Scammers are using AI tools to build fake SARS eFiling pages that look and work like the real thing, according to new research from Kaspersky. The fake page asks for usernames, passwords and phone numbers. A second version spins up an Adobe PDF sign-in screen to harvest email credentials.
The timing is deliberate, with the tax season filing deadline falling on 23 October.
Insights on the SARS eFiling scams
The advantage South Africans used to rely on has gone: Chris Norton, Kaspersky's general manager for Sub-Saharan Africa, says the old visual clues, awkward wording and amateur-looking correspondence no longer carry the same weight, and a message can look completely professional and still be fraudulent.
SARS itself warned in July that scammers were using AI to generate professional-looking email templates that are harder to identify as fraudulent, typically promising a large refund or claiming a court summons for unpaid tax or tax evasion.
The deadline is doing work for the attackers too, because people already expect messages about returns, assessments and refunds at this point in the season, and pressure makes social engineering easier.
Kaspersky adds a second warning that has nothing to do with phishing: do not upload tax records, ID documents or banking details to public AI chatbots.
In 2025, more than 370,000 Grok chat logs were indexed by Google and Bing because of how the platform's share feature generated public URLs, exposing private medical and business information, and most major AI platforms have had comparable leaks.
What others are saying about the SARS eFiling scams
MyBroadband reported the Kaspersky research and Norton's warning about sensitive records in public AI tools. SARS published its own scam alert in July covering the wave of SMS and email scams directing taxpayers to fraudulent sites. The revenue service maintains a scams page listing known fraudulent communications, which is the reference point if you are unsure about a message you have received.
The detection advice no longer works
For years the standard guidance was to look for bad grammar, odd formatting and a dodgy-looking layout. AI has removed all three as signals, which means every piece of advice built on spotting a fake is now unreliable. What still works is refusing to act on the message itself.
Do not click a link in any communication claiming to be from SARS. Open eFiling directly, or use the SARS MobiApp, and check whether the notice exists in your actual account. That is the same instruction that applies to bank calls, where the professional advice is to hang up and dial back on a number you already hold.
For businesses, the exposure is wider than personal tax, because a finance team member clicking a fake SARS notice hands over credentials to whatever else that email account reaches. Tell your people now, while the deadline is still five weeks out and before the volume peaks.
You might also like our piece on why banking scam advice keeps failing, the SA banking trojan reading one-time PINs off Android phones, and the RelyComply breach that exposed identity data held by a compliance provider.
Get more SA tech and business news and subscribe to The Open Letter.


