On a Tuesday in July, weeks after filing your tax return, a text arrives announcing a refund pending in your name and a link to claim it before it expires. Whoever sent it is committing the offence of fraud under article 248 of the Spanish Criminal Code, because the Agencia Tributaria, the Spanish Tax Agency and the body being impersonated, pays refunds by transfer into the account stated in the return itself and never asks anyone to confirm anything through a link. The message belongs to a campaign that repeats every year with two peaks, the income tax filing season between April and June and the refund season between July and December, and the harm it causes takes two distinct forms, a charge on your card or account and the later misuse of the details you handed over.
How to recognise the message
The pattern is stable even when the wording changes. A text or email claiming to come from the Tax Agency, from Hacienda or from a ministry tells you that a refund is pending, that your return has been processed or that a reimbursement is being held, and points you to a link to collect it. The link opens a page that imitates the Agency’s online office and asks, depending on the version, for your identity details, the full card number with expiry date and security code, or your online banking credentials. Some variants also ask for the code your bank sends by text to validate transactions, and that code is what turns stolen data into money.
Some signs never fail. The link’s domain is not that of the official online office, which ends in agenciatributaria.gob.es, however much the visible text disguises it with hyphens or look-alike domains. The message does not identify you by name or tax number, or does so with details available from any data leak. It sets a deadline of hours or days to collect. It asks for card details, which the Tax Agency does not use to refund anyone. And it often arrives at a time when, if you have filed, you really are waiting for a refund, which is why it works.
Why it looks genuine
The impersonation rests on things the fraudster does not have to invent. The refund exists or may exist, because most returns with a refund due are paid in those months. The sender of a text can be spoofed, so the message shows a name that looks official or even lands in the same thread as legitimate ones. The fake page copies the design, logos and administrative language of the online office, and on a phone screen the address is barely visible. None of this requires special technical skill, the kits to build these pages are sold ready-made, and that is why the campaigns return with every tax season.
What the Tax Agency never does
This works as a rule because it has no exceptions. The Tax Agency does not send texts or emails with links to collect a refund, does not ask for card details or banking credentials through any channel, and does not charge fees or handling costs to release a reimbursement. Refunds are paid by transfer into the account you gave in your return. When the Agency needs to tell you something, it does so by formal notification in its online office, through the enabled electronic mailbox (Dirección Electrónica Habilitada) or by post, with access through a digital certificate, Cl@ve or the official identification systems. A penalty, a request for information or a withheld refund is never notified by text with a payment link. The online office itself publishes security warnings and a list of the fraudulent texts and emails detected, and the status of your refund is checked there, by logging in on your own and never through a link you received.
What offence it is and what can be recovered
Sending the message and running the fake page constitute fraud under article 248 of the Spanish Criminal Code, punishable with six months to three years in prison where the amount defrauded exceeds 400 euros and with a fine where it does not, that figure being the threshold between an offence and a minor offence. It makes no difference whether the money was taken through a charge using your card details or through a payment you ordered yourself believing you were paying a fee, in both cases there is sufficient deception, an act of disposal and a loss. That the deceiver poses as a public authority mitigates nothing, it is precisely the mechanism of the deception. The number of victims and the organisation behind these campaigns allow higher sentences in aggravated cases, but in practice the perpetrators are outside Spain and the criminal case, on its own, rarely gets the money back.
That is why recovery is decided on different ground, and here one distinction settles everything else. If, with the details taken from you, someone made charges on your card or transfers from your account that you did not order, those are unauthorised transactions, and payment services legislation obliges the bank to refund them. If it was you who typed the card into the fake site and authorised a payment, even a small amount presented as a handling fee, the payment is formally authorised and the bank does not refund it on that basis, without prejudice to a possible chargeback through the card scheme on the ground that the merchant was fraudulent, and to criminal and civil action against the fraudster. In the first case the bank usually replies that you were the one who gave out the details, and whether that argument succeeds depends on how the claim is framed, with what documentation and at what point. That is the work we do at the firm within our cybercrime practice, and in this article on bank refunds after phishing I explain in more detail what the bank is obliged to return.
What to do right now
The first hours are worth more than the following weeks. If you entered card details, call your bank on the number printed on the back of the card or shown in its app, never a number that appears in the message, and block the card. If you entered online banking credentials, change them from a different device and check your transactions, including those still pending. If you handed over the validation code that reached you by text, assume a transaction is under way and act with that urgency.
Do not delete the message. Keep a full screenshot showing the sender, date, time and link, and copy the link’s address somewhere separate, because the fake page usually disappears within days and without it the deception is harder to prove. Also keep the charge alerts, the bank app notifications and any later contact from the fraudsters, who sometimes call back posing as your own bank to “cancel” the transaction. That second call is part of the same fraud and is after the code they are missing.
Report it as soon as you can. You can do so at any National Police station, Guardia Civil post or duty court in the town where you live, even if the money has gone to an account abroad. A police report is not a legal precondition for the bank to refund an unauthorised transaction, but in practice the bank asks for it, and it is the document that allows the money to be traced and the receiving account to be frozen if there is still time. The offence is not lost by waiting a few days, the evidence and the chance to hold the money are.
If you already paid or gave your details
What you can achieve depends on what actually happened, and the scenarios are worth separating because they are easily confused.
| What happened | Main risk | What can be pursued |
|---|---|---|
| You only opened the link, without typing anything | Low, unless something was downloaded onto the phone | Check the device and watch your accounts, nothing more |
| You typed personal details, no card or credentials | Later misuse of your identity, contracts and loans in your name | Precautionary police report and monitoring of credit files |
| Charges or transfers were made that you did not order | Direct loss of your balance or card limit | Refund by the bank as an unauthorised transaction |
| You paid a supposed fee with your card on the fake site | Payment authorised under deception, the bank does not refund it by itself | Chargeback for a fraudulent merchant and action against the fraudster |
| You installed an app or your SIM was duplicated | Remote control of the phone and of the validation codes | Immediate block with the operator and the bank, then a claim for the transactions |
The scenario of personal details with no money involved is the one most often neglected. With a name, tax number, date of birth, address and a photo of the identity document, which some fake pages request under the pretext of verifying identity, phone lines are contracted, microloans are applied for and accounts are opened. When that happens the rule is simple to state, you contracted nothing and owe nothing, and it is the lender that granted the credit that has to prove you were the one who applied. Getting someone removed from a debtor file they were placed on for a debt that is not theirs, and stopping the lenders’ demands, takes time, and we handle that so you do not have to argue with each of them.
SIM duplication and remote-control apps change the nature of the problem. If your phone suddenly loses signal, someone may have obtained a duplicate of your SIM from the operator and may be receiving your bank’s validation codes. If you installed an app from the link, that app may be reading your texts and operating your online banking. In both cases the transactions carried out are unauthorised even though they passed the bank’s controls, and in both cases access has to be cut off first and the claim made afterwards.
Your real tax return is not affected by the fraud. The refund you are owed will follow its normal course and be paid into the account stated in the return, unless someone accessed your file with your credentials and changed the payment account, which you can check by logging into the online office on your own. Informing the Tax Agency is not compulsory and does not get your money back, but if you entered your online office credentials you should renew them and review your file. As for the telephone operator and the Agency itself, neither is liable for the loss simply because the text arrived, the Agency is the impersonated body and the operator carried a message whose sender can be spoofed.
When the criminal case is shelved because the perpetrator is not identified, which is the usual outcome, the claim against the bank does not close with it. They are independent routes, and in this piece on bank impersonation scams I explain why the shelving of the complaint does not weaken your position against your bank.
What is at stake if you handle it alone
The concrete risk of claiming on your own lies in the first document. A bank form filled in hastily in which you describe that you “entered the details on the page” becomes the argument the bank uses to refuse the refund, and once that first refusal is accepted, reversing it costs more than framing the claim properly from the start. In a case like this we gather the evidence of the deception and of the transactions, bring the claim against the bank or against the lenders that extended credit in your name, and if they do not refund we take the matter to court alongside the criminal complaint. You can call us on +34 677 841 007 or write to us through the contact page. For that first call, have ready the screenshot of the message with sender, date and time, the link’s address, the statement showing the charges and the time of each, the list of details you entered on the page, the bank’s reply if you already have one and a copy of the police report if you have already filed it.
Frequently asked questions
I only clicked the link but did not type anything, do I need to do anything?
Opening the page does not hand the fraudster your banking details, so the financial risk is low. Check that no new app has been installed on your phone and no file has been downloaded, and if it has, remove it or restore the device before using online banking again. Watch your account activity over the following weeks. There is no need to file a report or hire anyone over a single click.
Do I have to report it to the police for the bank to refund my money?
Payment services legislation does not make a police report a condition for refunding an unauthorised transaction, but banks ask for one as a matter of course and without it the claim starts on a weaker footing. The report is also the only way to have the money traced and frozen. You can report at any National Police station, Guardia Civil post or duty court in the town where you live, bringing the screenshots of the message, the link’s address and the statement showing the charges.
Do I have to tell the Tax Agency that I was defrauded by a fake text?
It is not compulsory and does not affect your return, which follows its course and is paid into the account you gave. You should log into the Tax Agency’s online office on your own to check that nobody has changed the payment account, and renew your credentials if you entered them on the fake page. The Tax Agency is the impersonated body and is not liable for the money lost.
Is it worth claiming with a lawyer or should I let it go?
It depends on the amount and on what happened. If the charge is a few dozen euros and the bank has already refunded it, hiring anyone is not worth it and a police report is enough. If there are charges or transfers of a significant amount, if the bank has replied that it was your fault, if credit has been opened in your name or if your SIM was duplicated, then it is worth it, because the difference between recovering the money and not recovering it lies in how the claim is framed and in not accepting the first refusal. Claiming on your own usually ends in a letter from the bank attributing the transaction to your carelessness, and reversing that afterwards is harder than framing it properly from the start.