SABRIC's own Annual Crime Statistics reports document a sustained, industry-wide surge in vishing- and SIM-swap-driven digital banking fraud across South.
Social Engineering Examples·8 sources
Between 2023 and 2025, South Africa's banking industry, through its shared fraud-intelligence body SABRIC (South African Banking Risk Information Centre), documented a sustained and accelerating wave of digital banking fraud driven overwhelmingly by vishing (voice phishing) combined with SIM-swap-enabled OTP interception, rather than by technical breaches of banking systems.
SABRIC's Annual Crime Statistics report for 2023 (published Oct 2024) recorded 52,584 digital banking fraud incidents (+45% year-on-year) with gross losses of R1,082,393,109 (+47%); within that total, banking-app fraud alone, the single biggest driver, accounted for 31,612 incidents (60% of digital banking crime) and R625,712,552 in losses (+74%). SABRIC's Annual Crime Statistics report for 2024 (published 28 Aug 2025) showed the trend intensifying sharply: 97,975 digital banking fraud incidents (+86%) and R1.888 billion in gross losses (+74%), with banking apps making up 65.3% of incidents.
SABRIC explicitly attributed the surge to social engineering: phishing, vishing, and SIM-swap abuse exploiting human trust and error, rather than to any compromise of the banks' own platforms, and separately warned that criminals were increasingly using generative AI (AI-written phishing emails, AI-generated WhatsApp lures, and early voice-cloned/deepfake calls) to make the scams more convincing.
Absa, FNB, Nedbank, and Standard Bank each issued numerous individual customer warnings across this period (Standard Bank launched an in-app "vishing alert" feature in Aug 2024; Nedbank and Standard Bank issued repeated fraud alerts through 2025) describing the same core vishing/SIM-swap playbook. A claim circulating in the case brief and in some 2026 secondary reporting that 2025 banking-fraud losses reached "R3.9 billion" and that the four major banks issued one unified, rare joint public alert could not be corroborated: SABRIC's own published report archive runs only through the 2024 report (Aug 2025), a 2025 annual report was not yet published in the sources checked, and the R3.9bn/joint-alert claims traced only to a low-reliability outlet and a LinkedIn post rather than to any SABRIC or bank primary source; this specific figure and event should be treated as unverified.
SABRIC's 2024 report describes the dominant attack chain in detail: criminals first send a phishing email or SMS that resembles legitimate bank communication, directing the victim to a spoofed look-alike banking website where the victim unknowingly enters their username and password. Immediately afterward, a vishing call follows from a fraudster posing as a bank "fraud department" employee (using caller-ID spoofing so the call appears to come from the bank's real number), who creates urgency by claiming the account has been compromised and needs an OTP to "secure" it.
The victim, primed by the earlier phishing step and believing the call is legitimate, reads out the OTP, which the fraudster uses in real time to complete login or authorize a transaction on the legitimate banking site/app. In the SIM-swap variant, instead of intercepting the OTP live over the phone, criminals use stolen personal/ID information (harvested from social media, data breaches, or the phishing step) to convince a mobile network operator's customer-service agent to port the victim's number to a SIM card the criminals control, silently redirecting all future OTP/SMS codes so 2FA no longer protects the account.
Standard Bank and Nedbank also documented variants where vishing callers, without a prior phishing step, simply persuade the victim over the phone to transfer funds directly into a fraudster-controlled "safe/secure account," or to authorize an Instant Money/EFT payment, exploiting fear that the account is already under attack. SABRIC states these losses are overwhelmingly the product of social engineering exploiting human error/trust, not technical breaches of bank systems.
The lure had two connected stages. Stage one (phishing lead-in): an email or SMS made to look like it came from the customer's own bank, urging a login via a link that led to a convincing spoofed banking site, harvesting username/password. Stage two (the vishing call): a follow-up phone call, often with a spoofed caller ID matching the bank's real fraud-department number, from someone who already had some of the victim's real personal/account details (from the phishing step, a prior data breach, or public/social-media information), creating urgency ("your account has been compromised," "we've detected fraud," "we need to move your money to a secure account") to extract the OTP or push the victim into authorizing a transfer themselves.
Standard Bank's Dr Belinda Rathogwa noted scammers specifically targeted older clients nearing or in retirement with fake high-return investment pitches layered onto the same vishing/urgency playbook. The "tell" that distinguished it from a real bank contact, per every bank's own guidance: a legitimate bank will never ask a customer to read out a PIN, password, OTP, or CVV over the phone, and will never instruct a customer to move money into a new "safe" account; any call doing either is fraudulent regardless of how convincing the caller ID or the caller's script sounds.
SABRIC's data shows the trend accelerating rather than resolving during the documented period: digital banking fraud incidents rose 45% in 2023 and a further 86% in 2024, with losses up 47% and 74% respectively, even as banks rolled out new countermeasures (Standard Bank's in-app vishing-alert feature, biometric/MFA pushes, AI-driven "intent" detection).
Individually, Absa, FNB, Nedbank, and Standard Bank each issued repeated, separate customer warnings throughout 2024-2025 (Standard Bank Aug 2024 and Aug 2025; Nedbank Feb, March, and Aug 2025) about vishing and SIM-swap/impersonation fraud, and SABRIC itself, together with the Southern African Fraud Prevention Service, ran public-awareness campaigns (e.g., SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025).
SABRIC's total financial-crime figure across all categories (including non-digital crime such as robbery, which fell sharply due to bank/SAPS collaboration) actually declined 18% overall between 2023 and 2024 (R3.3bn to R2.7bn), even though digital/vishing-driven fraud specifically kept rising, illustrating that the vishing/SIM-swap problem grew even as the banking sector made real gains elsewhere.
Individual victims largely bore uncompensated losses: Standard Bank's Rathogwa noted that this social-engineering tactic "leaves little recourse for consumers," most of whom recover none of their lost funds even with bank assistance, because victims authorized the transactions themselves under deception (distinct from an unauthorized system breach the bank might be liable for).
No specific arrests, prosecutions, or named perpetrator group tied to the overall statistical surge were identified in the sources reviewed; SABRIC/banks describe the perpetrators generically as fraud syndicates/criminal networks.
This case is a rare instance of an entire national banking sector publishing multi-year, quantified, first-party loss data that isolates vishing and SIM-swap social engineering (as opposed to malware or system breaches) as the dominant driver of fraud growth: R625.7m in 2023 banking-app fraud alone, rising to a total digital banking fraud bill of R1.888bn by 2024, an 86% jump in incident volume in a single year.
It demonstrates that strong technical authentication (MFA/OTP) can be systematically defeated at scale not by breaking the cryptography but by manipulating the two weakest links around it: the human on the phone, and the mobile network's own SIM-provisioning process. It also shows how a preceding phishing step (credential theft) chained directly into a vishing call (OTP extraction) turns two individually survivable failures into a complete account takeover, and it illustrates the emerging role of generative AI in lowering the production cost/quality bar for convincing phishing lures and voice impersonation.
Finally, the case is a useful caution about source hygiene in fast-moving fraud reporting: a specific, precise-sounding figure (R3.9bn, 2025) and dramatic claim (a rare joint four-bank alert) spread through secondary and social coverage without ever tracing back to the issuing body's own report, a reminder to verify statistics against the primary regulator/industry-body publication before treating them as fact.
SABRIC's core, repeated advice: banks will never ask for a PIN, password, OTP, or CVV by phone, SMS, or email, and never ask a customer to move money into a "safe"/"secure" account. Customers are told to hang up on any caller claiming to be from a bank's fraud department and call back only via the number on the bank's app or official website (not a callback number the caller supplies, since fraudsters spoof caller ID and can intercept "verification" callbacks).
Absa specifically warns that a sudden loss of cellphone signal, missed calls, or a missing expected OTP can indicate a SIM swap, and to contact the network operator and bank immediately. Standard Bank built a dedicated in-app "vishing alert" feature (launched Aug 2024) that flags suspicious calls to customers. SABRIC recommends multi-factor authentication, biometric verification, avoiding links in unsolicited SMS/WhatsApp/email, downloading apps only from official app stores, and treating any urgent, fear-based call about "compromised" funds as a red flag.
Banks and SABRIC also collaborate with SAPS and the Southern African Fraud Prevention Service (SAFPS/Yima) on suspect identification and public awareness campaigns (e.g. SAFPS's "Just Say Goodbye" vishing campaign, Nov 2025). SABRIC has also flagged that by 2024-2025, AI-driven "intent" analysis and biometric verification were being adopted industry-wide specifically to counter AI-enhanced/deepfake-assisted vishing.
Social Engineering Examples. “SABRIC-Documented Vishing and SIM-Swap Fraud Surge Against South African Bank Customers (2023-2025)”. Accessed 19 September 2026. https://socialengineeringexamples.com/sabric-vishing-sim-swap-banking-fraud-surge-2023-2025
SABRIC's reporting is consistent with attackers typically building a partial profile of the intended victim (name, bank, phone number, and some real account or personal details) from prior data breaches, social media, or a preceding phishing response, giving a later phone call enough real detail to sound legitimate.
personal-data exposure from social media and third-party data breaches is very hard for a bank to eliminate at the source; the realistic control assumes attackers already hold some real victim details and instead hardens the verification steps later in the chain that this information gets used against.
before contact, operators typically stand up look-alike phishing domains that closely mimic a bank's real login page and acquire caller-ID spoofing capability so a vishing call appears to originate from the bank's genuine fraud-department number; SABRIC's 2024 and 2025 statements describe criminals increasingly using generative-AI tools to draft error-free phishing emails and AI-generated WhatsApp lures, and early voice-cloning services to make follow-up calls more convincing.
the nearest practical controls sit at the mobile network operator (stronger identity verification, PIN, or biometric confirmation before any SIM port or number transfer is processed) and at brand-protection monitoring for newly registered look-alike banking domains, rather than at the tooling stage itself, which is largely invisible to the victim or bank beforehand.
a mass phishing email or SMS made to resemble legitimate bank communication is sent to a large pool of customers, directing anyone who clicks through to the spoofed banking site, where they unknowingly enter their username and password.
customer education to distrust links in unsolicited SMS, WhatsApp, or email and to navigate to banking sites directly or via the official app, combined with bank-side email-authentication standards (SPF/DKIM/DMARC) and a policy of never sending transactional login links, reduces how many recipients reach the spoofed page.
in the vishing path, a fraudster calls posing as bank fraud-department staff, using the spoofed caller ID and the details already gathered, and manufactures urgency to get the victim to read out an OTP or approve a transaction prompt; in the parallel SIM-swap path, the same harvested personal/ID information is used to convince a mobile network operator's customer-service agent to port the victim's number to a SIM the criminals control, silently rerouting future OTP/SMS codes.
SABRIC and every major bank's core, repeated advice is that a bank will never ask a customer to read out a PIN, password, OTP, or CVV by phone, and will never ask a customer to move money into a new 'safe' account; customers are told to hang up and call back only on the number from the bank's official app or website, never a number the caller supplies, and Absa specifically flags sudden loss of cellphone signal as a SIM-swap indicator to escalate to the network operator immediately.
the fraudster uses the stolen credentials together with the live-relayed OTP (vishing path) or the intercepted OTP stream (SIM-swap path) to log into the banking app or authorize a funds transfer in real time, completing the technical bypass of MFA.
authentication methods resistant to being relayed over a phone call, such as in-app push approvals that display the actual transaction details for the customer to confirm, biometric verification, and Standard Bank's dedicated in-app vishing-alert feature (launched Aug 2024), are harder for a live vishing caller to talk a victim through than a plain numeric OTP.
SABRIC describes the proceeds typically being moved quickly into money-mule accounts or via Instant Money/EFT payments to frustrate tracing, which is consistent with why, per Standard Bank's Rathogwa, most victims recover little or none of the money even with bank assistance.
bank and SABRIC-level transaction monitoring, mule-account detection, and cross-bank/SAPS collaboration can sometimes freeze or trace funds quickly, but SABRIC's own outcome data shows this rarely helps individual victims recover money once funds have moved, since the customer authorized the transaction themselves under deception; this stage is where the case's own reporting shows the defense is weakest in practice.
Browse by what this case has in common with others in the library.
A smishing text plus a follow-up phone call using a deepfaked colleague's voice tricked a Retool employee into surrendering MFA…
A Pakistani national in Sydney allegedly ran a callback-vishing scheme impersonating Optus and TPG Telecom support.
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
Scheme participants posed as veteran finance professionals inside private WhatsApp investment groups to lure at least 18 U.S. retail investors…
A fraudster spoofed Wells Fargo's real 800 number nine minutes after a legitimate advisor call, phished a 2FA code from…
A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438.
DOJ/IRS-CI unsealed four indictments charging 28 members of a Chinese organized-crime money-laundering ring tied to India-based "mistaken refund".
The Crelan Bank phishing attack: fraudsters impersonating the CEO tricked staff into wiring nearly €70M (~$75.8M) in Belgium's costliest CEO…
A four-man Manhattan fraud ring compromised a nonprofit CFO's and a portfolio company employee's business email accounts to redirect $3.49M…
The FBI's IC3 issued a December 2024 public advisory detailing how criminals use AI-generated text, images, voice cloning.
A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
A Bengaluru retiree lost Rs 6.88 lakh after an AI-generated deepfake Facebook video falsely showed Finance Minister Nirmala Sitharaman endorsing…
Fraudsters plastered fake QR-code stickers over genuine PayByPhone parking codes at UK council car parks in Cheltenham, Swindon and Somerset.
A blogger paid $89.95 to an online data broker (CellTolls.com) to buy retired Gen. Wesley Clark's cell-phone call log obtained…
Fraudsters hijacked a WhatsApp account via a malicious ZIP file, swapped in their own number while keeping the real display…
Scattered Spider's ten-minute vishing call to MGM's help desk reset MFA and seized identity systems, an incident Moody's called credit-negative.
A long-running, India-based network of call centres impersonated the Canada Revenue Agency and RCMP in mass vishing calls that threatened…
A single vishing call impersonating Carnival's own IT security team convinced an employee to hand over credentials.