SARS sends a warning to anyone who filed a tax return this year
The South African Revenue Service (SARS) has noted increasing use of AI among scammers to generate realistic-looking correspondence from the tax service.
This is making it difficult for many taxpayers to distinguish between official and scam notices, with the revenue service urging extra caution.
The warning comes as SARS has identified a new wave of scams hitting the country, circulating via both SMS and email.
As South Africa is in the midst of its 2026 tax season, any taxpayers who have filed their tax returns are particularly vulnerable to scammers looking for a target.
Taxpayers doing their manual filing are on the lookout for correspondence from SARS and may be eager to claim any refunds owed.
While the scam follows the same modus operandi as the long list of examples to date, the use of AI is complicating matters.
In the latest round, the scammers are telling recipients they are owed a refund, usually for a high amount—up to R50,000—and directing them to a fraudulent website.
This kind of phishing scam is well-known and has been repeatedly communicated by SARS, but new AI generation technology is making the typical markers of a scam difficult to detect.
“SARS is noting with concern that the scammers are now using AI to generate professional-looking email templates that are harder to identify as fraudulent,” the revenue service said.
“If you receive a scam notice, please delete and block [the sender]. If in doubt, email the SARS IT Security team at [email protected].”
The revenue service has added the latest AI-generated correspondence to the long list of scams and phishing examples, urging taxpayers to visit the page and familiarise themselves with various styles.

Scammers are getting smarter
SARS’ latest warning echoes recent alerts from the Southern African Fraud Prevention Service (SAFPS), which said that cybercriminals were catching on to the latest technological developments.
This includes using increasingly convincing scams that closely resemble legitimate SARS communications, but also other crimes like profile hijacking, which uses information stolen in these scams.
The SAFPS said that scammers rely heavily on urgency, fear and the appearance of legitimacy to pressure victims into acting without verifying the request.
Looking legitimate is key to this, with scammers often making only subtle changes to email addresses or website links that are difficult to detect at first glance.
“These messages may ask taxpayers to verify banking details, confirm personal information or update their eFiling profile,” it said.
Clicking the embedded links can expose confidential information or compromise devices with malicious software.
Official SARS correspondence comes from an **@sars.gov.za** domain—If the address differs, treat it as suspicious and avoid clicking any links.
However, a spoofed SARS address could also be used, so taxpayers should always confirm communication, payments, or refunds through the official SARS eFiling or MobiApp platforms.
SAFPS noted that scammers getting hold of taxpayer details through scams could lead to eFiling profile hijacking, highlighting how sensitive this is for anyone caught in the trap.
Hijacking involves fraudsters using stolen personal information to change banking details linked to taxpayer accounts.
This allows legitimate refunds to be redirected into fraudulent bank accounts opened using stolen identities.
“Victims often only become aware of the fraud after discovering that their refund has already been paid into an unfamiliar account,” the group said.
“This emerging trend highlights the importance of protecting personal information and regularly monitoring eFiling profiles for unauthorised changes.”
To get ahead of scammers, taxpayers have been urged to:
- Never share eFiling usernames or passwords, and avoid disclosing banking information, PINs or card details in response to emails, SMSs or phone calls.
- Handle all tax-related payments through official SARS platforms or verified banking channels.
- Avoid clicking on links received via email, SMS or WhatsApp and instead access SARS services directly through the official website.
- Use strong passwords, multi-factor authentication and avoiding public Wi-Fi when accessing sensitive financial information can further reduce exposure to cybercrime.
- Be cautious whenever communications create a sense of urgency or attempt to intimidate you into making immediate decisions.
Echoing SARS’ warning, the SAFPS said that if there is any uncertainty, taxpayers should contact SARS immediately using verified contact details.