Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

April 1st, 2011, 08:58 GMT · By

New Wave of HMRC Phishing Emails Hits Inboxes

SHARE:

Adjust text size:


New fake HMRC emails in circulation
Enlarge picture
Security researchers from Belgian email security provider MX Lab warn about a new wave of HMRC tax refund phishing emails that is currently hitting people's email inboxes.

The rogue emails have forged headers to appear as originating from a srvcs@hmrc.gov.uk address and bear a subject of "Please Submit Your Payment Refund."

The tax refund theme is extremely common, not only with phishing emails spoofing the HMRC, but also with those targeting taxpayers in other countries.

There is, however, one particular aspect that sets this spam run apart. The emails discourage recipients from calling HMRC, something which both the tax agency and security researchers have advised for years.

In addition, unlike most phsihing emails which direct users to a rogue website, these ones have an HTML attached to them.

"Due to the high volume of refunds due you must complete the online application, the telephone help line is unable to assist with this application. In oder to process your refund you will need to complete the application form attached to this email," the email's body reads.

The attachment is called Refund_Form.htm and displays an HMRC-branded page for inputting personal and credit card details. As also seen in other phishing scams, images displayed on the page are loaded directly from the legit hmrc.gov.uk domain.

After submitting the form, users are redirected to the real HMRC website in order to avoid raising suspicions. Meanwhile, the inputted information is sent to an Yahoo! email address.

Apparently, there is also a second, more traditional, phishing campaign using fake HMRC tax refund notifications, going around. However, this one uses links to an external site.

Despite recommendations to the contrary, users are strongly encouraged to verify all financial-related claims with the corresponding organizations over the phone.

TELL US WHAT YOU THINK:

617 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:

Multi-Bank Phishing Kit Targets Australian TaxpayersNumerous Phishing Emails with HTML Attachments in CirculationMulti-Bank Phishing Toolkit Tailored for Different CountriesMulti-Bank Phishing Attack Targets Indian Taxpayers

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM