Seitfin

The Scam Doesn’t Look Like a Scam Anymore (Here’s How SMEs Stay Safe)

Impersonation scams, AI-generated phishing, and ransomware are getting harder to spot. Here's the one SME-friendly rule that stops most of them.

Most South African SMEs already know cybercrime exists. What has changed is how realistic scams have become and how often they target everyday business processes: email, supplier payments, and account logins.

Threat intelligence reporting shows the pressure is increasing. In January 2026, South African organisations faced an average of 2,145 cyberattacks per week (reported as a 36% year‑on‑year increase), with commentary linking the environment to ransomware activity and wider Gen AI‑related exposure risks. That does not mean every attempt succeeds, it means SMEs operate in a high‑attempt environment where the safest approach is steady habits and sensible controls, not fear.

What’s “Most Recent” in Scam Tactics Right Now

Cybersecurity threat trends affecting South African SMEs

1. Impersonation Is Sharper, and It’s the Main Play

Impersonation scams targeting South African businesses

Criminals increasingly impersonate trusted brands and institutions because it works: banks, suppliers, couriers, and sometimes SARS. SARS itself keeps an updated list of scam examples (summonses, penalties, demands, audit/refund themes, and more), which shows how persistent and believable these messages can be.

Why SMEs should care: impersonation targets decisions, especially around payments and access, not “IT systems” in isolation.

2. AI Is Being Used to Make Scams Feel “Clean” and Convincing

AI-generated scam messages and deepfake fraud risks

The South African Banking Risk Information Centre (SABRIC) has warned that criminals are using AI-generated content (including WhatsApp messages) and even voice-cloned deepfakes, and cautioned that real-time deepfake audio/video may become more common.

What this means in real life: fewer obvious mistakes, more natural language, and more pressure tactics that sound credible.

3. Ransomware Remains a Business Risk (Downtime, Disruption, Recovery)

Ransomware disruption and business downtime risk

Verizon’s 2025 Data Breach Investigations Report (DBIR) reports ransomware is present in 44% of breaches, reinforcing that this is not a rare edge case. Recent threat commentary also points to ransomware activity as part of the broader environment SMEs operate in.

For SMEs: the risk is not only the “attack”, it’s the operational impact that follows, which is why preparation matters more than panic.

4. Third-Party Exposure Is Rising

Third-party vendor and supplier security exposure

Modern SMEs rely on vendors, cloud platforms, and partners. Verizon’s 2025 DBIR reports third-party involvement doubled to 30% of breaches.

Translation for SMEs: security is no longer just about your devices, it’s also about supplier interactions and shared systems.

What to Look Out For (Without Becoming Paranoid)

You don’t need to catch every scam. The practical goal is to recognise high-risk moments and apply a consistent check. Treat these as “slow down and verify” moments:

  1. Anything involving money: Payments, refunds, beneficiary changes, “urgent transfer” requests.
  2. Anything involving logins or access: Password resets, “verify your account”, “confirm your login”, unexpected MFA prompts.
  3. Anything involving sensitive information: Banking details, IDs, OTPs, staff/customer data.
  4. Any message that creates urgency or fear: “Final demand”, “legal action”, “account will be blocked”. SARS impersonation is one example of this pattern because it triggers compliance fear and deadlines.
  5. Anything that bypasses your normal process: “Don’t call”, “I’m in a meeting”, “just approve it”, “use these new bank details”.

These aren’t technical red flags, they’re process red flags.

The SME-Friendly Rule That Reduces Risk the Most

Don’t verify inside the message. Verify outside the message.

In practice:

  • Don’t click the link in the email/SMS/WhatsApp.
  • Don’t use the number included in the message.
  • Don’t confirm a payment change by replying to the same thread.

Instead:

  • Open the site from a bookmark or type the address manually.
  • Call a known number from your records.
  • Confirm changes using a second channel (especially for payments).

This keeps business moving but adds one safety layer where it matters most: money, access, and sensitive information should always be verified.

Risk and Mitigation (Practical Layers for South African SMEs)

Cyber risk can’t be eliminated entirely, but it can be reduced and managed with controls that fit real SME operations.

  1. Email & phishing protection: Reduces the number of harmful messages that reach staff and helps prevent impersonation attempts landing in inboxes.
  2. Access control (MFA + sensible permissions): Credential abuse and exploited access are major entry routes in large breach datasets; tightening access reduces the blast radius if something slips through.
  3. Payment controls: A simple payment rule, banking detail changes must be verified independently, prevents a large portion of invoice/payment diversion style incidents.
  4. Backups + recovery readiness: Ransomware remains common; tested backups and a recovery plan protect continuity.
  5. POPIA-ready incident handling: POPIA enforcement is real-world. A well-publicised case involved a R5 million administrative fine, and POPIA allows administrative fines up to R10 million, reinforcing why structured incident readiness matters.

If It Happens: What to Do (Calm, Fast, Practical)

If someone clicked, entered credentials, or actioned a suspicious request:

  1. Contain quickly: Disconnect the affected device from the internet if you suspect compromise.
  2. Secure access: Reset passwords (start with email), enable MFA, and check for mailbox rules/forwarding changes.
  3. Protect cash flow: Review recent payments and beneficiary changes; contact the bank quickly if money or approvals were involved.
  4. Escalate early: Engage professional support to assess scope and reduce downtime.
  5. If personal information may be involved: Document what happened and handle it appropriately under POPIA.

Frequently Asked Questions

What are common examples of impersonation scams SMEs are seeing?
Criminals usually impersonate organisations or people you already deal with. Common examples include:

  • Banks – messages about “suspicious activity”, “account verification”, or urgent approval prompts.
  • Suppliers – emails advising “updated banking details” or asking for urgent payment confirmation.
  • Couriers/service providers – delivery notices or invoices with links or attachments.
  • Payroll/HR platforms – requests to reset passwords or confirm access.
  • SARS – messages referring to audits, penalties, refunds, or legal consequences (SARS lists examples of these scam formats publicly).

The organisation changes, but the approach is consistent: urgency + authority + pressure to act quickly.

How do we stay alert without becoming paranoid?
Focus on high-impact moments, not every message. Treat anything involving money, logins/access, sensitive information, or changes to normal process as a reason to slow down and verify independently. Everything else can continue as normal.

Do we need to understand cybercrime in detail to operate safely?
No. What matters most is recognising when a message pushes urgent action or shortcuts your normal process, then verifying the information outside the message.

Why are SMEs targeted so often?
Because SMEs move quickly, rely on trust, and handle real transactions daily, and attackers exploit speed, access, and third-party connections.

What should we do if something slips through?
Act early: contain, secure access, review financial activity, and escalate to professional support. Early action limits disruption and cost.

How Seitfin Can Help

Seitfin helps South African SMEs reduce risk without overcomplicating things, by putting practical layers in place where scams typically start:

  • Email & phishing protection
  • Firewall & endpoint protection
  • Threat detection and prevention
  • POPIA support (governance + incident readiness)
  • Security best practice reviews and audits

If you want to strengthen your controls without slowing down operations, contact Seitfin and ask about SME cybersecurity options for email/phishing protection, endpoint/firewall protection, monitoring, and POPIA support.