Search
  • Home
  • The ever-evolving threat of cybercrime in South Africa
  • The ever-evolving threat of cybercrime in South Africa

    Data_security_24

    Mongezi Mpahlwa, Partner, Cox Yeats and Tshilidzi Mudau, Candidate Legal Practitioner, Cox Yeats unpack the growing number of cyber-attacks in South Africa in 2025 and beyond, in comparison with previous years, as well as the current trends in the ever-evolving digital world.

    South Africa remains one of the most targeted countries in the world when it comes to cyberattacks. Interpol’s Africa Cyberthreat Assessment Report of 2025 (4th Edition) identifies South Africa as a particularly significant target, especially in the finance and government sectors.

    According to recent data published by Kaspersky, it was reported that, in the first half of 2025, South Africa experienced more than six million online attack attempts and 10.3 million malware-related incidents including ransomware, banking trojans, spyware, and infostealers.

    While backdoor attacks surged by 123%, banking trojans and password stealers increased by 136% and 122% respectively compared to 2024[1].The financial toll is staggering. According to the Annual Crime Statistics published by South African Banking Risk Information Centre, banking customers suffered losses in the region of R1.8 billion in 2024 alone.

    These alarming statistics are backed up by data obtained by the Council of Scientific and Industrial Research, which had previously estimated that cybercrime costs South Africa over R2.2 billion a year. This figure is widely regarded as conservative. Seemingly, small and medium-sized enterprises (SMEs) continue to be the low hanging fruit, with businesses experiencing attempted intrusions on a near-daily basis.

    Tactics: Old tricks, new sophistication

    The tools of cybercrime remain familiar: phishing, ransomware, business email compromise (BEC), but the execution has become far more sophisticated.

    Criminals are now using artificial intelligence (AI) to generate phishing emails that are virtually indistinguishable from real correspondence. Deepfake audio and video are being used to impersonate executives on calls, bypassing voice-verification and authorising fraudulent payments[2].

    BEC remains the most financially damaging cybercrime category in South Africa. Attackers now monitor email chains for weeks, learning the language and approval processes of their targets before striking.

    Ransomware-as-a-Service (RaaS) has made launching attacks easier than ever. RaaS is an illicit subscription base model where cybercrime developers lease out pre-built ransomware tools and infrastructure to other hackers. Criminal groups sell ready-made toolkits on the dark web, complete with customer support. The result is more attacks by less skilled but highly motivated actors targeting South African businesses.

    The accessibility of Distributed Denial‑of‑Service (DDoS) – an attack where a large number of devices send huge amounts of traffic or requests to a website, server or network at the same time, overwhelming it and making the service slow or unavailable to legitimate users – and the proliferation of unsecured internet-connected devices (that have weak/default passwords, outdated software, unpatched vulnerabilities, or inadequate security controls) have further widened the attack surface. Criminals no longer need deep technical expertise. They need only a credit card and a target[3].

    A shift in targeted sectors

    Financial services and government remain prominent targets, but the threat is no longer confined to traditional high-value sectors. Telecommunications, energy and utilities, education and other organisations holding valuable operational or personal data are increasingly exposed[4].

    Government departments and municipalities have been hit hard, with attacks disrupting service delivery and exposing citizen data. Logistics companies are targeted because taking one down causes cascading disruption across multiple industries. Universities, holding valuable research and personal data on tight budgets, have become soft targets.

    Energy and utilities have also emerged as a concern, with critical infrastructure attacks drawing attention from both criminal syndicates and state-sponsored actors.

    The legal landscape tightens

    The regulatory environment around cybercrime is tightening, and businesses that are not keeping pace face real consequences. The Cybercrimes Act 19 of 2020 is gaining traction. While the Act has been in force since December 2021, its practical application when it comes to enforcement is maturing.

    It imposes reporting and preservation obligations on electronic communications service providers and financial institutions in respect of specified offences, requiring reporting to the Beyond direct financial losses, a cyber incident may have wider legal, regulatory and reputational implications for organisations, particularly where personal information is involved.

    But it is the civil courts that are sending the loudest message to South African businesses and banking customers.

    If you fail to verify before you pay, you bear the loss

    The recent decision by Supreme Court of Appeal (SCA) in Intengo Imoto (Pty) Ltd t/a Northcliff Nissan v Zoutpansberg Motor Wholesalers CC t/a Hyundai Louis Trichardt[5] is now the leading authority on BEC payment risk. In that case, a motor vehicle purchaser made payment by EFT into what turned out to be a fraudulent account after emails were intercepted and banking details altered. The SCA held that, on the facts of the case, the purchaser had failed to discharge its onus of proving payment. Payment into an unauthorised account, without verifying the seller’s banking details, did not discharge the purchaser’s payment obligation and Hyundai had neglected basic verification steps and failed to verify banking details before transferring funds. Crucially, the SCA rejected the High Court’s reasoning that because the seller had chosen EFT and email as its payment and communication methods, it bore the inherent risk of those systems.

    This decision is underpinned by the SCA’s earlier decision in Edward Nathan Sonnenberg Inc v Hawarden[6], where a purchaser transferred R5.5 million into a fraudster’s account during a property transaction after intercepted emails altered the conveyancer’s banking details. The SCA declined to recognise a general legal duty on creditors to warn debtors about BEC risks, holding that imposing such a duty would create “indeterminate liability” and that the purchaser could reasonably have protected herself by verifying the account details.

    These principles have been consistently applied across South African courts. In Manganye v National Education Health and Allied Workers Union and Another[7], the High Court stated plainly that “where payment is intercepted or misappropriated by a fraudster, the risk lies with the debtor. It is the debtor’s duty to ensure that payment reaches the creditor.” Furthermore, the court noted that “it is well-known amongst business professionals who utilize computer-based communication and payment methods that cybercrime is prevalent.” While in Gripper & Co v Ganedhi Trading Enterprises CC[8], the court held that paying funds into a fraudster’s account after receiving a spoofed email does not discharge the payer’s obligations to prudently verify changed banking details.

    The pattern across all of these cases is unmistakable: if you fail to verify before you pay, you bear the loss. A simple phone call to confirm banking details could prevent millions in losses. Ignorance of the risk is no longer a defence – it is evidence of negligence.

    Criminals are adopting AI faster than businesses are

    AI is both the biggest threat and the best defence. Criminals use it to craft convincing attacks. Businesses use it for threat detection and automated response.

    The problem is that criminals are adopting AI faster than businesses are. SMEs in particular lack the resources to deploy defensive AI effectively, and this gap will only widen without investment in accessible cybersecurity solutions.

    What must change

    Cybercrime evolves faster than most defences. Building resilience requires action now:

    • Verification protocols are non-negotiable: Promote basic hygiene like strong passwords, multi-factor authentication, callback verification on payments, and segregation of duties are baseline requirements.
    • Test your incident response plan: A plan that has never been rehearsed will fail under pressure.
    • Review cyber insurance annually: Policy wordings and exclusions must keep pace with the threat.
    • Assess supply chain risk: Your vendors are an attack vector. Due diligence on their cybersecurity is essential.

    The bottom line is that cybercrime in South Africa has not plateaued, it has accelerated. The question is no longer whether your business will face a cyber incident, but whether it will survive one.

    The threat has evolved. Have you?

    For more articles like this click here.  

    If you enjoyed this website then check out our other sites: Wedding and Function, Home Food and Travel, Kids Connection, Thirsty Traveler, Bargain Buys, Boat Trips for Africa. 

    Need help with your online marketing then visit Agency One

    Facebook
    Twitter
    LinkedIn
    Pinterest