South Africa’s four major retail banks — Absa, First National Bank, Nedbank and Standard Bank — have issued a rare joint public alert warning customers about a surge in two related fraud typologies: voice phishing (also called “vishing”) and SIM-swap fraud, which are increasingly being used in combination by criminal syndicates to drain bank accounts in minutes.
In the vishing scheme, a caller impersonating a bank fraud officer contacts the victim and creates a sense of urgency by claiming their account has been compromised. The caller, using personal information harvested from social media or data breaches, convinces the victim to share their card details, PIN, or one-time password. Armed with this information, criminals complete the account takeover in real time while keeping the victim engaged on the phone.
The SIM-swap variant exploits weaknesses in mobile network operator verification processes. By persuading a network operator’s customer service agent to transfer a victim’s phone number to a new SIM card — using fraudulently obtained copies of ID documents — criminals intercept all OTP messages sent to that number, bypassing two-factor authentication protections that most banks now require for large transactions.
The banks have emphasised that no legitimate bank employee will ever ask a customer to share their PIN, OTP, or CVV number over the phone or via email. They have urged customers to immediately hang up on any caller claiming to be a bank representative and to verify directly with their branch or the bank’s official helpline number.
Customers who suspect they have been targeted are advised to immediately call their bank’s fraud hotline, lock their online banking profile, and contact their mobile network operator to flag potential SIM-swap activity. Early reporting is critical to improving the chances of fund recovery before transfers are processed.