Banking Sector Sounds Alarm: Cybercrime Attacks Up 40% in One Year With Losses Exceeding R2 Billion

By Sipho “The Investigator” Ndlovu | Hard News & Strategy Editor, EZA News


A major South African bank has reported a 40% increase in cyber attacks against its systems and customers over the past twelve months, with total losses from successful attacks exceeding R2 billion – a figure that represents not just a financial shock but a structural warning about the readiness of South Africa’s financial infrastructure to withstand the escalating sophistication of criminal cyber operations.


The nature of the attacks has evolved in ways that make traditional perimeter defences insufficient. The most significant losses are no longer coming from the blunt-force attacks of earlier generations of cybercrime – brute force password attempts, basic phishing emails, unsophisticated malware. The current threat profile involves highly targeted social engineering campaigns, credential theft operations that harvest banking login information through fake applications and fraudulent websites that are visually indistinguishable from legitimate banking portals, and increasingly sophisticated SIM-swap fraud that circumvents two-factor authentication by taking control of a victim’s mobile number.

The R2 billion loss figure almost certainly understates the true cost when downstream effects are included: the operational cost of incident response, the customer attrition that follows high-profile breaches, the investment required in upgraded security infrastructure, and the reputational damage that affects banking relationships across both retail and institutional client segments.

South Africa’s banking sector is among the most developed on the continent, which makes it both a more attractive target for sophisticated criminal operations and a more capable responder to them than financial systems elsewhere in the region. But capability is relative, and the 40% increase in attack frequency demonstrates that the sophistication of the threat is currently outpacing the pace of defensive adaptation. The South African Banking Risk Information Centre has previously warned that South Africa ranks among the highest-risk countries globally for cyber fraud relative to the size of its financial sector.

The practical implications for ordinary South Africans are significant and immediate. The most effective defensive layer is customer behaviour – not clicking links in unsolicited communications, verifying banking application authenticity before downloading, treating any unexpected request for OTP codes as a probable fraud attempt, and reporting suspicious activity immediately. These are not complicated instructions, but their consistent application requires a level of digital literacy that remains unevenly distributed across South Africa’s population.

The regulatory and legislative environment is also under pressure to respond. South Africa’s Protection of Personal Information Act places legal obligations on institutions that suffer data breaches, but the enforcement framework is still maturing. Whether the Information Regulator has the capacity and the political backing to hold major financial institutions to account for preventable breaches is a question that the 40% attack increase figure makes newly urgent.

About The Author