Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

13 Romanians Arrested for Phishing the UK’s Tax Service

Investigators from HMRC joined more than 100 Romanian police officers to arrest the 13 Romanian suspects in the counties of Ilfov, Giurgiu and Calarasi. 

Britain’s tax service (His Majesty’s Revenue and Customs, or HMRC) was the third most spoofed UK government body in 2022, behind the NHS and TV Licensing.

In early June 2025, HMRC told the UK government’s Treasury Committee about a massive loss to phishing. The Committee subsequently tweeted: “HMRC officials told us today that 100,000 HMRC customers were victims of a phishing scam, resulting in £47m of losses to the taxpayer.”

Separately, in a press release dated July 10, 2025, issued via mynewsdesk, HMRC announced “Fourteen arrested in phishing attack investigations.” Thirteen men and women, aged between 23 and 53, were arrested in Romania by the Romanian Police. A fourteenth, presumably British, was arrested in Preston, UK.

Romanian Police searching properties during arrest operation in a joint tax fraud investigation with HMRC.

Investigators from HMRC joined more than 100 Romanian police officers to arrest the 13 Romanian suspects in the counties of Ilfov, Giurgiu and Calarasi. 

It doesn’t seem likely that Preston and Romanian arrests were linked by anything other than fraud against HMRC and timing, since HMRC also states, “A fourteenth man was arrested in another investigation in Preston.”

Simon Grunwell, operational lead in HMRC’s fraud investigation service commented, “We have a number of live criminal investigations, and we are grateful to our Romanian partners for their support.” The completion of this investigation suggests that HMRC is actively working against other phishing campaigns and may well result in further operations against other phishers wherever they operate.

In this case, a Romania / UK joint investigation team has been established combining the Prosecutor’s Office attached to the Court of Appeal in Bucharest, HMRC and the Crown Prosecution Service (CPS) in the UK.

Advertisement. Scroll to continue reading.

No specific details on the Romania-based phishing campaign have been released other than a general comment, “It’s suspected that organized criminal gangs have stolen data and used it to submit fraudulent PAYE claims [pay as you earn in the UK, similar to payroll tax withholding in the US], as well as VAT repayments and Child Benefit payments,” and that the Romanians, “Were arrested by Romanian Police’s Economic Crimes Investigation Directorate on suspicion of computer fraud, money laundering and illegal access to a computer system.”

And, of course, the obligatory, “We are unable to provide any more detail about today’s arrest operations.” Meanwhile HMRC has confirmed that the phishers stole money from HMRC rather than its customers, that it has written to affected customers, locked down the accounts, deleted log in credentials (Government Gateway user ID and passwords) to prevent future unauthorised access, and that the phishing attacks have not involved a cyber attack against HMRC.

Related: Tax Phishing Campaign Reminds of DMARC Limitations

Related: Email Attacks Use Fake VAT Returns to Deliver Malware

Related: AI-Powered Polymorphic Phishing Is Changing the Threat Landscape

Related: AI Now Outsmarts Humans in Spear Phishing, Analysis Shows

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.