SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South Africa's major banks: digital banking losses rose from roughly R1.08bn (2023, including R625.7m in banking-app fraud alone) to R1.888bn (2024, +74%), with SABRIC explicitly attributing the rise to social engineering rather than technical hacks, while a widely circulated "R3.9bn in 2025" figure and claim of a single four-bank joint alert could not be verified against any primary SABRIC or bank source.
Reviewed by the Social Engineering Examples team.
Between 2023 and 2025, South Africa's banking industry, through its shared fraud-intelligence body SABRIC (South African Banking Risk Information Centre), documented a sustained and accelerating wave of digital banking fraud driven overwhelmingly by vishing (voice phishing) combined with SIM-swap-enabled OTP interception, rather than by technical breaches of banking systems. SABRIC's Annual Crime Statistics report for 2023 (published Oct 2024) recorded 52,584 digital banking fraud incidents (+45% year-on-year) with gross losses of R1,082,393,109 (+47%); within that total, banking-app fraud alone, the single biggest driver, accounted for 31,612 incidents (60% of digital banking crime) and R625,712,552 in losses (+74%). SABRIC's Annual Crime Statistics report for 2024 (published 28 Aug 2025) showed the trend intensifying sharply: 97,975 digital banking fraud incidents (+86%) and R1.888 billion in gross losses (+74%), with banking apps making up 65.3% of incidents. SABRIC explicitly attributed the surge to social engineering: phishing, vishing, and SIM-swap abuse exploiting human trust and error, rather than to any compromise of the banks' own platforms, and separately warned that criminals were increasingly using generative AI (AI-written phishing emails, AI-generated WhatsApp lures, and early voice-cloned/deepfake calls) to make the scams more convincing. Absa, FNB, Nedbank, and Standard Bank each issued numerous individual customer warnings across this period (Standard Bank launched an in-app "vishing alert" feature in Aug 2024; Nedbank and Standard Bank issued repeated fraud alerts through 2025) describing the same core vishing/SIM-swap playbook. A claim circulating in the case brief and in some 2026 secondary reporting that 2025 banking-fraud losses reached "R3.9 billion" and that the four major banks issued one unified, rare joint public alert could not be corroborated: SABRIC's own published report archive runs only through the 2024 report (Aug 2025), a 2025 annual report was not yet published in the sources checked, and the R3.9bn/joint-alert claims traced only to a low-reliability outlet and a LinkedIn post rather than to any SABRIC or bank primary source; this specific figure and event should be treated as unverified.
SABRIC's 2024 report describes the dominant attack chain in detail: criminals first send a phishing email or SMS that resembles legitimate bank communication, directing the victim to a spoofed look-alike banking website where the victim unknowingly enters their username and password. Immediately afterward, a vishing call follows from a fraudster posing as a bank "fraud department" employee (using caller-ID spoofing so the call appears to come from the bank's real number), who creates urgency by claiming the account has been compromised and needs an OTP to "secure" it. The victim, primed by the earlier phishing step and believing the call is legitimate, reads out the OTP, which the fraudster uses in real time to complete login or authorize a transaction on the legitimate banking site/app. In the SIM-swap variant, instead of intercepting the OTP live over the phone, criminals use stolen personal/ID information (harvested from social media, data breaches, or the phishing step) to convince a mobile network operator's customer-service agent to port the victim's number to a SIM card the criminals control, silently redirecting all future OTP/SMS codes so 2FA no longer protects the account. Standard Bank and Nedbank also documented variants where vishing callers, without a prior phishing step, simply persuade the victim over the phone to transfer funds directly into a fraudster-controlled "safe/secure account," or to authorize an Instant Money/EFT payment, exploiting fear that the account is already under attack. SABRIC states these losses are overwhelmingly the product of social engineering exploiting human error/trust, not technical breaches of bank systems.
The lure had two connected stages. Stage one (phishing lead-in): an email or SMS made to look like it came from the customer's own bank, urging a login via a link that led to a convincing spoofed banking site, harvesting username/password. Stage two (the vishing call): a follow-up phone call, often with a spoofed caller ID matching the bank's real fraud-department number, from someone who already had some of the victim's real personal/account details (from the phishing step, a prior data breach, or public/social-media information), creating urgency ("your account has been compromised," "we've detected fraud," "we need to move your money to a secure account") to extract the OTP or push the victim into authorizing a transfer themselves. Standard Bank's Dr Belinda Rathogwa noted scammers specifically targeted older clients nearing or in retirement with fake high-return investment pitches layered onto the same vishing/urgency playbook. The "tell" that distinguished it from a real bank contact, per every bank's own guidance: a legitimate bank will never ask a customer to read out a PIN, password, OTP, or CVV over the phone, and will never instruct a customer to move money into a new "safe" account; any call doing either is fraudulent regardless of how convincing the caller ID or the caller's script sounds.
SABRIC's data shows the trend accelerating rather than resolving during the documented period: digital banking fraud incidents rose 45% in 2023 and a further 86% in 2024, with losses up 47% and 74% respectively, even as banks rolled out new countermeasures (Standard Bank's in-app vishing-alert feature, biometric/MFA pushes, AI-driven "intent" detection). Individually, Absa, FNB, Nedbank, and Standard Bank each issued repeated, separate customer warnings throughout 2024-2025 (Standard Bank Aug 2024 and Aug 2025; Nedbank Feb, March, and Aug 2025) about vishing and SIM-swap/impersonation fraud, and SABRIC itself, together with the Southern African Fraud Prevention Service, ran public-awareness campaigns (e.g., SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025). SABRIC's total financial-crime figure across all categories (including non-digital crime such as robbery, which fell sharply due to bank/SAPS collaboration) actually declined 18% overall between 2023 and 2024 (R3.3bn to R2.7bn), even though digital/vishing-driven fraud specifically kept rising, illustrating that the vishing/SIM-swap problem grew even as the banking sector made real gains elsewhere. Individual victims largely bore uncompensated losses: Standard Bank's Rathogwa noted that this social-engineering tactic "leaves little recourse for consumers," most of whom recover none of their lost funds even with bank assistance, because victims authorized the transactions themselves under deception (distinct from an unauthorized system breach the bank might be liable for). No specific arrests, prosecutions, or named perpetrator group tied to the overall statistical surge were identified in the sources reviewed; SABRIC/banks describe the perpetrators generically as fraud syndicates/criminal networks.
This case is a rare instance of an entire national banking sector publishing multi-year, quantified, first-party loss data that isolates vishing and SIM-swap social engineering (as opposed to malware or system breaches) as the dominant driver of fraud growth: R625.7m in 2023 banking-app fraud alone, rising to a total digital banking fraud bill of R1.888bn by 2024, an 86% jump in incident volume in a single year. It demonstrates that strong technical authentication (MFA/OTP) can be systematically defeated at scale not by breaking the cryptography but by manipulating the two weakest links around it: the human on the phone, and the mobile network's own SIM-provisioning process. It also shows how a preceding phishing step (credential theft) chained directly into a vishing call (OTP extraction) turns two individually survivable failures into a complete account takeover, and it illustrates the emerging role of generative AI in lowering the production cost/quality bar for convincing phishing lures and voice impersonation. Finally, the case is a useful caution about source hygiene in fast-moving fraud reporting: a specific, precise-sounding figure (R3.9bn, 2025) and dramatic claim (a rare joint four-bank alert) spread through secondary and social coverage without ever tracing back to the issuing body's own report, a reminder to verify statistics against the primary regulator/industry-body publication before treating them as fact.
SABRIC's core, repeated advice: banks will never ask for a PIN, password, OTP, or CVV by phone, SMS, or email, and never ask a customer to move money into a "safe"/"secure" account. Customers are told to hang up on any caller claiming to be from a bank's fraud department and call back only via the number on the bank's app or official website (not a callback number the caller supplies, since fraudsters spoof caller ID and can intercept "verification" callbacks). Absa specifically warns that a sudden loss of cellphone signal, missed calls, or a missing expected OTP can indicate a SIM swap, and to contact the network operator and bank immediately. Standard Bank built a dedicated in-app "vishing alert" feature (launched Aug 2024) that flags suspicious calls to customers. SABRIC recommends multi-factor authentication, biometric verification, avoiding links in unsolicited SMS/WhatsApp/email, downloading apps only from official app stores, and treating any urgent, fear-based call about "compromised" funds as a red flag. Banks and SABRIC also collaborate with SAPS and the Southern African Fraud Prevention Service (SAFPS/Yima) on suspect identification and public awareness campaigns (e.g. SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025). SABRIC has also flagged that by 2024-2025, AI-driven "intent" analysis and biometric verification were being adopted industry-wide specifically to counter AI-enhanced/deepfake-assisted vishing.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into…
A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…