site stats WHAT to do if your SARS e-filing profile has been hacked – Posopolis

WHAT to do if your SARS e-filing profile has been hacked

Here’s how to protect your SARS e-filing profile from ambitious cybercriminals. According to the Office of the Tax Ombud (OTO) in South Africa, more than 16 000 profiles were compromised in the last tax season. Millions of Rands in tax returns were compromised as a result.

The release of the OTO’s damning report was delayed for several months (initially scheduled for release back in July). As such, a marked increase in SARS e-filing profile hijackings over the tax season has been revealed. So, what can you do to beef-up security on the SARS portal?

SARS E-FILING PROFILE HACKS

SARS e-filing profile
The days of paper-based tax returns are a thing of the past in this digital age. But cybercriminals are only getting bolder … Image: File

Reportedly, cybercriminals target SARS e-filing profiles due for healthy tax returns. As such, they impersonate the specific taxpayer and take control of their online account. This is possible after stealing login credentials for the South African Revenue Service portal – through phishing and/or SIM swaps.

Then the criminal adds beneficiaries and files returns unbeknownst to the real taxpayer to pocket the refund. SARS e-filing profile hacks are most common with personal income tax accounts, followed by corporate VAT accounts, says the OTO.

R20-MILLION GONE IN ONE INSTANT

According to TimesLive, a prominent Sandton-based IT firm lost R20 million after its e-filing profile was reportedly hijacked. Plus, the OTO revealed that some individual taxpayers lost as much as R100 000 through this type of fraud in 2024. In the interim, SARS has denied any accusations of negligence in its security protocols, reports TimesLive.

“We have been found of no negligence or liability. Therefore, SARS cannot be held liable for the alleged criminal action reported. In this respect, it works closely with role players in the tax ecosystem, including the OTO. Such cooperation enables the organisation to resolve SARS e-filing profile hacks as soon as possible. This work is ongoing between all parties,” concluded SARS spokesperson Siphithi Sibeko.

SEVEN SAFETY TIPS FOR SARS E-FILING PROFILE

SARS e-filing profile
Sophisticated cybercriminals are gaining access to poorly protected SARS e-filing profiles. But you can improve yours … Image: File

To protect your SARS profile:

  • Choose a strong, unique password that combines uppercase letters, lowercase letters, numbers, and symbols.
  • Never reuse your banking or email passwords for SARS, as this creates a domino effect if one account is compromised, so will the others.
  • Enable two-factor authentication, which acts like having both a key and a security code to enter your vault.
  • Always log into SARS eFiling by typing – www.sarsefiling.co.za – directly into your browser.
  • Never click any links in emails, as fraudsters often create convincing fake websites to your steal credentials.
  • Regularly monitor your account for unauthorised submissions or changes, and immediately report these if suspicious.
  • Never access your SARS e-filing profile from public Wi-Fi networks or shared computers, as this is perfect for cybercriminals.

CLICK HERE TO READ MORE ARTICLES FROM RAY LEATHERN

About admin