Sunday, 13 September 2026
ZAR/USDR16.160.06%. Rand weaker against the US dollar
ZAR/EURR18.730.13%. Rand stronger against the euro
ZAR/GBPR21.830.00%. Rand flat against the pound
Retail & Consumer

Banking app fraud claims double to R2.41bn in South Africa 2025

Banking app fraud claims double to R2.41bn in South Africa 2025
Illustrative image, not of the subject of this story. · Photo: Domenico Loia

For anyone who checks their account on a smartphone, the risk of losing money has risen sharply. The South African Banking Risk Information Centre (SABRIC) says the total value of client claims linked to digital banking crime more than doubled over the past three years, reaching R2.41 billion in 2025.

Digital banking crime means fraud that uses online or mobile banking channels. In 2025, 110,074 incidents were reported, up from 97,547 in 2024 and 52,588 in 2023. The average loss per incident climbed to R21,865, compared with R19,095 the year before.

Banking apps were by far the biggest channel involved. SABRIC recorded 97,555 investigations into banking-app claims in 2025, accounting for 88.6% of all digital banking crime cases. Those cases generated R1.70 billion in claims, or 70.5% of the total amount.

How the scams work

The centre stresses that the apps themselves are not being hacked. In many cases the fraud starts outside the banking platform. Criminals impersonate trusted organisations, create a sense of urgency and guide victims through transactions in real time. The app is then used simply to add a new beneficiary, approve a payment or move funds that the victim has already been deceived into sending.

Vishing, or voice-phishing, remains a major method. Fraudsters call, claim to be from a bank or a government agency, and convince the victim that the account is at risk. The victim is then persuaded to transfer money to a “safe account” while the caller stays on the line, giving step-by-step instructions.

Remote-access scams are another prominent threat. Victims are told they need to install software or enable screen sharing for technical support or fraud-prevention assistance. Once the fraudster controls the device, they typically move funds in a single decisive transaction to a newly created beneficiary.

SABRIC also warned that artificial intelligence could make impersonation scams more convincing. Deep-fake voice recordings and polished phishing messages are becoming easier to produce, and isolated cases of cloned voices have already been reported.

Internet banking, accessed through a computer browser, accounted for only 8.5% of investigations but still generated R688.3 million in claims. Mobile banking via USSD and basic cellphone channels was responsible for 3,165 investigations and R22 million in claims.

The broader fraud picture is also worrying. Combined gross losses on South African-issued credit and debit cards rose 18% year-on-year to R1.75 billion in 2025. Credit-card losses jumped 29.3% to R739.2 million, while debit-card losses increased 10.9% to R1.01 billion.

For small business owners who rely on mobile banking to receive payments and pay suppliers, the trend signals a need for tighter controls. Simple steps such as confirming beneficiary details through a separate channel, limiting the number of new beneficiaries per day, and educating staff about vishing can reduce exposure.

Why the fraud keeps outrunning the technology

SABRIC’s own framing, that the apps are not being hacked, is the single most important detail in this data for a business owner to internalise. Banking-app security has genuinely improved over the same period these losses have risen, which means the growth in fraud value is being driven almost entirely by social engineering rather than any technical vulnerability in the banking software itself. That distinction matters because it means no banking app update or security certification can fully close this gap: a criminal who successfully manipulates a victim into approving their own fraudulent transaction defeats even a technically flawless app, since the app is correctly doing exactly what an authenticated user told it to do. For a business handling client or supplier payments through mobile banking, the practical implication is that staff training on recognising manipulation tactics is now at least as important a control as any software safeguard.

This report is based on a wire report from businesstech.co.za.