A caller posing as a Standard Bank representative persuaded 18-year-old Reabetswe Modisane to move her R438,900 education trust fund to a "safe" Capitec account, with three transfers completed within 20 minutes; Standard Bank's own investigation attributed the loss to vishing while denying any breach of its systems, and the case has been escalated to the National Financial Ombud and North West police.
Reviewed by the Social Engineering Examples team.
In May 2026, R438,900 that Reabetswe Modisane's late father had set aside in a Standard Bank trust account for her university education was deposited into her account after she matriculated. A day later, on 23 May 2026, a man called her claiming to be a Standard Bank representative and told her the money needed to be moved to a different, "safer" account so it would not be misused. Believing the call, she authorized three transfers, R48,900, R190,000 and R200,000, to a Capitec Bank account, and all the money was gone within about 20 minutes. Standard Bank's subsequent investigation found that the Capitec beneficiary account had actually been added to her digital banking profile on 13 May 2026, roughly 10 days before the call, and that her own device and valid security credentials were used both to create the beneficiary and to authorize the transfers. The bank publicly stated she "could have been a victim of a vishing (voice-phishing) scam" and that its findings did not support any compromise of Standard Bank's systems or an internal data breach. The family, through the victim's uncle Lefa Tolo, disputed this framing, suspecting an insider leak because only relatives knew about the deposit and the call came so soon afterward. Capitec's own investigation likewise found no fault on its side. Standard Bank offered a "goodwill" settlement rather than a full refund; the family escalated the dispute to South Africa's National Financial Ombud (preliminary stage as of the report), and North West police opened a fraud case with no suspects identified as of 20 July 2026, when TimesLive published the story.
According to Standard Bank spokesperson Ross Linstrom, a Capitec beneficiary account was added to Reabetswe Modisane's Standard Bank digital banking profile on 13 May 2026, about 10 days before both the disputed transfers and the fraudulent phone call, and before the R438,900 education-trust deposit even landed in her account (the family says the call came "a day after" the money was deposited). On 23 May 2026 a man phoned her claiming to represent the bank and told her the money needed to be moved to a different, "safe" account "to save her money and not misuse it," a protective-account pretext paired with urgency. Acting on the call, she authorized three transfers (R48,900, R190,000, R200,000) from her Standard Bank account to the pre-created Capitec beneficiary, all completed within about 20 minutes, using her own device and the standard security credentials/authentication (e.g. OTP-based) on her registered digital banking channel. Standard Bank's investigation concluded this chronology showed the beneficiary was staged in advance and that the transactions were authenticated through her own registered profile, which it says rules out a Standard Bank systems breach or internal data leak immediately preceding the transfers; i.e., the bank's official position is that this was vishing (voice-based social engineering) rather than a bank-side security failure. The victim's uncle publicly disputes this reading, arguing that because only family knew about the trust deposit and the call came so soon after, the leak of information "seems like an inside job," an allegation Standard Bank's statement does not address directly and which remains unresolved/unconfirmed.
Lure: an inbound call from someone claiming to be a Standard Bank representative, telling her that her recently-deposited education money needed to be moved to a "safe" account so it wouldn't be "misused", combining spoofed authority (posing as the bank) with protective urgency (act now to prevent loss) against an 18-year-old with no prior experience of bank fraud tactics. Tell (identified only after the fact): her sister ran the caller's number through Truecaller and found it already flagged as a scam number; more fundamentally, no legitimate bank asks a customer to move funds by phone to a third-party "safe" account for protection; Standard Bank's own fraud-education material states this explicitly and says it will never request PINs, passwords or OTPs over the phone.
Reabetswe Modisane lost her entire R438,900 education fund. Standard Bank's internal investigation found the beneficiary Capitec account was created on her own device/digital profile 10 days before the fraudulent call and that the transfers were properly authenticated, concluding this was likely vishing and explicitly stating the facts do not support a Standard Bank systems breach or internal data leak. Capitec's own investigator likewise found no fault on Capitec's side, noting the transactions were "legally" made and were only flagged roughly a day later (by which point only R406 remained in the receiving account). Standard Bank offered the family a "goodwill" settlement rather than a full refund. The family disputes the bank's framing, suspecting an insider tip given that only relatives knew of the deposit, and has escalated the matter to South Africa's National Financial Ombud (preliminary stage as of the 20 July 2026 report). North West police confirmed a fraud case was opened, with no suspects identified at the time of reporting.
The case is a clean, on-the-record illustration of "safe account" vishing aimed at a large, one-time deposit (an inheritance/education trust) landing in the account of a young, first-time account holder unfamiliar with bank-fraud patterns, exactly the profile fraudsters look for. It also exposes the liability gap victims face: because the transfers were technically authenticated through the customer's own device and credentials, both banks involved (Standard Bank and Capitec) concluded they bore no fault, leaving the victim to pursue redress only through goodwill gestures and a formal ombud complaint rather than an automatic refund. The apparent 10-day gap between beneficiary creation and the actual vishing call also highlights that these scams can involve pre-staging steps well before the "final call," which is harder for victims and even banks to trace back to a single moment of compromise.
Standard Bank's own published guidance states a bank will never ask for PINs, passwords or OTPs over the phone, and warns customers that a caller creating urgency and telling them to move money to a "safe" account is a hallmark of vishing. Recommended controls illustrated by this case: cooling-off/hold periods on newly-added beneficiaries before high-value transfers are permitted (especially on young/first-time digital-banking profiles); step-up verification or an outbound callback to the customer's registered number, independent of any inbound caller, before authorizing large transfers to a newly created beneficiary; velocity/anomaly flags for multiple large transfers to a brand-new beneficiary within minutes of a large deposit; customer education that legitimate banks never solicit a transfer "for safekeeping" and that any such call should be ended and verified by calling the bank's official number directly; checking suspicious caller numbers against caller-ID/scam databases (as the family did, after the fact, via Truecaller) before acting, not after.
Censys researchers used passive DNS to unravel a live USPS/UPS "package awaiting action" smishing operation, exposing 682 rotating lookalike hostnames…
A Singaporean businessman transferred at least S$4.9 million after WhatsApp and email lures citing the Strait of Hormuz crisis drew…
A small Columbus, Ohio public materials manufacturer disclosed in a February 2026 SEC 8-K that it lost $898,325 to an…