Fake tax agency email: IRS, HMRC and AEAT phishing — how to detect it
Tax agencies are among the most impersonated institutions in phishing campaigns worldwide. The IRS in the United States, HMRC in the United Kingdom, and the Agencia Tributaria (AEAT) in Spain share a common characteristic that makes them ideal targets for scammers: virtually every adult citizen has a reason to expect a communication from them at some point during the year. That mix of authority, expectation, and anxiety is the perfect breeding ground for fraud.
In April 2026, Kaspersky documented an international wave of phishing campaigns targeting taxpayers across several European countries, using fake websites that precisely mimic official tax portals. The pattern is not limited to Europe: the IRS publishes its annual Dirty Dozen list of tax scams every year, and impersonation emails consistently rank at the top. HMRC received over 130,000 phishing reports from UK citizens in 2025 alone.
This article explains how these campaigns work, what specific signals to look for depending on the agency being impersonated, and how to perform a forensic analysis of a suspicious email.
🔍 Suspicious message?
Analyze senders, links or files in real time with our scanner.
Why tax agencies are the perfect phishing target
Scammers choose tax agencies for three structural reasons:
- Universal reach. Almost every adult is a potential target, regardless of technical knowledge or age.
- Built-in urgency. A message about a pending refund, an audit, or an unpaid debt triggers immediate emotional response — fear or greed — before rational analysis kicks in.
- Seasonal predictability. Tax campaigns follow fixed calendars. Scammers time their attacks to coincide with filing deadlines, refund periods, and penalty notices.
IRS phishing: patterns targeting US taxpayers
The IRS is the most impersonated tax authority in the world by volume. Campaigns targeting US taxpayers typically use these patterns:
- Fake refund notifications. Emails claiming "Your federal tax refund of $847.00 is ready to be processed" with a link to a form requesting bank account details.
- Threatening audit notices. Messages warning of an imminent audit or criminal investigation, demanding immediate action via a link or phone number.
- Identity Verification scams. Fake IRS portals asking for Social Security Number, date of birth, and banking information under the pretext of "verifying your identity before releasing your refund."
- Economic Impact Payment fraud. Recurring campaigns exploiting stimulus payment periods, directing victims to fake claim portals.
Key verification rule for IRS communications: The IRS never initiates contact via email, text message, or social media. All official correspondence arrives by postal mail. Any email claiming to be from the IRS is fraudulent by definition.
Official IRS domain: irs.gov. Any link pointing elsewhere is a red flag.
HMRC phishing: patterns targeting UK taxpayers
HMRC received over 130,000 phishing reports in 2025, making it one of the most targeted institutions in the UK. Common patterns include:
- Tax refund emails. "You are entitled to a tax refund of £312.50. Click here to claim." These campaigns peak between January and April, coinciding with the end of the UK tax year.
- Self Assessment reminders. Fake deadline warnings for Self Assessment submissions, with links to credential-harvesting portals.
- HMRC SMS (smishing). Text messages with shortened URLs claiming the recipient owes unpaid tax and must act immediately to avoid prosecution.
- Voicemail and call-back scams. Emails claiming HMRC left a voicemail about an urgent tax matter, with a callback number reaching a fraudulent call centre.
Key verification rule for HMRC communications: HMRC does send emails and SMS in some circumstances, but will never ask for payment details, passwords, or personal information via these channels. All genuine HMRC online services operate from gov.uk domains exclusively.
AEAT phishing: patterns targeting Spanish taxpayers
In Spain, phishing campaigns impersonating the Agencia Tributaria peak between April and June, coinciding with the income tax (IRPF) campaign. The ORTSLAB forensic engine has detected a consistent increase in these emails every spring, using two primary variants: the promise of a pending refund and the threat of an audit or sanction.
- Alarming or tempting subject lines. "Pending refund of €347.82," "Tax audit notification," "Action required before June 30," or "Your return contains errors."
- Fake but convincing sender. The visible name may be "Agencia Tributaria" or "AEAT," but the actual sending address does not end in @agenciatributaria.es. Domains like aeat-notificaciones.com or variants with hyphens are clear indicators of fraud.
- Links that do not point to sede.agenciatributaria.gob.es. The Tax Agency operates exclusively from .gob.es domains. Any link leading elsewhere is suspicious.
- Requests for bank details or ID. The AEAT never requests account numbers, credit card data, or copies of your DNI via email.
Key verification rule for AEAT communications: Access sede.agenciatributaria.gob.es directly using your digital certificate or Cl@ve PIN. If there is a real notification, it will appear there. Never follow links from emails.
Forensic analysis: what these attacks look like under the hood
Regardless of which agency is being impersonated, the forensic signature of these campaigns is remarkably consistent. A real example analyzed by the ORTSLAB engine showed the following evidence:
- The visible From field displayed "Agencia Tributaria," but the actual Return-Path pointed to a server in Romania.
- The SPF record failed — the sending server was not authorized to send email on behalf of the declared domain.
- No DKIM signature — the email was not cryptographically signed by the sending domain.
- The link inside the email pointed to a domain registered just 4 days prior, hosted on a Ukrainian server.
- The destination website was a near-perfect visual replica of the official tax portal, with a form requesting tax ID, account number, and password.
This pattern — spoofed sender, failed authentication, recently registered domain, credential-harvesting page — is structurally identical whether the impersonated agency is the IRS, HMRC, or AEAT. The branding changes. The infrastructure does not.
The new variant: fake AI tax tools
Kaspersky documented in 2026 an emerging tactic: websites offering "AI assistants" to help users file their tax returns. Victims input their fiscal data believing they are receiving a legitimate service. The tool collects the data for scammers without providing anything in return. This variant is particularly dangerous because it does not rely on urgency or fear — it exploits the genuine demand for help with complex tax processes.
Phishing-as-a-Service: how Bluekit automates these campaigns
Until recently, running a phishing campaign required technical knowledge, time, and access to several different services. Researchers at Varonis discovered Bluekit, a platform that turns phishing into a turnkey operation. Bluekit is a Phishing-as-a-Service (PhaaS) tool: any cybercriminal can subscribe and launch campaigns — including bypassing multi-factor authentication — without writing a single line of code. Tax agency impersonation is one of its most common use cases.
What to do if you receive a suspicious tax email
- Do not click any links. Open your browser and navigate directly to the official portal (irs.gov, gov.uk, sede.agenciatributaria.gob.es).
- Analyze the email in ORTSLAB. Paste the headers or full text and the engine will identify the forensic signals in seconds.
- Check the actual sender address, not just the visible name.
- Never provide bank details, passwords, or ID documents in response to an unsolicited email.
- Report it — to the IRS at phishing@irs.gov, to HMRC at phishing@hmrc.gov.uk, or in Spain to OSI at osi.es or INCIBE on 017.
Need to document a tax phishing attempt?
If you need to formally document a tax phishing incident for a legal complaint, insurance claim, or corporate security report, Oscar Orts — a registered judicial computer expert — issues certified forensic reports on email fraud and digital impersonation.