New U.K. Phishing Scam uses a £400 Tax Cut as Bait

Stu Sjouwerman | Aug 5, 2020

phishing attackPretending to be the U.K. Governments’ Digital Service Team, this latest COVID-related phishing attack seeks to con victims out of their credit card details.

Nearly everyone today has been impacted by COVID-19 – so much so, we’re all tired of hearing about it… that is, until you receive an email offering up a £385.50 Council Tax Reduction.

The email scam begins by informing the recipient “You are getting a Council Tax Reduction considering you’re on a low income or get benefits.” The Council Tax Reduction actually exists, but has strict requirements. In the case of the phishing scam, shown below, the email goes on to offer “The refunded amount will be transferred directly on your Debit/Credit card. Apply now to claim the reductions made over your past two years of Council Tax payments.”

Counciltax

“Applicants” are asked to provide credit card details which will, no doubt, be used to commit fraud.

This email demonstrates how little more than a good scam and reasonable presentation can create enough credibility to fool victims into becoming the unwitting participant.

Employees should be taught via Security Awareness Training to verify email details, such as the from sender’s email address, as well as to scrutinize every detail in an unsolicited email that seems too good to be true.

For example, in the case shown above, the tax reduction amount mentioned in the subject and within the email’s body don’t match – something you wouldn’t expect to see.

Creating a phishing scam is easy. And so is creating a victim. Security Awareness Training is an organization’s best means to elevate defenses, and reduce the risk of email-based scams succeeding.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.