Editor's Note

Last issue we looked at what happens when a client asks you to prove your security. Several of you replied. The common theme: the questions are getting harder to answer.

This issue is about a different kind of question. The one your finance team asks silently when a payment instruction arrives from you. Is this really him?

Several days ago the FSCA published the detail behind the largest penalty in its history. The case turned on deepfakes. It is the clearest signal yet that synthetic media has moved from novelty to a working tool of financial crime in South Africa. Here is what it means for your business.

The Voice on the Phone Was Not Your FD

The threat is now local, and the regulator has proved it

A deepfake is AI-generated audio or video that convincingly imitates a real person. Until recently, most South African businesses treated it as a foreign problem. That position is no longer defensible.

On 21 August 2026 the Financial Sector Conduct Authority set out its findings against online trading platform Banxso in its 2026 Regulatory Actions report. The FSCA fined the firm and its directors more than R2 billion and debarred four key individuals from the industry for 30 years each. It is the largest penalty in the regulator's history.

The mechanism was deepfake advertising. Fabricated videos of Johann Rupert and Elon Musk promoted an investment scheme called Immediate Matrix, promising returns of R300,000 a month from a R4,700 deposit. People who responded were funnelled to platform representatives. The FSCA found the scheme took roughly R1 billion from South African investors. The evidence has been referred to the Hawks.

Separately, identity verification firm Smile ID reported this year that South Africa records the highest share of deepfake-driven fraud in Africa, at 22% of cases. In one local example, Momentum Group's financial director was impersonated in a WhatsApp scam built from a photograph taken off LinkedIn.

The mistake: treating recognition as verification

Most payment controls in South African businesses rest on an unwritten assumption. If you recognise the voice, or the face, it is them.

That assumption was reasonable for a long time. It is now the weak point attackers aim at.

The attack does not target your firewall. It targets the moment of authorisation. An attacker gathers public audio and video of a senior person, which for most executives means LinkedIn, conference recordings, podcast appearances, and company videos. They then contact a member of the finance team, usually with an existing pretext by email or WhatsApp, and escalate to a voice or video call when they need the approval pushed through.

The request is urgent. It is confidential. It comes from someone the employee recognises. Every instinct that normally protects the business is turned into the thing that defeats it.

The consequence lands on the finance team

The Association of Certified Fraud Examiners, in its 2026 Anti-Fraud Technology Benchmarking Report covering Sub-Saharan Africa, recorded deepfake social engineering as the most cited area of significant increase over the past two years, at 44%.

Finance teams carry the exposure because they are the only department that can move money directly. They approve transfers. They handle urgent payment requests as routine work. An attacker who defeats one person's judgement for ninety seconds gets a legitimate, system-approved payment that is very difficult to reverse.

Note what does not help here. The payment is not fraudulent in any technical sense. No control was bypassed. No system was breached. A person with authority approved it. Your bank sees a valid instruction from an authorised user, which is why recovery is rare.

The fix is a process, not a product

Detection software exists and it is improving. It is also not where the answer sits for an SME, because the failure happens at the authorisation step, not the detection step.

What works is removing identity recognition from the payment decision entirely.

Set a rule that any payment above a defined value, and any change to banking details, is confirmed on a second channel before it is released. Not a reply to the same thread. Not a callback to the number that made the request. A call to the number already held on file for that person, made by the person releasing the payment.

Then give your team explicit permission to use it. The reason these attacks work is social, not technical. A junior finance clerk will not challenge someone who sounds like the managing director unless leadership has said clearly, in advance, that verifying is expected and never insubordinate. Say it out loud, and say it before you need it.

Finally, look at how much executive audio and video your business publishes. You are not going to stop marketing. But knowing that the raw material for an impersonation is publicly available should change how much weight a familiar voice carries in your controls.

The Bottom Line

The regulator has now demonstrated that deepfakes are being used at scale against South Africans, and that the losses run to a billion rand. For your business, the exposure is not the technology. It is a payment process that treats recognition as proof of identity. Fix that with a second channel and a stated policy, and the attack has nothing left to work with.