Thirteen people have been arrested in Romania, accused of taking part in an organised phishing ring that allegedly defrauded the UK tax authority HMRC. Authorities suspect that the stolen data was used for tax fraud.

His Majesty's Revenue & Customs (HMRC) said the arrests were made with the assistance of more than 100 police officers in Romania, as part of a European partnership aimed at dismantling organised cybercrime groups . The raids took place in the southern counties of Ilfov, Giurgiu and Calarasi , and luxury cars, cash and technological equipment were seized.
At the same time, another person, aged 38, was arrested in Preston , England, as part of the same investigations.
See also: Hackers abuse Vercel v0 for phishing attacks
The raids come after HMRC revealed last month that a criminal gang had stolen £47m by using phishing tacticsto gain access to more than 100,000 customer accounts and falsely claim payments from the government.
It is worth noting that the target of the fraud was not the customers themselves, but the tax office and its systems, according to an official statement from HMRC. Nevertheless, more than 100,000 citizens have already been notified that they may have been affected.
The new arrests are part of a series of HMRC investigations into phishing attacks. Fraudsters are sending emails that appear to come from the tax office itself. The messages contain misleading links, designed to trick people into revealing personal details, passwords and details credit card.
See also: Microsoft 365: Phishing attacks abuse 'Direct Send'

HMRC's Reaction
Simon Grunwell , head of operations at HMRC's Fraud Enforcement Directorate, said :
«We have already taken action to protect our customers by detecting and blocking attempts to access accounts. We continue to work closely with authorities to dismantle such networks».
This investigation is part of a wider effort by HMRC to combat the growing trend of tax fraud through digital attacks, as cybercriminals now target not only individuals but also public bodies.
See also: Trezor: Phishing attack abuses customer support system
What It Means for Users and Cybersecurity
The case once again highlights the seriousness of phishing attacks and the need for digital vigilance. As such attacks become increasingly convincing, it is crucial for citizens and businesses to:
- validate authenticity of emails they receive from government agencies or banks.
- Avoid clicking on suspicious links and never disclose sensitive data via email.
- Use multi-factor authentication (MFA) for all their accounts.
This case is a stark reminder that cybercriminals don't need technical expertise, just trust people's. And as long as they continue to do so, they will continue to profit at the expense of society and the economy.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.reuters.com
