October is Cybersecurity Awareness Month and SABRIC’s latest figures show South Africans lost R2,4-billion to digital banking crime in 2025 – much of it to messages built to make someone pay before they think.

A prime example?  “Hi Mom, my phone broke. This is my new number, please save it.”

Most parents save the number without thinking twice. The second message asks for money. The banking app won’t work on the new phone, or there’s a lift to pay for and no other way home. By the time anyone thinks to check, the money sits in a stranger’s account and the child’s phone was working all along.

South Africans lost R2,4-billion to digital banking crime in 2025 – 29,2% more than the year before – across more than 110 000 incidents, according to the South African Banking Risk Information Centre’s (SABRIC) 2025 Annual Crime Statistics Report.

SABRIC attributes most of those losses to social engineering, in which criminals persuade people to approve the payments or hand over access themselves. The report specifically warns that payment requests arriving on WhatsApp should be checked through a trusted channel before any money moves.

“A criminal has no need to hack anything when a parent will open the banking app for them,” says Richard Ford, Group CTO at Integrity360. “The whole trick runs on 10 minutes of panic. They invent an emergency and count on the parent paying before anyone picks up the phone to check.”

 

When the message comes from their real number

The second version is harder to catch. Criminals take over a genuine WhatsApp account by talking its owner into sharing the six-digit registration code that WhatsApp sends by SMS. From there they message everyone in the contact list from a number and profile photo the family already trusts.

“Your daughter’s name and photo sit at the top of the chat, with years of family messages underneath,” says Ford. “Parents trust that thread completely, and whoever has taken over the account inherits all of that trust.”

Both versions get more convincing when the criminal has done some homework.

Integrity360’s Cybersecurity Awareness Month advice on social engineering warns that attackers gather details from social media, public profiles, and conversations. A public post about a child’s matric dance, gap year or first job hands a stranger the names and plans that make “Mom, it’s me” sound right.

 

Make the call yourself before you pay

A single call to the number already saved in your phone exposes the first version. For the second, reach your child another way: an ordinary phone call, an SMS, or a message to a friend or partner who is with them. Either way, you make the call. A voice note, or a call coming in from the new number, proves nothing.

“Set a family rule now, while nobody is panicking,” says Ford. “Any request for money gets confirmed by a call you make to a number you already trust – however urgent it sounds. Some families add a code word only they know. A child who really is stranded will understand why you want to hear them first. If you can’t reach them, wait until someone else has confirmed it.

“Voice cloning means ‘it sounded just like him’ has stopped being a safe test,” Ford continues. “A code word is the one thing a criminal can’t lift from a voice note or a video posted online.”

Protecting your own account takes two minutes. Never share a WhatsApp registration code, whoever claims to need it, and switch on WhatsApp’s two-step verification, which adds a password a criminal holding your registration code still has to get past.

“If your WhatsApp account has been compromised, warn your contacts through another channel so they don’t fall for the same scam – and tell the family about any attempt, even if nobody paid,” says Ford. “Whoever tried it on you is working through a whole contact list.”

 

If the money has already gone

Phone your bank’s fraud line immediately, using the number in its official app or on the back of your card. SABRIC notes that criminals move stolen funds quickly through several accounts, so every hour you wait leaves the bank less to trace.

When the hijacked account belongs to an employee, colleagues and customers are next on the contact list. Ford says organisations need incident response procedures for compromised accounts before that happens because, as Integrity360’s own response guidance puts it, time becomes critical from the moment an incident is detected.