Services Free tool Articles Get in touch
Article

Business email compromise: how South African companies lose money by email

Someone emails your client a fake invoice with changed banking details. The money is gone within hours. Here is how the fraud actually works, what the courts have said about who carries the loss, and the controls that stop it.

A client pays an invoice. The banking details on it are not yours. By the time anyone notices, the money has moved through two accounts and is unrecoverable.

This is business email compromise, and it is the most common way South African businesses lose money to cybercrime. It needs no malware and no technical brilliance. It needs one mailbox and some patience.

How it actually works

The pattern is consistent enough to be predictable.

  1. Access. Someone gets into a mailbox, usually with a password from an unrelated breach or a convincing fake login page. Nothing is stolen and nothing is broken, so nobody notices.
  2. Reading. The intruder sits quietly for weeks, learning who pays whom, how much, when, and how your invoices are worded. Often a mailbox rule is added so certain replies are diverted to a folder the owner never opens.
  3. Timing. They wait for a real transaction. A property transfer, a large order, a month-end run.
  4. The switch. A message arrives from the correct address, in the correct thread, in the correct tone, attaching a real invoice with one field changed.
  5. Collection. The payment lands in a mule account and is dispersed within hours.

Note what is absent. No spelling errors, no odd sender address, no suspicious attachment. The staff training that teaches people to look for those things does not help here, because the email is genuine.

Who carries the loss

This is where South African businesses tend to be surprised, and it is worth understanding before it happens to you rather than after.

In Hawarden v Edward Nathan Sonnenberg, a property buyer transferred R5.5 million to what she believed were the conveyancer's bank details. Her own email account had been compromised and the details had been altered. The Gauteng High Court found the law firm liable in 2023, on the reasoning that it had sent its banking details by unprotected email and owed her a duty of care.

The Supreme Court of Appeal overturned that on 10 June 2024. It held that the firm owed her no such duty, that she could reasonably have verified the details by telephone, and that she therefore had to carry her own loss. The court noted that finding otherwise would expose every creditor who emails banking details to indeterminate liability.

The practical lesson is blunt. If you pay a fraudulent invoice, the loss is very likely yours. You cannot rely on the other party having warned you, and you cannot rely on your bank reversing it.

The controls that actually work

Verify banking details by voice, every time

Any new or changed account number gets confirmed by telephone, on a number you already hold, not one taken from the email. This single control stops most of these losses and costs nothing. Put it in writing as a payment procedure so it does not depend on who happens to be processing the run.

Multi-factor authentication on every mailbox

The fraud starts with mailbox access. Multi-factor authentication removes the stolen-password route almost entirely. It is included in Microsoft 365 at no extra cost, and it is the highest-value thing most businesses have not switched on.

Get your domain records right

SPF, DKIM and DMARC make it materially harder for anyone to send email that appears to come from your domain. They do not stop an attacker who is inside a real mailbox, but they close off the easier impersonation routes and they protect your clients from fake messages bearing your name.

You can see how your own domain is configured right now with our free email security checker. It takes a few seconds and needs nothing installed.

Watch for mailbox rules

Unexpected forwarding or move-to-folder rules are one of the clearest signals that a mailbox has been compromised. Microsoft 365 can alert on them, but somebody has to be watching the alerts.

Train people on the payment process, not the phishing email

Since the fraudulent message is often indistinguishable from a real one, the defence has to sit in the process rather than in the reader's judgement.

If it has already happened

  1. Telephone your bank immediately and ask for a recall. Speed is the only thing that helps.
  2. Report it to the receiving bank as well, in writing.
  3. Change the password and revoke active sessions on the affected mailbox, then check for forwarding rules.
  4. Open a case with the South African Police Service. Insurers and banks will ask for the case number.
  5. Check your insurance. Cyber cover and some commercial crime policies respond to this, but usually only if stated controls were in place.
  6. Work out how the mailbox was accessed. If you skip this, it happens again.

Where we come in

Most of what prevents this is configuration rather than software you need to buy: multi-factor authentication enforced properly, domain records published correctly, mailbox rule alerting switched on, and a payment verification procedure your staff actually follow.

We do that as part of managed cybersecurity, and we will assess where your environment stands at no cost. Start with the email security checker if you want a look at your own domain first.