Reviewed 8 July 2026 ✓ Fact-checked Reviewed by Shephard Dube Credit Cards Add as a preferred source on Google

How Credit Card Fraud Works in South Africa — and How to Beat Every Version of It

☆ Save
How Credit Card fraud works in South Africa? — Rateweb

Credit-card fraud feels random from the victim's side; from the criminal's side it's a small set of repeatable scripts. That's good news: scripts can be learned, and every one of them has a counter. This guide walks through how each major type of card fraud actually works in South Africa, the settings and habits that block them, where your liability starts and ends, and the first-hour playbook if you're hit — because in fraud, speed is money.

The big one: card-not-present fraud

Most card fraud today never touches your physical card. Card-not-present (CNP) fraud uses your card number, expiry date and CVV — harvested from a phishing site, a breached merchant database, malware, or simply a photo of your card — to shop online. The industry's counter is 3-D Secure: the OTP or in-app approval step your bank triggers on online payments. That's why the criminal's real target is usually not your card number (those are cheap and abundant) but your OTP — which only you can hand over. The defences: use a virtual card for online shopping where your bank offers one (a disposable number that never exposes the real card), keep the CVV off any form that doesn't need it, and treat every OTP as the payment itself — because functionally, it is. Reading the OTP to a caller, or typing it into a link someone sent you, is signing the transaction.

The enabler: phishing, vishing and the fake bank call

The dominant South African script is social: an SMS or email that looks like your bank ("suspicious activity — verify your account") linking to a cloned login page, or a confident caller from the "fraud department" who warns that your card is being defrauded right now and helpfully offers to stop it — if you'll just confirm your card number and the OTP arriving on your phone. The tell is universal: the real bank never asks for your PIN, password, CVV or OTP — ever, in any channel, for any reason. The counter-move is equally universal: hang up, and call the number on the back of your card yourself. Urgency is the weapon; your calm callback disarms it. Banks' real fraud teams will freeze first and talk after — they don't need your OTP to protect you.

The multiplier: SIM swaps and account takeover

Because OTPs travel by SMS, criminals attack the phone number: with harvested personal details they request a SIM swap or number port from your network, and once your number is theirs, every OTP flows to them. The warning sign is your phone dropping to no signal for hours for no reason — if that happens alongside any banking oddity, treat it as an active attack: contact your network and your bank immediately. Defences: use in-app transaction approval instead of SMS OTPs where your bank offers it (app approvals don't travel through the SIM), add a porting PIN or extra verification with your mobile network, and be stingy with your ID number and personal details — they're the raw material for the swap request. Full account takeover works the same way one level up: with your credentials plus your number, the criminal changes limits, adds beneficiaries and drains accounts — which is why the combination of "new device linked" and "limit changed" notifications must never be ignored.

The classics: skimming, shoulder-surfing and card swapping

Physical fraud is smaller but persists. Skimmers clone magstripe data at compromised ATMs and point-of-sale devices; shoulder-surfers capture your PIN at the ATM; distraction teams "help" you at the machine and swap or palm your card. Chip-and-PIN and contactless have squeezed this space hard, but the hygiene still matters: cover the keypad, refuse help from strangers at ATMs no matter how friendly, prefer ATMs inside bank branches or busy retail, never let your card leave your sight at restaurants and fuel stations, and if a machine swallows your card or behaves oddly, block the card from your banking app before you leave the spot — not when you get home.

Where your details leak from — and shrinking the surface

Most victims never did anything obviously wrong; their details leaked upstream. The common sources: merchant and service-provider breaches (databases of cards and identities sold in bulk), documents — copies of IDs, bank statements and proof of address handed over for every rental application and store account, then stored carelessly; public oversharing that answers security questions (birthdays, pet names, mother's maiden name are all on most people's social media); and malware on a phone or PC quietly logging keystrokes. You can't control the breaches, but you can shrink your surface: give copies of your ID only when genuinely required and write the purpose across the copy ("for X application only"); use unique passwords per site with a password manager so one breached retailer doesn't unlock your email; keep your banking app and phone OS updated; and check your credit report (free annually from each bureau) for accounts you didn't open — the earliest visible symptom of identity-driven card fraud is usually a credit enquiry you don't recognise.

Your liability — and why the notifications setting is financial armour

The broad principle in South African banking: unauthorised transactions you didn't enable are disputable and generally refundable — but your position weakens sharply if you were negligent (shared your PIN or OTP, wrote the PIN on the card) or if you delayed reporting once you knew. That makes two settings disproportionately valuable. First, transaction notifications on everything, no minimum amount — fraud is usually tested with a small transaction before the real hit, and the customer who queries the R9.99 test charge stops the R9,000 follow-up. Second, your own limits: daily online, tap and withdrawal caps sized to your real life, so even a successful compromise has a ceiling. Add the free extra: SAFPS Protective Registration, which flags your identity so credit applications in your name face extra verification — cheap armour if your ID or documents have leaked anywhere.

Debit orders and subscription skims: the slow fraud

Not all card crime is a dramatic drain. A quieter version bleeds accounts through unauthorised debit orders and subscription traps: a "free trial" that harvested your card and bills monthly, a service you cancelled that keeps collecting, or outright rogue debit orders placed against thousands of accounts in small amounts calculated to slip under attention. The counters: actually read your statement line by line once a month (the R99 you don't recognise is the whole game), dispute unauthorised debit orders through your banking app promptly — banks provide streamlined reversal for recent unauthorised collections — and be deliberate about where your card number lives on file. For subscriptions, a virtual card with a low limit is the elegant fix: services can charge it only what you've allowed, and killing the virtual card kills every subscription attached to it without touching your real card.

The first hour after you're hit

  • Freeze or stop the card in the app immediately — this is faster than any call queue and stops the bleeding;
  • Call the bank's fraud line and dispute the transactions; note the reference number and the agent's name;
  • Change your banking passwords and check for devices or beneficiaries you didn't add;
  • If OTPs were involved, check your SIM — call your network and confirm no swap or port was processed;
  • Report at SAPS and get a case number — banks and insurers may require it, and it feeds the record;
  • Follow up in writing — an email trail of what you reported and when protects your dispute if it's ever contested. Escalate unresolved disputes to the banking ombud service — it's free.

Card features like virtual numbers and granular limits differ by issuer — compare them in our credit card comparison.

Frequently asked questions

Will my bank refund fraudulent transactions?

Generally yes for genuinely unauthorised transactions reported promptly — and your case is strongest when you didn't share credentials and reported the moment you knew. Gross negligence and delay are what sink disputes.

How did criminals get my card details in the first place?

Usually from phishing, a breached merchant, or malware — not from your bank. Card numbers are commodities; that's why the OTP layer exists and why protecting it matters more than hiding the number.

Is tap-to-pay safe?

Contactless fraud is rare and capped — the bigger risks are online and social. Set your own tap limit in the app if the default makes you uncomfortable.

What's the safest way to shop online with a card?

A virtual card with notifications on: unique number, your own limit, disposable if a merchant leaks it. Failing that, only 3-D Secure merchants, and never save your card on sites you won't use again.

What is a SIM swap and how do I know it's happening?

A criminal takes over your phone number to intercept OTPs. The sign is unexplained loss of signal for an extended period — if it coincides with any banking anomaly, call your network and bank immediately.

Who do I contact if my bank won't resolve a fraud dispute?

Exhaust the bank's formal dispute process first, then escalate to the National Financial Ombud Scheme — the free external adjudicator for banking disputes in South Africa.

Tools to act on this today

LN
Lethabo Ntsoane · Analyst & Reviewer
Lethabo Ntsoane holds a Bachelor's degree in Mathematics from the University of South Africa and specialises in economics and statistics. He is Rateweb's most prolific contributor,... This article is general information, not personalised financial advice.
More from Lethabo Ntsoane →

Related on Rateweb