HMRC scam message (refund/penalty): what to do
Scammers often impersonate HMRC with “refund”, “penalty”, or “urgent action” messages. If you're unsure, paste the message into FraudSentry.
Tip: Do not paste passwords, OTP codes, or full card/bank numbers.
Example message (Example)
“HMRC: You're owed a tax refund. Claim within 24 hours: example-link.com”
Red flags
- Refund or penalty with a tight deadline
- Link asking for bank details or personal details
- Threatening language (“lawsuit”, “enforcement”, “final notice”)
- Sender address/number looks unusual
- Requests for passwords or access codes
What to do now
- Do not click links or reply with details.
- If you want to check your tax position, go via official HMRC routes (type the address yourself or use the HMRC app).
- If you shared personal or payment details, contact your bank immediately.
- Report the message using the official HMRC reporting routes below.
Official UK reporting links
FraudSentry is independent and is not affiliated with or endorsed by these organisations.
HMRC guidance for reporting suspicious messages/calls/social accounts: https://www.gov.uk/report-suspicious-emails-websites-phishing/report-scam-HMRC-messages-calls-social-media
Common HMRC reporting routes (from GOV.UK):
- Suspicious emails: phishing@hmrc.gov.uk
- Suspicious texts: forward to 60599 (may be charged at your network rate)
- WhatsApp/app messages: screenshot and email to phishing@hmrc.gov.uk
- Suspicious social accounts: branddefence@hmrc.gov.uk
General phishing reporting (UK):
- Forward suspicious emails to: report@phishing.gov.uk
- Forward suspicious texts to: 7726 (free)
FAQ
Will HMRC ask for personal or payment details by text/email/WhatsApp?
If a message asks for sensitive info or pressures you urgently, treat it as suspicious and verify via official channels.
I'm worried I clicked � what now?
Stop, don't enter more info, contact your bank if you shared payment details, and report the message.
Check your message now
Related scam guides
Disclaimer
FraudSentry helps people check, review, and take safer next steps. It does not guarantee detection, prevention, or recovery. Always verify through official channels.