
In March 2026, Standard Bank publicly warned about AI-generated voices, cloned emails and deepfake content being used to mimic legitimate bank communications and staff. This type of activity has continued through to mid-2026 with the South African Banking Risk Information Centre (Sabric) also warning that criminals are using AI tools to impersonate bank officials, create fake apps and manipulate digital platforms to steal money.
However, many local banks are still struggling with legacy tech, slow change processes, limited data visibility and a risk that is growing faster than their response.
According to the 2026 Anti-Fraud Technology Benchmarking Report from the Association of Certified Fraud Examiners, which includes input from sub-Saharan Africa, the AI-driven fraud schemes most cited as having increased significantly over the past two years were deepfake social engineering (44%) and consumer fraud and scams (38%).
What’s more, over the next two years, significant growth is expected in generative AI document fraud and forgery (55%), deepfake social engineering (55%) and deepfake digital injection (54%).
Despite this growing threat, the same report shows that only 7% of organisations are more than moderately prepared to detect and prevent AI-powered fraud.
It’s not theoretical anymore. South African consumers are already speaking to well-scripted AI agents posing as bank staff and being coached in real time over the phone to approve transactions and share credentials. In most cases, the fraudsters already hold key personal details like ID numbers, which instantly lowers a victim’s guard. Or attackers use a slight variation where they impersonate financial personalities rather than bank staff to carry out investment-endorsement fraud, as the Financial Sector Conduct Authority warned in June.
Widening gap
There is a widening gap between what consumers think their bank will do for them and what it actually can. Many still believe the bank will catch fraud before it reaches their accounts, but those days are gone. Once a customer has been socially engineered into giving away login details or approving a transaction themselves, there is often no control that can fully protect them. South Africans need to develop a higher degree of fraud intelligence, because the liability is shifting towards them.
While some banks have invested heavily in modernising their core systems, this security spend can remain trapped in a traditional mindset.
Read: South African fraud surge runs on trust, not hacking
Inside banks, fraud teams fight an uphill battle for budget. Senior decision-makers weigh current fraud losses of perhaps a couple of hundred thousand rand against the cost of integrating sophisticated AI-based controls. The question is whether it is simply cheaper to absorb those losses and adapt later, a calculation that is almost always reactive and usually too late. What gets missed is how quickly a R200 000 exposure becomes R10-million or R100-million once criminals find a weakness and exploit it at scale.

Local banks are fiercely competitive and remain understandably wary of sharing intelligence on confirmed fraud cases. The result is a cycle in which hard-won lessons stay siloed even as losses mount.
Data privacy rules further complicate collaboration, with regulations like Popia limiting how freely institutions exchange information on known fraudsters. Even within shared industry databases, conflicting signals (where the same ID is flagged as both victim and perpetrator) create uncertainty, reinforcing cautious and fragmented responses.
In contrast, fraud syndicates operate with a level of coordination that mirrors well-run enterprises, but with none of the regulatory pain. Organised networks systematically test vulnerabilities across onboarding processes, branch staff and call centres, before pooling insights to refine their tactics. While banks treat fraud prevention as a competitive advantage, criminals treat it as a shared intelligence exercise.
Rethinking the checkpoint
For decades, banking security has rested on a single moment of truth: the login. Get past the password, the OTP and the security question, and you are in – trusted for the rest of the session. That made sense when the biggest threat was a stolen card or a guessed password. It makes far less sense now.
A fraudster coaching a victim by phone does not need to break in. The customer opens the door themselves, often mid-call, still convinced they are talking to their bank. No amount of front-gate security stops fraud that walks through with a legitimate, if manipulated, user behind it.
Read: SA’s digital economy is booming – but so is the fraud that comes with it
The shift this demands is away from a single checkpoint and towards continuous authentication: watching how someone behaves, not just what they type. Typing rhythm, device fingerprints, navigation patterns and the context around a transaction all carry signals a static login never could. A customer who logs in normally but then hesitates over instructions, moves through screens in an unusual order and initiates a transfer that breaks every pattern in their history is telling the system something a password cannot.

Rule-based systems that simply pile on verification steps punish genuine customers as often as they catch criminals, and syndicates learn to route around fixed rules quickly enough anyway.
The more durable answer is to treat risk as something that moves, reassessing it at every meaningful step – login, adding a beneficiary, changing a password, pushing through a large transfer – so that authentication strength flexes with what is actually happening rather than being fixed at the door.
It’s a mindset change as much as a technology one: banks stop asking, “Did this person get in correctly?” and start asking, “Does everything about this session still look like the person we think it is?” Institutions that treat login as the sole moment of trust will keep discovering, after the money has moved, that it was misplaced.
No luxury of waiting
Local banks no longer have the luxury of waiting. External pressure is beginning to mount, with international card schemes such as Visa and Mastercard enforcing fraud thresholds and imposing penalties on non-compliant institutions.
South African banks can take heart that they are not facing this challenge alone. According to a new intelligence report from Liminal, global financial institutions are facing a sharp increase in AI-driven identity fraud, with one institution reporting 8 065 deepfake attempts in eight months, tied to US$347-million in verified losses.
Read: Hackers are hiding malware behind AI agents that antivirus cannot see
Stronger analytics, ongoing verification and better consumer education are all part of the answer, but the first step is acknowledging that the balance of power has shifted. Sabric’s 2025 annual banking crime statistics, published this week, show digital banking crime losses climbing to R2.4-billion from about R1.9-billion in 2024, with banking apps accounting for more than 70% of reported digital banking losses. We cannot afford to keep playing catch-up.
- The author, Nishan Maharaj, is fraud analyst at Entersekt
- Subscribe to TechCentral’s daily newsletter
- Get breaking news alerts on WhatsApp



