Hackers exploit HMRC Coronavirus Job Retention Scheme with phishing email scam

Phishing email
(Image credit: Lanop Accountancy Group)

A phishing email scam is already being used to target business owners applying for the government’s Coronavirus Job Retention Scheme. Cyber criminals are exploiting the aid package with a highly realistic bogus email, purporting to be from HMRC.

The email, revealed today by the Lanop Accountancy Group, is targeting business owners using official HMRC branding and purports to be from ‘Jim Harra, First Permanent Secretary and Chief Executive of HMRC’. Around 50 business owners have so far reported receiving the suspicious emails to Lanop after noticing the email was sent via an obviously dubious address, despite its user title being ‘HM Revenue & Customs’.

The email asks for the bank account details of the recipient and includes the following message with typos. “Dear customer, We wrote to you last week to help you prepare to make a claim through the Coronavirus Job Retention Scheme. We are now writing to tell you how to access the Covid-19 relief. You will need to tell your us which UK bank account you want the grant to be paid into, in order to ensure funds are paid as quickly as possible to you.”

Security threat

Recent research from cyber security company Barracuda Networks has suggested that Coronavirus-related phishing emails have risen by 667 per cent since the start of March. The scams included fraudulent communication purporting to be from the World Health Organisation (WHO) and the NHS and private health suppliers selling facemasks and other personal protection equipment (PPE).

Aurangzaib Chawla FCCA, Managing Partner, Lanop Accountancy Group comments: “We're calling upon all businesses to think twice before handing over bank details and making bank transfers in response to email requests during this crisis. Cyber crime is rising rapidly and this is the first of what we expect to be many scam emails, designed to trick unsuspecting owners into handing over private company data. We are also offering free advice about how to tackle these scams and reporting any suspicious activity direct to HMRC.”

Cyber security expert Chris Ross, SVP, Barracuda Networks adds: “We’re seeing a sharp rise in phishing emails relating to the Covid-19 outbreak and this example underlines how hackers will prey upon vulnerable business owners who are trying to protect jobs.

As always with these scams, the victim is encouraged to disclose personal data and financial information under the false assumption that the email is legitimate. It is absolutely vital that businesses have the cyber security systems in place to identify and quarantine phishing emails and ensure that every employee is properly trained to spot suspicious communication and think twice before giving out personal information.”

Take-up of the Job Retention Scheme has been swift following its online launch earlier today. HMRC chief executive Jim Harra told the BBC Today programme that 67,000 claims for workers had been made in the first 30 minutes alone.

Rob Clymo

Rob Clymo has been a tech journalist for more years than he can actually remember, having started out in the wacky world of print magazines before discovering the power of the internet. Since he's been all-digital he has run the Innovation channel during a few years at Microsoft as well as turning out regular news, reviews, features and other content for the likes of TechRadar, TechRadar Pro, Tom's Guide, Fit&Well, Gizmodo, Shortlist, Automotive Interiors World, Automotive Testing Technology International, Future of Transportation and Electric & Hybrid Vehicle Technology International. In the rare moments he's not working he's usually out and about on one of numerous e-bikes in his collection.