
VAT fraud – Avoid getting caught out by phishing attacks
Scammers are increasingly targeting VAT-registered businesses with phishing attacks.
Warnings have been issued by a number of organisations, and taxpayers are being encouraged to check requests carefully.
To help you avoid becoming a victim of these fraudsters, here is what you need to know to avoid getting caught out.
Phishing and VAT fraud
Phishing is when cyber criminals send fraudulent emails or text messages containing links to malicious websites.
These websites often trick users into revealing sensitive information (such as passwords) or encourage taxpayers to transfer money.
They can also contain malware that sabotages systems and organisations or ransomware, which holds sensitive information or systems ransom in return for a fee.
For example, scammers are manipulating and submitting form VAT 484 to HM Revenue & Customs (HMRC) to change legitimate bank details to theirs.
Once a repayment return is processed and verified by HMRC, funds are directed to the fraudsters’ accounts instead of the legitimate ones.
Many businesses are currently being targeted by these methods as they submit their regular VAT report to HMRC and make payments.
While they can be hard to identify, there are recurring scams that target both individual finances and businesses.
The most common ones include:
- Texts or calls offering HMRC tax refunds
- Email scams about tax rebates
- Automated phone call scams that claim HMRC is filing a lawsuit.
Never disclose personal or financial information about you or your business to people or websites claiming to be HMRC – unless you are 100 per cent sure that you are speaking to the tax authority.
HMRC will only ever email you about a tax rebate or ask for personal or payment information from an email address that ends in hmrc.gov.uk.
To find out more about how you can prevent yourself from falling victim to an HMRC scam, please visit the tax authority’s dedicated advice page.
How to prevent phishing attacks
It is difficult to mitigate against all phishing attacks. However, there are steps you can take to protect your organisation as much as possible.
The National Cyber Security Council (NCSC) recommends a four-layer defence system:
- Make it difficult for attackers to reach your users.
- Help users identify and report suspected phishing messages.
- Protect your organisation from the effects of undetected phishing emails.
- Respond quickly to incidents.
You can implement these four layers of defence by:
- Using secure, encrypted connections for business transactions and HMRC communications.
- Conducting regular phishing awareness training for all employees.
- Implementing multi-factor authentication for access to sensitive accounts.
- Reporting suspicious emails to HMRC (phishing@hmrc.gov.uk) to help fight phishing scams.
If you are unsure whether a communication from HMRC is legitimate or not, please seek advice from our team at the earliest opportunity.
For more information, please get in touch.
Social

Recent Posts
- Capital Gains Tax clampdown – What HMRC’s surge in investigations means for you
- What are the Inheritance Tax benefits of writing a life insurance policy in trust?
- How neonatal care leave will affect your payroll and policies
- Welcome news for thousands as Income Tax reporting threshold set to increase
- The tax traps of director’s loans – How to avoid unnecessary charges
Archives
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
Categories
- Accountancy
- Accounting
- Agriculture
- Apprentices
- Asset and Wealth Management
- Ben Allen
- Blog
- Blogs
- Bookkeeping
- Brexit
- Budget
- Business
- Business Advice
- Business Advice News
- Business Blog
- Business News
- Business Start-ups
- Capital Allowances
- Cash Flow
- Cash flow management
- Charities
- Corporate Tax
- Corporation Tax
- Covid-19 Home working and expenses
- Economy
- Employees
- Employment
- Employment and payroll
- Family Businesses
- Finance
- Financial News
- Financial Planning
- Fraud
- Funding
- Government Funding
- Grants
- Guide
- HMRC
- Home working and expenses
- Income Tax
- Inflation
- Inflation / Interest Rates
- Inheritance
- Insurance
- Investment
- Latest Business News
- Latest News
- Legal
- leisure and hospitality
- Loans
- Making Tax Digital
- Money
- MTD
- News
- PAYE
- Payroll
- Pension
- Pensions
- Personal Tax
- Personal taxes and finances
- Property
- Property News
- R&D
- Redundancy
- Scam
- Self Assessment
- Self Employed
- SME
- SMEs
- SMEs / Business
- Start ups
- Tax
- Tax Blog
- Tax News
- Tax Planning
- Tourism
- Uncategorized
- VAT
- VAT and MTD
- VAT deferral
- Wages
- Wealth Management