Phishing-fraud attempt

For discussions about security.
Post Reply
Message
Author
Jasper

Phishing-fraud attempt

#1 Post by Jasper »

Hi,

Today I received a fraudulent email which falsely purports to be from HMRC (the relevant Government Agency) saying that I am due an Income tax refund.

From: HM Revenue & Customs Refund <sec.prog@hmrc.gov.uk>
Date: Almost two months ago though received today
To: I have withheld my email address
Subject: Your payments and latest tax returns

Dear Applicant:

Following and upgrade of our computer systems and review of our
records we have investigated your payments and latest tax returns
over the last seven years our calculations show that you have
made over payments of GBP 658.83

Due to the high volume of refunds due you must complete the
online application, the telephone help line is unable to assist
with this application. In order to process your refund you will
need to complete the application form attached to this email
download -> unpack -> open in a browser -> and complete the form.
Your refund may take up to 6 weeks to process please make sure
you complete the form correctly.

NOTE: If you've received an Income Tax ‘repayment’ it will either
be following a claim you've made or because HM Revenue & Customs
(HMRC) has received new information about your taxable income or
entitlement to allowances. The refund may come through your tax
code or as a payment and could relate to the current tax year or
earlier years.

An Income Tax repayment is a refund of tax that you've overpaid.
So, if you've paid too much tax for example through your job or
pension this year or in previous years HMRC will send you a
repayment. You'll get the repayment by bank transfer directly to
your credit or debit card.

--------------------------------------------------------------

Copyright 2011, HM Revenue Customs UK All rights reserved

-----------------------------------------------------------------------------------------------
The text above is littered with technical errors which would require some detailed knowledge of our British Tax System. However the text I have emboldened is enough to indicate an attempted fraud. The sender does not know my Name or my Unique Tax Reference No or my National Insurance No, but even if they did it is an obvious scam to get my credit card and/or bank details.

I have previously had scam emails claiming to be from my bank and others offering me prizes or rewards, but this one is new to me and whilst few, if any, forum readers would be caught by this type of message I decided to publish it here.

My regards

User avatar
Lobster
Official Crustacean
Posts: 15522
Joined: Wed 04 May 2005, 06:06
Location: Paradox Realm
Contact:

#2 Post by Lobster »

You don't think this is a new scam by the tax people to ensure you do not claim a rebate you are entitled too? :wink:

That is a convincing email
I am pretty sure it is a fraud as they just send out a check by post.

If you report it, it will be taken very seriously.
No one messes with HM Revenue & Customs
Apart from James Bond and the 00's they are one of the few depts
with a license to kill . . . :wink:
Puppy Raspup 8.2Final 8)
Puppy Links Page http://www.smokey01.com/bruceb/puppy.html :D

User avatar
Makoto
Posts: 1665
Joined: Fri 04 Sep 2009, 01:30
Location: Out wandering... maybe.

#3 Post by Makoto »

It could well be a valid email address for someone or a service at that agency. The problem is, the spammers and phishers have no issues whatsoever spoofing a legitimate email address. All they have to do is get you to give them your personal information (by the attached form, in this case), and the phishing attempt has worked.

Just to be safe, contact the agency directly. Most governmental groups/agencies have a policy in place (for reasons like these) to NOT ask anyone for personal information over email (or to direct you to a website where you'll have to enter it), I believe.
If it is a phishing attempt, they may want a copy of the email to help them track down the culprit(s).
[ Puppy 4.3.1 JP, Frugal install ] * [ XenialPup 7.5, Frugal install ] * [XenialPup 64 7.5, Frugal install] * [ 4GB RAM | 512MB swap ]
In memory of our beloved American Eskimo puppy (1995-2010) and black Lab puppy (1997-2011).

Jasper

#4 Post by Jasper »

Hi,

With my detailed tax knowledge I know it is a scam. If any reader(s) would like to respond by listing all the errors they can spot I will advise if I know of any they have missed.

Below is the result my google check of that email address. This particular scam email would almost certainly been sent to thousands, but as it was dated September (though only just received) I believe HMRC will already be aware of it (it is even likely to have been received by HMRC employees).
Attachments
googlepic.jpg
(40.61 KiB) Downloaded 544 times

User avatar
Makoto
Posts: 1665
Joined: Fri 04 Sep 2009, 01:30
Location: Out wandering... maybe.

#5 Post by Makoto »

It can't hurt for them to have the information, though. It might help them narrow the location of the phishers down, or it could be that they're trying from a new location (or someone different is), etc.
[ Puppy 4.3.1 JP, Frugal install ] * [ XenialPup 7.5, Frugal install ] * [XenialPup 64 7.5, Frugal install] * [ 4GB RAM | 512MB swap ]
In memory of our beloved American Eskimo puppy (1995-2010) and black Lab puppy (1997-2011).

Post Reply