SARS Scams and eFiling Profile Hijacking: Taxpayers Beware
“All role players must play their part to prevent criminals from accessing taxpayers’ information.” (SARS)
Every day, too many taxpayers fall victim to convincing scams that use SARS’ name to steal personal information and money.
Cybersecurity Awareness Month (every October) raises awareness about digital security, empowering South Africans to protect their personal data from digital forms of crime. It’s a good time to revisit the growing threat of SARS scams and eFiling profile hijackings.
Common SARS scam types
- Phishing emails: Members of the public randomly receive false ‘spoofed’ emails, made to look as if they were sent from SARS, but which are fraudulent. Examples include emails appearing to be from returns@sars.co.za or refunds@sars.co.za, indicating that taxpayers are eligible to receive tax refunds. These emails contain links to false forms and fake websites designed to look like SARS sites, with the aim of fooling taxpayers into entering personal information such as bank account details, which criminals then extract and use fraudulently.
- Fake SMS messages: SARS does not send *.htm or *.html attachments. Any SMS claiming to be from SARS with such attachments is fraudulent.
- Fake WhatsApp messages: SARS will not provide links to be opened or SARS bank account details for payments on a WhatsApp message.
- eFiling profile hijacking: Criminals gain access to taxpayers’ eFiling profiles, change banking details, and divert refunds.
What SARS will and won’t do
| SARS will: | |
| ✔ | Verify your personal details for telephonic engagement and authentication purposes |
| ✔ | Communicate through official SARS channels only |
| ✔ | Direct you to check your SARS profile on eFiling or the SARS MobiApp for legitimate debts |
| SARS won’t: | |
| ✘ | Request passwords, one-time pins (OTPs), banking PINs or eFiling login credentials through email, SMS, social media or telephone |
| ✘ | Request your banking details in any communication via post, email or SMS (but SARS will verify your personal details for telephonic authentication) |
| ✘ | Send hyperlinks to other websites, even those of banks |
| ✘ | Ask for your credit card details |
| ✘ | Send *.htm or *.html attachments |
| ✘ | Provide a SARS bank account number for payments |
| ✘ | Ask you to click any link to access its website or services |
What to do if you suspect a scam
Do not respond to communications that you suspect to be a scam. Simply contact us and let us provide certainty.
We will check whether the message is part of an official SARS communication campaign or if it’s a known scam message currently in circulation. If it’s a new scam, we can report it to the right authorities.
Before you share personal information or make any payments, we can verify the communication through official SARS channels. For example, if the communication pertains to outstanding debt, we can verify this directly on SARS platforms, as any legitimate debt will reflect on your SARS profile.
How to stay safe beyond Cybersecurity Month
- Do not open or respond to emails from unknown sources
- Be suspicious if a message asks for personal information or creates urgency
- Never share confidential details with unauthorised individuals
- Never click on any link to access SARS’ website or SARS services or to verify an account
- Only use secure internet platforms to access electronic services such as eFiling
- Enable two-factor authentication on eFiling profiles
- Use strong, unique passwords and change these regularly
SARS scams are becoming more sophisticated, but the rules for spotting them remain unchanged. When in doubt, and before taking any action, contact us.
Disclaimer: The information provided herein should not be used or relied on as professional advice. No liability can be accepted for any errors or omissions nor for any loss or damage arising from reliance upon any information herein. Always contact us for specific and detailed advice.
© AccountingDotNews

Previous Post