Portugal: Tax Authority Security Alert: Fraudulent Message Circulating 28 July 2026

On 28 July 2026, the Portuguese Tax Authority issued a targeted security alert regarding a circulating fraudulent message campaign directed at taxpayers and businesses, exploiting themes related to recent customs reforms and tax compliance deadlines. The alert, disseminated through the authority’s official communication channels, warns of SMS and email messages bearing subject lines such as “Urgent: ICS2 Declaration Update Required” and “CBAM Declaration Deadline Extended,” which prompt recipients to click on malicious links or download attachments containing malware designed to harvest Tax Identification Numbers, fiscal passwords, and sensitive corporate financial data. The messages leverage the timing of the mid-year tax compliance cycle and the recent implementation of the ICS2 stop word list effective 3 August 2026, as well as the ongoing CBAM rollout, to lend apparent legitimacy to the scam. The authority has clarified that no official tax directive or declaration update notice is ever distributed via unsolicited electronic channels, and that all legitimate communications concerning ICS2, CBAM, or other fiscal obligations are published on the Tax Portal and delivered to registered taxpayer accounts. The authority further advises recipients to exercise caution, verify any such message through official channels, and report suspicious communications to the authority’s cybersecurity team. This alert forms part of the authority’s ongoing public awareness campaign to mitigate the rising tide of tax-related phishing, particularly during periods of regulatory change when taxpayers are most attentive to procedural updates.

Key Takeaways

  • Phishing Campaign Themes and Delivery Mechanisms: The July 2026 phishing campaign employs a dual-vector strategy combining SMS and email to target a broad spectrum of recipients, including individual taxpayers, small business owners, and corporate finance officers. Email subjects typically read “Urgent: ICS2 Declaration Update Required” or “CBAM Declaration Deadline Extended,” while accompanying text urges immediate action to avoid penalties or loss of tax refund privileges. SMS messages feature shortened links and concise urgent language such as “Tax update required – click here now” or “CBAM declaration pending – verify now.” The messages frequently reference the mid-2026 implementation of the ICS2 stop word list and the ongoing Carbon Border Adjustment Mechanism rollout, exploiting the heightened public awareness of these regulatory changes to appear credible. Cybersecurity analysis conducted by the authority has identified the use of dynamic DNS domains and compromised legitimate business websites as hosting infrastructure, allowing the perpetrators to evade static blacklist filters and prolong the campaign’s lifespan. Attachments distributed via these messages are observed to contain obfuscated Visual Basic scripts and macro-enabled documents that, when executed, deploy information-stealing trojans targeting browser-stored credentials, Tax Identification Numbers, and financial transaction details.
  • Authority Guidance and Recommended taxpayer Protocols: The Portuguese Tax Authority reiterates its long-standing position that it does not initiate contact concerning tax obligations, declaration updates, or fiscal data verification through unsolicited email or SMS, and that all legitimate communications are channeled through the Tax Portal and delivered to the registered taxpayer’s personal area. In response to the July 2026 campaign, the authority recommends that taxpayers immediately delete unsolicited messages claiming to represent the tax administration, avoid interacting with any embedded links or attachments, and report the incident to the authority’s dedicated phishing reporting channel (phishing@portaldasfinancas.gov.pt). Additional protective measures include ensuring that all devices used for online tax services are protected by current antivirus solutions and operating system security updates, enabling two-factor authentication where available on the Tax Portal, and educating employees and family members about the visual and linguistic red flags of phishing, such as generic salutations, spelling discrepancies, mismatched sender domains, and requests for sensitive credentials. The authority also provides a step-by-step recovery protocol for individuals who have inadvertently disclosed credentials, involving immediate password reset, notification to their financial institution, and formal notification to the authority to initiate fraud monitoring.
  • Legal Consequences and Enforcement Measures: The fraudulent message campaign described herein constitutes a prosecutable offense under the Portuguese Penal Code, particularly provisions addressing unauthorized access to personal data, identity theft, and the execution of deceptive schemes targeting public financial systems. Additionally, the campaign falls within the scope of the EU Directive on attacks against information systems, enabling coordinated law enforcement responses with the National Cybersecurity Centre (CNCS) and Europol’s EC3 (European Cybercrime Centre). The authority possesses the legal power, pursuant to Decree-Law No. 315/2003 as amended, to pursue criminal complaints, seek judicial orders for the takedown of fraudulent domains, and impose administrative sanctions on individuals or entities found orchestrating such campaigns. Administrative penalties for successful phishing attacks that result in non-compliant tax filings may reach up to 20,000 euros for natural persons and substantially higher fines for organized networks. The July 2026 alert further authorizes the authority to request expedited interim measures from the competent courts to block access to identified phishing websites, thereby protecting the broader taxpayer community from ongoing exposure.

Disclaimer:This article is compiled and summarized based on publicly available information and is for general information and academic exchange purposes only. It does not constitute any form of formal tax advice, legal opinion, or basis for performance. For tax planning, please consult a qualified professional tax advisor or legal counsel.

Source: Read Original Announcement