Portugal: Fraudulent Emails and SMS Targeting Taxpayers: Tax Authority Phishing Alert 3 August 2026

On 3 August 2026, the Portuguese Tax Authority issued a new security alert warning taxpayers of a sophisticated phishing campaign involving fraudulent emails and text messages (SMS) purportedly sent on behalf of the institution. This alert forms part of an ongoing series of security warnings that the authority has periodically released since 2022 to inform the public about evolving social engineering techniques targeted at taxpayers, businesses, and tax representatives. The current campaign, identified through the authority’s cybersecurity monitoring units, employs spoofed sender addresses, cloned official letterheads, and urgent language concerning tax refunds, outstanding liabilities, or mandatory update of fiscal data to deceive recipients into disclosing sensitive personal information, banking details, or digital credentials. The messages often direct victims to counterfeit portal pages that mimic the visual design of the official Tax Portal website, prompting unwary users to enter their Tax Identification Number (NIF), password, or to download malware-infected attachments. The authority has emphasized that genuine communications from the authority never request passwords, PINs, or banking information via email or SMS, and that all official tax notices are delivered through the taxpayer’s registered personal area on the Tax Portal or via registered mail. The August 2026 alert specifically highlights a spike in messages referencing the recent ICS2 stop word updates and CBAM declaration requirements, exploiting taxpayers’ heightened awareness of customs and tax compliance changes to increase the credibility of the fraud. The authority has concurrently released technical guidance and a public awareness notice, urging recipients to verify the authenticity of any unsolicited tax-related message by contacting the authority’s dedicated phishing reporting line and to forward suspicious messages to the authority’s cybersecurity analysis team for immediate investigation.

Key Takeaways

  • Sophisticated Phishing Techniques and Campaign Characteristics: The current phishing campaign, active since late July 2026 and formally alerted on 3 August 2026, leverages a multi-vector approach combining email and SMS to maximize reach and impact. Fraudulent emails feature subject lines such as “Important Tax Update,” “Refund Initiated,” or “Fiscal Data Verification Required,” and contain attachments or links that redirect to meticulously replicated versions of the official Tax Portal login page. These counterfeit pages request the user’s Tax Identification Number (NIF), full name, date of birth, and banking coordinates under the pretext of processing a tax refund or verifying fiscal compliance. Simultaneously, the SMS vectors deliver shortened links accompanied by urgent text such as “Tax Authority: Immediate action required – update your fiscal data now” or “Refund pending – confirm your International Bank Account Number (IBAN) to receive €XX.XX.” The use of time-sensitive language, references to recent tax policy changes (including the August 2026 ICS2 stop word updates), and spoofed sender IDs that mimic official short codes significantly increases the likelihood of recipient interaction. Cybersecurity analysts at the authority have traced the origin of the domain hosting the fake portal to a rapidly changing network of compromised legitimate websites, a tactic designed to evade blacklisting and enhance the scheme’s persistence.
  • Authority’s Official Stance and Recommended Protective Measures: The Portuguese Tax Authority has consistently maintained that it does not initiate contact regarding tax obligations, refunds, or data updates via unsolicited email or SMS, and that all legitimate fiscal communications are channeled through the taxpayer’s secure personal area on the Tax Portal or via registered correspondence dispatched to the registered address. In response to the August 2026 campaign, the authority advises the public to adhere to the following protective protocols: (1) refrain from clicking on links or downloading attachments in unsolicited messages claiming to represent the tax authority; (2) verify the legitimacy of any tax-related communication by independently logging into the official Tax Portal using bookmarked URLs or the official mobile application; (3) report suspected phishing attempts immediately to the authority’s dedicated email address (phishing@portaldasfinancas.gov.pt) or via the online reporting form available on the authority’s website; (4) ensure that all devices used for tax-related transactions are equipped with up-to-date antivirus software and operating system security patches; and (5) educate employees and family members about the indicators of phishing, including generic greetings, spelling errors, mismatched sender domains, and requests for sensitive information. The authority also underscores that taxpayers who inadvertently provide credentials should promptly change their passwords, contact their financial institution, and notify the authority to mitigate potential fraudulent use.
  • Legal Framework, Penalties, and Authority Enforcement Actions: The phishing campaign described above constitutes a serious threat not only to individual taxpayers’ financial security but also to the integrity of the national tax administration and the broader EU tax transparency framework. Under Portuguese law, unauthorized access to personal data, identity theft, and the execution of fraudulent schemes targeting public financial systems are prosecutable offenses under the Penal Code and the General Data Protection Regulation (GDPR), with administrative fines reaching up to 20,000 euros for individuals and significantly higher penalties for organized criminal networks. The authority possesses the legal mandate, pursuant to Decree-Law No. 315/2003, as amended, and the EU Directive on attacks against information systems, to initiate criminal complaints, cooperate with the Judicial Police, and implement temporary blocking measures against identified fraudulent domains. The August 2026 alert empowers the authority to request expedited judicial orders for the takedown of phishing websites, in coordination with the National Cybersecurity Centre (CNCS) and EU law enforcement agencies such as Europol’s EC3 (European Cybercrime Centre). Furthermore, businesses that fall victim to such phishing may face administrative penalties for non-compliance with declarative obligations if compromised credentials lead to inaccurate filings, underscoring the necessity of robust corporate cybersecurity policies and regular staff training programs.

Disclaimer:This article is compiled and summarized based on publicly available information and is for general information and academic exchange purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. For tax planning, please consult a qualified professional tax advisor or legal counsel.

Source: Read Original Announcement