Monday, December 15, 2025

FIRST WITH SECURITY NEWS

Office of the Tax Ombud invites public comment on eFiling Profile Hijacking

Published on

The Office of the Tax Ombud (OTO) has invited the public to comment on its Draft Report into alleged eFiling Profile Hijacking.

“The OTO hereby invites written comments on the eFiling profile hijacking draft report. By inviting public participation, the OTO aims to develop a robust and effective response to eFiling profile hijacking, thereby ensuring protection of taxpayers’ rights and enhancing trust in South Africa’s tax administration system,” the OTO said in a statement on Wednesday 1 October 2025.

The draft report was drafted by the ombud following its investigation into alleged eFiling profile hijacking.

“Between 3 February and 5 March 2025, the OTO conducted the eFiling Profile Hijacking Survey to capture taxpayers’ experiences and challenges related to eFiling profile hijacking. Preliminary findings from the survey were presented during a public workshop held on 28 May 2025.

“Initially, the OTO planned to publish the draft report for public comment in July 2025. However, SARS formally requested additional time to respond to the draft report and its recommendations. Consequently, on 2 July 2025, the OTO announced that the publication of the draft report would be postponed to 31 August 2025. Due to ongoing and extensive engagements with SARS, the publication was further delayed,” the statement read.

The report’s key findings include:
• eFiling profile hijacking is most prevalent among tax practitioners and individual taxpayers.
• The majority of cases involve Personal Income Tax and Value-Added Tax (VAT).
• Fraudulent transactions typically involve amounts under R10 000 but can reach up to R100 000.
• Vulnerabilities include inadequate authentication processes, challenges in fraud detection, delayed SARS response times, insider threats, and low digital security awareness among taxpayers.

The key recommendations include:
• South African Revenue Service (SARS): Enhance authentication protocols, improve fraud detection and refund verification systems, boost taxpayer education, and strengthen collaboration with banks, the Companies and Intellectual Property Commission (CIPC), and the South African Police Service (SAPS).
• Tax Practitioners: Implement stricter controls on third-party access and uphold high professional conduct standards.
• Taxpayers: Use strong passwords, activate two-factor authentication, and regularly monitor eFiling profile activities.
• National Treasury: Amend certain provisions in the Tax Administration Act and establish an Inspector-General as recommended by the Nugent Commission of inquiry.
• South African Reserve Bank: Investigate banking irregularities linked to eFiling profile hijacking.

The draft report can be accessed at https://www.taxombud.gov.za/oto-draft-report-on-the-investigation-into-alleged-efiling-profile-hijacking/

Written comments can be sent via: communications@taxombud.gov.za and for more information, visit www.taxombud.gov.za before the deadline on 31 October 2025.

MOST READ

SITE SPONSORS

More like this

Phishing evolves with AI and stealth

Currently, phishing is going through a shift driven by sophisticated AI-powered deception techniques and...

SARS, Tax Ombud join forces against cybercrime

The South African Revenue Service (SARS) and the Office of the Tax Ombud (OTO)...

260 suspected scammers arrested in pan-African cybercrime operation

Authorities in 14 African countries have arrested 260 suspects and seized 1 235 electronic...