South Africa recorded 123 reported occupational-fraud cases in the ACFE’s 2026 Occupational Fraud Report, the highest number recorded in sub-Saharan Africa. That represents 31% of the 397 cases reported across sub-Saharan Africa. Nigeria was second with 64 cases and Kenya had 33.
Occupational fraud is particularly difficult for businesses to confront because it involves people inside the organisation, including employees, managers and executives who may have access to systems, information and financial controls.
The report defines occupational fraud as fraud committed by people inside an organisation or abusing a position of trust, including employees, managers, executives and suppliers.
Banks, fintechs, investment platforms and other financial-service providers are investing heavily in cybersecurity.
But is the complex network of third-party providers, technology partners, verification services, cloud platforms and outsourced services they depend on as well protected as their internal operations?
Recent incidents in SA
In September, EasyEquities and Bidvest Bank both notified customers of cybersecurity incidents involving a third-party service provider.
EasyEquities said the provider was used for client-verification checks and that there was no evidence its own systems or client trading accounts had been compromised.
Bidvest Bank similarly said data was held in the affected third-party environment, although the extent of any access was still being investigated. Cell C Fibre also warned customers about a related third-party incident.
The incidents illustrate a fundamental challenge for financial-sector executives: an organisation can have strong internal cybersecurity controls and still be exposed through a weakness somewhere in its technology and service-provider ecosystem.
“In the field, we sometimes see a relaxing of critical checks and balances, especially as the relationship between the organisation and its providers matures,” says David Loxton, CEO at Loxton Forensics.
Left unchecked, such complacency could spell a cybersecurity disaster with severe legal consequences and reputational damage.
A growing threat
With the introduction of AI and AI agents, new and dangerous forms of attack have become available to cybercriminals, state-sponsored groups, hacktivists, and anyone else wishing to breach corporate systems. That’s in addition to existing methods.
Cybersecurity is no longer a set of tried-and-true principles, but an evolving battleground on which organisations must continually adapt.
For financial institutions, the consequences of a breach extend beyond the immediate loss or exposure of data. A compromised third party can potentially create regulatory, operational, contractual and reputational consequences for the bank, fintech or investment platform that entrusted it with customer information.
This new reality was illustrated in July when autonomous AI agents broke free of their sandboxed testing environment at OpenAI, accessed the internet, and launched an unauthorised cyberattack on the Hugging Face AI platform. Their reason: to obtain information needed to complete a task assigned by their trainers.
Imagine how much worse it could be in the hands of a determined cyberattacker.
“Organisations are rushing to keep up, but they need to assure themselves that their vendors are moving at the same pace and all routes in their service supply chain are locked down,” says Loxton.
Trust no one
Adhering to the principle of Zero Trust, companies should treat service providers and their systems as untrusted and vulnerable to attack, even if cybersecurity audits suggest otherwise.
This stance demands strict and continuous verification of every attempt by an external party to access, transfer, or process their data.
For banks and fintechs, this is particularly important because third-party relationships can involve highly sensitive customer information, identity-verification data, payment information and other regulated data.
“However, once the data is outside the organisation, providers must guarantee the appropriate level of system security required to protect it, one that cascades down to their own vendors,” says Loxton.
Most companies ensure they have ironclad contracts in place that bind their providers to strict SLAs, timely intrusion alerts, prompt patching, regular audits, and other good practices.
Trouble arises when human relationships interfere with and compromise these commitments. Loxton says the worst sin is leniency.
Relationship woes
He has come across poorly drafted contracts, even at some of the largest financial institutions in the country, that give too much leeway to vendors on how well they implement essential standards, simply because of their industry reputation or previous dealings.
Yet, even an ironclad contract can unravel over time. Renewals may be awarded without applying the same strict reviews performed at the initial signing.
“Unfortunately, the trust developed between the parties can lead to an almost automatic renewal that assumes, without question, that the vendor has maintained its original standard,” says Loxton.
Recent South African incidents involving financial-services companies and third-party providers demonstrate why this risk cannot be treated as a once-off onboarding exercise. A vendor that was considered secure when appointed may have changed its systems, suppliers, access controls or risk profile considerably by the time a contract comes up for renewal.
One-time deviations or lapses in compliance might be overlooked initially, but they become more pronounced with each contract extension or renewal.
“This can result in a fairly unregulated relationship with the vendor, leading to unacceptable operational and legal risks that go unnoticed until catastrophe strikes,” says Loxton.
Assured impartiality
Carrying out due diligence checks when onboarding a vendor is not enough. Non-compliance typically surfaces through ongoing monitoring, auditing of access rights, and reviewing incident notification obligations.
For financial institutions, this should extend to regularly reassessing the security of critical vendors and understanding where sensitive information travels beyond the organisation’s immediate perimeter.
That works best when a department independent of the service users is tasked with regularly monitoring the vendor, ensuring they are delivering what they are paid for, and reviewing contractual obligations for practical inconsistencies.
“Most importantly, this independent body should monitor and review the relationship between the approver and the vendor to ensure contracts are based on demonstrable value rather than industry reputation or personal trust,” says Loxton.