Fake tax agency email: IRS, HMRC and AEAT phishing — how to detect it

Tax agencies are among the most impersonated institutions in phishing campaigns worldwide. The IRS in the United States, HMRC in the United Kingdom, and the Agencia Tributaria (AEAT) in Spain share a common characteristic that makes them ideal targets for scammers: virtually every adult citizen has a reason to expect a communication from them at some point during the year. That mix of authority, expectation, and anxiety is the perfect breeding ground for fraud.

In April 2026, Kaspersky documented an international wave of phishing campaigns targeting taxpayers across several European countries, using fake websites that precisely mimic official tax portals. The pattern is not limited to Europe: the IRS publishes its annual Dirty Dozen list of tax scams every year, and impersonation emails consistently rank at the top. HMRC received over 130,000 phishing reports from UK citizens in 2025 alone.

This article explains how these campaigns work, what specific signals to look for depending on the agency being impersonated, and how to perform a forensic analysis of a suspicious email.

Email falso de Hacienda phishing fiscal

🔍 Suspicious message?

Analyze senders, links or files in real time with our scanner.

Analyze now

Why tax agencies are the perfect phishing target

Scammers choose tax agencies for three structural reasons:

IRS phishing: patterns targeting US taxpayers

The IRS is the most impersonated tax authority in the world by volume. Campaigns targeting US taxpayers typically use these patterns:

Key verification rule for IRS communications: The IRS never initiates contact via email, text message, or social media. All official correspondence arrives by postal mail. Any email claiming to be from the IRS is fraudulent by definition.

Official IRS domain: irs.gov. Any link pointing elsewhere is a red flag.

HMRC phishing: patterns targeting UK taxpayers

HMRC received over 130,000 phishing reports in 2025, making it one of the most targeted institutions in the UK. Common patterns include:

Key verification rule for HMRC communications: HMRC does send emails and SMS in some circumstances, but will never ask for payment details, passwords, or personal information via these channels. All genuine HMRC online services operate from gov.uk domains exclusively.

AEAT phishing: patterns targeting Spanish taxpayers

In Spain, phishing campaigns impersonating the Agencia Tributaria peak between April and June, coinciding with the income tax (IRPF) campaign. The ORTSLAB forensic engine has detected a consistent increase in these emails every spring, using two primary variants: the promise of a pending refund and the threat of an audit or sanction.

Key verification rule for AEAT communications: Access sede.agenciatributaria.gob.es directly using your digital certificate or Cl@ve PIN. If there is a real notification, it will appear there. Never follow links from emails.

Forensic analysis: what these attacks look like under the hood

Regardless of which agency is being impersonated, the forensic signature of these campaigns is remarkably consistent. A real example analyzed by the ORTSLAB engine showed the following evidence:

This pattern — spoofed sender, failed authentication, recently registered domain, credential-harvesting page — is structurally identical whether the impersonated agency is the IRS, HMRC, or AEAT. The branding changes. The infrastructure does not.

The new variant: fake AI tax tools

Kaspersky documented in 2026 an emerging tactic: websites offering "AI assistants" to help users file their tax returns. Victims input their fiscal data believing they are receiving a legitimate service. The tool collects the data for scammers without providing anything in return. This variant is particularly dangerous because it does not rely on urgency or fear — it exploits the genuine demand for help with complex tax processes.

Phishing-as-a-Service: how Bluekit automates these campaigns

Until recently, running a phishing campaign required technical knowledge, time, and access to several different services. Researchers at Varonis discovered Bluekit, a platform that turns phishing into a turnkey operation. Bluekit is a Phishing-as-a-Service (PhaaS) tool: any cybercriminal can subscribe and launch campaigns — including bypassing multi-factor authentication — without writing a single line of code. Tax agency impersonation is one of its most common use cases.

What to do if you receive a suspicious tax email

Need to document a tax phishing attempt?

If you need to formally document a tax phishing incident for a legal complaint, insurance claim, or corporate security report, Oscar Orts — a registered judicial computer expert — issues certified forensic reports on email fraud and digital impersonation.