South Africa’s telecommunications sector is facing a rapidly intensifying wave of fraud, cybercrime and interconnected operational threats, with subscription fraud cases surging 307% in a single year.

This is according to the new Communications Risk and Information Centre (COMRiC) Telecommunications Sector Report 2026, which adds that the sector has entered what it describes as an “active systemic-risk phase”, where cyberattacks, fraud, infrastructure crime, energy volatility, civil unrest, regulatory pressure, climate events and supply-chain disruption increasingly amplify one another.

The report shows that subscription fraud climbed to 14 897 cases in the 12 months to April 2026, with every month recording more incidents than the corresponding period a year earlier. March was the worst month, with 2 475 cases. While the average loss per case fell 75% to around R13 400, total subscription fraud losses still reached R198,9-million.

SIM-swap fraud added a further 383 cases and R4,26-million in losses, pushing the combined financial impact of subscription and SIM-swap fraud beyond R200-million during the period reviewed.

COMRiC CEO Advocate Thokozani Mvelase says the numbers reveal a fundamental change in telecommunications fraud: “The real warning in these numbers is not simply how much money is being lost in an individual case. It is the extraordinary increase in the number of attacks. Criminals are reaching more people, more often, and they are doing it through channels that consumers know and trust.

“WhatsApp messages, phone calls, SMSs, and increasingly sophisticated impersonation scams have become a major gateway for fraud. Technology remains essential to protecting customers, but technology alone cannot solve a problem where human trust itself has become the attack surface.”

The report finds that social engineering conducted through trusted communications channels is increasingly replacing purely technical attacks as the preferred route into victims’ accounts, while criminals are beginning to use AI-generated voices, deepfakes and more convincing impersonation techniques. International research cited in the report projects deepfake fraud to rise sharply during 2026, while voice cloning can now be achieved using only a few seconds of recorded audio.

The sheer volume of unwanted and potentially fraudulent communications is also accelerating. The report cites 8,72-billion spam calls in South Africa during the first quarter of 2026 alone, including 3,33-billion in March, while 1,92-billion spam messages reached consumers.

Cyber risk is also escalating beyond the traditional boundaries of corporate IT departments. South African organisations are experiencing around 2 065 cyberattacks a week, while cyberattacks on the telecommunications sector have increased by 13%. COMRiC identifies ransomware, distributed denial-of-service attacks, state-sponsored cyber activity, and the potential for attacks to spread through shared infrastructure and supply chains as major threats.

Mvelase says the critical concern is that these risks can no longer be treated as separate problems: “A cyber incident does not necessarily stop at the boundary of one company. A stolen cable can make recovery from another crisis harder. Civil unrest can prevent technicians reaching critical infrastructure, while an energy shock can immediately raise the cost of keeping networks operational.

“No single operator can see that entire risk picture on its own. That is why COMRiC exists. By bringing intelligence together across the industry, we can identify how individual threats connect and give the sector a much stronger early-warning capability.”

The report does, however, provide compelling evidence that coordinated intervention can deliver results. Telecommunications infrastructure crime fell from 15 917 incidents in the previous financial year to 9 579 in 2025/26, a decline of 40%. Financial losses also fell sharply, with quarterly losses declining from R73,5-million at the beginning of the reporting period to R42,2-million in the final quarter. Around one in six attempted incidents was stopped before completion, suggesting that increased security, monitoring and rapid response are having a measurable effect.

Battery theft fell by around 90%, while armed-response callouts also dropped dramatically. But the report cautions that criminal activity is shifting rather than disappearing. Copper cable theft remains chronic at 256 incidents a month, while the Western Cape was the only province to record an increase in infrastructure crime, with incidents more than doubling from 553 to 1 184.

Mvelase says the decline in infrastructure crime demonstrates what sustained industry action can achieve: “A 40% reduction in infrastructure crime is significant. It tells us that investment in prevention, better intelligence sharing, stronger site protection and coordinated intervention is working.

“But organised crime adapts. When one avenue becomes more difficult, criminals move to another asset, another method, or another province. The lesson is not that the problem has been solved. The lesson is that prevention works and that we cannot afford to ease the pressure.”

COMRiC also highlights what it describes as a serious criminal justice and deterrence gap. Of 1 280 suspects arrested in connection with telecommunications infrastructure crime, only 291 resulted in convictions, producing an arrest-to-conviction rate of just 22,7%. The report points to slow prosecutions, withdrawn cases and repeat offenders receiving bail as continuing weaknesses in the fight against organised infrastructure crime.

Mvelase says stronger cooperation between telecommunications companies, law-enforcement agencies and the criminal justice system will be essential if the gains made against infrastructure crime are to be sustained.

“Operators can harden sites, improve surveillance and stop more attacks, but there is a limit to what industry can achieve if criminals believe the consequences of being caught are low.

“We need to convert more arrests into convictions, disrupt the syndicates behind these crimes and recognise telecommunications infrastructure for what it is, critical national infrastructure on which businesses, communities and millions of South Africans depend.”

COMRiC says the next phase of its work will focus on deeper cross-operator intelligence sharing, joint action against criminal syndicates, stronger collaboration with SAPS, the Hawks and the NPA, greater public awareness around social engineering and the development of intelligence systems that allow the telecommunications sector to move from reacting to incidents towards anticipating them.

“The uncomfortable message from this report is that the risks facing telecommunications are moving faster, becoming more sophisticated and increasingly crossing the boundaries between companies, industries and government institutions.

“But there is another message too. Where the sector shares intelligence, coordinates its response and acts collectively, we are seeing tangible results. Our task now is to identify the next threat earlier and act before it becomes the next crisis.”