This article will count 0.25 units (15 minutes) of unverifiable CPD. Remember to log these units under your membership profile.

Your client forwards an email. It carries a SARS official's name and says a tax return of R68 652.86 has been approved. There is a PDF attached. They have already opened it.

What SARS published

On 22 July 2026, SARS issued a scam alert logged as SARS-SCAM-396. The subject line refers to an approved tax return of R68 652.86.

The email is built to look like it comes from a real SARS employee. SARS masked that employee's name in the published example, which tells you the scammers are using genuine staff names to buy credibility.

The payload is the attachment. SARS warns taxpayers not to open the PDF and not to click the link inside it. That link is a phishing link designed to harvest personal details. ‍

Note the timing. This landed one day after SARS-SCAM-395, the refund-themed wave we covered in The New SARS Refund Scam and What You Can Do. Two official alerts in two days, in the busiest fortnight of filing season.

Why this one works

The number is the trick. R68 652.86 is not a round figure. It reads like something a system calculated, not something a scammer typed.‍ ‍

Think about a small construction subcontractor. Retentions held back, VAT input claims sitting in a drawer, cash flow permanently tight. An email saying R68 652.86 has been approved does not feel suspicious to that client. It feels like relief. They click before they think, and by the time they call you, their eFiling credentials are gone.‍ ‍

You then spend unbilled hours on damage control. Profile recovery, banking detail verification, a nervous client phoning daily. That is the real cost of a scam email, and it lands on your desk, not SARS's.‍ ‍

The newsletter says the same thing

SARS published the July 2026 Tax Practitioner Connect on 24 July. It covers Filing Season 2026 developments, Auto Assessment enhancements, provisional taxpayer changes, tax practitioner registration challenges, historical income tax assessment notifications, and new SARS digital services. It also covers the online traveller declaration requirements that took effect on 1 July 2026.

Buried in that list is a reminder to practitioners and taxpayers to stay alert to scams and use only official SARS channels. SARS is telling you twice in one week, through two separate channels. Treat that as a signal, not noise.

Do this today

Send one message to your whole client base. Not a forward of the SARS alert, a short note in your own words. Below is an example that you can use:


“Good Morning [Client name]

SARS issued a scam warning on 22 July 2026 about a fake email doing the rounds. We want you to see it before it lands in your inbox.

The email looks like it comes from a named SARS official. It says a tax return of R68 652.86 has been approved. There is a PDF attached, and the link inside that PDF is designed to steal your login and banking details.

Please do not open the attachment and do not click the link. Scammers change the amount and the subject line, so treat any similar refund email the same way.

Three things worth remembering:

  1. SARS will never send you a link asking for your login details, banking details or an OTP.

  2. Real SARS communication sits inside eFiling or the official SARS app. If you want to check something, type the SARS address into your browser yourself rather than using a link in an email.

  3. Suspicious emails can be forwarded to phishing@sars.gov.za.

If anything looks off, please call me before you act on it. It takes two minutes to check and it is far easier than undoing the damage afterwards.

Kind regards”


Tell them three things. SARS will never send a link asking for login, banking or OTP details. Real SARS communication sits inside the eFiling portal or the official SARS app. Any refund or return email with an attachment gets forwarded to you first, and to phishing@sars.gov.za.

‍Then check your own house. Two-factor authentication on every eFiling profile you administer. If a client has already clicked, the five practical steps in SARS Refutes Breach. Now Calm Your Clients. will get you moving fast.

‍One proactive email costs you twenty minutes. One hijacked profile costs you a client relationship, and possibly your reputation with everyone that client talks to.

‍This is also billable. Client protection is advisory work. Practitioners who name the risk, act early and document it are the ones who charge for judgement instead of data capture.

Previous
Previous

Self-Created Urgency: Why the High Court Ruled in Favour of SARS

Next
Next

New Transfer Pricing Certainty and What You Need to Know.