The Tax Authority Warns of Fake Emails Telling Freelancers to Issue 'Missing' Green Receipts
Portugal's tax authority (AT) has warned self-employed workers about fake emails, sent in its name, claiming they have 'missing' recibos verdes to issue and pushing them to a malicious link built to steal Portal das Finanças logins. Here is how the scam works and what the AT advises.
Portugal's tax authority has warned freelancers and independent workers about a fresh wave of fraudulent emails sent in its name. The Autoridade Tributária e Aduaneira (Tax and Customs Authority, or AT) says the messages, which impersonate the Fisco, tell recipients who issue recibos verdes — the electronic "green receipts" used to invoice self-employed work — that they have outstanding receipts still to issue, and push them to click a link to "emit the missing documents."
The AT is blunt about it: these messages are false and should be ignored. The whole point of the email, the authority says, is to lure the recipient onto a malicious page designed to harvest their login details for the Portal das Finanças, the government tax portal. Once a fraudster holds those credentials, they can see a taxpayer's fiscal data, change bank details for refunds, or file in the victim's name.
Why freelancers are the target
The choice of bait is deliberate. Anyone registered for atividade independente has a real, recurring obligation to issue green receipts through the Portal das Finanças, so a message about a "missing" receipt lands as plausible rather than absurd — especially for newer freelancers still unsure of the rules, and for foreign residents working through the Portuguese system for the first time. Portugal has hundreds of thousands of people invoicing this way, from designers and consultants to delivery riders, and a scam that feels like routine tax admin needs only a small hit rate to pay off.
The AT notes this is not an isolated campaign. It has also logged SMS phishing that impersonates the Chave Móvel Digital (the state's official digital-authentication service, or CMD), asking people to "update" their personal data through a link. The tactic is the same across both: manufacture a small sense of obligation or urgency, then steer the target to a fake login screen.
What to do
The authority's guidance is straightforward, and worth committing to memory because these campaigns recur:
- Ignore and delete unsolicited messages that claim to come from the Fisco and demand you click through to act.
- Do not click links or open attachments in a suspicious email or text, even if the sender looks official.
- Never enter your Portal das Finanças password anywhere you reached by clicking a link. If you need to check your tax situation, type the address yourself or use the official app.
- Verify directly. The AT communicates real obligations inside your area on the Portal das Finanças and through registered post — not by asking you to log in via an emailed link.
The safest habit is to reach official services only through channels you already trust. The same discipline applies to your Chave Móvel Digital, whose one-time codes should never be entered on a page you did not open yourself. It is a pattern residents have seen before: earlier this year the AT flagged fake emails and texts during IRS season, and AIMA has run its own alerts about appointment fraud aimed at foreign residents. When a message about your taxes arrives out of the blue, the official advice is the same each time — slow down, and go to the source yourself.