HOW-TO
How to Spot SARS and Banking Phishing Scams
Stay safe from cyber threats by learning how to recognize and respond to SARS and banking phishing scams.
Quick answer
To spot SARS and banking phishing scams, remember that SARS and your bank will never ask for passwords, PINs, OTPs, or eFiling logins via email, SMS, social media, or phone. If you receive such a request, it is likely a scam. Always verify directly through official channels.
Key points
- SARS and banks never request sensitive information via email, SMS, or phone.
- Phishing messages often create a sense of urgency to prompt immediate action.
- Do not click on links or open attachments from suspicious messages.
- Verify communications by logging into your SARS eFiling or banking app directly.
- Report phishing attempts to the appropriate authorities.
- Change passwords immediately if you suspect you have been compromised.
- Warn others about the scam to prevent further victims.
Step by step
- Pause before you reactPhishing works by triggering panic or excitement, a surprise refund, a 'locked account', a 'final demand'. The moment a message pushes you to act immediately, slow down. That urgency is itself a red flag.
- Check what is really being askedSARS and banks never ask you to confirm a password, PIN, OTP or login through a message or call. If that is the request, it is a scam, no matter how official the logo or sender name looks.
- Do not click links or open attachmentsSARS does not send hyperlinks to other websites, nor .htm or .html attachments. Never click a link in a tax or bank message. Instead, type sars.gov.za or your bank's web address into the browser yourself.
- Verify inside the real accountLog in to SARS eFiling or your banking app directly and look for the notice there. If SARS has genuinely issued something, it appears in your eFiling profile. If the message is not there, it was fake.
- Report the phishingForward suspicious SARS emails and SMS details to [email protected], or call the Fraud and Anti-Corruption Hotline on 0800 00 2870. For a bank scam, report to your bank's official fraud line.
- Delete and warn othersAfter reporting, delete the message. If you clicked or entered anything, change that password from a trusted device and tell your bank at once. A quick warning to family and colleagues can stop the next victim.
How to Spot SARS and Banking Phishing Scams is crucial knowledge in today’s digital age, where cybercriminals constantly devise new ways to trick individuals into revealing sensitive information. These scams often come in the form of fake SARS refund emails or messages claiming your bank account is locked, designed to create panic and prompt immediate action.
Recognizing these phishing attempts is essential to protect your personal and financial information. This guide will help you understand the tactics used by scammers, how to differentiate between legitimate communications and scams, and the steps to take if you encounter a potential phishing attempt.
How Can I Identify a SARS Phishing Scam?
How Can I Identify a SARS Phishing Scam?
Recognizing a SARS phishing scam is crucial for protecting your personal and financial information. These scams often rely on creating a sense of urgency or panic, such as claiming you are owed a refund or that your account has been locked. SARS will never request sensitive information like your password, PIN, One-Time Password (OTP), or eFiling login details via email, SMS, social media, or phone calls. Plus, SARS does not send hyperlinks or attachments like.htm or.html files in their communications. If you receive a message urging you to click a link or share confidential information, it is likely a phishing attempt.
Here are some key indicators to help you identify a SARS phishing scam:
- Urgency and Threats: Messages that push you to act immediately, such as “Final demand” or “Your account will be suspended,” are red flags.
- Requests for Personal Information: SARS will never ask you to confirm your password, PIN, OTP, or login credentials through a message or call.
- Links and Attachments: Avoid clicking on any links or opening attachments in emails or SMS messages claiming to be from SARS. Instead, manually type sars.gov.za into your browser to check for any official notices.
- Unexpected Refunds or Payments: Be wary of messages announcing unexpected refunds or payments. Verify such claims by logging into your SARS eFiling account directly.
To further protect yourself, always verify the authenticity of any SARS-related communication by logging into your SARS eFiling profile or contacting SARS through official channels. If you suspect a phishing attempt, report it immediately by forwarding the suspicious email or SMS to [email protected] or by calling the Fraud and Anti-Corruption Hotline at 0800 00 2870. For bank-related scams, contact your bank’s official fraud line. After reporting, delete the message and, if necessary, change your passwords from a trusted device. Warn your family and colleagues to prevent them from falling victim to similar scams.
What Are the Common Tactics Used in Banking Phishing Scams?
What Are the Common Tactics Used in Banking Phishing Scams?
Banking phishing scams are designed to create a sense of urgency or panic, prompting you to act without thinking. These scams often mimic official bank communications and use various tactics to trick you into revealing sensitive information. One common tactic is sending fake messages claiming that your account has been “locked” or “suspended.” These messages urge you to click on a link or call a number to resolve the issue immediately. The goal is to make you panic and act without verifying the message’s authenticity.
Another prevalent tactic is the use of “refund” or “overpayment” notifications. These scams inform you that you have an unexpected refund or overpayment and instruct you to click a link to process the transaction. The link often leads to a fake website that looks like your bank’s official site, where you are asked to enter your login credentials, passwords, or other personal information. Remember, your bank will never ask for sensitive information through email, SMS, or unsolicited calls.
Scammers also use official-looking logos and email addresses that closely resemble those of legitimate banks to make their messages appear authentic. They may even use your name and other personal details to make the message seem more credible. However, these are red flags that should alert you to a potential scam.
Here are some common tactics used in banking phishing scams:
- Urgent Requests: Messages that demand immediate action, such as “Your account will be closed if you do not respond within 24 hours.”
- Unexpected Refunds or Overpayments: Notifications claiming you have an unexpected refund or overpayment that needs to be processed.
- Fake Websites: Links that lead to websites designed to look like your bank’s official site, where you are prompted to enter personal information.
- Personal Information Requests: Requests for sensitive information such as passwords, PINs, or OTPs.
- Official-Looking Emails: Emails that use official logos and language to appear legitimate.
To protect yourself, always verify the message by logging into your bank’s official website or app directly. Never click on links or open attachments from suspicious emails or messages. If you suspect a phishing attempt, report it to your bank’s official fraud line immediately.
What Should I Do if I Receive a Suspicious SARS or Bank Message?
What Should I Do if I Receive a Suspicious SARS or Bank Message?
If you receive a message claiming to be from SARS or your bank, You should remain calm and vigilant. Phishing scams often try to create a sense of urgency or panic to trick you into acting without thinking. Here are the steps you should take if you receive a suspicious SARS or bank message:
- Pause and Reflect: Resist the urge to click or respond immediately. Phishing attempts often use urgent language like “final demand” or “account locked” to pressure you into acting quickly.
- Check the Request: Remember that SARS and your bank will never ask for sensitive information such as passwords, PINs, OTPs, or eFiling login details via email, SMS, social media, or phone calls. If such a request is made, it is a scam.
- Avoid Clicking Links or Opening Attachments: SARS does not send hyperlinks or.htm/.html attachments. Do not click on any links or open attachments in suspicious messages. Instead, manually type the official web address (e.g., sars.gov.za or your bank’s website) into your browser.
- Verify Through Official Channels: Log in to your SARS eFiling account or banking app directly to check for any genuine notifications. If the message is not reflected in your account, it is likely a scam.
- Report the Scam: Forward any suspicious SARS-related emails or SMS details to [email protected] or call the Fraud and Anti-Corruption Hotline at 0800 00 2870. For bank scams, contact your bank’s official fraud line immediately.
- Delete the Message: After reporting, delete the suspicious message from your device.
- Secure Your Accounts: If you clicked on a link or entered any information, change your passwords from a trusted device and inform your bank right away.
- Warn Others: Inform family and colleagues about the scam to prevent them from falling victim.
To help you quickly identify the legitimacy of a message, refer to the table below for a comparison of genuine SARS and bank communications versus phishing attempts:
| Characteristic | Genuine Communication | Phishing Attempt |
|---|---|---|
| Request for Sensitive Information | Never asks for passwords, PINs, OTPs, or login details | Asks for passwords, PINs, OTPs, or login details | Method of Contact | Primarily through official channels and secure messaging within the app/account | Via email, SMS, social media, or phone calls |
| Urgency | Communicates important information without creating panic | Uses urgent language to pressure you into immediate action |
By following these steps and being aware of the characteristics of phishing scams, you can protect yourself from falling victim to fraudulent activities.
How Do I Report a SARS or Banking Phishing Scam?
How Do I Report a SARS or Banking Phishing Scam?
Recognizing a phishing scam is the first step, but knowing how to report it is equally crucial. If you suspect that a message is a phishing attempt impersonating SARS or your bank, take immediate action. For SARS-related phishing scams, you should forward the suspicious email or SMS to [email protected]. Alternatively, you can report the incident by calling the Fraud and Anti-Corruption Hotline at 0800 00 2870. Providing detailed information about the scam can help SARS investigate and prevent others from falling victim to the same scam.
If the phishing attempt appears to be from your bank, contact your bank’s official fraud line immediately. Most banks have dedicated hotlines for reporting such incidents. Do not use any contact information provided in the suspicious message, as this could be part of the scam. Instead, use the contact details listed on your bank’s official website or on the back of your bank card.
After reporting the scam, take the following steps to protect yourself:
- Delete the Message: Remove the phishing message from your inbox or phone to avoid accidental engagement in the future.
- Change Passwords: If you clicked on any links or entered any personal information, change your passwords immediately from a trusted device.
- Monitor Accounts: Keep a close eye on your bank and SARS eFiling accounts for any unauthorized activity.
- Warn Others: Inform your family, friends, and colleagues about the scam to prevent them from becoming victims.
To help you understand the key differences between legitimate communications and phishing attempts, refer to the table below:
| Legitimate Communication | Phishing Scam |
|---|---|
| SARS and banks never ask for passwords, PINs, OTPs, or eFiling logins via email, SMS, or phone. | Requests for passwords, PINs, OTPs, or logins. |
| SARS does not send hyperlinks or.htm/.html attachments. | Contains links to click or attachments to open. |
| Communication urges you to verify information by logging into your account directly. | Creates a sense of urgency, pushing you to act immediately. |
By being vigilant and knowing how to report phishing scams, you can protect yourself and others from falling prey to these fraudulent activities.
What Information Do Scammers Typically Ask For?
What Information Do Scammers Typically Ask For?
When it comes to How to Spot SARS and Banking Phishing Scams, understanding the kind of information that scammers typically ask for is crucial. Scammers often craft messages that create a sense of urgency or panic, pushing you to act quickly without thinking. They may pretend to be from SARS or your bank and ask for sensitive information that they can then use for fraudulent activities. Here are some common pieces of information that scammers often request:
- Passwords and PINs: Scammers will ask for your account passwords or PINs, claiming that there is a problem with your account that needs immediate attention.
- One-Time Passwords (OTP): They may request the OTP sent to your phone or email, which is often used for verifying transactions or logging into accounts.
- eFiling Login Details: For SARS-related scams, they might ask for your eFiling login information, pretending that you need to confirm details for a refund or to avoid penalties.
- Personal Identification Information: This includes your ID number, address, and other personal details that can be used for identity theft.
- Bank Account Numbers: They may ask for your bank account number, claiming it is needed to process a refund or to verify your account.
Remember, SARS and your bank will never ask for this kind of information via email, SMS, social media, or over the phone. If you receive a message asking for any of the above, it is likely a scam. Always be cautious and take a moment to verify the request through official channels.
To help you quickly identify suspicious requests, here is a table summarizing the information that scammers typically ask for and the official stance of SARS and banks:
| Type of Information | Scammers | SARS/Banks |
|---|---|---|
| Passwords and PINs | Yes | No |
| One-Time Passwords (OTP) | Yes | No |
| eFiling Login Details | Yes | No |
| Personal Identification Information | Yes | No |
| Bank Account Numbers | Yes | No |
By being aware of these tactics and knowing what SARS and your bank will never ask for, you can better protect yourself from falling victim to phishing scams.
Are There Any Fees or Deadlines I Should Be Aware Of?
Are There Any Fees or Deadlines I Should Be Aware Of?
When it comes to spotting SARS and banking phishing scams, understanding the legitimate practices of SARS and your bank is crucial. Notably, there are no fees associated with reporting phishing attempts. SARS and your bank will never charge you for reporting suspicious activity. If you receive a message demanding a fee to unlock your account or process a refund, it is a scam. Always remember that legitimate financial institutions do not solicit fees via email, SMS, or unsolicited calls.
Another critical point is the absence of deadlines in such communications. Phishing scams often create a false sense of urgency, pressuring you to act immediately to avoid consequences like account suspension or loss of a refund. SARS and banks do not impose such urgent deadlines through insecure communication channels. If you feel rushed, take a moment to pause and verify the message through official channels.
To help you identify phishing attempts, here are some key indicators to watch for:
- Unexpected Requests: SARS and banks will never ask for your password, PIN, OTP, or eFiling login through email, SMS, or social media.
- Links and Attachments: Avoid clicking on links or opening attachments in suspicious messages. SARS does not send hyperlinks or.htm/.html attachments.
- Official Communication: Verify any suspicious messages by logging into your SARS eFiling account or banking app directly. Check for any official notices there.
- Reporting: Forward suspicious emails and SMS details to [email protected] or call the Fraud and Anti-Corruption Hotline at 0800 00 2870. For bank scams, contact your bank’s official fraud line.
By being aware of these practices, you can better protect yourself from falling victim to phishing scams. Always remember that legitimate institutions prioritize your security and will never compromise it by requesting sensitive information through insecure methods.
What Documents Are Legitimate SARS Communications Likely to Mention?
What Documents Are Legitimate SARS Communications Likely to Mention?
When dealing with SARS (South African Revenue Service), You should be able to distinguish between legitimate communications and phishing scams. Legitimate SARS communications will typically reference specific documents and information related to your tax affairs. These documents are part of the standard procedures SARS uses to communicate with taxpayers and will never ask for sensitive information like passwords, PINs, or OTPs via email, SMS, or phone.
Here are some of the documents and information you might encounter in genuine SARS communications:
- Notice of Assessment (ITA34): This document outlines the results of your tax return assessment, including any changes made by SARS, and will detail any refunds due or additional tax owed.
- Statement of Account: This document provides a summary of your tax account, including payments made, outstanding amounts, and any interest or penalties applied.
- Confirmation of Registration: This document confirms your registration details with SARS, such as your income tax number and registered particulars.
- Completion Certificate: Issued upon completion of a tax audit or investigation, this document confirms that your tax affairs are in order for a specific period.
- Request for Supporting Documents: SARS may request additional documents to support your tax return, such as IRP5 certificates, medical aid certificates, or proof of expenses.
It is important to note that SARS will never send you hyperlinks or attachments in emails or SMS messages. If you receive a message with a link or attachment claiming to be from SARS, it is likely a phishing scam. Always access your SARS eFiling account directly through the official website, sars.gov.za, to verify any communications.
| Legitimate SARS Communications | Phishing Scams |
|---|---|
| Reference specific documents and tax information | Ask for sensitive information like passwords and OTPs | Do not include hyperlinks or attachments | Include links and attachments to trick you into clicking |
| Provide clear instructions on next steps | Create a sense of urgency to prompt immediate action |
By familiarizing yourself with the types of documents SARS uses and the methods they employ to communicate, you can better protect yourself from falling victim to phishing scams. If in doubt, always verify the communication through official SARS channels.
⚠ Stay safe
Beware of messages claiming your SARS refund is ready or your bank account is locked. These are common phishing tactics designed to trick you into sharing sensitive information.
Frequently asked questions
How do I know if a SARS message is real?
What should I do if I clicked on a phishing link?
Can scammers spoof official logos and names?
Is it safe to click on links in SARS or bank messages?
What is the best way to report a phishing attempt?
How can I protect myself from phishing scams?
What should I do if I accidentally shared information with a scammer?
Are there any specific deadlines or fees associated with SARS communications?
Official sources
CluedUp is an independent guide and is not affiliated with any government agency. Fees, links and steps can change — always confirm on the official portal before you act. This is general information, not legal or financial advice.