SARS has flagged a growing trend of scammers using artificial intelligence to produce convincing correspondence that mimics official tax communication, making it harder for taxpayers to tell genuine notices from fraudulent ones and prompting the revenue service to call for greater vigilance. The alert follows a fresh batch of scams spreading via SMS and email, and with South Africa in the middle of its 2026 tax filing season, taxpayers who have already filed, especially those hoping for refunds, are especially exposed to opportunistic fraudsters.
Key Takeaways
- AI is making scams harder to detect: Fraudsters are now using artificial intelligence to generate polished, professional-looking SARS correspondence, eroding the usual warning signs like poor grammar or awkward phrasing that people once relied on to spot fraud.
- Refund scams are targeting active filers: With South Africa in the middle of its 2026 tax season, scammers are sending SMS and email messages promising refunds of up to R50 000 to lure taxpayers, especially manual filers, to fake websites designed to steal personal information.
- Profile hijacking can follow a successful scam: Once fraudsters obtain stolen personal details, they can hijack a taxpayer’s eFiling profile and redirect legitimate refunds into fraudulent bank accounts, with victims often only discovering the fraud after the money is already gone.
About Arcadia Finance
Find a loan you can trust with Arcadia Finance. Choose from 19 reputable lenders, all NCR compliant, with no application fees. A smooth process built around your financial needs.
The Growing Role of Artificial Intelligence in These Scams
Although this particular scam operates in much the same way as the numerous examples SARS has previously catalogued, the involvement of AI tools has added a new layer of difficulty to spotting them.
In this most recent version, fraudsters inform recipients that they are due a refund, frequently citing a substantial sum of up to R50 000, before steering them towards a fake website designed to harvest their information.
This type of phishing attempt is a familiar tactic that SARS has warned about on numerous previous occasions, yet the emergence of advanced AI generation tools is eroding the usual warning signs people would normally rely on to identify fraud.
SARS’ Response to the AI-Driven Scams
According to SARS, the organisation has observed with concern that scammers are now employing artificial intelligence to craft polished, professional looking email templates that are considerably more difficult to recognise as fake.
The revenue service has advised that anyone who receives a suspicious notice should delete it immediately and block the sender, and if there is any uncertainty, they should contact the SARS IT Security team via email at phishing@sars.gov.za.
SARS has also updated its extensive catalogue of known scams and phishing attempts to include examples of the newest AI generated correspondence, encouraging taxpayers to visit this resource and become familiar with the different formats being used.
Cybersecurity researchers have noted that AI language tools can now replicate an organisation’s tone, formatting and even typical turns of phrase within seconds, which is part of why scam detection that once relied on spotting poor grammar or awkward phrasing is becoming far less reliable.

Fraudsters Are Becoming More Sophisticated
SARS’ latest caution mirrors recent warnings issued by the Southern African Fraud Prevention Service (SAFPS), which reported that criminals are keeping pace with the newest technological advances available to them.
This encompasses not only increasingly persuasive scams that closely mirror authentic SARS communications, but also related offences such as profile hijacking, a crime that relies on information obtained through these very scams.
SAFPS explained that fraudsters lean heavily on tactics involving urgency, fear and a convincing sense of legitimacy in order to pressure victims into acting hastily, without pausing to verify whether the request is genuine.
Appearing legitimate is central to this strategy, and scammers frequently make only minor alterations to email addresses or website links, changes so subtle that they often go unnoticed at first glance.
What These Fraudulent Messages Typically Request
According to SAFPS, these deceptive messages may ask taxpayers to do any of the following:
- Verify their banking details
- Confirm personal information
- Update their eFiling profile
Clicking on the embedded links within these messages can expose confidential personal information or infect devices with malicious software.
Genuine SARS correspondence will always originate from an official @sars.gov.za domain, and should the address differ in any way, this should be treated as a clear warning sign, with taxpayers advised not to click on any accompanying links.
That said, a convincingly spoofed SARS email address is also a possibility, which is why taxpayers are urged to always confirm any communication, payment request or refund notification through the official SARS eFiling platform or the SARS MobiApp.
The Danger of eFiling Profile Hijacking
SAFPS pointed out that once scammers manage to obtain a taxpayer’s personal details through these schemes, it can pave the way for a more serious crime known as eFiling profile hijacking, underscoring just how sensitive this issue is for anyone who falls victim to the initial scam.
Hijacking occurs when fraudsters use stolen personal information to alter the banking details that are linked to a taxpayer’s account.
This manipulation allows legitimate refunds that would otherwise go to the rightful taxpayer to instead be redirected into fraudulent bank accounts, which are often opened using identities that have themselves been stolen.
SAFPS noted that victims frequently only become aware that something is wrong after they discover their refund has already been paid out to an account they do not recognise.
The organisation further explained that this emerging pattern highlights just how important it is to safeguard personal information carefully and to routinely check eFiling profiles for any changes that were not authorised by the account holder.
Identity theft used to fund fraudulent bank accounts is a growing global problem, and financial institutions in several countries have begun using biometric verification, such as facial recognition during account opening, specifically to make this kind of fraud harder to pull off.

How Taxpayers Can Protect Themselves
To stay a step ahead of scammers, taxpayers have been strongly encouraged to follow a number of precautionary measures.
| Precaution | Why It Matters |
|---|---|
| Never share eFiling usernames or passwords | Prevents direct unauthorised access to your account |
| Avoid disclosing banking information, PINs or card details via email, SMS or phone | Legitimate institutions will not request this information this way |
| Use strong passwords and multi-factor authentication, and avoid public Wi-Fi for sensitive transactions | Reduces the risk of payments being intercepted or redirected |
| Avoid clicking on links received via email, SMS or WhatsApp | Access SARS services directly through the official website instead |
| Use strong passwords and multi factor authentication, and avoid public Wi-Fi for sensitive transactions | Adds extra layers of protection against interception and unauthorised access |
| Be cautious of messages that create urgency or attempt to intimidate | Scammers rely on panic to bypass careful thinking |
Multi-factor authentication is particularly effective because even if a scammer manages to obtain a password through a phishing email, they would still need access to a secondary device or code to actually break into the account, which stops the vast majority of automated attacks in their tracks.
Echoing the concerns raised by SARS, SAFPS reiterated that whenever taxpayers feel uncertain about the authenticity of a message, they should contact SARS directly using officially verified contact details rather than any details supplied within the suspicious communication itself.
A Quick Recap of Warning Signs
- Unexpected messages promising a large refund, particularly amounts close to R50,000
- Sender addresses that differ even slightly from the official @sars.gov.za domain
- Requests to click a link and immediately confirm banking or personal details
- A tone of urgency, pressure or intimidation designed to prompt quick action
- Emails that look unusually polished or professional compared to previous SARS correspondence
South Africa’s tax season traditionally sees a seasonal spike in phishing activity every year, since scammers know that large numbers of taxpayers are actively expecting communication from SARS during this period, making people more likely to lower their guard.

Conclusion
The rise of AI-generated phishing correspondence has made it significantly harder for South African taxpayers to distinguish genuine SARS communication from fraudulent attempts, particularly during the busy 2026 tax filing season when scammers are actively targeting those awaiting refunds. Taxpayers are urged to remain cautious of unsolicited messages, verify any correspondence through official SARS channels rather than embedded links, and regularly monitor their eFiling profiles for unauthorised changes, since early vigilance remains the most effective defence against both phishing scams and the more serious threat of profile hijacking that can follow.
Fast, uncomplicated, and trustworthy loan comparisons
At Arcadia Finance, you can compare loan offers from multiple lenders with no obligation and free of charge. Get a clear overview of your options and choose the best deal for you.
Fill out our form today to easily compare interest rates from 19 banks and find the right loan for you.