It can start with a message asking whether you authorised a transaction.
You didn’t.
The message says there is a problem with your account. It may ask you to call a number, click on a link, or confirm some details. Then someone phones. The person on the other end says they are calling from your bank and that they can help.
This is how a growing number of digital banking fraud begins.
According to the South African Banking Risk Information Centre’s latest Annual Crime Statistics Report, digital banking crime remained one of the most significant reported financial crime risks in 2025. Banking apps accounted for approximately 89% of reported digital banking crime cases and 70.5% of the total client claim amount.
Claims reached R2.41 billion in 2025, up 29.2% from R1.86bn in 2024 and more than double the R1.09bn recorded in 2023. There were 110 074 reported incidents last year, compared with 97 547 in 2024 and 52 588 in 2023. The average loss per incident was R21 865.
Internet banking accounted for fewer than 9% of cases, but 28.6% of the claim amount. Mobile banking made up fewer than 3% of cases and less than 1% of the claim amount but remained relevant because of its association with SIM-swap-related risk.
The figures come from Absa, First National Bank, Nedbank, Standard Bank, Capitec Bank, Bidvest Bank, Discovery Bank, Investec, and GoTyme Bank. SABRIC says they cover client claims and investigations reported by its participating members and are not a complete measure of digital banking crime across every bank and financial institution in South Africa.
It starts with social engineering
Social engineering sounds like something that should involve a computer. It doesn’t.
It is the use of deception to persuade someone to hand over information, provide access, or do something they would not normally do. And often, there is a human voice at the other end of it – someone who sounds friendly, helpful, and as though they know exactly what they are talking about.
SABRIC says digital banking crime in 2025 was driven primarily by social-engineering-led fraud rather than direct attacks on banking systems.
Criminals exploited trust, urgency, and real-time interaction to persuade customers or employees to disclose information, approve access, or authorise transactions.
The fact that a banking app is involved in a transaction does not mean the app or the bank’s systems were hacked. SABRIC says the fraud often starts outside the banking platform. The customer is deceived first, and the banking application is then used to add a beneficiary, approve a payment, or move the money.
“The banking application served as the final transaction channel through which socially engineered or deception-led fraud was executed,” the risk information centre noted.
The first contact
SABRIC says criminals impersonated banks, law-enforcement officials, service providers, and trusted institutions through telephone calls, SMS messages, email, and messaging platforms.
A customer may be told that an account is at risk or that a suspicious transaction has taken place. The supposed bank employee may then stay on the line, giving instructions and creating enough urgency that there is little time to stop and check whether the request is genuine.
The caller may know some basic information about the customer. The message may look like other messages received from the bank. Even the telephone number can appear familiar. SABRIC warns that criminals can manipulate caller ID to make a call appear to come from a legitimate number.
Add familiar wording to the mix, and the call can feel entirely genuine.
SABRIC says criminals are using artificial intelligence to create polished messages, realistic images, and believable voice recordings. It has also received reports of isolated cases involving cloned voices that could be used to impersonate bank officials, company executives, or other trusted people during telephone or video engagements.
AI is not the fraud itself. SABRIC describes it as an enabling tool that can make phishing, impersonation, and social-engineering attacks more convincing. That can be enough to make the person on the other end sound and look exactly like someone the customer expects to trust.
Then comes the payment
Vishing – voice phishing – was a dominant form of authorised payment fraud during 2025, according to SABRIC.
The criminal impersonates a trusted institution or official and coaches the victim through the transaction while they are on the phone. That can mean opening the banking app, adding a beneficiary, or making a payment.
A once-off payment instruction (OPI) may be used to move money to a new beneficiary. The customer may be told that the payment is needed to secure the account, reverse a suspicious transaction, or move money to a supposedly safe account.
The instruction can sound perfectly reasonable in the moment because it forms part of the conversation with the person claiming to be from the bank.
Transactions may be made in quick succession and sometimes involve several newly created beneficiaries. SABRIC identifies false payment instructions and fraudulent beneficiary changes as part of the digital banking crime it recorded.
When the screen is no longer yours
SABRIC says victims were persuaded to install remote-access software or enable screen sharing under the pretence of receiving technical support, fraud prevention assistance, or account verification.
Once access is granted, criminals can view sensitive information, influence the transaction process, capture credentials, or help move money to newly added beneficiaries.
In the cases reported to SABRIC, the money was often transferred through a single decisive transaction shortly after access was obtained. There was little time left to intervene once the criminal had control of the device.
Where the money goes
The money does not necessarily stay in the first account it reaches.
Once the funds have been extracted, they can be moved rapidly through a series of accounts, making them harder to trace and recover. SABRIC says mule accounts play a significant role in this process, receiving and transferring stolen funds, withdrawing cash, and rapidly emptying balances.
Not every mule account holder is necessarily a willing participant. Some people knowingly allow their accounts to be used, while others may have been recruited under false pretences and not fully understand what their accounts are being used for.
The money can then be moved beyond the traditional banking system. SABRIC reports the use of cash withdrawals, gaming platforms, and crypto-asset services during the dissipation of criminal proceeds.
Identity compromise, stolen credentials, synthetic identities, and SIM-swap activity can also be used alongside the fraud to facilitate the movement of money and make it harder to establish where the proceeds have gone.
The faster the money moves through multiple accounts and channels, the smaller the window for intervention.
The Banking Industry Anti-Scam Centre is working on faster information sharing and co-ordinated case handling so that funds can be identified, traced, and preserved before they are dissipated.
The signs are there
There are a few things SABRIC says should make a customer stop:
- An unexpected call or message that creates urgency or fear.
- A request for a PIN, password, card details, or one-time password (OTP).
- Being told to move money to a “safe account”.
- Being asked to approve a transaction that you did not initiate.
- A request to install remote-access or screen-sharing software.
- A beneficiary change or payment instruction received by email, WhatsApp, or telephone that cannot be independently confirmed.
- An unexpected SIM-swap notification, missing verification messages, or a sudden loss of mobile signal.
SABRIC warns that SIM-swap activity can be used alongside other forms of identity and credential compromise. A SIM swap moves the customer’s mobile number to a different SIM card. Cellphone numbers are often linked to banking alerts, authentication, and OTPs.
A sudden loss of mobile signal or an unexpected SIM-swap notification should be reported to both the bank and mobile network immediately.
A bank will not ask a customer to disclose a PIN, password, or OTP to another person.
“When any of these warning signs appear, the safest response is to end the interaction, use an official contact channel to verify the request, and report suspicious activity immediately,” says SABRIC.
Who is left holding the can?
The message has been deleted. The phone call has ended. The money has moved.
And whether it comes back – or even a portion of it – can depend on what happened in those few minutes, what the bank can establish from its records, how quickly the fraud was reported, and what happened to the money afterwards.
The Banking Association of South Africa’s Code of Banking Practice says customers are responsible for taking reasonable steps to prevent fraud and theft and for keeping access credentials and PINs confidential.
It also says a customer may be liable for losses where they acted fraudulently, negligently, or without reasonable care in protecting their credentials or PIN, and a disputed transaction should be reported immediately.
But that does not mean every customer who has been defrauded is automatically responsible for the loss.
The National Financial Ombud Scheme (NFO) considers the circumstances and evidence in each complaint. Its Banking Division says it looks at information including transaction records, authentication records, device information, OTP records, audit trails, and, where available, call recordings, as well as the bank’s fraud controls and what it did after the fraud was reported.
One recent NFO case involved R500 000.
The consumer was contacted by fraudsters pretending to be from her bank. She was persuaded to provide confidential access information for her online banking profile.
Once they had access, the fraudsters created several virtual cards and made online purchases totalling R500 000. The purchases were authenticated through in-app approvals on her banking application.
She reported the fraud to her bank and asked for the money to be refunded.
The bank rejected the claim.
The bank told the NFO that the consumer’s online banking credentials had been compromised and provided evidence of the virtual cards being created and the authentication messages delivered to the banking application. The consumer confirmed that her phone had remained in her possession.
The NFO found that the consumer had compromised her online banking credentials and approved the in-app messages used to authorise the purchases.
It found no evidence of maladministration or a safety or security failure by the bank and therefore found no basis to recommend reimbursement of the R500 000.
So, the next time you receive a message or a call from a professional-sounding voice, urging you to act quickly, take a breath. Stop engaging and contact your bank directly using a number or email address sourced from an official channel. A few unguarded minutes can cost you what took a lifetime to build.



