Insights

The Mechanics of SARS Return Fraud in South Africa

efficiency and trust. Not all of it reaches the rightful taxpayer. SARS return fraud is not loud or theatrical — it is engineered inside legitimate digital infrastructure, calibrated to sit below risk thresholds, and scaled through stolen identity data and compromised eFiling profiles. This article goes beyond surface-level scams to examine the legal exposure, systemic vulnerabilities, and governance failures that allow income tax refund fraud to persist — and what individuals, employers, and policymakers must confront in a digital tax economy.

MK Fraud Insights3 March 20266 min read
SARS return fraudincome tax refund fraud South AfricaeFiling fraudTax Administration Act 28 of 2011Cybercrimes Act 19 of 2020POCA South Africatax evasion South Africapayroll data riskSIM swap fraudidentity theft South Africafinancial crime South Africafraud risk managementPOPIA complianceorganised tax crimedigital fraud South Africa

Every year, millions of South Africans log into SARS eFiling expecting administrative closure. For some, filing season is a compliance obligation. For others, it represents financial relief. A refund may fund school fees, reduce debt, or stabilise a tight household budget. Tax season feels procedural and predictable. It is precisely this sense of routine that makes it attractive to organised fraud networks.

SARS return fraud, more accurately income tax refund fraud, is the deliberate manipulation of tax submissions to generate refunds that are not legally due or to divert legitimate refunds into criminal control. Unlike retail scams that rely on urgency and impersonation, this form of fraud operates within official systems. It uses real tax numbers, real forms, and legitimate digital infrastructure. The deception lies in misrepresentation.

The Legal Framework: Why This Is Criminal, Not Administrative

South Africa’s legal position on this is clear.

Under the Tax Administration Act 28 of 2011, particularly sections dealing with false statements and tax evasion (including section 234), it is a criminal offence to knowingly submit false information to SARS. Conviction may result in fines or imprisonment of up to two years per offence, with more serious matters prosecuted under broader fraud statutes.

The common law crime of fraud, as articulated in cases such as S v Heyne 1956 (3) SA 604 (A), defines fraud as the unlawful and intentional making of a misrepresentation which causes actual or potential prejudice. In the context of SARS return fraud, the misrepresentation lies in falsified deductions, manipulated income figures, or altered banking details. The prejudice lies in the payment of a refund not lawfully due, or in the risk of such payment.

Where digital intrusion occurs, such as unlawful access to eFiling accounts through SIM swaps or credential harvesting, exposure may arise under the Cybercrimes Act 19 of 2020, which criminalises unlawful access to data and computer systems. In organised schemes involving coordinated identity theft and refund extraction across multiple returns, charges under the Prevention of Organised Crime Act 121 of 1998 (POCA) may apply, particularly where racketeering or money laundering is present.

The legal architecture treats this as layered criminality. It is not a mere compliance failure. It is intentional financial deception against the fiscus.

How the Fraud Is Engineered

Income tax refund fraud rarely begins inside SARS. It begins with data.

Identity numbers, IRP5 certificates, and payroll information are harvested from compromised HR systems, phishing campaigns impersonating SARS, or broader data breaches. In many cases, SIM swap fraud plays a central role. Once criminals intercept one-time passwords, they reset eFiling credentials and assume control of the taxpayer’s profile.

Once access is obtained, the manipulation is calibrated rather than dramatic. Travel deductions are inflated within plausible ranges. Medical expenses are adjusted carefully. Retirement contributions are exaggerated just enough to create a refund position. Fraudsters understand that aggressive claims trigger automated verification. Sustainable fraud operates below thresholds.

If a syndicate processes 600 manipulated returns during filing season with an average illicit refund of R9,000, the result is R5.4 million extracted. Even at R7,000 per return, the yield exceeds R4 million. The power lies not in one exaggerated claim but in volume. Detection lag allows repetition before enforcement action begins.

A quieter variant involves refund diversion. In these cases, the return itself may be accurate. The fraud lies in altering the banking details associated with the eFiling profile. The refund is processed legitimately but paid into a mule account. By the time the taxpayer queries the missing funds, they have been layered and withdrawn. The delay between processing and complaint becomes the criminal advantage.

Practitioner Exposure and Liability

An uncomfortable dimension arises when practitioners inflate deductions under the guise of “optimisation.” Even where a client believes the practitioner is acting lawfully, the submission of false information constitutes misrepresentation. The Tax Administration Act does not shield professionals who knowingly assist in false filings.

South African courts have consistently affirmed that professionals who facilitate fraudulent misrepresentation are criminally liable. The doctrine of intention extends to those who knowingly participate in the deception, even if they do not directly receive the refund.

Taxpayers should understand that signing off on a return carries personal exposure. Reliance on a practitioner does not automatically remove criminal liability where misrepresentation is deliberate.

The Systemic Risk to the Fiscus

Income tax refund fraud may appear smaller in scale compared to VAT fraud, but the structural risk is significant. SARS processes millions of returns annually. Even if a small fraction is manipulated successfully, the aggregate fiscal impact runs into millions of rands.

Prejudice in fraud law includes potential prejudice. The mere risk of unlawful refund payment satisfies part of the legal test. Where refunds are paid, the prejudice becomes actual and measurable. Those funds would otherwise contribute to public services, including infrastructure, healthcare, education, and social support.

Fraud against the state is not abstract. It reduces collective fiscal capacity.

The Governance Lens: Employers and Data Custodians

Employers often underestimate their indirect exposure to SARS return fraud. Payroll systems contain high-value identity and income data. Weak access controls, excessive system permissions, and insufficient monitoring increase the probability of data leakage.

The Protection of Personal Information Act 4 of 2013 (POPIA) imposes obligations on responsible parties to secure personal information against loss, damage, or unauthorised access. Where payroll data is compromised and subsequently used for tax fraud, questions of governance and compliance arise.

Fraud prevention in the tax ecosystem is therefore inseparable from data governance.

The Educational Lens: Practical Protection

The response to SARS return fraud is not alarmism but layered vigilance.

Individual taxpayers should enable multi-factor authentication on eFiling, review submission confirmations carefully, and verify that banking details have not been altered without consent. Unexpected SIM signal loss should be treated as urgent due to the prevalence of SIM swap fraud in financial crime.

Taxpayers using practitioners should review returns personally before submission and ensure that all deductions reflect actual economic activity. Refunds that appear unusually large should be reconciled rather than celebrated.

For organisations, payroll data access should be restricted, logged, and audited periodically. Employee identity information must be treated as strategically sensitive financial data rather than routine administrative information.

For policymakers and regulators, the equilibrium challenge remains balancing digital efficiency with digital resilience. SARS has strengthened data-matching capabilities, integrating employer submissions, financial institutions, and retirement funds into its verification processes. However, fraud networks adapt by studying thresholds and exploiting timing gaps.

A Broader Reflection

SARS return fraud survives because it hides within compliance architecture. It does not look like crime in the conventional sense. It resembles process. It resembles paperwork. It resembles digital administration.

But when misrepresentation is engineered at scale, it becomes organised extraction of public funds.

Understanding the legal framework clarifies the stakes. Understanding the mechanics clarifies the vulnerabilities. Strengthening governance and digital identity protection clarifies the path forward.

Tax compliance is not merely a regulatory obligation. In a digital economy, it is a fraud risk domain. Recognising that shift may be one of the most important defensive moves South Africa can make.

References

Tax Administration Act 28 of 2011

Value-Added Tax Act 89 of 1991

Cybercrimes Act 19 of 2020

Prevention of Organised Crime Act 121 of 1998

Protection of Personal Information Act 4 of 2013

S v Heyne 1956 (3) SA 604 (A)