Article
How to Combat Scams From HMRC: A Guide for Contact Centers
Laura Fitzgerald
August 28, 2025 (UPDATED ON August 28, 2025)
9 minutes read time
Fraudsters pretending to be His Majesty’s Revenue and Customs (HMRC) agents frequently target banking, financial, or even retail contact centers through phone calls, emails, and text messages.
These fraudsters aim to manipulate sensitive tax issues, steal confidential information, make unauthorized payments, and more.
Many of these types of scams are increasing due to deepfakes of synthetic audio and AI-driven voice cloning.
Pindrop’s 2025 Voice Intelligence & Security Report analyzed over 1.2 billion calls, identifying how, in 2024 alone, there was a:
+61% increase in bank fraud since 2020.
680% rise in deepfake activity year-over-year.
26% increase in fraud attempts, far exceeding predictions.
475% increase in synthetic voice fraud in insurance.
This article examines the various types of HMRC scams, offers detailed guidance on identifying and verifying legitimate communications, and introduces effective fraud detection strategies.
Why HMRC scam threats specifically target businesses
Businesses, especially those in finance, banking, and retail, are desirable targets for fraudsters posing as HMRC.
They exploit the complexity and urgency surrounding business tax processes, knowing that businesses typically handle higher transaction values and are subject to regular communication from HMRC.
A notable incident in 2025 saw HMRC report a phishing campaign that affected approximately 100,000 taxpayer accounts, resulting in losses of £47 million ($64 million), which highlighted the scale and impact of such attacks. Cybercriminals gained unauthorized access using stolen credentials, successfully claiming fraudulent tax rebates, as reported by The Guardian.
According to Loughborough University, this case highlights the continued effectiveness of simple social engineering tactics, whether over the phone or via phishing emails, particularly when combined with stolen personal data and institutional trust, such as HMRC.
Types of HMRC business scams
Recognizing different scam methods is essential. Here are the most common.
HMRC phone call scams
Phone call scams involve fraudsters impersonating HMRC officials, claiming urgent tax issues or overdue payments. Fraudsters manipulate emotions by creating immediate fear of legal consequences or business penalties to extract sensitive details or financial transactions.
These scams have become especially dangerous with the rise of AI-driven synthetic voice technology. The 2025 Voice Intelligence & Security Report revealed that synthetic voices accounted for 0.33% of contact center calls in Q4 2024, representing a 173% increase from Q1.
Fraudsters now effectively mimic real voices through pitch modulation, tone manipulation, and cadence adjustments, making traditional authentication measures inadequate.
HMRC scam phishing emails and texts
HMRC scams, particularly phishing emails and texts, are a persistent problem. According to the U.K. government, in the 12 months prior to September 2023 alone, HMRC received a significant increase in scam reports, with over 130,000 reports of tax scams, of which 58,000 involved fake tax rebates.
Fraudsters disguise messages as official HMRC communication, often mentioning tax refunds or urgent tax issues. Messages include malicious links or attachments designed to capture login credentials or install malware.
A typical scenario involves receiving an email claiming there’s an urgent tax liability or a refund waiting. Once clicked, these links direct users to a fake HMRC website, prompting them to enter sensitive business credentials or financial details.
HMRC tax rebate or refund scams
Fraudsters commonly exploit people’s and businesses’ anticipation of tax refunds. Once again, the U.K. government announced that nearly half of the 144,298 scams reported to HMRC in the 12 months prior to October 2024 were fake self-assessment tax rebates, with a 16.7% increase in the number of scam referrals.
Scammers contact businesses claiming they are eligible for a significant tax rebate and encourage the targeted recipient to share sensitive banking or tax information in exchange for the alleged refund.
In real-world scenarios, businesses receive official-looking communications claiming immediate refunds, directing them to enter confidential financial information on fraudulent websites, which ultimately results in account compromise.
Verifying legitimate HMRC communication
Genuine HMRC communications always contain specific official identifiers, such as unique taxpayer reference numbers, precise information that should only be known to the business and HMRC, and clearly defined contact protocols.
Authenticating communication that claims to be from HMRC is essential for financial contact centers, as scammers exploit the trust and urgency associated with tax-related matters.
According to official HMRC guidelines, legitimate HMRC representatives will never:
Request sensitive financial details, like passwords or PINs, over unsolicited calls or emails.
Demand immediate payment through unconventional channels, such as prepaid gift cards or cryptocurrency, to expedite the process.
Threaten instant arrest or legal actions without prior official written correspondence.
To reliably distinguish between genuine and fraudulent communications, banking and finance contact centers should implement comprehensive, multilayered verification procedures.
Authentication protocols and best practices
Effective authentication best practices include:
Ask for unique reference numbers
Genuine HMRC calls or communications will always include specific identifiers, such as your Unique Taxpayer Reference (UTR), National Insurance number, or other HMRC-issued codes that have been documented.
Cross-verify via outbound calls
Staff should initiate outbound calls using verified HMRC contact numbers from official documentation or the official government website.
Official communication patterns
Authentic HMRC notifications typically involve letters or secure online messages before initiating phone contact.
Multifactor authentication (MFA)
Advanced multi-factor authentication solutions combine voice biometrics, behavioral analytics, and metadata analysis to verify identities quickly and securely.
IVR containment
IVR containment authenticates callers before agent involvement, reducing risk exposure and supporting quick fraud detection.
Advanced fraud detection methods from a banking perspective
Today’s financial institutions and businesses alike require more than manual reviews and basic caller authentication to effectively detect and respond to scams, such as those pretending to be from HMRC.
Advanced technology-driven detection strategies enhance protection, reduce false positives, and improve efficiency. By integrating voice analytics, machine learning, and automated cross-referencing systems, contact centers can proactively identify and disrupt more fraudulent activities.
Real-time voice analysis examines subtle audio characteristics, such as pitch variations, tone anomalies, background noise discrepancies, and speech patterns, to instantly detect synthetic or manipulated voices.
Behavior analysis via artificial intelligence (AI) and machine learning algorithms enables contact centers to quickly and more accurately recognize unusual caller behaviors, interactions, and transaction patterns.
Cross-referencing with fraud databases using real-time fraud detection solutions allows for rapid identification of potential threats.
Institutional protocols and cross-reference systems
To fully leverage these advanced detection methods, banking institutions and/or contact centers serving them must establish comprehensive institutional protocols that may include:c
Internal call logs
Maintain detailed records of caller interactions, including caller IDs, call frequency, duration, and outcomes.
Suspicious number databases
Keep databases of flagged phone numbers and known scammers up to date for cross-referencing with automated systems.
Integration with official HMRC reporting channels
Synchronize internal fraud detection systems with HMRC’s official fraud-reporting platforms.
Dynamic alerts and responses
Promptly notify fraud teams of suspicious activity to ensure immediate response.
Reporting and post-scam actions
Rapid and systematic reporting is crucial in limiting damage from HMRC scams and facilitating quicker investigations and resolutions. Banking contact centers should establish and communicate transparent reporting and documentation procedures to all employees.
Here’s an example of a reporting workflow to follow:
Immediate documentation
Record call details meticulously, including the caller’s number, time of the call, stated identity, and exact wording used by the caller.
Prompt internal notification
Escalate documented information of high-risk calls to your internal fraud management team without delay for further scrutiny and action.
Official reporting to HMRC
Use the official HMRC channels available via the HMRC manuals website to report fraudulent calls or phishing attempts.
Regular compliance audits and training
Conduct periodic reviews and compliance checks to help staff adhere to established reporting procedures and guidelines.
Safeguard your business from HMRC scams with PindropⓇ Solutions
Protecting your banking, finance, or business contact center from sophisticated HMRC scams demands an advanced, layered approach.
Pindrop offers tailored fraud-detection and authentication solutions specifically designed to strengthen security and streamline authentication, helping protect your operations and customer relationships.
Pindrop® Protect
Receive near real-time fraud alerts and reduce your average handle time (AHT). Equip your agents with instant, actionable risk assessments, enabling them to quickly and more accurately identify fraud attempts. Learn more about Pindrop® Protect.
Pindrop® Passport
Transition away from outdated authentication methods. Implement seamless multifactor authentication that reduces friction for customers and agents while providing security. Learn more about Pindrop® Passport.
Pindrop® Pulse
Stay ahead of rapidly advancing deepfake scams. Pulse offers state-of-the-art detection for synthetic voice and video threats, enabling agents to identify and block sophisticated impersonation attempts in real time. Learn more about Pindrop® Pulse.
With proven results across financial institutions globally, Pindrop solutions help your organization proactively detect threats, save valuable agent time, and protect customer trust.
Don’t wait for fraud to impact your business. Take action now to secure your operations and customers.
Schedule a call with a Pindrop expert, and experience firsthand how our solutions can help safeguard your business from HMRC scams and beyond.