SPF Finance and MyMinfin Fraud

First assess what is being requested, which channel was used and what has already happened. Do not use the received link or imposed phone number as the verification channel.

Information checked : 2026-09-10

Transparency and Sources

Page checked
2026-09-10
Sources checked
2026-09-17
Content status
information published with visible sources and clear limits
Official sources cited
5
Editorial responsibility
StopArnaques

StopArnaques is an independent Belgian service. It is not a public authority and does not speak on behalf of the organisations cited.

Report a correction

What you need to understand

  • Refund, regularisation or tax document leading to an external portal.

The scenario, step by step

  • The message impersonates SPF Finance or MyMinfin and announces a tax refund, a debt, a regularisation or a document to view.
  • The link leads to a fake login screen or a form asking for identity, banking or card details under the pretext of paying out the refund.
  • The fraudster may combine the fake portal with an itsme request. A real notification should only be accepted if it matches a MyMinfin login started by the user themself.

What the fraudster is trying to get

  • Identity details and login details that allow them to impersonate the taxpayer.
  • Banking details, card details or a validation meant to divert money.

Common variations

  • Fake tax refund that must be claimed quickly.
  • Fake tax debt with a threat of a surcharge.
  • Fake MyMinfin document, eBox or message in the name of a debt collection service.

Warning signs in your case

  • External link
  • Promise of money
  • Login or IBAN outside the official portal

What a legitimate service would do

  • A tax file is checked by opening MyMinfin yourself from the official SPF Finance domain.
  • SPF Finance publishes a dedicated phishing page and explains the channels that allow its communications to be recognised.

Belgian context and fraud chain

  • SPF Finance and MyMinfin are well-known reference points for tax returns, assessment notices, debts and tax refunds. The fraudster chooses a believable period or pretext, without necessarily knowing the victim's real tax situation.
  • The fake portal may come before a real itsme request. Consistency must be checked in MyMinfin opened manually and in the exact details of the request shown by itsme.

Decision points to check

  • Do not judge the message by the refund amount or the quality of the logo. Check whether the document or debt exists in MyMinfin.
  • Check the domain before any identification. A subdomain or an address containing words such as SPF, finances or MyMinfin may belong to another domain.
  • Do not give card details to receive a tax refund. Any banking request must be compared with the procedures and information visible in the official channel.

How to check without taking a risk

  • Do not reply to the message and do not use the link, QR code or number it contains.
  • Open the official app or website yourself, then check whether the same request appears in your personal space.
  • If in doubt, contact the organisation using a number found on its official website, a reliable invoice or your bank card.

What to do immediately

  • Go only through myminfin.be.
  • Do not give any banking details outside the official portal.

If you have already clicked, paid or replied

  • Stop the exchange and do not try to negotiate with the sender.
  • Change the access details that were shared through the official service. Contact the bank immediately if a payment, card, IBAN or validation is involved.
  • Keep the exchanges, payment references and observed addresses for the report, without publicly sharing personal data.

Reacting after an incident

  • If login details or an itsme validation have been shared, identify the service that was actually approved and secure the affected accounts through their official channels.
  • If a card or a payment is involved, contact the bank immediately. Do not pay a second amount to someone who promises to correct the first transaction.
  • Keep the message, the fake domain and the useful screens, then use the reporting channels indicated by SPF Finance and Safeonweb.

Limits and level of proof

  • An unexpected refund is a reason to check, not automatic proof of fraud. MyMinfin remains the source to confirm the tax file.
  • This page does not interpret a debt or a tax decision and does not replace SPF Finance for the substance of the matter.

Analysis grid for the MyMinfin tax message

  • To review a the MyMinfin tax message case, separate four questions: who is contacting you, through which channel, what action is being requested and which independent element can confirm it. One reassuring answer does not make up for the other inconsistencies.
  • The priority signs in this case are: external link; promise of money; login or iban outside the official portal. Their combination matters more than the isolated presence of a word, a logo or a typo.
  • Always compare the message with the actual status of the service. For the MyMinfin tax message, a request that is absent from the app, the account or the official contact must remain unexecuted until confirmed.

When to ask for immediate help

  • In a case of the MyMinfin tax message, contact the service concerned without delay if a code, validation, payment, card, identity document or remote access has already been shared. Describe the exact action rather than simply saying that you were hacked.
  • If no sensitive action was taken, keep the useful elements, block the contact and use the detector to document the signs. This distinction avoids confusing prevention, a confirmed incident and a simple unsolicited message.

What to do now

  • If you have not acted, do not click further and open the named service's official channel yourself.
  • If you clicked, close the page, enter nothing else and note what information was shown or requested.
  • If you shared a code, card, password or payment, contact your bank or the relevant official service immediately.
  • Keep the message, time, link used and any useful screenshots. Share them only with an official reporting channel or a trusted helper.

Limits of this page

  • This page does not prove that a message is safe and does not replace your bank, the police, Safeonweb, a platform or a public service.
  • A scam may be new, very well written or described with too little context. Use the result as decision support, not as absolute certainty.
  • Before taking a final action, checking through the official channel matters more than the appearance of the received message.

Check through an official channel

  • Type the service address yourself or open the official app. Do not use a phone number, link or QR code from the suspicious message to verify the situation.
  • When money, card details, a code or account access are involved, the safety action comes first. The analysis can then help organise the evidence.

How to read the result

  • A low number of signals does not mean that everything is safe. It only means that this page or analysis did not find decisive evidence with the information available.
  • Focus on the requested action: paying, sharing a code, installing an app, approving a bank action or leaving an official platform. That action matters more than a logo, sender name or polished wording.
  • If the situation feels urgent, step away from the received message first. Then check calmly through a channel you already trusted before the message arrived.

Belgian reading of this situation

  • For the MyMinfin tax message, focus on the relevant Belgian next step: open the official channel yourself, contact the bank, use Safeonweb or preserve evidence.
  • The right decision for the MyMinfin tax message depends on what has already happened. Reading a message is not the same as clicking, paying, sharing a code or granting remote access.

Frequently asked questions

How can I check a request linked to the MyMinfin tax message without clicking?

Go only through myminfin.be. Then compare the request with your official space and test the text or link in the StopArnaques detector.

Which signs should make me stop?

Stop the interaction if you see, among others: external link, promise of money, login or iban outside the official portal. A known visual identity never makes up for an unusual request.

Does the detector replace the official check?

No. The detector helps you understand the risk and the signs observed. For a banking, administrative or account-related operation, always confirm with the official service through an independent channel.

Useful official sources

Test another suspicious message

I already took action

Prepare my next steps