SARS Warns Taxpayers of AI-Generated Refund Phishing

The South African Revenue Service warned on July 29 that scammers are using AI-generated emails and SMS messages impersonating SARS to advertise false tax refunds. BusinessTech reports that the messages direct recipients to fraudulent websites and can request personal, banking, or eFiling information. SARS advised recipients to delete and block suspicious notices and report them to its IT security team.
The South African Revenue Service (SARS) has warned taxpayers during the 2026 filing season about phishing messages that use AI-generated templates to impersonate the tax authority and advertise false refunds. According to BusinessTech, the scam campaign circulates by both SMS and email, directing recipients to fraudulent websites after claiming they are owed a refund.
SARS told BusinessTech that scammers are using AI to generate professional-looking email templates that are harder to identify as fraudulent. The South African reports that one example promised a payout of R48 900, while BusinessTech described refund claims reaching as much as R50,000.
The messages imitate SARS branding, formatting, and language, according to The South African. One reported email used the subject line Tax Return Notification - Assessment Complete and instructed the recipient to complete an online form to receive the supposed refund. The linked site was fraudulent, the publication reported.
Refund-themed lures during filing season
BusinessTech reported that the warning arrived while South Africa's 2026 tax season was under way, when taxpayers who have submitted returns may be anticipating SARS correspondence and possible refunds. That timing gives refund-themed phishing messages a credible pretext, even though the underlying technique of directing targets to credential-harvesting sites is well established.
A separate Accounting Weekly report described a SARS alert published on July 22 concerning an email claiming that a R68 652.86 tax return had been approved. According to that report, the message used the name of a real SARS employee and carried a PDF attachment containing a phishing link. SARS warned recipients not to open the attachment or click the embedded link.
The Accounting Weekly report also noted that this alert followed another refund-themed wave, identified as SARS-SCAM-395, by one day. These examples document separate scam variants built around the same operational goal: persuade taxpayers to disclose personal information or account credentials through a convincing SARS impersonation.
AI raises the quality bar for phishing detection
Generative AI can reduce the linguistic and formatting mistakes that historically helped recipients identify phishing attempts. In comparable phishing campaigns, defenders increasingly need to rely on verification of sender domains, URLs, attachment behavior, and independent access to official portals rather than grammar or visual presentation alone.
For tax and finance teams, the reported examples reinforce the importance of treating unsolicited refund notices as untrusted until verified through an independently opened official SARS channel. Automated email controls can help detect known malicious domains and attachments, but targeted messages can still reach users when they rely on legitimate-looking branding and changing infrastructure.
SARS advised taxpayers to delete and block scam messages, and BusinessTech reported that it directed people with doubts to email the SARS IT Security team at [email protected]. The South African also reported that SARS advised people not to disclose banking details, passwords, or one-time PINs in response to unsolicited email or SMS communications. SARS has added examples of the latest correspondence to its Scams & Phishing page, according to BusinessTech.
Key Points
- 1SARS reported AI-generated refund phishing through email and SMS, increasing the realism of tax-season impersonation attempts targeting taxpayer credentials and banking data.
- 2Reported examples use precise refund amounts, official-looking branding, staff names, attachments, and fraudulent links to create plausible credential-harvesting workflows.
- 3Across comparable phishing campaigns, organizations increasingly need URL, sender, attachment, and portal verification because polished language is no longer a reliable warning signal.
Scoring Rationale
The alert documents a practical misuse of generative AI in a high-volume, financially sensitive phishing context during tax filing season. It is regionally focused, but it offers relevant security lessons for teams designing email defenses, identity controls, and user-verification processes.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems

