{"id":8175,"date":"2015-07-24T12:00:16","date_gmt":"2015-07-24T10:00:16","guid":{"rendered":"http:\/\/blogs.sun.ac.za\/it\/?p=8175"},"modified":"2016-01-18T14:44:53","modified_gmt":"2016-01-18T12:44:53","slug":"tax-season-cyber-scams","status":"publish","type":"post","link":"https:\/\/blogs.sun.ac.za\/it\/2015\/07\/tax-season-cyber-scams\/","title":{"rendered":"<!--:en-->Tax season = cyber scams<!--:--><!--:af-->Belastingseisoen = kubermisdaad<!--:-->"},"content":{"rendered":"<p><!--:en--><\/p>\n<p>Only people with an unusual desire for pain and discomfort look forward to a trip to the dentist. The same goes for tax.<\/p>\n<p>Criminals know this and prey on our vulnerability. Every year at this time, e-mails like the one below end up in SU staff inboxes. It informs you that the taxman owes you money and all you have to do to receive it, is to click on a link.<\/p>\n<p>This is a scam, and you should never respond or go to the site or open up the attached file, as this could compromise your banking security.<\/p>\n<ol>\n<li>SARS has your banking details on record and keeps it in secure and encrypted form. They do not need you to confirm or enter your\u00a0banking details.<\/li>\n<li>SARS will always either SMS or send you a registered letter in the post to inform you of tax returns. They will never contact you by unsecured e-mail.<\/li>\n<li>They also have enough data to address the mail to you PERSONALLY and not via some vague \u201cDear Taxpayer\u201d or &#8220;Good\u00a0Day&#8221; salutation.<\/li>\n<li>There is no <a href=\"mailto:EFiling@sars.gov.za\">EFiling@sars.gov.za<\/a> address.<\/li>\n<li>The attached file is usually a html (webpage) file and will connect you to a server controlled by the criminals. This server downloads a Trojan virus to your computer that will install\u00a0software, malware and do all sorts of nasty things to your computer and data. Another tactic is to present you with a \u201clogin page\u201d where you enter your banking account details, your PIN code etc.<\/li>\n<li>Unless you have added your university e-mail address as the primary contact address on the SARS system, you should never receive mail on your\u00a0university account.<\/li>\n<\/ol>\n<p>This phishing scam will allow the criminals to log into and take control of your bank account via the internet.<\/p>\n<p>They can create themselves as beneficiaries, transfer your money to their account, and then delete the evidence pointing to their account.<\/p>\n<p>These scam e-mails will never stop. It is always difficult to block them too because scammers change their addresses, details and methods on a daily\u00a0basis. So it is always best to dump these mails in the junk mail folder, blacklist the sending domain and delete the mail immediately.<\/p>\n<p>Why do these criminals continue to send their mail? Because they catch people regularly. In 2012 R14+ million was stolen from South Africans alone using\u00a0phishing tactics such as this one.<\/p>\n<p>Also read more on this on the <a href=\"http:\/\/mybroadband.co.za\/news\/industrynews\/131938-its-tax-season-and-the-cyber-criminals-are-out.html\" target=\"_blank\">mybroadband <\/a>website.<\/p>\n<p>EXAMPLE OF E-MAIL:<\/p>\n<table>\n<tbody>\n<tr>\n<td>\n<table>\n<tbody>\n<tr>\n<td valign=\"top\"><strong>From:<\/strong> SARS eFiling [<a href=\"mailto:eFiling@sars.gov.za\">mailto:eFiling@sars.gov.za<\/a>]<br \/> <strong>Sent:<\/strong> Saturday, 27 June 2015 10:14<br \/> <strong>Subject:<\/strong> Your account has been credited with R3,167.14<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-8176 alignleft\" src=\"http:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling.jpg\" alt=\"efiling\" width=\"746\" height=\"105\" srcset=\"https:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling.jpg 746w, https:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling-300x42.jpg 300w\" sizes=\"auto, (max-width: 746px) 100vw, 746px\" \/><\/td>\n<\/tr>\n<tr>\n<td>\n<table>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p>Your account has been credited with R3,167.14<\/p>\n<p>Please click below to accept and verify payment.<\/p>\n<p><a href=\"http:\/\/blogs.sun.ac.za\/gergablog\/2013\/03\/18\/attack-vectors-getting-in-through-the-back-door\/\">Accept Payment <\/a><\/p>\n<p>During this process, there will be verifications. If you don&#8217;t receive codes on time, come back to finish verification when received<\/p>\n<p>SARS eFiling<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: right;\">[ARTICLE BY DAVID WILES]<\/p>\n<p><!--:--><!--:af--><\/p>\n<p>Net iemand met `n ongewone voorliefde vir pyn en ongemak sien uit na `n uitstappie na die tandarts. Dieselfde geld vir belasting.<\/p>\n<p><span style=\"line-height: 1.5;\">Kuberkriminele buit ons SARS-vrese uit en misbruik\u00a0belastingseisoen om e-posgebruikers uit te vang. \u00a0<\/span><\/p>\n<p><span style=\"line-height: 1.5;\">Elke jaar rondom Julie maak\u00a0e-posse (soos die een heel onder) hul opwagting in US-personeel se posbusse. Op die oog af lyk dit soos `n SARS e-pos wat jou in kennis stel dat Jan Taks geld aan jou wil betaal. Om dit te kry, moet jy net op `n skakel te kliek.<\/span><\/p>\n<p>Natuurlik is dit `n slenter. Moet nooit hierop reageer, op die skakel kliek, na die webwerf gaan, of die aangehegte dokument oopmaak nie. Jy sal bloot jou bankrekening in gevaar stel.\u00a0<\/p>\n<ol>\n<li>SARS het reeds jou bankbesonderhede en dit word veilig gestoor in enkripteerde formaat. Hulle het nie nodig om te vra dat jy dit weer\u00a0bevestig nie.\u00a0<\/li>\n<li>SARS sal jou SMS of `n geregistreerde brief per\u00a0pos stuur om jou in kennis te stel van belastinguitbetalings. Hulle sal jou nie met\u00a0onsekure e-pos kontak nie.<\/li>\n<li>SARS het jou inligting en sal jou persoonlik aanspreek &#8211; \u00a0nie as\u00a0\u201cDear Taxpayer\u201d of met `n vae &#8220;Good\u00a0Day&#8221; nie.<\/li>\n<li>Daar bestaan nie `n <a href=\"mailto:EFiling@sars.gov.za\">EFiling@sars.gov.za<\/a> adres nie.<\/li>\n<li>Die aangehegte le\u00ear is gewoonlik `n html (webblad) le\u00ear en sal jou verbind aan `n bediener wat deur kriminele beheer word. \u00a0Hierdie bediener laai `n Trojan-virus wat sagteware en <em>malware<\/em>\u00a0installeer op jou rekenaar en verskeie onre\u00eblmatighede met jou data wil uitvoer. `n Alternatiewe metode herlei jou na `n aantekenblad waar jy jou bankrekeningdetails, PIN-kode, ens. invul.<\/li>\n<li>Behalwe as jy jou universiteit e-posadres as die hoofkontakadres op die SARS-stelsel ingevul het, sal jy nooit kommunikasie van SARS op jou sun e-pos kry nie.<\/li>\n<\/ol>\n<p>Bogenoemde\u00a0phishing-poging sal kuberkrakers toelaat om aan te teken en beheer te kry \u00a0oor jou bankrekening via die internet.\u00a0Hulle kan hulself as begunstigdes byvoeg, geld oorplaas na hul rekeninge en daarna bewyse van die transaksies\u00a0verwyder.<\/p>\n<p>Dit bly moeilik om hierdie e-posse te blok aangesien adresse, details en metodes op `n daaglikse basis verander word.\u00a0Die enigste oplossing is om dit\u00a0dadelik in die gemorspos <em>(junk mail) <\/em>vouer te gooi, die domein waarvandaan dit gestuur word te swartlys, en die e-pos onmiddellik uit te vee.<\/p>\n<p>Hoekom word hierdie e-posse steeds gestuur? Omdat dit suksesvol is.\u00a0In 2012 is meer as R14 miljoen rand van Suid-Afrikaners gesteel alleenlik met<em> phishing<\/em>\u00a0pogings.<\/p>\n<p>Lees ook meer hieroor op\u00a0<a href=\"http:\/\/mybroadband.co.za\/news\/industrynews\/131938-its-tax-season-and-the-cyber-criminals-are-out.html\" target=\"_blank\">mybroadband<\/a>\u00a0se webwerf.\u00a0<\/p>\n<p>VOORBEELD VAN E-POS:\u00a0<\/p>\n<table>\n<tbody>\n<tr>\n<td>\n<table>\n<tbody>\n<tr>\n<td valign=\"top\"><strong>From:<\/strong> SARS eFiling [<a href=\"mailto:eFiling@sars.gov.za\">mailto:eFiling@sars.gov.za<\/a>]<br \/> <strong>Sent:<\/strong> Saturday, 27 June 2015 10:14<br \/> <strong>Subject:<\/strong> Your account has been credited with R3,167.14<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td><img loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-8176 alignleft\" src=\"http:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling.jpg\" alt=\"efiling\" width=\"746\" height=\"105\" srcset=\"https:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling.jpg 746w, https:\/\/blogs.sun.ac.za\/it\/files\/2015\/07\/efiling-300x42.jpg 300w\" sizes=\"auto, (max-width: 746px) 100vw, 746px\" \/><\/td>\n<\/tr>\n<tr>\n<td>\n<table>\n<tbody>\n<tr>\n<td valign=\"top\">\n<p>Your account has been credited with R3,167.14<\/p>\n<p>Please click below to accept and verify payment.<\/p>\n<p><a href=\"http:\/\/blogs.sun.ac.za\/gergablog\/2013\/03\/18\/attack-vectors-getting-in-through-the-back-door\/\">Accept Payment <\/a><\/p>\n<p>During this process, there will be verifications. If you don&#8217;t receive codes on time, come back to finish verification when received<\/p>\n<p>SARS eFiling<\/p>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: right;\">[ARTIKEL DEUR DAVID WILES]<\/p>\n<\/p>\n<p><!--:--><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Only people with an unusual desire for pain and discomfort look forward to a trip to the dentist. The same goes for tax. Criminals know this and prey on our vulnerability. Every year at this time, e-mails like the one below end up in SU staff inboxes. It informs you that the taxman owes you [&hellip;]<\/p>\n","protected":false},"author":259,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[29187],"tags":[29170,20381,29229,40411],"class_list":["post-8175","post","type-post","status-publish","format-standard","hentry","category-security-2","tag-malware","tag-phishing","tag-sars","tag-sars-e-mail"],"publishpress_future_action":{"enabled":false,"date":"2026-08-02 18:48:09","action":"change-status","newStatus":"draft","terms":[],"taxonomy":"category","extraData":[]},"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/8175","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/users\/259"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/comments?post=8175"}],"version-history":[{"count":22,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/8175\/revisions"}],"predecessor-version":[{"id":8316,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/posts\/8175\/revisions\/8316"}],"wp:attachment":[{"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/media?parent=8175"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/categories?post=8175"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.sun.ac.za\/it\/wp-json\/wp\/v2\/tags?post=8175"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}