The National Cyber Security Centre coordinated the removal of 412 HMRC-themed phishing domains in September, the agency said Tuesday, as criminals ramp up SMS lures ahead of January self-assessment deadlines.

Takedown mechanics

Most sites mimicked Gov.uk styling and urged taxpayers to “verify” bank details for fictitious rebates. NCSC’s Active Cyber Defence programme worked with hosting providers and the HMRC security team to suspend certificates and sinkhole traffic within hours of detection.

The September total exceeds the summer monthly average, reflecting seasonal campaigns that peak when paper filing reminders hit doormats. Officials urged filers to start returns only at gov.uk and to forward suspicious texts to 7726.

Enterprise angle

Accounting firms reported a parallel wave of spear-phishing aimed at payroll administrators, with attackers swapping display names of senior partners. NCSC reissued guidance on multi-factor authentication for cloud tax software tenants.

What HMRC will not do

Revenue officials repeated that they never request online banking passwords or gift-card payments. Refund timing depends on return processing, not clicking links in unsolicited messages.

Smaller businesses using Making Tax Digital were told to check software update channels after two vendors flagged tampered plug-ins distributed outside official marketplaces.

With January filing pressure building, NCSC plans weekly bulletins for chartered institutes and payroll bureaus listing fresh domain patterns—small comfort for taxpayers, but a measurable drag on criminals’ conversion rates when takedowns stay fast.

Reporting channels

Police-led cyber reporting units said HMRC-themed referrals rose week on week in September, though officials caution that reporting rates lag actual exposure. NCSC shares indicators of compromise with major email providers so similar domains can be blocked proactively.

Cyber insurers said premiums for accountancy practices ticked up after a midsize firm disclosed a credential breach in August, reinforcing demand for monitored inboxes during tax season.

HMRC’s customer protection team runs tabletop exercises with payroll software vendors each quarter, testing how quickly bogus login pages are escalated when discovered by white-hat researchers.