Tax office shuts credits site after identity theft

Criminals used stolen details of civil servants to make false claims via site

Written by Daniel Thomas

The government has shut down the tax credits web site after discovering it has been targeted by online fraudsters.

HM Revenue & Customs (HMRC) took the decision last week to close the site, which processes tax credit claims, after discovering that civil servants’ personal identities had been stolen and were being used to try to steal money from the department through false online applications.

Criminals are believed to have stolen the personal details of more than 1,500 employees at the Department for Work and Pensions (DWP). The information was subsequently used to make fraudulent claims.

HMRC and the DWP are working with law enforcement agencies to carry out a criminal investigation, but say that public records have been unaffected by the security breach.

A spokeswoman for HMRC told Computing that the fraud attempts were discovered during compliance work.

The department has subsequently identified and stopped attempts to defraud the tax credit system using its online portal.

‘In light of this, HMRC has closed the e-portal while it develops new checks to ensure that the system remains secure,’ said HMRC in a statement.

The DWP declined to comment on how hundreds of employee records had fallen into the hands of internet criminals, but says it is working quickly to identify which records have been stolen.

‘At the moment it appears that 1,500 DWP staff have been affected by this,’ said a spokeswoman for the DWP. ‘But we are conducting a criminal investigation and cannot comment on how this has happened.’

HMRC was unable to confirm when the tax credits e-portal would be available for public use again, but says that customers can still process applications via its telephone helpline, post, or in person at Inland Revenue enquiry centres.

In June, the UK’s National Infrastructure Security Co-ordination Centre warned that public sector employees were being targeted by sophisticated Trojan email attacks, which had been designed to trick them into giving out commercially and economically sensitive data (Computing, 23 June).

But sources told Computing the DWP identity theft is not related to this warning.

See also:

reader comments

related articles

 

Card fraud factory raided

Devices for stealing Chip and PIN card details found by police 13 Aug 2008

Fraud-as-a-service looms over firms

Criminals are offering fraud services via chat rooms and forums 28 Oct 2008

Renewed calls to criminalise data loss

MPs put pressure on government following revelations of more lost data 24 Jan 2008

latest news

Dell quits Irish production

Vendor to slash 1,900 jobs in Limerick as it migrates assembly for EMEA customers to Poland 08 Jan 2009

Business confidence lower than 1991

Staff appointments plummeted last month as firms expect worst economic climate in 20 years 08 Jan 2009

Lenovo to lose one in 10 staff

Chinese PC vendor announces 2,500 job losses as executive pay packets are cut in half 08 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

In the Studio with CRN: Oracle

CRN TV catches up with Alan Hartwell, vice president of technology solutions and channels at Oracle

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation