
South Africa’s tax season is in full effect for businesses and individuals. Every year, millions of South Africans log into their SARS eFiling and submit personal, sensitive and financial information in order to remain compliant with the South African Revenue Service (SARS). The one scary part about tax season is that cybercriminals are also on the hunt for unknowing potential victims.
In 2025, more than 10 million unique users accessed its digital channels – the SARS eFiling platform and the SARS mobile app – to file their returns. Additionally, more than 2,1 million taxpayers interacted with SARS through its digital channels. Of these, 1,1 million interactions were serviced by the SARS Online Query System, 707 000 through WhatsApp, and 290 000 with Lwazi Chat Bot.
To protect users, in 2025 SARS, Standard Bank, Capitec and Nedbank issued warnings to customers about the rise in scams throughout this period, and SARS Commissioner Edward Kieswetter alerted taxpayers to the scams, emphasising that SARS will not ask for personal information over email or via SMS.
For small to medium-sized enterprises (SMEs), the potential fraud poses a greater risk. SMEs can lose money they cannot afford to lose or be liable for any data breaches that might occur. This is why it’s important to know what kind of scams can occur during tax season and have risk mitigation plans in place to deal with them effectively.
In this article, we look at what tax scams are, how cybercriminals leverage technology for scams and what to do to protect yourself and your business.
What is a Tax Scam?
A tax scam is a fraudulent scheme where criminals impersonate government revenue authorities (such as SARS) or act as dishonest tax practitioners to steal your money or personal information.
How Cybercriminals Leverage Technology for Scams
According to Lucas Molefe, Cybersecurity Expert at ESET Southern Africa, the South African Fraud Prevention Service described how fraudsters leverage the auto-assessment process, specifically exploiting the same digital convenience that SARS introduced to improve the taxpayer experience to launch sophisticated campaigns.
“The Office of the Tax Ombud’s investigation into hijacked eFiling profiles found that weaknesses in SARS’ authentication, profile management and fraud detection processes created exploitable gaps, which allowed fraudsters to change banking details and redirect funds before victims or the authorities realised what had happened,” explains Molefe.
The role of Artificial Intelligence (AI) in Phishing Attacks
Beyond the exploitation of SARS’ auto-assessment process, cybercriminals are leveraging AI-enhanced attacks to scam taxpayers. They create hyper-realistic phishing to craft messages that impersonate SARS.
More alarmingly, these criminals also create deepfake voice calls. They employ advanced voice synthesisers and AI-generated cloned voices to mimic SARS agents or company executives. These realistic voice impersonations are used to pressure victims into making urgent tax payments or divulging sensitive information.
SIM Fraud and Profile Fraud
Fraudsters send fake communications with banking details, claiming that the customer owes funds to SARS. Some customers may in fact have funds due to SARS, making the communication seem legit. But the account details provided belong to fraudsters, not SARS.
Molefe says that case reports on eFiling profile hijacking show how attackers are combining data breach information, social engineering and fraudulent SIM swaps to take over a taxpayer’s mobile number, intercept the SARS one-time PINs, reset eFiling credentials and then alter bank account details so refunds are paid into accounts controlled by criminal syndicates.
“In short, if an attacker can swap your SIM, they own your OTP, and this is often the last line of defence for banking and SARS transactions,” says Molefe.
How Financial Institutions Navigate Tax Season
The pressure of tax season and potential fraud is not only on the businesses and individual taxpayers. Molefe says that for banks and fintech institutions, tax season has become a security stress test.
During this time, transaction volumes increase, customer anxiety follows suit, and the pressure on authentication and fraud detection infrastructure increases exponentially. Molefe says that to mitigate this, banks and fintechs are using AI telemetry to maintain detection at the speed and scale of digital.
“AI-driven telemetry provides a continuous, personalised baseline built for every user. It analyses and monitors their device, location, login patterns and typical transaction behaviours through AI to create a living baseline. When that baseline deviates, the system flags it in real time before a transaction is completed.
“In addition, AI-powered identity authentication now uses behavioural biometrics such as typing cadence, swipe pressure and even the angle at which a device is held to create a security layer that operates without adding friction to the customer experience. It is the invisible layer of protection that institutions can control, but that doesn’t impede how customers engage with systems and services,” explains Molefe.
How SMEs Can Protect Themselves
Because cybercriminals use modern technologies for their tax scams, protecting your business becomes a cybersecurity practice with little human intervention. Cybercriminals often target SMEs because they typically lack stringent cybersecurity protocols.
Leverage the following strategies to ensure your business is protected during tax season.
1. Verify SARS Communications
SARS explicitly explains that it will never send you emails with unrequested attachments, demand banking details via email or SMEs, or send live hyperlinks for payment. If you receive any communication claiming to be from SARS, log into your eFiling account directly from a secure browser rather than clicking on a link in a message.
2. Institute Strict Access Controls
Limit your eFiling and payroll access to essential personnel only. This means you do not share passwords or eFiling one-time pins (OTPs) with anyone, including third-party tax practitioners. Additionally, enable two-factor authentication for all platforms, especially in the payroll department.
3. Educate and Train Your Staff
All businesses of all sizes must regularly train and educate staff on cybersecurity, especially when it comes to financial records and personal information. Training your employees will enable them to spot phishing attempts such as a false sense of urgency (“claim now”), poor grammar, and generic greetings.
This will not only protect your business but also the personal information of customers that lives on your servers.
4. Report Suspicious Activity
If you recognise any suspicious activity, you must report it immediately to SARS. You can forward any fraudulent communication to SARS ([email protected]) and report suspected tax profile hijacking to the SARS anti-corruption hotline on 0800 00 2870.
5. Deploy Endpoint Security
You must ensure all work devices have updated antivirus software, firewalls and operating system updates to prevent keylogging or malware infections. This is critical because if a cybercriminal targets your business, your systems are your first line of defence. Without robust security systems, you risk exposing your business and customers to data breaches.
Things to Remember
Always remember the following to ensure you are prepared for potential tax scams:
- SARS will never request your banking details via post, email, or SMS. They may verify your personal details for security purposes during phone calls.
- SARS will not send hyperlinks to other websites.
- Notices from SARS will prompt you to log into eFiling or the SARS MobiApp.
- SARS does not send *.htm or *.html attachments.
SMEs must remember that a robust cybersecurity system is not only for protecting against known threats. It’s also about ensuring that during vulnerable periods like tax season, your business is protected and so is any personal information stored.
