How to prevent fraud: practical steps for South Africans
Back to Blog

How to prevent fraud: practical steps for South Africans

August 8, 2026
AI Webhook

How to prevent fraud: practical steps for South Africans

Hands verifying supplier banking details via phone

Protecting yourself and your business from fraud comes down to a handful of habits: verify every unexpected request, never share your OTP or PIN, enable multi-factor authentication (MFA) on every account, and call your bank the moment something feels wrong. Most fraud in South Africa succeeds not because criminals are sophisticated, but because victims are caught off guard. These seven actions stop the majority of attempts before they cause damage.

  • Verify contacts using known numbers. Never call back a number from a suspicious SMS or email. Look up the official number independently.
  • Never share your OTP, PIN, or CVV with anyone, including someone claiming to be from your bank. Banks will never ask for these.
  • Enable MFA on your banking app, email, and any financial platform you use.
  • Keep devices and apps updated. Unpatched software is one of the most common entry points for fraud.
  • Set transaction limits on your accounts and activate push notifications for every payment.
  • Monitor accounts daily, even briefly. Catching an unauthorised debit on day one is far easier to reverse than one discovered three weeks later.
  • Pause before you pay. Any unexpected request for payment, especially via EFT to a new account, warrants a phone call to a known contact before you proceed.

South African reporting contacts at a glance:

  • SAPS (South African Police Service): criminal fraud report
  • SABRIC (SA Banking Risk Information Centre): bank-related fraud coordination
  • FIC (Financial Intelligence Centre): suspicious transaction reporting

Key takeaways

Preventing fraud in South Africa requires combining immediate protective habits with structured business controls and knowing exactly who to call when something goes wrong.

Point Details
Verify before you pay Call a known number to confirm any banking-detail change or unexpected payment request.
Never share credentials No bank or SARS official will ever ask for your OTP, PIN, or CVV.
Enable MFA everywhere Multi-factor authentication on banking and email stops most account-takeover attempts.
Segregate duties in your business Split payment capture and approval between two people to close the most common internal fraud gap.
Readyaccounting Provides automated audit trails, dual-approval payment controls, and forensic accounting reviews for South African SMEs.

Table of Contents

What do common scams look like in South Africa?

Fraud follows recognisable patterns. Once you know the shape of each scam, spotting one takes seconds.

Phishing arrives as an email that mimics a trusted institution, SARS, your bank, or a courier company, and asks you to click a link and enter credentials. The tell: the sender’s domain is slightly wrong (“sars-gov.co.za” instead of “sars.gov.za”), and there is always urgency. SAPS advises never responding to unsolicited requests for banking details, regardless of how official the message looks.

Vishing is the phone version. A caller claims to be from your bank’s fraud department, creates panic about a suspicious transaction, and then asks you to “confirm” your OTP to reverse it. The OTP actually authorises a payment to the fraudster.

Smishing is phishing via SMS. A message says your account is locked or a parcel is held, with a link to a fake login page. The link harvests your credentials.

SIM-jacking is more targeted. A criminal convinces your mobile operator to transfer your number to a new SIM, then intercepts all your OTPs. If your phone suddenly loses signal for no reason, contact your operator immediately.

Invoice and CEO fraud hit businesses hardest. A supplier sends an email (often from a compromised or spoofed address) requesting a banking detail change. The next payment goes to the fraudster’s account. CEO fraud follows the same logic: an email appears to come from the MD, instructing finance to make an urgent transfer. SME South Africa highlights supplier-bank-change requests as one of the most common and costly SME scams.

Investment scams promise guaranteed high returns, often through WhatsApp groups or social media. If the return sounds too good and the pressure to invest quickly is high, it is a scam. Finblog’s investment scam guide outlines the classic signals: unlicensed operators, vague strategies, and requests for cash or crypto.

Romance scams build a relationship over weeks before a financial emergency conveniently arises.

Scam type Typical red flags First action
Phishing Urgent email, suspicious domain, link to login page Do not click; go directly to official site
Vishing Caller asks for OTP or PIN to “protect” your account Hang up; call your bank on the official number
Smishing SMS with link claiming account issue or parcel hold Delete; access your account via the official app
SIM-jacking Phone loses signal unexpectedly Call your mobile operator immediately
Invoice/CEO fraud Request to change supplier banking details via email Call the supplier on a known number to verify
Investment scam Guaranteed returns, pressure to act fast, unlicensed Check FSCA registration; do not transfer funds
Romance scam Online relationship followed by financial request Stop contact; report to SAPS

The single red flag that cuts across every scam type: urgency combined with a request for money or credentials. Slow down. Verify. Then decide.


How can individuals protect themselves step by step?

The highest-impact habits are MFA, unique passwords for every account, keeping devices updated, and never sharing OTPs under any circumstances. Everything else builds on those four.

Your action plan

  1. Today: Enable MFA on your banking app, email, and any account linked to money. Use an authenticator app (Google Authenticator or Microsoft Authenticator) rather than SMS where the platform allows it.
  2. Today: Change any password you reuse across multiple sites. Use a password manager such as Bitwarden or 1Password to generate and store unique passwords.
  3. This week: Check that automatic updates are on for your phone’s operating system and all apps. Install reputable antivirus software if you use a Windows PC.
  4. This week: Log into your banking app and activate push notifications for every transaction. Set a daily transaction limit that reflects your normal spending, not your account balance.
  5. This month: Check your credit report with TransUnion South Africa or Experian South Africa. You are entitled to one free report per year. Unexplained accounts or enquiries are a warning sign.
  6. Ongoing: Never use public Wi-Fi for banking. If you must, use a VPN. Only download apps from the Google Play Store or Apple App Store.

Pro Tip: To verify a suspicious email or call from your bank in under 90 seconds, close the message, open your bank’s official app, and check the in-app notification centre. If the bank genuinely needs you, the alert will be there. If it is not, the contact was fraudulent. Never use a phone number or link from the suspicious message itself.

SIM-jacking: lock your number

Contact your mobile operator (Vodacom, MTN, Cell C, or Telkom) and ask them to add a SIM-swap block or a RICA verification requirement before any SIM swap is processed on your number. This single step significantly reduces SIM-jacking risk. If your phone loses signal unexpectedly, call your operator from another device immediately.

For identity theft specifically, SAFPS (South African Fraud Prevention Service) offers a free Protective Registration that flags your identity to member institutions and helps prevent fraudulent accounts being opened in your name.


How should small businesses prevent fraud?

For SMEs, the three highest-impact controls are segregation of duties, a verification culture for any payment or banking-detail change, and automation that creates an immutable audit trail. Technology helps, but the research is clear: fraud is primarily a human problem, and the most effective defences are behavioural.

Segregation of duties

No single employee should be able to both create a payment and approve it. The person who captures a supplier invoice should not be the same person who releases the EFT. Even in a two-person finance team, this split is achievable: one person prepares, the owner or a second signatory approves. This one control eliminates a large category of internal fraud.

Vendor onboarding and banking-detail changes

Every new supplier should go through a documented onboarding process: verify the company registration on CIPC, confirm VAT registration with SARS eFiling, and call the supplier’s main switchboard (not a number from the email) to confirm banking details before the first payment. Any subsequent request to change banking details must trigger the same phone verification, every time, no exceptions. Supplier-bank-change fraud is one of the most common and costly attacks on South African SMEs.

Diagram of vendor onboarding and banking detail verification process

Approval workflows and transaction limits

Set a rand threshold above which two signatories are required. For most small businesses, R10,000 is a reasonable starting point, though the right number depends on your typical transaction size. Payments above the threshold should require a second approval in your banking platform before release. Document this policy in writing so it applies consistently, not just when the owner is watching.

Reconciliations and automation

Monthly bank reconciliations catch discrepancies before they compound. Automated accounting platforms such as Xero or Sage Business Cloud create timestamped records of every transaction, making it far harder to alter entries without leaving a trace. Automation reduces manual errors and builds the audit trail that forensic accountants rely on when fraud is suspected. Pair automation with strong financial reporting practices and you close most of the gaps that fraudsters exploit.

Staff training

Run a short fraud-awareness session at least once a year. Cover phishing emails, vishing calls, and the rule that no legitimate instruction to change a supplier’s banking details will ever come only by email. SME South Africa recommends restricting payroll and tax-system access to essential personnel only and verifying any SARS communication directly in eFiling rather than by clicking a link.

Pro Tip: Bring in an external forensic accountant when you notice unexplained transaction anomalies, repeated requests from a supplier to change banking details, or an employee who resists oversight of their financial tasks. These are the three clearest triggers. Waiting for certainty before acting usually means the fraud has already grown. Forensic accounting reviews can be scoped narrowly and completed quickly.


What should you do immediately if fraud occurs?

Stop the movement of funds first. Every minute matters.

  1. Call your bank’s fraud hotline immediately and instruct them to freeze the affected account or card. Most South African banks have 24-hour fraud lines.
  2. Change your online banking password and PIN from a clean, trusted device, not the one you suspect may be compromised.
  3. Screenshot and preserve all evidence: suspicious emails (do not delete), SMS messages, call logs, and any communication related to the fraud.
  4. Open a case with SAPS. You need a case number for insurance claims and for follow-up with other agencies. Visit your nearest police station or use the SAPS online reporting portal.
  5. Report to SABRIC (SA Banking Risk Information Centre) for bank-related fraud. SABRIC coordinates between banks and law enforcement.
  6. Report suspicious transactions to the FIC (Financial Intelligence Centre) via their online portal. The FIC focuses on money laundering and large-scale financial crime.
  7. Lodge a complaint with the NCC (National Consumer Commission) if the fraud involved a supplier or retailer violating consumer protection law.
  8. Contact the credit bureaus. Place a fraud alert with TransUnion South Africa and Experian South Africa to prevent new accounts being opened in your name.
  9. Register with SAFPS for Protective Registration if your identity documents were compromised.

For SMEs, add these steps: notify your business insurer (check whether your policy covers cyber or fraud events), engage a forensic accountant to scope the loss and preserve evidence for legal proceedings, and consult a commercial attorney if the amount is material. Early forensic involvement speeds recovery and strengthens any civil or criminal case.


How do you make fraud prevention a lasting habit?

Prevention works best when it becomes routine rather than reactive. A short weekly and monthly rhythm is all it takes.

Weekly: Scan your bank statements for unfamiliar transactions. Check that your transaction alerts are still active. If you run a business, review any new supplier-change requests and confirm they followed your verification protocol.

Monthly: Reconcile your accounts. Review user access rights in your accounting platform and remove anyone who no longer needs access. Check your credit report quarterly at minimum.

The decision rule for professional help is straightforward. Call an expert when: the amount at risk is material to your business or household, you suspect the fraud is internal (an employee or trusted person), or you have experienced more than one incident in a short period. These three conditions together suggest a systemic weakness that a checklist alone will not fix. A controls review or forensic accounting engagement scoped to your situation is the faster path to resolution.

Building fraud awareness into your business culture means making the verification rule non-negotiable: no banking-detail change goes through on email alone, ever. For households, it means agreeing as a family that no one shares OTPs, even with someone claiming to be from the bank. The rule is simple enough to remember and strong enough to stop most attacks.


How do you make fraud prevention a lasting habit? — overview diagram

A forensic perspective: why most fraud prevention fails

The conventional advice on fraud prevention focuses almost entirely on technology: better passwords, stronger MFA, updated antivirus. That advice is correct, but it misses the more common failure mode.

Most fraud that reaches me in a professional context succeeded because a person bypassed a control, not because the control did not exist. A business had a dual-approval policy for payments, but the owner approved a transfer on a Friday afternoon without calling the supplier because it “seemed fine.” An employee knew the rule about banking-detail changes but made an exception for a long-standing supplier. The control was there. The habit was not.

The businesses that genuinely prevent fraud treat verification as a cultural norm, not a checklist item. When the finance team knows that every banking-detail change requires a phone call to a known number, no exceptions, the policy enforces itself. When the owner models that behaviour, it spreads. That is harder to implement than installing software, but it is also far harder for a fraudster to defeat.

The cybersecurity guide for South African SMEs and the financial integrity practices we recommend at Readyaccounting are built around this principle: technology supports the habit, but the habit has to come first.


Readyaccounting helps South African SMEs close fraud gaps fast

Fraud prevention for a growing SME is not just about awareness. It requires the right systems: automated payment workflows with dual-approval controls, cloud accounting that creates a timestamped audit trail, and reconciliations that flag anomalies before they become losses. Readyaccounting builds exactly these controls for South African SMEs as part of its outsourced accounting and fractional CFO service. If you have experienced a fraud incident or want a controls review before one happens, the accounting automation guide is a practical starting point. For a direct conversation about your business, visit Readyaccounting’s outsourced accounting service and book a consultation. This article provides general guidance only; report fraud to SAPS, SABRIC, and the FIC, and consult a qualified professional for legal or forensic advice specific to your situation.


Useful South African fraud reporting contacts

  • SAPS (South African Police Service): Open a criminal case for any fraud. You need a case number for insurance and follow-up. Visit your nearest station or report online at Saps.
  • SABRIC (SA Banking Risk Information Centre): Coordinates bank-related fraud between financial institutions and law enforcement. Contact via your bank’s fraud line, which routes to SABRIC where relevant.
  • FIC (Financial Intelligence Centre): Report suspicious financial transactions, especially large or unusual ones, via the FIC’s online portal at fic.gov.za.
  • NCC (National Consumer Commission): For fraud involving suppliers or retailers breaching consumer protection law. File a complaint at thencc.org.za.
  • CIPC (Companies and Intellectual Property Commission): Check company registration details to verify a supplier’s legitimacy before payment at cipc.co.za.
  • TransUnion South Africa: Place a fraud alert and access your credit report at transunion.co.za.
  • Experian South Africa: Request a fraud alert and free annual credit report at experian.co.za.
  • SAFPS (South African Fraud Prevention Service): Register for free Protective Registration if your identity documents are lost or compromised.
  • Readyaccounting: For SME controls reviews, automated accounting, and forensic accounting support, visit Readyaccounting.

Preserve your evidence first. Before you report anywhere, screenshot all suspicious communications, save emails, note call times and numbers, and download your bank statements. Evidence gathered in the first hour is the most valuable.

Sources