Case Library / Vishing (Voice Phishing) / SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)

SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South Africa's major banks: digital banking losses rose from roughly R1.08bn (2023, including R625.7m in banking-app fraud alone) to R1.888bn (2024, +74%), with SABRIC explicitly attributing the rise to social engineering rather than technical hacks, while a widely circulated "R3.9bn in 2025" figure and claim of a single four-bank joint alert could not be verified against any primary SABRIC or bank source.

Share:

Reviewed by the Social Engineering Examples team.

What Happened

Between 2023 and 2025, South Africa's banking industry, through its shared fraud-intelligence body SABRIC (South African Banking Risk Information Centre), documented a sustained and accelerating wave of digital banking fraud driven overwhelmingly by vishing (voice phishing) combined with SIM-swap-enabled OTP interception, rather than by technical breaches of banking systems. SABRIC's Annual Crime Statistics report for 2023 (published Oct 2024) recorded 52,584 digital banking fraud incidents (+45% year-on-year) with gross losses of R1,082,393,109 (+47%); within that total, banking-app fraud alone, the single biggest driver, accounted for 31,612 incidents (60% of digital banking crime) and R625,712,552 in losses (+74%). SABRIC's Annual Crime Statistics report for 2024 (published 28 Aug 2025) showed the trend intensifying sharply: 97,975 digital banking fraud incidents (+86%) and R1.888 billion in gross losses (+74%), with banking apps making up 65.3% of incidents. SABRIC explicitly attributed the surge to social engineering: phishing, vishing, and SIM-swap abuse exploiting human trust and error, rather than to any compromise of the banks' own platforms, and separately warned that criminals were increasingly using generative AI (AI-written phishing emails, AI-generated WhatsApp lures, and early voice-cloned/deepfake calls) to make the scams more convincing. Absa, FNB, Nedbank, and Standard Bank each issued numerous individual customer warnings across this period (Standard Bank launched an in-app "vishing alert" feature in Aug 2024; Nedbank and Standard Bank issued repeated fraud alerts through 2025) describing the same core vishing/SIM-swap playbook. A claim circulating in the case brief and in some 2026 secondary reporting that 2025 banking-fraud losses reached "R3.9 billion" and that the four major banks issued one unified, rare joint public alert could not be corroborated: SABRIC's own published report archive runs only through the 2024 report (Aug 2025), a 2025 annual report was not yet published in the sources checked, and the R3.9bn/joint-alert claims traced only to a low-reliability outlet and a LinkedIn post rather than to any SABRIC or bank primary source; this specific figure and event should be treated as unverified.

How the Attack Worked

SABRIC's 2024 report describes the dominant attack chain in detail: criminals first send a phishing email or SMS that resembles legitimate bank communication, directing the victim to a spoofed look-alike banking website where the victim unknowingly enters their username and password. Immediately afterward, a vishing call follows from a fraudster posing as a bank "fraud department" employee (using caller-ID spoofing so the call appears to come from the bank's real number), who creates urgency by claiming the account has been compromised and needs an OTP to "secure" it. The victim, primed by the earlier phishing step and believing the call is legitimate, reads out the OTP, which the fraudster uses in real time to complete login or authorize a transaction on the legitimate banking site/app. In the SIM-swap variant, instead of intercepting the OTP live over the phone, criminals use stolen personal/ID information (harvested from social media, data breaches, or the phishing step) to convince a mobile network operator's customer-service agent to port the victim's number to a SIM card the criminals control, silently redirecting all future OTP/SMS codes so 2FA no longer protects the account. Standard Bank and Nedbank also documented variants where vishing callers, without a prior phishing step, simply persuade the victim over the phone to transfer funds directly into a fraudster-controlled "safe/secure account," or to authorize an Instant Money/EFT payment, exploiting fear that the account is already under attack. SABRIC states these losses are overwhelmingly the product of social engineering exploiting human error/trust, not technical breaches of bank systems.

The Lure & the Tell

The lure had two connected stages. Stage one (phishing lead-in): an email or SMS made to look like it came from the customer's own bank, urging a login via a link that led to a convincing spoofed banking site, harvesting username/password. Stage two (the vishing call): a follow-up phone call, often with a spoofed caller ID matching the bank's real fraud-department number, from someone who already had some of the victim's real personal/account details (from the phishing step, a prior data breach, or public/social-media information), creating urgency ("your account has been compromised," "we've detected fraud," "we need to move your money to a secure account") to extract the OTP or push the victim into authorizing a transfer themselves. Standard Bank's Dr Belinda Rathogwa noted scammers specifically targeted older clients nearing or in retirement with fake high-return investment pitches layered onto the same vishing/urgency playbook. The "tell" that distinguished it from a real bank contact, per every bank's own guidance: a legitimate bank will never ask a customer to read out a PIN, password, OTP, or CVV over the phone, and will never instruct a customer to move money into a new "safe" account; any call doing either is fraudulent regardless of how convincing the caller ID or the caller's script sounds.

Outcome

SABRIC's data shows the trend accelerating rather than resolving during the documented period: digital banking fraud incidents rose 45% in 2023 and a further 86% in 2024, with losses up 47% and 74% respectively, even as banks rolled out new countermeasures (Standard Bank's in-app vishing-alert feature, biometric/MFA pushes, AI-driven "intent" detection). Individually, Absa, FNB, Nedbank, and Standard Bank each issued repeated, separate customer warnings throughout 2024-2025 (Standard Bank Aug 2024 and Aug 2025; Nedbank Feb, March, and Aug 2025) about vishing and SIM-swap/impersonation fraud, and SABRIC itself, together with the Southern African Fraud Prevention Service, ran public-awareness campaigns (e.g., SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025). SABRIC's total financial-crime figure across all categories (including non-digital crime such as robbery, which fell sharply due to bank/SAPS collaboration) actually declined 18% overall between 2023 and 2024 (R3.3bn to R2.7bn), even though digital/vishing-driven fraud specifically kept rising, illustrating that the vishing/SIM-swap problem grew even as the banking sector made real gains elsewhere. Individual victims largely bore uncompensated losses: Standard Bank's Rathogwa noted that this social-engineering tactic "leaves little recourse for consumers," most of whom recover none of their lost funds even with bank assistance, because victims authorized the transactions themselves under deception (distinct from an unauthorized system breach the bank might be liable for). No specific arrests, prosecutions, or named perpetrator group tied to the overall statistical surge were identified in the sources reviewed; SABRIC/banks describe the perpetrators generically as fraud syndicates/criminal networks.

Why It Matters

This case is a rare instance of an entire national banking sector publishing multi-year, quantified, first-party loss data that isolates vishing and SIM-swap social engineering (as opposed to malware or system breaches) as the dominant driver of fraud growth: R625.7m in 2023 banking-app fraud alone, rising to a total digital banking fraud bill of R1.888bn by 2024, an 86% jump in incident volume in a single year. It demonstrates that strong technical authentication (MFA/OTP) can be systematically defeated at scale not by breaking the cryptography but by manipulating the two weakest links around it: the human on the phone, and the mobile network's own SIM-provisioning process. It also shows how a preceding phishing step (credential theft) chained directly into a vishing call (OTP extraction) turns two individually survivable failures into a complete account takeover, and it illustrates the emerging role of generative AI in lowering the production cost/quality bar for convincing phishing lures and voice impersonation. Finally, the case is a useful caution about source hygiene in fast-moving fraud reporting: a specific, precise-sounding figure (R3.9bn, 2025) and dramatic claim (a rare joint four-bank alert) spread through secondary and social coverage without ever tracing back to the issuing body's own report, a reminder to verify statistics against the primary regulator/industry-body publication before treating them as fact.

Defenses

SABRIC's core, repeated advice: banks will never ask for a PIN, password, OTP, or CVV by phone, SMS, or email, and never ask a customer to move money into a "safe"/"secure" account. Customers are told to hang up on any caller claiming to be from a bank's fraud department and call back only via the number on the bank's app or official website (not a callback number the caller supplies, since fraudsters spoof caller ID and can intercept "verification" callbacks). Absa specifically warns that a sudden loss of cellphone signal, missed calls, or a missing expected OTP can indicate a SIM swap, and to contact the network operator and bank immediately. Standard Bank built a dedicated in-app "vishing alert" feature (launched Aug 2024) that flags suspicious calls to customers. SABRIC recommends multi-factor authentication, biometric verification, avoiding links in unsolicited SMS/WhatsApp/email, downloading apps only from official app stores, and treating any urgent, fear-based call about "compromised" funds as a red flag. Banks and SABRIC also collaborate with SAPS and the Southern African Fraud Prevention Service (SAFPS/Yima) on suspect identification and public awareness campaigns (e.g. SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025). SABRIC has also flagged that by 2024-2025, AI-driven "intent" analysis and biometric verification were being adopted industry-wide specifically to counter AI-enhanced/deepfake-assisted vishing.

Sources
Attack Chain & Defense
The sequence the attacker ran
How it could have been stopped
1
Reconnaissance and data harvesting: SABRIC's reporting is consistent with attackers typically building a partial profile of the intended victim (name, bank, phone number, and some real account or personal details) from prior data breaches, social media, or a preceding phishing response, giving a later phone call enough real detail to sound legitimate.
Countering Stage 1: personal-data exposure from social media and third-party data breaches is very hard for a bank to eliminate at the source; the realistic control assumes attackers already hold some real victim details and instead hardens the verification steps later in the chain that this information gets used against.
2
Infrastructure and tooling setup: before contact, operators typically stand up look-alike phishing domains that closely mimic a bank's real login page and acquire caller-ID spoofing capability so a vishing call appears to originate from the bank's genuine fraud-department number; SABRIC's 2024 and 2025 statements describe criminals increasingly using generative-AI tools to draft error-free phishing emails and AI-generated WhatsApp lures, and early voice-cloning services to make follow-up calls more convincing.
Countering Stage 2: the nearest practical controls sit at the mobile network operator (stronger identity verification, PIN, or biometric confirmation before any SIM port or number transfer is processed) and at brand-protection monitoring for newly registered look-alike banking domains, rather than at the tooling stage itself, which is largely invisible to the victim or bank beforehand.
3
Phishing lead-in: a mass phishing email or SMS made to resemble legitimate bank communication is sent to a large pool of customers, directing anyone who clicks through to the spoofed banking site, where they unknowingly enter their username and password.
Countering Stage 3: customer education to distrust links in unsolicited SMS, WhatsApp, or email and to navigate to banking sites directly or via the official app, combined with bank-side email-authentication standards (SPF/DKIM/DMARC) and a policy of never sending transactional login links, reduces how many recipients reach the spoofed page.
4
Vishing call or SIM-swap execution: in the vishing path, a fraudster calls posing as bank fraud-department staff, using the spoofed caller ID and the details already gathered, and manufactures urgency to get the victim to read out an OTP or approve a transaction prompt; in the parallel SIM-swap path, the same harvested personal/ID information is used to convince a mobile network operator's customer-service agent to port the victim's number to a SIM the criminals control, silently rerouting future OTP/SMS codes.
Countering Stage 4: SABRIC and every major bank's core, repeated advice is that a bank will never ask a customer to read out a PIN, password, OTP, or CVV by phone, and will never ask a customer to move money into a new 'safe' account; customers are told to hang up and call back only on the number from the bank's official app or website, never a number the caller supplies, and Absa specifically flags sudden loss of cellphone signal as a SIM-swap indicator to escalate to the network operator immediately.
5
Account takeover or transaction authorization: the fraudster uses the stolen credentials together with the live-relayed OTP (vishing path) or the intercepted OTP stream (SIM-swap path) to log into the banking app or authorize a funds transfer in real time, completing the technical bypass of MFA.
Countering Stage 5: authentication methods resistant to being relayed over a phone call, such as in-app push approvals that display the actual transaction details for the customer to confirm, biometric verification, and Standard Bank's dedicated in-app vishing-alert feature (launched Aug 2024), are harder for a live vishing caller to talk a victim through than a plain numeric OTP.
6
Funds movement and objective completion: SABRIC describes the proceeds typically being moved quickly into money-mule accounts or via Instant Money/EFT payments to frustrate tracing, which is consistent with why, per Standard Bank's Rathogwa, most victims recover little or none of the money even with bank assistance.
Countering Stage 6: bank and SABRIC-level transaction monitoring, mule-account detection, and cross-bank/SAPS collaboration can sometimes freeze or trace funds quickly, but SABRIC's own outcome data shows this rarely helps individual victims recover money once funds have moved, since the customer authorized the transaction themselves under deception; this stage is where the case's own reporting shows the defense is weakest in practice.
Quick Facts
Victim
Customers of South Africa's major retail banks, collectively Absa, First National Bank (FNB), Nedbank, and Standard Bank, plus other SABRIC member banks, targeted individually at scale rather than the banks' own IT infrastructure being breached.
Location
South Africa (nationwide; SABRIC notes more than half of associated-crime incidents concentrated in Gauteng and KwaZulu-Natal)
Date
2023-01-01 to 2025 (ongoing); SABRIC 2023 Annual Crime Statistics report published Oct 2024; Standard Bank vishing warning/app feature launched 6 Aug 2024; SABRIC 2024 Annual Crime Statistics published 28 Aug 2025; individual bank vishing/SIM-swap alerts continued through Nov 2025 and into 2026
Impact
Per SABRIC's own primary Annual Crime Statistics reports: in 2023, digital banking fraud totalled R1,082,393,109 in gross losses across 52,584 incidents (+45% incidents / +47% losses vs. 2022); within that, banking-app fraud specifically was R625,712,552 across 31,612 incidents (60% of digital banking crime, +74% YoY); this is the "R625m" figure referenced in the case brief. In 2024 (per the SABRIC report published 28 Aug 2025), digital banking fraud rose to R1.888 billion across 97,975 incidents (+86% incidents / +74% losses vs. 2023); banking apps accounted for 65.3% of incidents. Confusingly, SABRIC's headline TOTAL financial-crime figure (which includes non-digital categories like cash-in-transit and branch robbery, where losses fell sharply) actually dropped from R3.3bn (2023) to R2.7bn (2024) even as digital/vishing-driven fraud kept climbing; both figures are real but describe different scopes, and press coverage sometimes conflates them. The R1.9bn figure in the case brief matches the confirmed 2024 digital banking fraud total. The claimed "R3.9 billion banking fraud in 2025" figure in the case brief could NOT be verified: SABRIC's own published Annual Crime Statistics report set (as listed on sabric.co.za/resources) runs only through the 2024 report (published Aug 2025); a 2025 annual report, following SABRIC's own ~8-9 month publication lag, would not be expected until roughly Aug-Sept 2026. The R3.9bn/"+23%" figure appears only in a handful of lower-tier or unverified outlets (e.g., an EBNewsDaily.co.za piece dated April 2026 and a LinkedIn post citing it) with no primary SABRIC report, media statement, or bank disclosure behind it, and R3.9bn also independently appears in the same period attached to an unrelated South African story (government "ghost employee" payroll fraud), raising the possibility of a garbled/misattributed statistic circulating online rather than a genuine, sourced SABRIC figure. This specific 2025 figure and the "rare joint public alert" issued jointly by all four major banks together (as opposed to each bank issuing its own separate, frequent vishing/SIM-swap warnings, which is well documented) should be treated as unconfirmed pending a genuine SABRIC 2025 report or a verifiable joint press release.
Status
Confirmed
Case Type
Real-World Incident
Sector
Financial Services & Insurance
Threat Actor
Organized Crime
Related

Related Cases

Retool smishing + deepfake vishing breach (2023)

A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…

Incident 2023Read →

Optus/TPG Telecom OTP-Interception Mobile-Upgrade Vishing Fraud (Sydney, 2023-2024)

A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support, tricking 100+ Australians into…

Incident 2023Read →

MGM Resorts Help-Desk Vishing Breach (Scattered Spider, 2023)

A roughly ten-minute phone call impersonating an MGM employee to the IT help desk let Scattered Spider reset MFA, seize…

Incident 2023Read →