The Office of the Tax Ombud (OTO) has released a draft report on the pervasive and escalating threat of eFiling profile hijacking.
This critical document, now open for public comment until 31 October 2025, provides a sobering analysis of the vulnerabilities within the South African Revenue Service's (SARS) systems and the broader digital ecosystem. While previous reports of widespread eFiling compromises were downplayed, the OTO's findings validate the real and present danger facing taxpayers.
The report, based on an extensive survey, highlights that eFiling profile hijacking is most prevalent among tax practitioners and individual taxpayers. The majority of these fraudulent activities involve Personal Income Tax and Value-Added Tax (VAT), with financial losses typically ranging from under R10,000 to as high as R100,000. These security breaches are attributed to a confluence of factors, including inadequate authentication protocols, delayed fraud detection and response times, insider threats, and a general lack of digital security awareness among the public.
In response to these findings, the OTO has put forth a comprehensive set of recommendations for SARS and other key stakeholders. The proposed interventions for SARS focus on bolstering authentication protocols, improving fraud detection and refund verification systems, and enhancing taxpayer education. The report specifically advocates for measures such as:
- Mandatory notifications for high-risk changes to profiles (e.g., password resets, banking details amendments).
- Alerts for login attempts from unusual devices or locations.
- The introduction of additional security measures like OTP location/device verification and optional authenticator app support.
- Strengthening biometric security and improving end-to-end digital fraud processes.
The OTO's recommendations extend beyond SARS, addressing the role of tax practitioners and individual taxpayers. It is clear that a multi-faceted approach is required to effectively counter these threats. Tax practitioners are advised to implement specific user IDs for each individual in a practice, strengthen two-factor authentication (2FA), and work with SARS to enable real-time notifications for taxpayer profile access requests. For taxpayers themselves, the advice is a stark reminder of fundamental cybersecurity hygiene: use strong, unique passwords, enable 2FA, remain vigilant against phishing scams, and avoid public Wi-Fi for sensitive transactions.
This report underscores a critical truth: cybersecurity is not merely an IT concern; it is a fundamental aspect of financial and personal security. The vulnerabilities identified in the tax system are symptomatic of the broader digital risks that pervade modern life. At StormWarning!, we understand that proactive defense is the only effective strategy. We specialize in providing bespoke cybersecurity consulting services that align with the OTO's recommendations. Our expertise includes conducting comprehensive vulnerability assessments, implementing robust authentication solutions, and delivering targeted cybersecurity awareness training to empower individuals and organizations against evolving threats.
The time for a reactive approach is over. The OTO's report is a clarion call for all South Africans to take digital security seriously. By adopting a proactive cybersecurity posture, in partnership with experts like StormWarning!, you can not only secure your personal and financial data but also contribute to a safer, more resilient digital landscape for all.