The Southern African Fraud Prevention Service (SAFPS) has cautioned taxpayers to remain vigilant during tax season as cybercriminals are employing convincing schemes that imitate official correspondence from the South African Revenue Service (SARS).
Adapting Scammer Tactics
As SARS simplifies tax filing through digital services and provisional assessments, fraudsters are modifying their methods to target unsuspecting payers. The head of SAFPS, Mani van Schalkwyk, noted that tax season consistently attracts criminals looking to exploit consumers.
He emphasized that scammers are constantly refining their approaches, making it crucial for consumers to be aware of the latest tactics and remain cautious throughout the filing process.
Common Types of Fraud
One of the most frequent forms of deception involves phishing emails and SMS messages allegedly originating from SARS. These messages often direct taxpayers to fake websites where criminals attempt to steal login credentials, bank details, and other personal information.
Van Schalkwyk reported that fraudsters frequently make subtle changes to email addresses or website links, which makes identifying fraudulent messages difficult. Taxpayers are strongly advised to carefully check the sender's address, remembering that official correspondence from SARS is sent from the @sars.gov.za domain.
Another common scheme relates to false tax refund notifications, claiming that a taxpayer is entitled to a refund. Victims are prompted to click a link to confirm banking details or complete a verification procedure before funds are transferred.
SAFPS advises verifying any refund notification by logging directly into one's eFiling profile on the SARS website or using official SARS communication channels, rather than following links in unsolicited emails or SMS.
Fake Payment Notifications
Scammers also send fraudulent notices about unpaid taxes, threatening fines, lawsuits, or account restrictions if immediate payment is not made. These messages often contain false bank details or links to fictitious payment portals.
SAFPS reminded taxpayers that SARS is a pre-approved recipient of funds in South African banks and never requests payments to unknown accounts provided through unauthorized correspondence.
The organization also warned about identity theft, where criminals impersonate SARS employees via phone, email, or messengers. They claim there is an issue with a tax return or refund before attempting to obtain identification numbers, tax reference numbers, bank details, or one-time passwords.
Van Schalkwyk stated: 'SARS representatives will never request confidential personal information or banking details in this manner.' Furthermore, SAFPS pointed to the growing threat of eFiling profile hijacking, where criminals use stolen personal data to change the bank details linked to taxpayers' accounts and redirect legitimate tax refunds to fraudulent accounts. Victims often only discover the fraud after their refund has already been sent to an unknown bank account.
Data Protection Precautions
To reduce the risk of fraud, taxpayers are advised never to share eFiling logins, passwords, banking information, PINs, or card details in response to calls, SMS, or emails. Consumers should contact SARS services directly through the official website, rather than clicking links received via email, SMS, or WhatsApp.
Additional protection can be achieved by using strong passwords, multi-factor authentication, and avoiding public Wi-Fi networks when accessing sensitive financial information. Anyone who suspects their tax profile or refund has been compromised should immediately contact their bank, notify SARS, and report the incident to the South African Police Service.
Suspected fraud can also be reported to SAFPS through its Yima platform, which allows users to report schemes, check suspicious web links, and receive information on the latest fraud trends. Van Schalkwyk concluded: 'Scammers continue to develop their tactics, but consumers can significantly reduce their risk by staying informed, checking every message, and using trusted platforms for reporting.'



