The Attacks You’ll Actually See

Not a list of scary hacker jargon — the handful of things that actually cost South African businesses money and customers, explained plainly, with real local examples.

The Glossary

Six Attacks You’ll Actually See

Skip the jargon. These are the six patterns behind almost everything that goes wrong for a South African business — and the one habit that stops each of them.

01

Business Email Compromise (BEC) / Invoice Fraud

Someone impersonates a supplier, your boss, or your own finance team by email — often from an address that looks almost right — and asks for banking details to be changed, or an invoice to be paid urgently. No malware, no hacking. Just a very convincing email and someone in a hurry.

The one thing that stops it

Never change payment details or approve an urgent payment based on an email alone — phone the person on a number you already have, not one from the email.

02

Phishing

An email, SMS, or WhatsApp message designed to get you to click a link and hand over a password or one-time PIN, or open an attachment that installs something bad. The starting point for most of the incidents below.

The one thing that stops it

Treat any message asking you to “verify,” “confirm,” or “urgently action” something as suspicious until proven otherwise.

03

Ransomware

Malware that quietly spreads through your systems, encrypts everything it can reach, then demands payment to unlock it. Often sits undetected for weeks before triggering. Can shut a business down completely, not just slow it down.

The one thing that stops it

Backups that are actually tested and kept somewhere the ransomware can’t also reach.

04

Credential Stuffing & Weak Passwords

Attackers take passwords leaked from one breach (any breach, anywhere) and try them against other accounts — because people reuse passwords. A weak, guessable password with no second check is often all it takes.

The one thing that stops it

Multi-factor authentication, everywhere it’s offered — it turns a stolen password into a dead end.

05

SIM-Swap Fraud

An attacker convinces or bribes their way into taking control of your phone number, then intercepts the one-time PINs your bank sends you — bypassing the very thing meant to protect you.

The one thing that stops it

App-based authentication (not SMS) where your bank offers it, and treating an unexpected “no signal” on your phone as a red flag, not an inconvenience.

06

Third-Party & Vendor Breaches

Your own security can be airtight and you can still be exposed — because a marketing contractor, statement provider, or other vendor you trusted with customer data wasn’t as careful as you were.

The one thing that stops it

Ask vendors handling your customer data what their security actually looks like, before you hand it over, not after something goes wrong.

It’s Already Happened Here

Ten Real South African Breaches

Fact-checked against the Information Regulator, the Reserve Bank, and company statements. Each one tagged back to the glossary above — honestly, not by force.

01

Experian South Africa

August 2020
Social engineering closest fit — not a hack, a con

A fraudster posed as a legitimate business client during Experian’s own onboarding process, requesting data for what looked like a normal marketing-leads deal. The deception only surfaced when the “client” didn’t pay and internal checks flagged the transaction.

Impact
~24 million individuals and 793,749 businesses had personal details (names, ID numbers, addresses, contact details) exposed. No financial or credit data was accessed.
Takeaway
The biggest data exposure on this list wasn’t a hack at all — it was someone talking their way past a verification process.
02

Nedbank

February 2020
Third-Party & Vendor Breaches

An external direct-marketing contractor handling SMS/email campaigns on Nedbank’s behalf was breached. Nedbank’s own core banking systems were never touched.

Impact
~1.7 million customers (1.1 million active, ~600,000 former) had personal details exposed.
Takeaway
The bank’s own security was fine. The vendor’s wasn’t — and customers were exposed anyway.

Dis-Chem’s third-party e-statement provider was hit by a brute-force attack — attackers simply guessed weak, poorly-protected database passwords. Dis-Chem notified the Information Regulator within days of discovering it, but South Africa’s Information Regulator later found the security measures at the vendor were inadequate and that no proper data-handling agreement was in place between Dis-Chem and that vendor.

Impact
~3.6 million customer records (names, emails, cellphone numbers) exposed.
Takeaway
Notifying people quickly is the right move — but it doesn’t undo the obligation to make sure a vendor is actually secure before handing them your customers’ data.
04

TransUnion South Africa

March 2022
Credential Stuffing & Weak Passwords

Attackers used a stolen, valid login belonging to an authorised business client — reportedly secured with nothing stronger than the password “Password” and no second factor — to access an isolated database and demand a multi-million-dollar ransom.

Impact
TransUnion confirmed at least three million South Africans had data exposed. The attackers separately claimed far higher numbers (tens of millions of records), which TransUnion disputed and were never independently confirmed.
Takeaway
One weak password on one account, with no MFA behind it, was the entire attack.
05

Postbank

2018–2019
Doesn’t fit neatly this one’s about insider access and key handling, not an outside attacker

During a data-centre move, Postbank’s Host Master Key — the master code used to secure every card and ATM PIN on the network — ended up printed on paper and mishandled by insiders. The exact financial loss has been reported inconsistently across different investigations over the years, but the response gives a sense of scale: the South African Reserve Bank ordered roughly 12 million bank cards replaced, at an estimated cost of around R1 billion.

Impact
Nationwide card replacement, ~R1 billion cost.
Takeaway
Not every breach starts with a hacker. Sometimes it’s your own most sensitive material, mishandled by people who already had access to it.
06

Department of Justice and Constitutional Development

September 2021
Ransomware

Ransomware encrypted the department’s systems nationwide, disrupting bail services, deceased-estate processing, court records, and child maintenance payments. The department had let its antivirus and intrusion-detection software licences lapse.

Impact
In July 2023, the Information Regulator issued its first-ever POPIA fine — R5 million — specifically for failing to keep basic security software active.
Takeaway
An expired software licence, left unrenewed, became a national outage and a landmark fine.
07

Life Healthcare

June 2020
Ransomware

South Africa’s second-largest private hospital operator was hit by ransomware and took its entire network offline to contain it — forcing staff across the group back to pen and paper for admissions, billing, and clinical notes, during COVID-19.

Impact
66 hospitals across South Africa and Botswana affected; systems substantially restored within about a month.
Takeaway
Even an organisation that can fall back to paper still pays a heavy price — the attack didn’t stop patient care, but it stopped nearly everything else.
08

Transnet

July 2021
Ransomware

Ransomware forced South Africa’s state logistics operator to take its container-terminal systems offline and declare force majeure at every major port.

Impact
Durban, Cape Town, Port Elizabeth and Ngqura ports frozen for about a week; Durban alone handles roughly 60% of the country’s container traffic.
Takeaway
Ransomware doesn’t have to touch your money to cost you money — it froze an entire country’s shipping for a week.
09

Mukuru / Standard Bank Business Accounts

Fraud 2021–2022, arrests December 2024
SIM-Swap Fraud

A criminal syndicate performed unauthorised SIM swaps on business owners’ phone numbers, intercepting the one-time PINs meant to protect their banking, and drained funds from online business accounts. It took years of investigation before six suspects were arrested.

Impact
Over R18 million stolen.
Takeaway
The fraud itself happened in 2021–2022 — the arrests only came three years later. The financial damage is immediate; justice, if it comes at all, is not.
10

FT Rams Consulting

2024
Doesn’t fit neatly this one isn’t an attack at all, it’s a compliance failure

A consulting firm kept sending unsolicited marketing messages after a consumer formally asked to be removed from their lists — a straightforward POPIA direct-marketing violation, not a breach or a hack.

Impact
R100,000 fine, among the Information Regulator’s earliest enforcement actions — unpaid, with the Regulator now pursuing recovery through the courts.
Takeaway
You don’t need to get hacked to get fined under POPIA. Ignoring an opt-out request is enough.

Not Sure If This Has Already Happened to You?

Ten real South African breaches. Six ways they usually start. If any of this sounds familiar — or you’d rather find out before it does — ask one of your advisors.

Ask an Advisor Meet the Advisors