Phishing emails caught by Dmarc
HMRC is recognised as one of the most-phished brands in the world, said Tucker, most commonly with the classic “Tax Refund Notification”.
“The resultant customer compromise [by phishing emails disguised as such notifications] leads to onward fraud against financial institutions and identity theft,” he said.
To make HMRC phishing emails look more authentic, criminals typically spoof, or masquerade, as legitimate HMRC domains, most commonly @HMRC.gov.uk.
HMRC’s cyber security team, said Tucker, has been working to tackle this issue by “gradually implementing security controls across all of our email domains”.
“We have already managed to reduce phishing emails by 300 million in 2016 through spearheading the use of Dmarc,” he said.
Dmarc enables HMRC and email service providers to identify fraudulent emails purporting to be from genuine HMRC domains and prevent their delivery to customers.
Tucker said HMRC’s customer protection team, part of the cyber security team, continues to utilise innovative approaches to combat these threats.
“In the first six months of 2016, they responded to more than 300,000 phishing referrals from customers. They’ve also instigated the takedown of more than 14,000 fraudulent websites that were attempting to harvest customer data,” he said.
“These figures represent record levels of performance and demonstrate HMRC’s continued dedication to protecting our customers,” he added.
HMRC has now moved Dmarc into “full reject” mode, which will prevent any emails spoofing HMRC.gov.uk from ever reaching customers’ inboxes, Tucker told Computer Weekly.
