AI fraud is outrunning South African banking defences
By Nishan Maharaj, Entersekt Fraud Analyst
South Africans are increasingly being targeted by AI-generated fraudsters who sound just like bank employees.
In March 2026, Standard Bank publicly warned about AI-generated voices, cloned emails and deepfake content being used to mimic legitimate bank communications and staff. This type of activity has continued through mid-2026 with the SA Bank Risk Information Centre (SABRIC) last month also warning that criminals are using AI tools to impersonate bank officials, create fake apps and manipulate digital platforms to steal money.
However, many local banks are still struggling with legacy tech, slow change processes, limited data visibility, and a risk that is growing faster than their response.
According to the 2026 Anti-Fraud Technology Benchmarking Report from the Association of Certified Fraud Examiners, which includes input from Sub-Saharan Africa, the AI‑driven fraud schemes most cited as having increased significantly over the past two years were deepfake social engineering (44%) and consumer fraud and scams (38%).
What’s more, over the next two years, significant growth is expected in genAI document fraud and forgery (55%), deepfake social engineering (55%), and deepfake digital injection (54%).
Despite this growing threat, the same report shows that only 7% of organisations are more than moderately prepared to detect and prevent AI-powered fraud.
Safety nets disappearing
It’s not theoretical anymore. South African consumers are already speaking to well‑scripted AI agents posing as bank staff and being coached in real time over the phone to approve transactions and share credentials. In most cases, the fraudsters already hold key personal details like ID numbers, which instantly lowers a victim’s guard. Or attackers use a slight variation where they impersonate financial personalities rather than bank staff to carry out investment-endorsement fraud, as the Financial Sector Conduct Authority warned in June.
This challenge is exacerbated by a growing gap between what consumers think banks will do for them, and what they actually can or will do when AI fraud is involved.
The wider problem is that many consumers still believe their bank will catch fraud before it hits their accounts. But those days are gone. Once a customer is socially engineered into giving away login details or approving a transaction themselves, there is often no control that can fully protect them. South Africans need to develop a higher degree of fraud intelligence because the liability is now shifting toward them.
The quiet before the storm
While some banks have invested heavily in modernising their core systems, this security spend can remain trapped in a traditional mindset.
Inside banks, fraud teams fight an uphill battle to secure budgets. Senior decision-makers look at current fraud losses of perhaps a couple of hundred thousand rand and weigh them against the cost of integrating sophisticated AI-based controls. The uncomfortable business question is whether it’s just cheaper to absorb the current losses and adapt controls, which is often too late and reactive. What then gets missed, however, is how quickly that R200 000 exposure can jump to R10 million or R100 million once criminals find and exploit a weakness at scale.
Banks more encumbered than the fraudsters
Banks face additional challenges that fraudsters aren’t encumbered by. Local banks are incredibly competitive and remain understandably wary of sharing intelligence on confirmed fraud cases. The result is a cycle in which hard-won lessons remain siloed, even as losses mount.
Data privacy rules further complicate collaboration, with regulations like POPIA limiting how freely institutions exchange information on known fraudsters. Even within shared industry databases, conflicting signals (where the same ID is flagged as both victim and perpetrator) create uncertainty, reinforcing cautious and fragmented responses.
In contrast, fraud syndicates operate with a level of coordination that mirrors well-run enterprises, but with none of the regulatory pain. Organised networks systematically test vulnerabilities across onboarding processes, branch staff, and call centres, before pooling insights to refine their tactics. While banks treat fraud prevention as a competitive advantage, criminals treat it as a shared intelligence exercise.
Rethinking the checkpoint
For decades, banking security has rested on a single moment of truth: the login. Get past the password, the OTP, the security question, and you’re in – trusted for the rest of the session. That model made sense when the biggest threat was a stolen card or a guessed password. It makes far less sense now.
AI has broken the assumption that a login is a reliable proxy for identity. A fraudster coaching a victim by phone doesn’t need to break in. The customer opens the door themselves, often mid-call, still convinced they’re talking to their bank. No amount of front-gate security stops fraud that walks through with a legitimate, if manipulated, user behind it.
The shift this demands is away from a single checkpoint and toward continuous authentication: watching how someone behaves, not just what they type in. Typing rhythm, device fingerprints, navigation patterns, the context around a transaction, all of these carry signals that a static login never could. A customer who logs in normally but then behaves in ways that don’t match their history, for example hesitating over instructions, following an unusual sequence of screens, initiating a transfer that breaks every pattern in their history, is telling the system something a password never can.
Rule-based systems that simply pile on extra verification steps tend to punish genuine customers as often as they catch criminals, and syndicates learn to route around fixed rules quickly enough anyway. The more durable answer is treating risk as something that moves, reassessing it at every meaningful step, from login through to adding a beneficiary, changing a password, or pushing through a large transfer, so that authentication strength flexes with what’s actually happening, rather than being fixed at the door.
It’s a mindset change as much as a technology one: banks stop asking “did this person get through the front door correctly?” and start asking “does everything about this session still look like the person we think it is?” Institutions that keep relying on login as the sole moment of trust will keep discovering, after the money has moved, that trust was misplaced.
A sense of urgency
Local banks no longer have the luxury of waiting. External pressure is beginning to mount, with international card schemes such as Visa and Mastercard enforcing fraud thresholds and imposing penalties and fines on non-compliant institutions.
South African banks can take heart that they are not facing this challenge alone. According to a new intelligence report from Liminal, global financial institutions are facing a sharp increase in AI‑driven identity fraud, with one institution reporting 8 065 deepfake attempts in eight months, tied to $347 million in verified losses.
Stronger analytics, ongoing verification, and better consumer education are all part of the answer, but the first step is acknowledging that the balance of power has shifted. Sabric’s 2025 annual banking crime statistics, published this week, show digital banking crime losses climbing to R2.4-billion from about R1.9-billion in 2024, with banking apps accounting for more than 70% of reported digital banking losses. We cannot afford to keep playing catch-up.
