News

Fake SARS refund messages: how to check before you click — 14 August 2026

SARS has warned about convincing fake tax-refund messages during filing season. Here is how to verify a notice safely and what to do if you already clicked.

By ebnewsadmin

South African taxpayers are being warned to slow down before responding to messages that promise a tax refund or demand an urgent payment during the 2026 filing season.

The South African Revenue Service said in a 28 July scam alert that a new wave of fraudulent SMS and email messages was telling recipients they were owed refunds and directing them to fake websites. One example dangled a refund of R48,900. SARS also warned that criminals are using artificial intelligence to create more professional-looking email templates, making poor spelling and crude layouts less reliable warning signs.

The safest check is not whether a message looks polished. It is whether the claim appears inside a channel you reached independently through the official SARS website, eFiling, MobiApp or another verified service.

Why refund messages are persuasive now

Filing season creates a believable context for both genuine tax communication and impersonation attempts. Non-provisional individual taxpayers who were not auto-assessed, or who need to change an assessment, are currently within the 13 July to 23 October 2026 filing window.

Scammers exploit that timing. A large promised refund can create excitement, while a supposed outstanding balance or legal deadline creates fear. Both approaches are designed to make the recipient click before checking.

SARS’s July tax digest advises taxpayers who did not receive an official auto-assessment notice to check their status through SARS digital channels. It also says valid refunds are processed after an assessment and verification where applicable; a surprise link is not a substitute for checking the taxpayer’s own profile.

Five checks before you act

1. Do not use the link in the message

Open a fresh browser window and type the official SARS address yourself, or use the installed SARS MobiApp. A link can display a convincing label while sending the user to a different domain.

2. Check correspondence inside eFiling

Sign in through the official route and look for the notice, assessment or correspondence referenced by the message. A claim that exists only in an SMS, email or attachment should be treated as unverified.

3. Treat requests for secrets as a red flag

SARS says it will never ask for a password, one-time PIN, banking PIN or eFiling login credentials through email, SMS, social media or telephone. Do not type those details into a page opened from an unsolicited message.

4. Inspect the full sender and destination

A display name can say “SARS” even when the underlying address has no connection to the revenue service. On a computer, hovering over a link may reveal its destination, but the safer response is still not to open it. On a phone, avoid pressing and holding an unknown link if that risks opening it accidentally.

5. Verify an unexpected refund or debt independently

Check eFiling or the SARS MobiApp, or contact SARS using details obtained from its official website. Do not call a number included only in the suspicious message.

Attachments can carry the trap

The revenue service’s scams and phishing page lists recent examples including fake tax-return approvals, refund notices and settlement demands. It warns against opening unknown attachments and says SARS does not send `.htm` or `.html` attachments.

A PDF is not automatically safe either. It can contain a button or link that leads to a credential-stealing page. If a message claims an official notice is attached, verify the notice inside eFiling instead of following the document’s link.

What to do if you already clicked

If you opened a suspicious page but did not enter information, close it and avoid downloading anything. Run the security checks recommended for your device, update the browser and operating system, and monitor the accounts connected to the information shown on the page.

If you entered an eFiling password, banking credentials, card information or an OTP, act immediately. Change compromised passwords through official apps or websites, contact the affected bank through its verified fraud channel and notify SARS. Do not wait to see whether money disappears.

Anyone who believes identity theft has occurred should also report the matter to the South African Police Service and follow the affected bank’s account-protection process. SARS lists its Anti-Corruption and Fraud Hotline as 0800 00 2870 and its general Contact Centre as 0800 00 7277; confirm contact details on the official site before calling in case they change.

Suspicious emails can be sent to the SARS IT security address published on its scam-alert pages. Forwarding the original message, rather than copying only its visible text, may preserve technical information useful to investigators.

A polished message is not proof

AI-assisted design means fake notices may use formal language, clean formatting and familiar colours. The practical defence is to separate the alert from the action: receive the message, but verify and act only through a channel you opened independently.

For a broader guide to checking suspicious social-media and messaging claims, read EBNewsDaily’s explainer on how to verify a viral WhatsApp claim before sharing it.

This consumer-safety article is based on current SARS scam and filing-season guidance checked on 14 August 2026. It does not assess an individual message or provide tax advice.

View the standard article