Three SARS refund scams in eight days: and the one rule that settles all of them
Between 21 and 28 July 2026 the South African Revenue Service published three separate scam alerts, all built on the same promise of a tax refund. One of them arrived as a PDF attachment quoting an oddly precise R68 652.86. Filing season is open until 23 October, which is exactly why the volume is where it is right now.
A SARS email that wants you to click and sign in is fake. Every time.
SARS publishes the test itself: it does not send hyperlinks to other websites, it does not send .htm or .html attachments, and it will never ask for your password, a one-time pin, a banking PIN or your eFiling login credentials by email, SMS, social media or telephone. That turns a fuzzy judgement call into a binary one. You do not have to work out whether the branding looks right, whether the rand figure is plausible, or whether the sender address is spelled correctly. If a message claiming to be from SARS is steering you to a link where you will sign in, it is a phishing attempt, and the well-written ones are now generated with AI, which SARS has said directly. Open sarsefiling.co.za yourself and check your assessment there.
Three alerts, eight days, one script
SARS keeps a numbered public register of scams it has confirmed, which is unusually useful because it lets you see the tempo rather than a single incident. Three consecutive entries landed inside eight days:
- SARS-SCAM-395, 21 July 2026 - "Get Your Tax Return".
- SARS-SCAM-396, 22 July 2026 - "Sars Tax Return Approve R68 652.86", the PDF one.
- SARS-SCAM-397, 28 July 2026 - "Tax Return Notification - Action required".
Read those subject lines next to each other and the pattern is obvious. Every one of them is a refund or a return, phrased as something already decided and waiting for you. None of them threatens you. That is a deliberate choice, because the fear-based tax scam, the one about an audit or a summons, makes people call an accountant. A refund makes people click quietly and tell nobody.
The timing is not accidental either. Filing season opened on 1 July 2026, with auto-assessments running from 1 to 12 July and the general filing window from 13 July to 23 October for non-provisional taxpayers, and 22 January 2027 for provisional ones. SARS expected to issue around six million auto-assessments. That is six million people who genuinely are waiting on a SARS outcome, and a refund email lands in the middle of a real expectation rather than out of nowhere. This is the same seasonal logic behind the HMRC refund scams in the UK and the CRA refund texts in Canada, and it is why the same campaign shape reappears in a different country every few months.
The R68 652.86 email, and why the PDF is the clever part
The 22 July variant is worth pulling apart because of how it is delivered. The email appears to come from a named SARS employee, complete with a plausible signature block. Attached is a PDF. The phishing link is not in the email body at all. It is inside the PDF.
That placement does real work for the attacker. Plenty of mail filtering inspects and rewrites links in the body of a message, and plenty of people have been trained to hover over a link before clicking it. A link buried in an attachment sidesteps both habits. You open what looks like an official statement, see a figure, and tap through from inside a document viewer where there is no status bar showing you where you are about to go.
SARS is blunt about it: "Please don't open the PDF attached to the email or click on the link in the PDF as it is a fraudulent phishing link designed to extract personal details from you to be used in a scam."
The specificity of the amount is doing work too. R68 652.86 is not a round number, and unrounded figures read as calculated rather than invented. It is the same instinct that makes a fake invoice for R4 317.09 feel more real than one for R5 000.
Why "just check the domain" quietly fails for SARS
The standard advice given to South African taxpayers is to trust only government addresses ending in .gov.za. It is reasonable advice and it is incomplete, in two specific ways that matter here.
First, SARS eFiling does not live on a .gov.za address. The official eFiling platform is sarsefiling.co.za, a commercial .co.za domain that SARS links to from its own site. So the one moment you most need the rule, the moment you are about to type your tax login, is the exact moment the rule stops applying. Anyone who has internalised "only .gov.za is real" has to make an exception, and an exception is precisely the gap a lookalike lives in. Something shaped like sars-efiling-secure[.]co.za is illustrative rather than a domain we have seen reported, but it shows the shape: it is not obviously wrong to someone who already knows the real login is a .co.za.
Second, SARS owns more than one domain. We checked this directly rather than repeat what gets written elsewhere: sars.co.za is registered to SARS and redirects to sars.gov.za. You will find advice online treating any sars.co.za sender as automatic proof of fraud. It is not. And it cuts the other way as well, because the sender line on an email is not authenticated by default and can be forged to show almost anything. A sender that looks right proves nothing, and a sender that looks odd proves nothing. That is why the rule about links is stronger than any rule about domains: it describes what SARS does, not what an attacker can imitate.
Spot the fake SARS page before the login form loads
SafeBrowz is a free browser extension for Chrome, Firefox and Edge, with Safari pending, plus a free Android app on Google Play. In this scam it engages at one specific moment: when the link from inside that PDF actually opens a page in your browser. Layer 1 checks the URL shape locally, Layer 2 cross-references the domain server-side against our 550+ brand database and the Google Safe Browsing, PhishTank and URLhaus feeds, and Layer 3 has the AI read the page itself. The AI deep scan (Premium, $14.99/year) reads pages in over 100 languages, which is what catches a credential form put online this week that no feed has heard of yet.
Got a link from a tax email you were not expecting? Check it free before you open it →
Where a link checker helps here, and where it honestly does not
Worth being straight about the boundary, because this scam arrives by email and we are not an email product.
- Where it does nothing. While the message is sitting in your inbox with a PDF attached, there is no URL in your browser, so there is nothing for our engine to look at. We do not scan your mailbox and we do not open your attachments. At that stage the rule is the defence: SARS does not send links, so the email is already answerable without any tool.
- Where it does help. The attack only pays off if you land on a credential page and type your eFiling details into it. That page is a URL, and it is usually hosted somewhere young and disposable. That is the moment our 3-layer engine is built for, and it happens before you have given anything away.
- What it will not do. It will not flag sars.gov.za or sarsefiling.co.za. South African government addresses on the gov.za suffix are on our whitelist, so the real thing stays green and the warning keeps its meaning. A scanner that cries wolf on the genuine tax site is worse than no scanner.
Detection signatures come from threat-intelligence research and our internal brand database, not from user browsing data. SafeBrowz does not store per-user browsing history.
If you already opened it, or already typed your details
Order matters less than speed. Work down this list rather than agonising over which step is first.
- Change your eFiling password immediately, and do it by going to eFiling directly rather than through anything in the email. If you reused that password anywhere else, change it there too, starting with your email account, because whoever controls your mailbox can reset most other things.
- Call your bank if you entered banking details or a PIN. Ask them to flag the account for attempted fraud. Do not wait to see whether anything happens first.
- Report it to SARS. Forward the email to [email protected], or call the SARS Fraud and Anti-Corruption Hotline on 0800 00 2870. SARS maintains a public scam register, and reports are what keep it current for everyone else.
- Check your eFiling profile for changes. Look at the registered bank account, the security contact number and the email address on file. Altering banking details so a genuine refund is redirected is the whole point of stealing a tax login, and it is a quiet change you will not notice unless you look.
- Keep the evidence before you delete anything. Screenshot the mail, the sender address and the PDF, and note the time. Our walkthrough of what to do in the first 24 hours after a scam covers the wider sequence, including the recovery-fraud follow-up that often arrives a few weeks later.
Got a link from a SARS email you were not expecting?
Paste it here before you open it. Our 3-layer engine (Local + APIs + AI) returns a verdict in about 3 seconds. Free, no signup.
Frequently asked questions
I got an email saying SARS approved a refund of R68 652.86. Is it real?
No. SARS published that exact email as a scam on 22 July 2026 under the reference SARS-SCAM-396. It arrives with a PDF attached, and the phishing link sits inside the PDF rather than in the email body. SARS states plainly that you should not open the attachment or click the link inside it. The amount is part of the lure, so treat any specific rand figure in an unexpected refund email the same way. Check your actual assessment by opening eFiling yourself, not from the email.
How can I tell a real SARS email from a fake one?
Use the rule SARS itself publishes: SARS does not send hyperlinks to other websites, and it does not send .htm or .html attachments. It will never ask for your password, a one-time pin, a banking PIN or your eFiling login credentials by email, SMS, social media or telephone. So an email that wants you to click through and sign in is fake regardless of how well it is written. Open eFiling yourself in a new tab and check there.
The sender address ended in sars.co.za, not sars.gov.za. Does that prove it is a scam?
It does not, and this trips people up. SARS owns sars.co.za as well, and it redirects to the official sars.gov.za site. A sender address is also trivially forged, so a domain that looks correct is not evidence the mail is genuine, and a domain that looks unusual is not proof it is fake. Judge the request, not the sender line. A genuine SARS message never needs your login.
SARS eFiling is on sarsefiling.co.za, which is not a .gov.za address. Is that site safe?
Yes. sarsefiling.co.za is the official eFiling domain and SARS links to it from sars.gov.za. It is worth knowing because the common advice to trust only .gov.za addresses breaks at the exact moment you are typing your tax login. Reach eFiling by typing the address yourself or from a bookmark, never from a link in an email.
Can SafeBrowz stop a SARS phishing email?
It stops the page, not the email. SafeBrowz is a browser extension and Android app that checks links and pages, so it has nothing to inspect while the mail is sitting in your inbox with a PDF attached. The moment that matters is when the link inside the PDF opens a page in your browser, because that is a URL our 3-layer engine can check before you type anything into it. For the email itself, the rule that SARS never sends links is the control that works.
Last updated 2026-08-03