The Scam Doesn’t Look Like a Scam Anymore (Here’s How SMEs Stay Safe)

Most South African SMEs already know cybercrime exists. What has changed is how realistic scams have become and how often they target everyday business processes: email, supplier payments, and account logins.  

Threat intelligence reporting shows the pressure is increasing. In January 2026, South African organisations faced an average of 2,145 cyberattacks per week (reported as a 36% year on year increase), with commentary linking the environment to ransomware activity and wider Gen AI related exposure risks.  
That does not mean every attempt succeeds, it means SMEs operate in a high attempt environment where the safest approach is steady habits and sensible controls, not fear.  

What’s “most recent” in scam tactics right now

scam

1. Impersonation is sharper and it’s the main play 

Criminals increasingly impersonate trusted brands and institutions because it works: banks, suppliers, couriers, and sometimes SARS. SARS itself keeps an updated list of scam examples (summons, penalties, demands, audit/refund themes, and more), which shows how persistent and believable these messages can be.  

Why SMEs should care: impersonation targets decisions especially around payments and access not “IT systems” in isolation.  

 

2. AI is being used to make scams feel “clean” and convincing 

The South African Banking Risk Information Centre (SABRIC) has warned that criminals are using AI-generated content (including WhatsApp messages) and even voice cloned deepfakes and cautioned that real-time deepfake audio/video may become more common.  

What this means in real life: fewer obvious mistakes, more natural language, and more pressure tactics that sound credible.  

 

3. Ransomware remains a business risk (downtime, disruption, recovery) 

Verizon’s 2025 Data Breach Investigations Report (DBIR) reports ransomware is present in 44% of breaches, reinforcing that this is not a rare edge case. 
Recent threat commentary also points to ransomware activity as part of the broader environment SMEs operate in.  

For SMEs: the risk is not only the “attack” it’s the operational impact that follows, which is why preparation matters more than panic.  

 

4. Third-party exposure is rising 

Modern SMEs rely on vendors, cloud platforms, and partners. Verizon’s 2025 DBIR reports third-party involvement doubled to 30% of breaches.  

Translation for SMEs: security is no longer just about your devices it’s also about supplier interactions and shared systems.  

What to look out for (without becoming paranoid)

You don’t need to catch every scam. The practical goal is to recognise high risk moments and apply a consistent check. 

Treat these as “slow down and verify” moments

1. Anything involving money 
Payments, refunds, beneficiary changes, “urgent transfer” requests.  

2. Anything involving logins or access 
Password resets, “verify your account”, “confirm your login”, unexpected MFA prompts. 

3. Anything involving sensitive information 
Banking details, IDs, OTPs, staff/customer data.  

4. Any message that creates urgency or fear 
“Final demand”, “legal action”, “account will be blocked”. SARS impersonation is one example of this pattern because it triggers compliance fear and deadlines.  

5. Anything that bypasses your normal process 
“Don’t call”, “I’m in a meeting”, “just approve it”, “use these new bank details”.  

These aren’t technical red flags they’re process red flags. 

The SME friendly rule that reduces risk the most

Don’t verify inside the message. Verify outside the message.

In practice: 

  • Don’t click the link in the email/SMS/WhatsApp. 
  • Don’t use the number included in the message. 
  • Don’t confirm a payment change by replying to the same thread. 

Instead: 

  • Open the site from a bookmark or type the address manually. 
  • Call a known number from your records. 
  • Confirm changes using a second channel (especially for payments). 

This keeps business moving but adds one safety layer where it matters most money, access, and sensitive information is and should be verified. 

Risk and mitigation (practical layers for South African SMEs)

Cyber risk can’t be eliminated entirely but it can be reduced and managed with controls that fit real SME operations. 

1. Email & phishing protection 

Reduces the number of harmful messages that reach staff and helps prevent impersonation attempts landing in inboxes.  

2. Access control (MFA + sensible permissions) 

Credential abuse and exploited access are major entry routes in large breach datasets; tightening access reduces the blast radius if something slips through.  

3. Payment controls 

A simple payment rule banking detail changes must be verified independently prevents a large portion of invoice/payment diversion style incidents.  

4. Backups + recovery readiness 

Ransomware remains common; tested backups and a recovery plan protect continuity.  

5. POPIA ready incident handling 

POPIA enforcement is real world. A well-publicised case involved a R5 million administrative fine, and POPIA allows administrative fines up to R10 million, reinforcing why structured incident readiness matters.

If it happens: what to do (calm, fast, practical)

If someone clicked, entered credentials, or actioned a suspicious request: 

1. Contain quickly 
Disconnect the affected device from the internet if you suspect compromise.  

2. Secure access 
Reset passwords (start with email), enable MFA, and check for mailbox rules/forwarding changes. 

3. Protect cash flow 
Review recent payments and beneficiary changes; contact the bank quickly if money or approvals were involved.  

4. Escalate early 
Engage professional support to assess scope and reduce downtime.  

5. If personal information may be involved 
Document what happened and handle appropriately under POPIA.  

Frequently asked questions (for SME owners and finance/admin teams)

What are common examples of impersonation scams SMEs are seeing?

Criminals usually impersonate organisations or people you already deal with. Common examples include: 

  • Banks – messages about “suspicious activity”, “account verification”, or urgent approval prompts.  
  • Suppliers – emails advising “updated banking details” or asking for urgent payment confirmation.  
  • Couriers/service providers – delivery notices or invoices with links or attachments.  
  • Payroll/HR platforms – requests to reset passwords or confirm access. 
  • SARS – messages referring to audits, penalties, refunds, or legal consequences (SARS lists examples of these scam formats publicly).  

The organisation changes, but the approach is consistent: urgency + authority + pressure to act quickly. 

How do we stay alert without becoming paranoid?

Focus on high impact moments, not every message. 

Treat anything involving money, logins/access, sensitive information, or changes to normal process as a reason to slow down and verify independently. Everything else can continue as normal. 

Do we need to understand cybercrime in detail to operate safely?

No. What matters most is recognising when a message pushes urgent action or shortcuts your normal process. Then verifying the information outside the message.  

Why are SMEs targeted so often?

Because SMEs move quickly, rely on trust, and handle real transactions daily and attackers exploit speed, access, and third-party connections.  

What should we do if something slips through?

Act early: contain, secure access, review financial activity, and escalate to professional support. Early action limits disruption and cost.  

Seitfin (built for SMEs)

Seitfin helps South African SMEs reduce risk without overcomplicating things, by putting practical layers in place where scams typically start: 

  • Email & phishing protection 
  • Firewall & endpoint protection 
  • Threat detection and prevention 
  • POPIA support (governance + incident readiness) 
  • Security best practice reviews and audits  

If you want to strengthen your controls without slowing down operations, contact Seitfin and ask about: 

  • SME cybersecurity options for email/phishing protection,  
  • endpoint/firewall protection,  
  • monitoring, and POPIA support.  

Secure Your Business Today

Cybersecurity doesn’t need to be complicated or expensive. Let’s protect your people, your data and your systems with smart, right-sized security.

Scroll to Top