About
Subscribe

Social engineering a growing cyber security headache for SA

Chris Tredger
By Chris Tredger, Technology Portals editor, ITWeb
Johannesburg, 07 Oct 2026
Richard Ford, group CTO, Integrity360.
Richard Ford, group CTO, Integrity360.

Social engineering remains a major threat to South Africans and was the main driver of the country’s R2.4 billion loss to crime in 2025. This is according to the 2025 Annual Crime Statistics Report by the South African Banking Information Centre (SABRIC).

The loss was 29.2% higher than the previous year, across more than 110 000 incidents, SABRIC reported.

Richard Ford, group CTO at Integrity360, said as the world marks Cyber Security Awareness Month in October, social engineering – where criminals persuade people to approve payments or hand over access themselves – is a growing threat, particularly through payment requests on WhatsApp.

He advised users to verify such requests through a trusted channel before transferring money.

Ford said a harder-to-detect threat occurs when messages come from a genuine number. Criminals can take over a WhatsApp account by persuading its owner to share the six-digit registration code sent by WhatsApp via SMS. From there they message everyone in the contact list, from a number and profile photo the family already trusts.

"Your daughter's name and photo sit at the top of the chat, with years of family messages underneath. Parents trust that thread completely, and whoever has taken over the account inherits all of that trust," said Ford.

"The whole trick runs on 10 minutes of panic. A criminal has no need to hack anything when a parent will open the banking app for them. They invent an emergency and count on the parent paying before anyone picks up the phone to check."

Shayimamba Conco, solution architect for SASE: Africa at Check Point Software Technologies, said the losses show that cyber criminals are increasingly exploiting the human element rather than simply attacking technology.

“Social engineering, phishing, impersonation and other forms of manipulation are effective because attackers are targeting trust, urgency and emotion. For individuals and organisations, the financial impact is significant, but so too are the reputational and operational consequences,” he added.

Ford said the official figures may be conservative because some victims do not report losses.

Shayimamba Conco, solution architect, SASE: Africa, Check Point Software Technologies.
Shayimamba Conco, solution architect, SASE: Africa, Check Point Software Technologies.

“Social engineering drives most digital banking losses, but plenty of WhatsApp cases never get reported. A family that loses R2 000 to a fake emergency may also feel embarrassed and write it off. The takeover version is serious because of how much one account carries. The criminal gets the contact list, the groups and the history in one step, and can message everyone in it before the owner realises the account has gone," said Ford.

"When it's an employee's account, colleagues, suppliers and customers can come next, and we treat it as an identity compromise for precisely that reason. Organisations see the same pattern when an attacker with valid credentials simply logs in and nothing looks out of place.”

Ford said criminals can make scams more convincing by gathering information from social media, public profiles and conversations.

“A public post about a child's matric dance, gap year or first job hands a stranger the names and plans that make 'mom, it's me' sound right,” added Ford.

Verify before paying

Ford advised people to independently verify any request for money. Anyone receiving a message claiming to be from their child should reach the child through a separate channel – an ordinary phone call, an SMS or a message to a friend or partner who is with them. "You make the call. A voice note, or a call coming in from the new number, proves nothing."

He said families should agree to a rule before any emergency arises. "Set a family rule now, while nobody is panicking. Any request for money gets confirmed by a call you make to a number you already trust, however urgent it sounds. Some families add a code word only they know. A child who really is stranded will understand why you want to hear them first. If you can't reach them, wait until someone else has confirmed it.

"Voice cloning means 'it sounded just like him' has stopped being a safe test. A code word is the one thing a criminal can't lift from a voice note or a video posted online," he added.

Ford also advised users never to share a WhatsApp registration code and to enable WhatsApp’s two-step verification.

"If your WhatsApp account has been compromised, warn your contacts through another channel so they don't fall for the same scam, and tell the family about any attempt, even if nobody paid. Whoever tried it on you is working through a whole contact list," he said.

Zero trust

Conco said zero trust principles can help reduce the impact of human error, but technology alone cannot prevent people from being manipulated into providing information or authorising actions.

“This is why zero trust needs to be complemented by strong identity protection, device security, e-mail and browser security, threat prevention and continuous user education. The objective should be to reduce the opportunity for a human mistake to become a security incident,” he added.

Ford said the same principle can be applied outside corporate networks.

“A message from your child's number is, at base, a claim. Whoever takes over the account inherits the name, the photo and years of chat history, so none of that really proves who is typing. Proof has to come from a channel you control: a call to the number you already had saved, or a question only the real person could answer. That's zero trust for families.

“Businesses are where I'd push harder,” said Ford. “Plenty of organisations run zero trust on their networks and still let a WhatsApp voice note from the 'CFO' approve a payment. Finance processes deserve the same rules as the firewall.”

Conco said people should slow down and verify unexpected requests through an independent channel, avoid clicking links in unexpected messages, and never share passwords or OTPs. Legitimate organisations, he noted, should never require anyone to disclose a PIN, password or authentication code.

"As attackers increasingly target people, every individual has become part of the security perimeter. Technology should make it harder for attackers to succeed, but informed and cautious users remain an important layer of defence," he said.

Share