With the start of tax season, South African taxpayers should be aware of the growing threat of fraud. The article examines the latest scams targeting taxpayers and offers important advice on ensuring security during the filing process.
The days of scams like 'the prince needs your help' are over. The South African Revenue Service (SARS) warns taxpayers that cybercriminals are increasingly using artificial intelligence (AI) to create highly convincing phishing attacks. This makes fraudulent emails and messages much harder to detect than before.
Previously, consumers were advised to look for signs of fraud such as poor grammar, spelling mistakes, and sloppy formatting. However, the advent of generative AI has changed this, allowing scammers to create flawless emails that closely resemble official correspondence from organizations like SARS, banks, and courier services.
This warning comes amid cybercriminals targeting South Africans during tax season, when millions of taxpayers are filing returns and are more likely to receive legitimate information from SARS.
AI Raises the Bar for Phishing Attacks
Generative AI tools can create professionally looking emails in seconds, correcting grammar, improving tone, and even mimicking the corporate style of well-known organizations. Consequently, the old advice about looking for typos is no longer sufficient.
Instead, scammers are focusing on creating a sense of urgency, claiming that taxpayers are due a refund, face penalties, or need to urgently confirm bank details. The language used is often persuasive, professional, and free of obvious errors. Some phishing attempts also use AI to personalize messages by including publicly available information about recipients, which adds further credibility to the emails.
How Phishing Attacks Work
Phishing is a type of cybercrime where criminals impersonate legitimate organizations to trick people into revealing sensitive information such as banking details, passwords, identification numbers, one-time PINs (OTPs), and credit card data.
Victims are usually redirected to fake websites that closely resemble the real ones or are persuaded to download malware disguised as official documents. In SARS-related schemes, scammers often promise tax refunds, demand debt repayment, or instruct taxpayers to 'confirm' personal information.
What Taxpayers Should Look Out For Instead
Since AI-generated phishing emails are becoming increasingly sophisticated, attention should be paid more to technical and behavioral indicators of danger rather than grammar. These indicators include unexpected requests for personal or banking information, unusual pressure demanding immediate action due to an alleged account suspension or refund cancellation, and links that do not lead to the official SARS website.
Email addresses that slightly differ from legitimate domains and unexpected attachments supposedly containing tax documents or assessments can also be suspicious. Instead of clicking links in emails or SMS, taxpayers should log into their tax profile by entering the official SARS website address directly into the browser, or by using the official SARS eFiling platform or the SARS MobiApp.
What Does SARS Advise?
SARS has repeatedly reminded taxpayers that it will never request bank passwords, PINs, CVV card values, or one-time PINs via email, SMS, or phone. The revenue service also cautions taxpayers against messages claiming that immediate payment is required or that a refund is expected if they simply click a link.
If in doubt, taxpayers should verify any message by logging into their SARS eFiling account directly, instead of using links contained in emails or text messages.
AI Changes the Cybersecurity Landscape
The emergence of generative AI may simplify life or make trends more engaging, but it has lowered the barrier for cybercriminals. Previously, creating convincing phishing campaigns required a relatively high level of linguistic literacy and technical knowledge. Today, AI tools can generate professionally looking content in seconds, allowing scammers to launch larger and more complex campaigns.
There is also a reported increase in fake invoices, customer support messages, and attempts to impersonate others across various sectors, including banking, retail, and government.


