Cyber criminals see opportunity in the current financial pressure and misplaced trust in AI across South Africa. SARS auto-assessments were issued in July, with non-provisional filing open until 23 October.
Two-pot retirement withdrawals continue monthly, and in June, the FSCA warned the public about a deepfake video using News24 financial journalists Maya Fisher-French and Bruce Whitfield to promote a fraudulent investment scheme.
Anna Collard, SVP content strategy and CISO advisor at KnowBe4 Africa, sees the pattern behind the dates.
“Fraudsters follow the money and the calendar,” she says. “Right now, both point at retirement savings.”
The overconfidence gap
KPMG and University of Melbourne research shows emerging markets, including South Africa, trust AI more than advanced economies do. 62% of South Africans say they’re willing to trust AI, against a global average of 46%. Only a quarter believe its risks outweigh its benefits. Globally, two-thirds of people admit they rely on AI output without checking whether it’s accurate.
KnowBe4’s own From Agentic Risk to Human Wins report found 86% of South African respondents agree that deepfakes have become so realistic it’s harder to know what to trust.
“So, people accept that the threat is real and hard to detect. They just don’t believe it applies to them,” says Collard.
Overconfidence is the real vulnerability and is a known pattern in security behaviour. “We rate the risk accurately but rate ourselves generously. We think bad things happen to other people. And generative AI has removed the bad grammar, the wrong logo and the stiff voice, while leaving our confidence entirely intact.”
Her conclusion is blunt. “Trust should attach to the channel, not the content. A video of someone you recognise, a message in a familiar voice, a polished PDF, none of it is evidence of anything anymore.”
Why the timing is dangerous
Tax season means millions of South Africans are expecting legitimate communication from SARS, often about a refund. That’s perfect cover for impersonation.
Two-pot adds confusion on top. Savings-pot withdrawals are taxed at your full marginal rate from the first rand, unlike retirement lump sums, which carry a lifetime exemption. If a withdrawal pushes you into a higher bracket, the portion above the threshold is taxed at the higher rate. And if you owe SARS money and haven’t arranged to pay it off, that debt comes off your payout before you see it.
Most of that money is being withdrawn out of necessity. Momentum reports that 71% of claims fall below R10 000, with the average claim down from R12 666 in September 2024 to R9 290 in March 2026. More telling: only 5% of this year’s claims are first-time withdrawals. 62% are people withdrawing for the third time.
“Urgency, financial stress and unfamiliar processes are precisely the conditions social engineering exploits,” says Collard. “Scammers don’t need to be clever when someone is already stressed, already expecting a message about their money, and already unsure what the correct process looks like.”
Where AI’s advice breaks down locally
“AI tools are fluent, and we mistake fluency for expertise,” Collard says. A chatbot will explain retirement withdrawals in confident, well-structured English drawn largely from US or UK sources – 401(k)s, ISAs, IRAs – none of which apply here.
“An AI tool that doesn’t understand two-pot will tell you a R50 000 withdrawal is a reasonable emergency measure. You’ll discover months later that the number in your bank account was never the number you planned around.”
The regulatory blind spot is worse. AI can’t tell you whether a product is FSCA-regulated or whether the person offering it is authorised for that risk category. “It would happily describe an unlicensed scheme in the same authoritative tone it uses for a legitimate one. Use these tools to understand concepts and formulate better questions. Don’t use them as your adviser.”
The one rule that still works
Don’t try to spot the deepfake. Detection is a battle you will eventually lose, and the FSCA register won’t save you either, hijacked FSP numbers and cloned websites are standard practice now.
“Verify through a channel you started yourself, not the one the message handed you,” says Collard. In practice:
- Never reply to the message. Go to the source you already had. Your fund’s app. The number on your benefit statement. Not a number, link or QR code from the message and not one you found by searching, either.
- Take 24 hours. No legitimate financial institution loses anything if you sleep on it. Only a scammer does.
- Treat guaranteed high returns as disqualifying. Legitimate providers are required to disclose that you can lose money. And no real provider solicits investments through WhatsApp, Telegram, TikTok or Instagram DMs.
- Check the tax before you commit. Model the net amount you’ll actually receive, and check what you owe SARS via eFiling or the MobiApp first.
“A human adviser becomes essential,” Collard says, “for any decision that’s irreversible, any amount that materially affects your retirement, anything involving a transfer between funds, and – critically – the moment you feel rushed or emotionally pressured.”
“AI can help you prepare for that conversation,” she says. “It can’t take accountability for the outcome, and it won’t be there in ten years when the consequences land.”