
Nedbank said it observed an increase in robberies, hijackings, and short-term abductions, during which criminals force victims to access banking apps and authorise transactions.
South African banks have revealed the tactics criminals use to access victims’ smartphone banking apps and steal their money.
Absa, FNB, and Nedbank told MyBroadband that while using banking apps on smartphones remains one of the safest and most secure ways to bank, there are risks.
This includes risks of banking customers being kidnapped by criminals to force them to transfer funds, and the use of social engineering techniques to coerce victims into downloading malware.
Nedbank executive for digital fraud and innovation, Lucas Venter, said the bank had observed more incidents of criminals directly targeting customers.
This is done through robberies, hijacking, or short-term abductions, during which criminals force victims to access their banking apps and authorise transactions.
“These cases remain a relatively small portion of overall fraud volumes, but they are concerning because the criminal is effectively bypassing security controls,” Venter said.
“The scourge of kidnapping and forced transaction incidents is an evolving threat which requires partnerships with key industry role players,” Giuseppe Virgillito, head of InterfaceX at FNB, said.
He added that FNB maintained a zero-tolerance stance against all forms of crime and that the bank has put strict measures in place to detect and report incidents.
“The bank takes incidents involving the safety and security of its customers seriously and is committed to working with the relevant authorities in matters involving criminal activity,” Virgillito said.
“In response to such incidents, the bank has established appropriate processes and specialist resources to assess and manage matters as they arise.”
He said each case is considered on its individual circumstances, with actions taken in accordance with applicable legal, regulatory, and operational requirements.
Virgillito said FNB has been a strategic enabler in the fight against kidnapping and forced transactions in South Africa by assisting in establishing the Industry Steering Committee.
“The committee is hosted at the South African Banking Risk Information Centre with the set objective to align on the governance and compliance of the industry response,” he said.
Absa executive for fraud risk, industry, and emerging threats, Caryn Gilmour, told MyBroadband that while banking apps remain very secure, fraudsters have adjusted their tactics.
“As these controls become stronger, fraudsters continue to adapt their tactics,” Gilmour stated, adding that criminals have shifted to manipulating customers rather than being forceful.
“Rather than trying to break into banking systems, many fraudsters now target customers directly using social engineering techniques designed to create fear, urgency, deception, and trust.”
Nedbank’s Venter said mobile malware was a very real threat, particularly on Android smartphones. However, he noted that criminals don’t directly compromise the banking app.
“Instead, they target the smartphone through malicious apps, phishing links, remote-access software, and banking trojans,” Venter said.
Virgillito told MyBroadband that criminals typically relied on social engineering to target banking customers rather than directly compromising banking apps.
“A common tactic involves fraudsters sharing links to fake promotions or offers and persuading customers to click on them,” he said.
“Following the prompts in these messages can result in malicious software being installed on a customer’s smartphone.”
Virgillito said FNB has established security measures designed to identify potentially compromised devices and that it may restrict access to services when it spots suspicious activity.
“However, no security measure can guarantee the detection of all threats,” he said. “Customers play a critical role in protecting themselves.”
He said this included ensuring their smartphones are kept secure, updated regularly, and remain free from malicious software.
“We encourage customers to remain vigilant and take responsibility for their digital security,” Virgillito stated.
“This includes avoiding unsolicited links, ignoring unexpected offers, downloading applications only from trusted sources, and keeping device software and security settings up to date.”
Gilmour explained that the objective was to manipulate victims into taking actions that could compromise their funds, banking information, or their devices.
“Customers must remember one important rule: Absa will never ask you to transfer money to another account in order to keep it safe,” she said.
“If someone tells you to create a new beneficiary, move money, approve a transaction, share a one-time password, or install an app to protect your funds, stop immediately.”
Gilmour said banking customers in South Africa should leverage the security features available on their banking apps.
“Absa customers, for example, can use In-App Calling to help verify that they are speaking to an authorised Absa representative to confirm if a transaction is genuine or not,” she said.
She also highlighted the “Login Protect” feature, which provides further authentication controls to help safeguard access to Absa customers’ banking profiles.
“Never share your PIN, password, passcode, OTP, or other authentication information with anyone, even if they claim to be from the bank or another trusted organisation,” Gilmour said.
FNB’s Virgillito highlighted 5 key aspects on which customers should focus to ensure their banking profiles remain secure:
Strengthen digital security
: Use biometric locks, such as fingerprint or facial recognition, and enable two-factor authentication on banking apps. Avoid simple or easy-to-guess PINs and passwords.
Control your exposure:
Set daily transaction limits and enable instant notifications for account activity. Where possible, limit the visibility of certain accounts or balances within your banking app.
Be situationally aware:
Remain vigilant, especially in higher-risk environments such as parking areas or ATMs, or when meeting unknown individuals. Keep your phone out of sight and remain vigilant.
Change your patterns:
Vary your routine, including shopping times and travel routes. Small changes to reduce predictability can reduce risks.
Know how to act quickly:
Save your bank’s fraud contact details and report any suspicious activity immediately.
Regarding the risk of malware being installed on smartphones, Virgillito said customers must only download apps from official app stores and never hand their devices to a third party.
“Don’t click on suspicious links or respond to unexpected offers, especially where you are asked to enter banking details, approve prompts, or install software,” he said.
“Keep your phone software and banking app updated, as software updates often include important security protections.”
Follow the story