Malicious software warning to taxpayers

Image

HMRC has issued a warning to tax agents about the risks of malicious software (malware) and malvertising being delivered by email, and particularly the risks of opening apparently benign attachments and clicking links

This follows a spike in malware attacks where criminals advise taxpayers they should click on a link to access a refund. The emails are sent out from email addresses which at a quick glance can appear to be bona fide, but normally have spelling mistakes and odd domain names.

All HMRC emails are sent from email addresses with the following @hmrc.gsi.gov.uk, preceded by the contact name or specific department name. The scale of phishing attacks featuring HMRC is vast, while malware breaches are increasingly significant.

An HMRC spokesperson told Accountancy Daily: 'In the last 12 months, 500 million emails were blocked so by the time the customer is actually getting an email millions have been intercepted. This still means that millions are still being received and this creates a real risk for anyone who opens them.' 

‘Email is a common method used by criminals, but other techniques are equally dangerous and require different defences. One such technique is exploiting security vulnerabilities in web browsers,’ HMRC warned in the latest Agent Update, issue 65.

Web browsers and associated software (eg, plug-ins like Flash) enable users to access extensive digital content, in a range of different data formats.

There is a lot of complexity behind the scenes in these programs, and security researchers and criminals work hard to find mistakes made by software developers that maintain them. These mistakes often relate to how the web browser processes data within a web page; by crafting the right content, an attacker can get the browser to mistakenly run the attacker’s code. When these vulnerabilities are discovered or reported, the software developers hurry to release software ‘patches’ (updates) to plug the holes.

The message to tax agents and accountants is to ensure that their web browsers are kept up-to-date to avoid malicious attacks, and to apply all software updates to keep IT systems secure from this type of attack.

HMRC said: ‘Not everyone applies these updates though, or they may even use older versions of web browsers that updates are no longer provided for.

‘This presents an opportunity for criminals, who use “exploit kits” - a collection of specially crafted code, on a website that will target a wide range of vulnerabilities.

‘Their only challenge is to get potential victims to visit their site - once they do, criminals are able to gain entry and install or run their malicious software. This includes sending out emails with links to these websites, littering social media sites with links, or paying for online adverts, which direct victims to the malicious site.’

Malvertising is a mix of malware and advertising, where criminals create dodgy advertisements, which can appear quite legitimate, and then try to dupe online marketing companies to publish the ads on popular websites.

National Cyber Security Centre (NCSC) 10 Steps to Cyber Security

HMRC Agent Update, issue 65

4
Average: 4 (1 vote)

Rate this article

Related Articles
Subscribe