HMRC loses £47m in phishing-related breach

HMRC admitted that £47m was stolen through a phishing-driven breach in December 2024 affecting thousands of PAYE tax accounts.

The incident came to light during a Treasury Select Committee hearing this week on HMRC’s performance. Senior civil servants said around 100,000 individuals are now being contacted about the breach.

According to a notice on HMRC’s website, its systems detected “unauthorised access to some customers’ online accounts”. The authority said it had locked affected accounts, deleted login credentials to block further access, removed incorrect information from tax records, and verified that no other data had been altered.

“This was an attempt to claim money from HMRC, not an attempt to take any money from you,” the notice read.

HMRC has faced mounting criticism over performance, with the National Audit Office describing customer service levels as being in a “declining spiral”.

A separate Freedom of Information request revealed that HMRC was responsible for more than 800 of the 1,200 public sector device losses reported between January and December 2024 – adding to mounting evidence of systemic security weaknesses at the tax authority.

In another setback, HMRC’s customer service phone lines went down on Wednesday due to a system outage.



Share Story:

YOU MIGHT ALSO LIKE

BANNER

Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.