VerbatimParliament, as it happens

Electronic Government: Security

Asked by Mr Andrew SnowdenConservativeTreasuryTabled Answered 12 March 2026UIN 118298

The question

To ask the Chancellor of the Exchequer, whether HM Revenue and Customs has conducted a recent assessment of vulnerabilities in the Government Gateway system relating to unauthorised changes to personal account details.

Answered by Dan Tomlinson

HM Revenue and Customs keeps the security of the Government Gateway under continual review.

As part of its standard cyber security and risk management processes, HMRC regularly undertakes security risk assessments, vulnerability management activity and testing to identify and mitigate potential threats, including risks associated with unauthorised changes to customer account details. These activities are complemented by fraud prevention controls, monitoring and investigation arrangements designed to detect and respond to suspicious or potentially fraudulent account activity. Where issues are identified, they are prioritised and addressed in line with HMRC’s security governance and incident management arrangements.

For security reasons, HMRC does not comment publicly on the detail or outcomes of specific security assessments.

Verbatim has judged this answer against the question that was actually asked — answered, partly answered, or evaded. Sign in to see the verdict →

Open this question in Verbatim →

Every written question, searchable

155,000 questions tabled since the election, with the answer each department gave — and the ones still unanswered, with the clock running. Free to search.

Search written questions →Read on Verbatim