Skip to main content
Guidance

Report a security issue in an HMRC online service

Find out how to report a potential security issue or vulnerability in an HMRC online service and what information to provide.

If you think you’ve found a security issue in an HMRC online service you should:

To help us understand the nature and scope of the issue, you will be asked about:

  • the type of issue (for example, buffer overflow, SQL injection, cross-site scripting)
  • a proof-of-concept or exploit code
  • the location of the bug or the relevant URL
  • the impact of the issue, including how an attacker could exploit it

What happens next

HMRC takes the security of online systems very seriously. We’ll investigate all reports and take action where necessary.

You will only receive an update for your report if you sign up to the NCSC platform.

Sign up for emails or print this page