov.uk directly.
Share this advisory with your team, your family, and anyone you think might be targeted. The more people understand these campaigns, the less effective they become.
Report HMRC phishing to PhishScout at phishscout.net or forward directly to phishing@hmrc.gov.uk