Xero Accounting Gold Champion Partner

SARS Scams 2026: How to Spot Filing-Season Traps

SARS Scams 2026: How to Spot Filing-Season Traps

Filing season opened on 1 July 2026, and so did open season for fraudsters. Every year, the moment SARS starts issuing auto-assessments and refunds, a wave of fake emails, SMSes and WhatsApp messages floods South African inboxes. The SARS scams 2026 crop is already circulating, with subject lines like “Settlement Notification” and “Final Demand” engineered to make you panic and click. This is the time of year when a single careless tap can hand a criminal your banking login.

The cruel irony is that scams work because filing season is legitimate. You’re expecting communication from SARS, you’re hoping for a refund, and the fraudster knows it. This guide breaks down exactly what the SARS scams 2026 wave looks like, the red flags that give it away, and the simple rules that keep your money, and your business, safe.

Why SARS Scams 2026 Are Surging Right Now

The timing isn’t a coincidence. Between 1 and 12 July 2026, SARS issues roughly six million auto-assessments, and millions of South Africans log into eFiling to check their status. That’s millions of people primed to receive a “SARS” message and act on it fast. Fraudsters simply ride the wave.

The current crop leans heavily on two emotions:

  • Greed, “Your refund of R8,432 is ready. Confirm your banking details to receive payment.”
  • Fear, “Final Demand: you owe SARS R12,600. Pay within 48 hours to avoid legal action.”

Both are designed to bypass your judgement. If you’ve just submitted a return, as many do during the 2026 filing season, a refund or demand message feels entirely plausible.

💡 ThriveCFO Tip: SARS will never ask for your banking details by email or SMS, and will never send you a hyperlink to a bank’s website. Any message that does either is a scam, full stop. Legitimate SARS communication is confirmed only inside eFiling or the official MobiApp.

The Anatomy of a SARS Scam

Most SARS scams 2026 messages share the same DNA. Once you know the pattern, they’re easy to spot.

Red flag What it looks like Why it’s fake
Urgent deadline “Pay within 24/48 hours” Pressure stops you thinking
Request for banking details “Confirm your account to receive your refund” SARS never asks this by email/SMS
Suspicious link sars-refunds.co.za, sars-secure.net SARS only links to sars.gov.za
Unofficial payment channel “Pay to this account” / EFT to a personal account SARS payments go only via eFiling/MobiApp
Spoofed branding Real-looking logo, wrong sender domain Logos are easy to copy; domains aren’t
Generic greeting “Dear Taxpayer” SARS uses your registered details

A worked example: how Naledi nearly lost R40,000

Naledi runs a small design studio. On 8 July she received an email headed “SARS Refund Notification, R6,740 approved”, with a SARS logo and a button reading “Verify banking details to release payment.” She’d just been auto-assessed, so it felt real.

What she nearly missed:

  • The sender was noreply@sars-refunds.co.za, not sars.gov.za.
  • The button led to a near-perfect clone of the eFiling login page.
  • Had she entered her credentials, the fraudsters would have had her eFiling and the banking profile linked to it.

The clone page was harvesting logins to change banking details on real refunds and divert them. One verified domain check saved Naledi roughly R40,000 in pending refunds across her personal and business profiles. The scam wasn’t sophisticated, it just arrived at the perfect moment.

⚠️ Action point: Before you click anything in a “SARS” email, hover over the sender address and every link. If the domain isn’t exactly sars.gov.za, delete it. When in doubt, don’t click the email at all, open eFiling yourself in a fresh browser tab.

The 6 Rules That Keep You Safe This Filing Season

  1. Never click links in SARS-branded emails or SMSes. Navigate to eFiling or the MobiApp yourself, every time.
  2. Verify the domain. Genuine SARS links end in sars.gov.za. Anything else is fraudulent.
  3. Never share banking details, passwords or OTPs in response to a message, SARS doesn’t ask.
  4. Treat urgency as a red flag, not a reason to rush. Real SARS deadlines are published on eFiling, not enforced by panic SMS.
  5. Enable two-factor authentication on your eFiling profile so a stolen password alone isn’t enough.
  6. Report and delete. Forward suspected phishing to phishing@sars.gov.za, then delete it.

💡 ThriveCFO Tip: Brief your team and your family. Business owners are high-value targets because they often control both personal and company eFiling profiles, and because staff handling admin may act on a “SARS” email without checking. One team-wide reminder in July is cheap insurance.

What to Do If You’ve Already Clicked

Mistakes happen, especially under a convincing “Final Demand”. If you’ve entered credentials on a suspicious page:

  • Change your eFiling password immediately, and any banking password you may have reused.
  • Log into eFiling directly and check your registered banking details haven’t been altered.
  • Contact your bank if you shared banking information, and watch for unauthorised changes.
  • Phone the SARS Contact Centre to flag your profile, and report the incident to phishing@sars.gov.za.
  • Tighten up by enabling two-factor authentication if you hadn’t already.

Speed matters. Fraudsters move fast to change banking details before a refund is paid, so the sooner you lock things down, the better your odds of stopping a loss.

Scams Are a Business Risk, Not Just a Personal One

For owner-managed businesses, filing-season fraud is a genuine operational risk. The same fraudsters who phish for personal refunds also target business eFiling profiles, VAT refunds and PAYE accounts. Building a basic “verify before you click” habit across your finance function is part of the same compliance discipline we cover in our guide to SARS compliance for SMEs, and it costs nothing but attention.

Frequently Asked Questions

How do I know if a SARS message is a scam in 2026?

Check the sender domain (must be sars.gov.za), look for requests for banking details or urgent deadlines, and never trust a hyperlink. SARS confirms all legitimate communication only through eFiling or the official MobiApp.

Will SARS ever ask for my banking details by email or SMS?

No. SARS will never request banking details, passwords or OTPs by email or SMS, and never links you to a bank’s website. Any message doing so is a SARS scam.

What are the most common SARS scams in 2026?

Fake “Settlement Notification” and “Final Demand” emails claiming you owe money, and fake “refund notification” messages asking you to confirm banking details. Both spike during the July filing season.

What should I do if I clicked a phishing link?

Change your eFiling and banking passwords immediately, check your registered banking details haven’t changed, contact your bank, enable two-factor authentication, and report it to phishing@sars.gov.za.

Where do I report a SARS scam?

Forward suspicious emails or messages to phishing@sars.gov.za and then delete them. You can also verify any genuine concern by logging into eFiling directly.

Don’t Let a Scam Undo Your Filing Season

The SARS scams 2026 wave succeeds on timing and panic, not technical genius. The defence is equally simple: never click, always verify the domain, and never share banking details. If you protect your eFiling profile the way you protect your bank account, the fraudsters move on to easier targets.

If you’d rather hand filing season, and the security that comes with it, to a team that does this every day, book a free discovery call with ThriveCFO. We’ll manage your SARS interactions through the proper channels, so a fake “Final Demand” never reaches your inbox in the first place.

This article is general information, not tax or security advice. Verify any SARS communication directly through official channels.

Further reading and references

Facebook
Twitter
LinkedIn
WhatsApp
Scroll to Top