Cyber criminals often approach financial fraud by targeting the exact grey area where business and customer incentives can struggle to align: the point of transaction. It’s here that customers want instant and seamless, but businesses need to secure and verify.

By Doros Hadjizenonos, regional director: southern Africa at Fortinet

It’s a layered issue. Nearly seven in ten online shopping carts worldwide are abandoned before checkout completes, according to the Baymard Institute, and clunky payment steps are consistently one of the leading reasons why.

A separate global survey by payments company Checkout.com found the opposite failure mode is just as costly: two in five shoppers said they had abandoned a cart specifically because they didn’t trust a site with their card details. Retailers are being punished for too much friction and too little visible security, sometimes on the same page, sometimes with the same customer.

South Africa has already run a version of this experiment at national scale. Instant payment rails and disruptive innovations for sending and receiving money have rapidly been built to strip out friction entirely – often a cellphone number is all that’s required. But a payment that settles in ten seconds can also be exploited in the same timeframe.

 

Where the fraud has moved

SABRIC’s most recent figures put 2025 banking fraud losses at R3.9 billion, with banking apps accounting for roughly two-thirds of reported incidents. The detail that matters is how those incidents happen: overwhelmingly through phishing, OTP interception and impersonation, rather than anyone breaching a bank’s actual systems.

A BioCatch survey of 100 South African bank fraud published in May 2026 found that three-quarters are reporting rising attack volumes, driven by faster payments, generative AI tools, and organised syndicates working across borders. Criminals are attacking at the very moment a legitimate customer proves who they are, which is precisely the moment every product team is under pressure to make shorter.

This shift is forcing organisations to move beyond traditional perimeter-based security models. Effective protection is increasingly dependent on continuous monitoring, threat intelligence and the ability to detect anomalous behaviour across the network, applications and user sessions as attacks unfold.

 

What passkeys actually fix

Passwords were never the most ideal compromise between security and convenience; they were simply the compromise everyone had already accepted. The FIDO Alliance’s State of Passkeys 2026 report, based on research across 11 000 consumers and 1 400 enterprise decision-makers, found passkey logins succeed 93% of the time versus 63% for passwords, with an estimated 5 billion passkeys now in active use worldwide. For once, a security control is measurably improving convenience rather than trading against it.

Yet the same report found that 57% of organisations still rely on phishable methods for everyday employee sign-in, even where passkeys have been deployed elsewhere in the business. Buying the technology and actually retiring the weaker option behind it are two different projects, and most organisations have only finished the first one.

Security leaders also need visibility into how new identity technologies are being adopted across the business. Without integrated monitoring and policy enforcement, organisations can unintentionally create inconsistent security controls that leave gaps for attackers to exploit.

 

Friction that doesn’t feel like friction

The more durable fix is not removing verification but making most of it invisible. Retailers and banks are increasingly checking device, location, and behavioural signals in the background, and reserving the visible speed bumps – a one-time PIN, a biometric prompt, a manual review – for the small share of transactions that look risky. Done well, a regular customer buying groceries on a familiar phone never sees a challenge screen.

A first-time purchase of a R30 000 item from a new device, at 2am, on a device that has never touched that account before, sees several. The friction hasn’t disappeared altogether, but it has been redirected toward the transactions that deserve it, instead of applied evenly to everyone as a blunt, one-size-fits-all tax on doing business.

AI is playing an increasingly important role in this process, helping organisations analyse vast volumes of behavioural and contextual data in real time. By using intelligent analytics to identify higher-risk activity, security teams can respond faster and focus resources where they are needed most, while allowing low-risk transactions to proceed with minimal disruption.

Getting that right is a product decision as much as a security one, which is exactly why it so easily falls through the cracks between departments measured on conversion and departments measured on losses. Instant payment innovations proved that South Africans will adopt a frictionless payment method at extraordinary speed once the friction is removed.

The open question is whether the industry can rebuild the safety net as quickly as it tore out the queue. Achieving that balance will require security to be embedded into the digital experience itself, supported by integrated platforms, with AI-powered threat detection and real-time risk assessment that enables trust without sacrificing convenience.