One recent HMRC scam consists of text messages claiming that the recipient’s national insurance number has been used in a fraud. Others promise tax rebates. Tax credit claimants are being particularly targeted at the moment, with tens of thousands of fake websites purporting to give information about tax credits. HMRC has alerted claimants to be wary of scam communications that falsely appear to come from HMRC. Typical scams include:
Other criminals have stolen personal data of employees of several large companies through a cyber attack on third-party payroll and human resources software. The data lost includes national insurance numbers, dates of birth, home addresses and bank details. The attack highlights the difficulty any organisation has in ensuring that suppliers providing critical services are cyber secure. Companies that outsource their payroll or any other sensitive operations should encrypt any data being transferred, and apply password protection with the password provided separately.
The government has recently unveiled a strategy for tackling scam texts, emails, phone calls and adverts, which, it says, now make up 40% of all crime. Among the proposals are:
Companies that outsource their payroll or any other sensitive operations should encrypt any data being transferred, and apply password protection with the password provided separately.
However there is much that individuals and businesses can do to protect themselves against fraud. One way of spotting an email scam is to examine the sender’s email address. For example, genuine government emails will always come from a gov.uk email address. Messages from banks and other financial organisations will never request passwords and other personal information. Don’t follow links in emails or texts.
Working from home is another risk area. Ideally, to minimise leaks of sensitive data, staff working out of the office should only do so within office-based computer systems and, ideally, using corporate computers and phones, although this inevitably comes at a cost. Personal WhatsApp and email accounts should not be used for work, and vice versa. Passwords must be secure and changed regularly. Businesses should consider using professional help to review their ways of working.