SARS Updates VAT Zero-Rating Evidence: Are You Compliant?
21/07/2026Why Tax Season Scams Pose a Critical Threat to Your Business
As the South African tax season reaches its peak, a sophisticated new wave of phishing attacks is targeting taxpayers across the country. Recently identified by the South African Revenue Service (SARS) as “SARS-SCAM-395,” this campaign specifically exploits the timing of auto-assessments and the filing window for non-provisional taxpayers. For business owners, directors, and SMEs, these scams represent more than just a nuisance; they are a direct threat to corporate financial security and data integrity.
Scammers understand the rhythm of the South African tax calendar. By launching these attacks during the busiest months of the year, they capitalize on the high volume of legitimate correspondence taxpayers expect to receive. When a business owner receives an email claiming a refund is waiting or a return is ready for review, the psychological urge to click is high. However, falling for these deceptive tactics can lead to the compromise of sensitive company information and the hijacking of corporate eFiling profiles.
Key Business Implications
The impact of a successful phishing attack on a business can be devastating. It is rarely limited to a single fraudulent transaction; rather, it often serves as a gateway for deeper criminal activity. Key implications for your business include:
- Unauthorized Access to Banking Credentials: Most phishing links lead to “cloned” websites that mimic official banking portals or SARS login pages. Once a director or financial officer enters their details, criminals gain the ability to drain corporate accounts.
- eFiling Profile Hijacking: By stealing login credentials, scammers can change the banking details registered with SARS. This ensures that legitimate refunds are diverted into fraudulent accounts, often without the business realizing it until months later.
- Identity Theft of Directors: Personal information harvested through these scams—such as ID numbers and addresses—can be used to open fraudulent credit lines or commit further identity-related crimes in the names of company leadership.
- Operational Disruption: Recovering from a security breach requires significant time and resources. It involves forensic audits, resetting security protocols, and potentially dealing with frozen accounts during the investigation.
Compliance and Financial Risks
Beyond the immediate loss of funds, businesses face significant regulatory and compliance risks when they fall victim to tax-related scams. Under the Protection of Personal Information Act (POPIA), businesses have a legal obligation to safeguard the personal and financial data they process. A breach resulting from a staff member clicking a phishing link could trigger mandatory reporting to the Information Regulator and potential legal liabilities.
Furthermore, there is a risk of “tax crime by proxy.” If a scammer gains access to your eFiling profile, they may submit fraudulent returns to trigger larger refunds. While the scammer pockets the money, the business remains legally responsible for the accuracy of the filings submitted under its profile. This can lead to grueling audits, penalties, and interest charges from SARS, even if the business was an unwitting victim of fraud.
What Business Owners Should Do Next
To protect your organization, a proactive approach to cybersecurity is essential. Business owners and directors should implement the following protocols immediately:
1. Educate Your Finance Team: Ensure that every employee with access to financial systems or tax portals understands that SARS will never send a hyperlink to an external website, nor will they ask for credit card details or OTPs via email or SMS. SARS does not use .htm or .html attachments; any such file should be treated as malicious.
2. Verify Through Official Channels Only: Never use a link provided in an email to access eFiling. Always type the official address (www.sars.gov.za) directly into your browser or use the official SARS MobiApp. If a notification claims a refund is due, it will be reflected within the secure eFiling environment without the need to “click to release” it.
3.

