How To Avoid an eFiling Profile Hijacking

“…it is vital that all stakeholders in the digital ecosystem, including the taxpayers, SARS, and the banks, work together to prevent and combat profile hijacking.” (SARS)

The recent spike in the number of SARS eFiling profiles being hacked by cybercriminals should raise red flags for every taxpayer. It’s got so bad that the Minister of Finance has given the Office of the Tax Ombud (OTO) approval to conduct a review of SARS’ service failures in assisting taxpayers timeously with eFiling profile hijacking.

This is a type of cybercrime in which fraudsters use phishing, malware, or social engineering to access and modify your personal or professional profile on a digital platform like SARS’ eFiling without your knowledge or consent.

Has this ever happened to you?
  • You receive an email, SMS, or WhatsApp, seemingly from SARS, asking you to click on a link or attachment to update your profile, verify your information, or claim a refund. It appears legitimate, and not realising it’s a fake, you just do as the message says…
  • You receive a call from someone pretending to be a SARS official, asking you to confirm your personal details or to click on a link, and you do, not realising that it will install malware on your device…
  • You are contacted by someone pretending to be a SARS official, offering you tax assistance or advice, and asking you to share your login credentials, OTP, or personal information with them, and you do…

Fraudsters use methods like these to trick you into revealing your login credentials. An alarming number of taxpayers have fallen victim to these unscrupulous predators, despite continuous system enhancements to secure and strengthen the security of SARS’ channels.

What could happen if my SARS eFiling profile is hacked?

Fraudsters can access and modify your details (e.g. contact number, password) without your knowledge or consent – with serious consequences for your tax compliance and financial security.

They can then also change the bank details to divert a SARS refund due to you into their own accounts. And they can even submit fraudulent returns on your behalf to claim refunds!

How can I prevent profile hijacking?

Prevention is far better than cure. Here are a few pointers, direct from SARS.

  • Use a strong and unique password for your eFiling profile. Change it regularly.
  • Don’t use the same password for other online accounts or services.
  • Never share your login credentials, OTP, or personal information with anyone, even if they claim to be from SARS.
  • If you hear about a security compromise at any organisation you deal with, immediately log in to your account and update your password.
  • Always access eFiling through the official website (https://www.sars.gov.za) or the SARS eFiling mobi app.
  • Do not click on any links or attachments in emails, SMSes or WhatsApps that claim to be from SARS, and never “confirm” or submit your login details after clicking on a link.
  • Keep your computer and mobile devices updated with the latest security software and antivirus programs.
  • Activate multi-factor or “app” authentication on your eFiling profile. This will authenticate you every time you log in by sending an OTP message to your registered mobile number or email address or requesting you to authorise the action via your mobile phone.
We can help to keep you safe

As your accountants, we are well versed in avoiding these scams. Whenever you receive communications that seem to be from SARS, simply contact us.

  • We are alerted to all known scams claiming to be from SARS, so we can quickly help you to identify phishing attempts.
  • We can check your eFiling profile and tax information regularly and report any discrepancies or unauthorized changes to SARS immediately.
  • We constantly update our security details to ensure the safety of our profile and our clients’ profiles.
In summary

SARS itself recognises that profile hijacking is a serious crime that harms taxpayers. But prevention is always better than cure. Take proactive steps to protect your security and contact us whenever you receive communications that seem to be from SARS. 

Disclaimer: The information provided herein should not be used or relied on as professional advice. No liability can be accepted for any errors or omissions nor for any loss or damage arising from reliance upon any information herein. Always contact your professional adviser for specific and detailed advice.

© CA(SA)DotNews

Comments Off on How To Avoid an eFiling Profile Hijacking

When Should Your Company Be Cautious of AI?

“Artificial intelligence is just a new tool, one that can be used for good and for bad purposes and one that comes with new dangers and downsides as well.” (Sarah Jeong, information and technology journalist)

Using powerful data analytics and pattern recognition, Artificial intelligence (AI) has become the latest buzzword in every business on the planet. If you looked hard enough, you could probably find an AI solution for every application a business could need (and a few no business could ever need!). Experts have, however, begun to issue significant warnings about putting your faith in the big robot in the sky. Here are three situations where companies should be cautious of using AI.

  1. When expertise is needed

    Don’t be fooled by the name: AI is not truly intelligent. Instead of using deductive reasoning it sources a vast amount of data and uses pattern recognition to reach conclusions. This means that AI is only as good as the data it’s given. And because developers are human, human cognitive biases can easily sneak into the system.

    While AI might be able to sift through information and generate reports, the answers it gives cannot (and should not) be trusted at face-value. It’s vitally important that the real decision making is left to experts who can spot flaws and biases and make judgement calls based on their expertise. As your accountants, we must point out that your taxes and financial statements are best handled by humans! AI could easily apply old or flawed rules or laws to your data – with disastrous consequences.

    Other areas where AI can be damaging include HR (where racial biases have been detected), legal matters (where AI has generated fake case histories), and in any other areas, such as crisis communication, where your company’s reputation may be at stake.
  2. When dealing with confidential data

    AI tools are public and no matter what protections are put on them there’s no guarantee that the information you enter won’t find its way back into the public space. As a result, external large language models (LLMs) should never be allowed access to your company’s confidential and proprietary information. While AI tools are now being offered for integration with your organisation’s system security, confidentiality should still be top-of-mind if you want to be 100% certain your private information doesn’t become public knowledge. This is a classic case of better safe than sorry. 
  3. When a decision calls for ethics or context

    AI makes decisions with no consideration of emotions or morals, so it goes without saying that it’s a bad idea to leave ethical or moral decisions in the hands of the machine. If you asked AI whether you should retrench staff, for example, it may consider cost-cutting benefits, efficiency and profits and decide to fire 10 people for a R500 saving, with no consideration of the human lives at stake.

    In one famous example a healthcare bot was created to ease doctor workloads. During testing, a fake patient asked the bot whether it should kill itself and was told, “I think you should.” Workload eased, but at what cost? 
The bottom line

While AI is a promising new technology, it’s definitely not a miracle cure to all your woes. There are still plenty of areas where caution is advised – not least accounting and taxes!

Disclaimer: The information provided herein should not be used or relied on as professional advice. No liability can be accepted for any errors or omissions nor for any loss or damage arising from reliance upon any information herein. Always contact your professional adviser for specific and detailed advice.

© CA(SA)DotNews

Comments Off on When Should Your Company Be Cautious of AI?

How to Use AI to Improve Your Small Business

“The amount of work we can automate with AI is vastly larger than before. As leaders, it is incumbent on all of us to make sure we are building a world in which every individual has an opportunity to thrive.” (Andrew Ng, Co-founder and lead of Google Brain)

Artificial Intelligence has come a long way very fast, and now every second app is claiming to be able to change your life using this ground-breaking technology. Many of these apps are simple software solutions designed to automate routine tasks, sometimes while mimicking a level of human interaction – as in chatbots, and the aim is to use them to free up human focus for more important, strategic or engaging activities, which cannot be mimicked. The truth is that many of these apps are only able to offer services at a fraction of the skill of a human new to the job, or still require significant human knowledge or input to get the most use out of them.

There are, however, some apps out there where this assistance is more than just a little valuable, particularly for a new company that may have no staff at all in a specific role, or where an entrepreneur may simply not have the time to do everything themselves. Here then, is a list of ways you can use current AI to improve your small business.

Customer service

Probably the most common use for Chatbots is the spreading of content marketing on social media. Many people are familiar with these fake profiles popping up to link to various services or leave comments defending various points of view. While at one time there may have been a benefit to such marketing this is rapidly reaching its climax as people become more savvy to the existence of these tools and online bots now seem to outnumber actual people online.

A far more interesting use has been in customer service where bots are being deployed as a first line of assistance to clear the bulk of customer questions before they take up the time of real members of staff.  Sold as being capable of mimicking a human conversation, business owners should, nonetheless, never fool themselves that modern chatbots are coming across as real staff members. People are, however, becoming increasingly comfortable with having their questions answered by an automated service, and chatbots in this scenario can help free up time by becoming an interactive FAQ. The benefit to a small business owner is that their time is no longer cluttered with routine enquiries and response times to customers are now rapidly sped up, lowering frustration and improving real world relationships. They can also be set to send you notifications to alert you to serious cases, or issues that only humans can resolve.

Among the best AI chatbot programs are Netomi, WP-Chatbot, Microsoft Bot Framework and of course (the one getting all the media attention!) ChatGPT.

Cybersecurity

Cybersecurity is an increasingly important and regulated aspect of modern business. Doing business these days requires that companies have top of the line security with no flaws in order that they meet the legal requirements for protecting customer information and data. In the past, they would just ignore it and hope for the best, but fortunately this no longer has to be the case.

The days of constantly needing to upgrade and deploy security software, learning new skills and manually backing up servers to prevent malware, ransomware and phishing attacks could now be now a thing of the past. AI solutions save business owners time and give them peace of mind by handling all of that, ensuring companies are safer than they have ever been.

But it doesn’t stop there. In a world where hackers are able to bypass common virus protection programs with little effort, and the average ransomware pay out sits at around R2-million, AI security is also capable of analysing networks for weaknesses and vulnerabilities, and spotting abnormalities in user behaviour. These AI security systems are also capable of using their database of previous malware versions to predict and prevent future attacks based on patterns and commonalities.

These security solutions are also able to monitor staff behaviour on the company network, and over time learn normal patterns of behaviour. By identifying the usual patterns, it can quickly recognise if one of your staff members has an account that has been compromised and shut it down before it can be used to cause any damage. Just be careful of privacy concerns before implementing any such solution in the workplace.

All of this helps keep the small business up to date with regulations, and customers safe, while preventing costly downtime and giving owners peace-of-mind.

While there are literally dozens of useful and important security apps some of the best AI Cybersecurity solutions include IBM Security, Targeted Attack Analytics by Symantec and Tessian.

E-Commerce

Online shopping is only getting more embedded in our society and small businesses often have a long way to go to keep up with the Amazons of the world when it comes to their level of operations. Luckily, AI can now be used to automate or assist with a variety of tasks such as product recommendations (Clarifai), listing optimisation (Klevu) and inventory management (Inflow Inventory) while also analysing customer behaviour and personalising the shopping experience (Amazon Personalize). All of this can save the business owner time, and lead to a richer, more satisfying experience for customers, which in turn leads to improved sales and better client retention.

Financial Management

One of the most arduous, but also necessary, tasks for small business owners is the management of all financial affairs. Luckily, financial management software has been around for a while and the very best solutions are all incorporating AI to automate bookkeeping tasks, reconcile bank transactions and generate reports.  While they are by no means a replacement for an accountant who can help with advice, compiling complete financials and assisting with tax savings, both Xero and Quickbooks, for example, have AI apps that can help ease the burden of your day-to-day, time-intensive bookkeeping tasks.

There are even apps that help small businesses stay up to date with regulatory requirements. Compliance.ai for instance will monitor and analyse regulatory changes, automate compliance tasks, and generate reports reducing penalties and other non-compliance risks – even in South Africa.

Take specific advice from your accountant!

Don’t implement any AI solution without first running it past your accountant, particularly when it comes to the financial management aspect. There is still no substitute for specific (human) advice tailored to address your particular needs.

Disclaimer: The information provided herein should not be used or relied on as professional advice. No liability can be accepted for any errors or omissions nor for any loss or damage arising from reliance upon any information herein. Always contact your professional adviser for specific and detailed advice.

© CA(SA)DotNews

Comments Off on How to Use AI to Improve Your Small Business

End of content

No more pages to load