Dealing with a phishing attack
A phishing attack is when a criminal communicates with you through deceptive emails, messages, phone calls, QR codes or websites to trick you into sharing sensitive information such as passwords, banking details, one-time passwords (OTPs), security codes or identity information.
Phishing emails often lure victims to fake websites that imitate legitimate organisations and encourage them to enter login details. Criminals can then use these credentials to access genuine accounts. Some phishing messages or websites may also install malicious software (malware) on your device, allowing criminals to steal information or launch further cyberattacks.
Scammers frequently impersonate trusted organisations such as banks, government departments, delivery companies, mobile network providers, employers or colleagues. They may also use personal information gathered from social media or other public sources to make their messages appear convincing.
In South Africa, phishing commonly appears as messages relating to:
SARS tax refunds or tax compliance
Banking security alerts
Courier deliveries or customs fees
Mobile account verification
Fake payment notifications
Employment or recruitment opportunities
Electricity, municipal or utility payments
We want to better understand the impact of you experiencing this issue, can you share your experience by filling in this online form? This will help us better protect future victims.
How to spot a phishing email
Modern phishing attacks are far more convincing than they once were. Criminals often carefully research their victims and create professional-looking communications.
Common warning signs include:
Suspicious sender address - An email may appear to come from your bank or another trusted organisation, but the sender's email address reveals otherwise. For example, a legitimate domain may be replaced with one that looks similar or contains additional words or characters.
Always inspect the sender's full email address rather than relying on the display name.
Requests for confidential information - Legitimate organisations will not ask you to provide passwords, PINs, one-time passwords (OTPs), banking security codes or other sensitive information by email or message.
Unexpected attachments - Be cautious of invoices, documents or files you were not expecting, particularly if they come from unknown senders. Attachments are a common way of delivering malware.
A sense of urgency - Messages claiming your account will be suspended, locked or closed unless you act immediately are designed to create panic and pressure you into making mistakes.
Suspicious links - Before clicking a link, hover your cursor over it to view the destination.
Watch for:
Misspelt website addresses
Extra words or numbers
Look-alike domains
Suspicious sub-domains
When in doubt, type the organisation's official website address directly into your browser instead of clicking the link.
Poor spelling and grammar - Although many phishing emails are professionally written, awkward wording, spelling mistakes or unusual formatting may still indicate a scam.
Generic greetings - Messages beginning with "Dear Customer" or similar greetings instead of your name should be treated with caution.
Offers that seem too good to be true - Unexpected prizes, investment opportunities or giveaways are common phishing tactics.
Fear-based messaging - Be cautious of messages designed to frighten you into acting quickly by threatening account closure, legal action or financial loss.
Spoofed organisation - Criminals often impersonate trusted South African organisations such as banks, SARS, courier companies, insurers, employers or government departments.
Example:
You might receive an email saying:
"Dear Customer, we have detected unusual activity on your account. Please click the link below and enter your details immediately to avoid being locked out."
This is a classic phishing attempt. If you are unsure, contact the organisation directly using contact details from its official website, not those provided in the suspicious message.
What to do if you have fallen for a phishing scam
Falling victim to phishing can be frightening, but it is important to act quickly to reduce the impact.
Quick response checklist
1) Disconnect from the internet
Turn off Wi-Fi or unplug your network cable, or on a mobile device, switch to Airplane Mode if appropriate.
This can prevent malware from communicating with criminals or spreading further.
2) Change your passwords
If possible, use a different device that you trust.
If you only have access to the affected device, scan it for malware before changing passwords.
Prioritise:
Email accounts
Online banking
Social media
Work accounts
Shopping accounts
Where available, enable multi-factor authentication (MFA) after changing your passwords.
3) Contact the organisation that was impersonated
Notify the legitimate organisation that criminals are impersonating them.
If you shared banking information or authorised a payment:
Contact your bank immediately using the official fraud contact details.
Ask whether cards, accounts or digital banking access should be blocked or replaced.
4) Scan your device for malware
Use antivirus software or built-in security tools to check for infections.
See our guide for finding and removing malicious software.
Remove any suspicious apps/software.
5) Watch for identity theft
If you shared your South African ID number, identity documents or other personal information:
Monitor your financial accounts carefully.
Enable transaction notifications where available.
Consider contacting the Southern African Fraud Prevention Service (SAFPS) regarding Protective Registration and identity fraud prevention.
Report the crime
If you are in South Africa:
Report fraud or cybercrime to SAPS by opening a case at your nearest police station.
You can also report crime through SAPS Crime Stop on 08600 10111, where appropriate.
If money or banking access was involved, contact your bank's fraud department immediately before or alongside reporting to SAPS.
If your identity information was exposed, consider contacting SAFPS for advice on fraud prevention and protective registration.
If the scam involved an investment, insurance product, financial adviser, broker, trading platform or someone claiming to be regulated, check whether they are authorised and consider reporting the matter to the Financial Sector Conduct Authority (FSCA)
How to protect yourself in future
Enable Multi-Factor Authentication (MFA) - MFA provides an additional layer of protection even if your password is stolen.
Keep your devices updated - Install operating system, browser, application and security updates promptly.
Be cautious of unexpected communications - Treat unexpected emails, SMS messages, WhatsApp messages, QR codes and phone calls with caution.
Verify requests independently -If you receive an unexpected request relating to banking, payments or personal information, contact the organisation using contact details you locate independently.
Trust your instincts - If something feels unusual, stop and verify before taking action.
Never share sensitive information - Legitimate organisations will not ask for passwords, banking PINs or one-time passwords through email or messaging services.
Type website addresses manually - Whenever possible, enter website addresses directly into your browser instead of clicking links.
Verify phone numbers - Never rely on contact numbers provided in suspicious emails or messages.
Use official contact details published by the organisation.
Enable spam and phishing protection - Use your email provider's spam filtering and security features.
If someone claims to be from your bank - End the conversation if you are unsure.
Contact your bank using:
the fraud number published in your banking app,
the number printed on your bank card,
your bank statement, or
your bank's official website.
Do not rely on phone numbers or links provided in suspicious emails, SMS messages or WhatsApp messages.
Continue Learning - Keep informed through trusted South African sources including:
Your bank's fraud awareness resources
SABRIC
SAFPS
Official government communications
SAPS cybercrime awareness campaigns
What types of phishing you should watch out for
Phishing doesn’t just happen by email. Criminals use a range of methods to try to catch you off guard:
Spear Phishing - Highly targeted attacks using personal information such as your employer, role or recent activities to make messages appear genuine.
Vishing- Phone calls from criminals pretending to represent banks, government departments, technology companies or other trusted organisations.
Smishing - Phishing delivered through SMS or messaging applications.
Whaling - Phishing attacks aimed at senior executives or other high-profile individuals within organisations.
Quishing - Criminals use QR codes instead of website links to direct victims to fraudulent websites that steal login credentials, banking details or payment information.
MFA Fatigue - Criminals repeatedly send authentication approval requests in the hope that you accidentally approve one. Never approve an unexpected authentication request. If you receive repeated MFA prompts that you did not initiate, change your password immediately and review your account security.
Being aware of these different phishing techniques makes it much harder for criminals to succeed.
Donate
Your generosity makes our free support possible. Please consider giving today.
Without donations, we cannot keep our service free or provide help to the most vulnerable victims of cybercrime when they need it most. As a not-for-profit organisation, every donation goes directly towards keeping The Cyber Helpline up and running. Donate now and help us support victims of cybercrime.