The South African Revenue Service has dismissed allegations circulating online that its systems were hacked, saying there is currently no evidence of a cyber breach affecting taxpayer data.
The claims emerged over the weekend after a group identifying itself as “Nullsec Nigeria” alleged that it had infiltrated systems linked to SARS and the South African Information Technology Agency, commonly known as SITA.
According to posts shared on hacker forums, the group claimed to possess sensitive information allegedly extracted from the two institutions. The supposed data reportedly included names, email addresses, passwords, and access credentials connected to official online platforms.
However, both SARS and SITA strongly rejected the allegations.
SARS said its cybersecurity teams immediately launched investigations after the reports surfaced and continue to monitor all digital infrastructure for suspicious activity.
“At this stage, there is no evidence that SARS systems have been compromised,” the tax authority said in an official statement.
The agency also attempted to reassure taxpayers that the integrity of its digital systems remains intact despite the online claims.
Cybersecurity concerns continue to grow in South Africa
South Africa has experienced a sharp rise in cybercrime incidents in recent years, with both government departments and private companies increasingly becoming targets of ransomware attacks, phishing campaigns, and data theft attempts.
Several major institutions have previously faced operational disruptions linked to cybersecurity incidents, raising public concerns about the safety of personal information stored on digital government platforms.
Against this backdrop, allegations involving SARS quickly attracted attention online, particularly because the institution manages highly sensitive taxpayer and financial information.
The hacker group behind the claims, Nullsec Nigeria, was previously associated with online operations conducted under the name “Anonymous Nigeria.” The group allegedly shared download links on underground forums as proof of the supposed breach.
Despite the claims, no independently verified evidence has yet emerged confirming that SARS or SITA databases were successfully infiltrated.
SARS warns public about phishing scams
While denying the breach allegations, SARS used the opportunity to warn South Africans about the growing risk of phishing scams and fraudulent communication pretending to originate from the tax authority.
Cybercriminals often exploit public fear surrounding data breaches by sending fake emails, SMS messages, or website links designed to steal login credentials and banking information.
SARS stressed that protecting taxpayer information remains one of its most important responsibilities and forms part of its broader strategy to build a modern and trustworthy digital tax administration system.
The agency said it would continue monitoring its online environment and provide updates through official communication channels if necessary.
The incident has once again highlighted the increasing pressure on South African institutions to strengthen cybersecurity defenses amid a global rise in digital attacks targeting public-sector systems.
Source: Adapted from official SARS statement and public reports.
