Join our Newsletter — 33% off our NHI Course

What should organisations tell staff to do after receiving a suspected HMRC phishing message?

Staff should stop interacting with the message, preserve it, and report it through the organisation’s fraud or security reporting process. They should not forward links to colleagues, enter details into the form, or reply to the sender. Clear reporting guidance helps security teams spot campaigns early, warn users quickly, and reduce the chance that one scam message turns into a wider incident.

What should staff do immediately after a suspected HMRC phishing message?

The right instruction is simple: stop interacting, keep the message intact, and report it through the organisation’s approved fraud or security route. That response limits the chance of credential theft, malware delivery, or wider exposure if the message is part of a broader campaign. It also gives security teams the evidence they need to spot patterns fast.

Why the first response matters

Phishing succeeds when people keep engaging with the message after the first warning sign. A reply, form submission, or link click can confirm the address is active, trigger a malicious login page, or open a path into an account or device. Preserving the message in its original form helps investigators review sender details, URLs, headers, and timing.

For staff, the most important practical distinction is between containment and curiosity. Containment means no clicking, no replying, no forwarding to colleagues, and no entering details into any form. Curiosity often creates the second failure: once one person interacts, the same lure can spread through the organisation by imitation or by an attacker using the response to refine the campaign.

Where phishing involves impersonation of a trusted public body, the operational risk is not just individual compromise. A single message can become a reporting and awareness issue across the business, especially if employees share screenshots or repeat the message without a clear process. That is why the organisation should make the reporting path obvious and easy to use.

What counts as the right reporting behaviour?

Staff should use the organisation’s fraud or security reporting process as soon as they suspect the message is fake. A good report preserves the original email or text, includes the sender, subject, timestamp, and any link or attachment if the reporting tool can capture it safely, and avoids retyping the suspicious content into another message.

If the message arrived in a corporate mailbox, the report should go to the team that can triage it centrally, not to a colleague who may also be targeted. If it arrived on a personal device but relates to work or payroll, the same principle applies: stop, preserve, report, and let the security or fraud function decide whether broader user warning or takedown action is needed.

Clear reporting guidance is also a control over delay. The faster a suspected phish is reported, the sooner security teams can correlate it with other complaints, block similar messages, and warn staff before the campaign spreads. That is often more valuable than trying to prove the message is malicious before reporting it.

How reporting supports wider phishing defence

Good user reporting turns a single inbox event into actionable detection. It gives defenders live evidence of what users are seeing, helps confirm whether the message is part of a larger wave, and supports quick internal advice such as adding a warning banner, updating mail filtering rules, or reminding staff what legitimate HMRC communication should look like.

If the organisation handles finance, payroll, or customer accounts, reported phishing messages can also expose whether the attacker is aiming at account takeover, payment diversion, or identity theft. That is why incident responders should treat the report as a lead, not just an FYI, and check for any sign that a link was opened or details were entered before the report was made.

Risk and Threat Considerations

Suspected HMRC phishing is risky because the attacker is usually trying to create urgency and harvest data before the target thinks carefully. The message may be a simple credential lure, or it may be the first step in a larger fraud chain that uses stolen details to access payroll, tax, or other accounts.

Failure mechanism: The failure occurs when a user clicks, replies, or submits information, which can expose credentials, confirm the mailbox is active, or move the user onto a fake portal designed to capture more sensitive data.

Impact: The impact can range from one compromised inbox to broader organisational fraud, including account takeover, internal spoofing, payment redirection, and repeated targeting of other staff once the attacker knows the message worked.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Phishing often seeks credentials, so preserving and reporting suspicious messages supports credential protection.
Recommendation — Enforce prompt reporting and rotation triggers for exposed credentials under IA-5.
NIST CSF 2.0 DE.CM-02 — Monitor high-risk events User-reported phishing is a key signal for detecting active campaigns and widening warning coverage.
Recommendation — Use user reports to feed monitoring and alerting for suspected phishing campaigns.
CIS Controls v8 5 — Account Management Phishing aims at account compromise, making reporting and rapid response part of account protection.
Recommendation — Tighten account-monitoring and response processes around suspected credential phishing.

Practitioner Guidance

What to prioritise: Make the reporting action faster than the decision to judge the message. Staff should know the exact channel to use, and that reporting is the correct action even when they are uncertain.

What to verify: Confirm that the reporting route preserves the original message and sends it to a mailbox or workflow that security or fraud staff actively monitor. If staff are told to screenshot or forward manually, the process is usually too weak.

Common mistake: Telling users to “be careful” without telling them exactly where to report. Ambiguous guidance delays escalation and increases the chance that someone will keep interacting with the lure.

Practitioner takeaway: The best user instruction is not just “spot phishing”, it is “stop, preserve, report”, because speed of reporting matters more than confidence in classification.